Vulnerability index

Browse CVEs

4,342 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
Unclassified MEDIUM 5.3
CVE-2023-25790

Improper Authentication, Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in xtemos WoodMart allows…

Mitigation only
Fix from $1,600 2024-04-24
Website Builder CRITICAL 9.8
CVE-2023-47504

Improper Authentication vulnerability in Elementor Elementor Website Builder allows Accessing Functionality Not Properly Constrained by ACLs.This iss…

Fix: 3.16.5+
Fix from $2,300 2024-04-24
Hios CRITICAL 9.8
CVE-2024-3701

The system application (com.transsion.kolun.aiservice) component does not perform an authentication check, which allows attackers to perform maliciou…

Mitigation only
Fix from $2,300 2024-04-15
Evolution HIGH 8.8
CVE-2024-29837

The Web interface of Evolution Controller Versions 2.04.560.31.03.2024 and below uses poor session management, allowing for an unauthenticated attack…

Fix: after 2.04.560
Fix from $1,950 2024-04-15
Reportico MEDIUM 6.5
CVE-2023-48865

An issue discovered in Reportico Till 8.1.0 allows attackers to obtain sensitive information via execute_mode parameter of the URL.

No fix yet
Fix from $1,600 2024-04-11
Form Maker HIGH 7.5
CVE-2024-2112

The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to Sensitive Information Exposure in al…

Fix: 1.15.23+
Fix from $1,950 2024-04-09
Secdiskapp HIGH 8.8
CVE-2024-24279

An issue in secdiskapp 1.5.1 (management program for NewQ Fingerprint Encryption Super Speed Flash Disk) allows attackers to gain escalated privilege…

No fix yet
Fix from $1,950 2024-04-08
Emui HIGH 7.5
CVE-2023-52540

Vulnerability of improper authentication in the Iaware module. Impact: Successful exploitation of this vulnerability will affect availability.

No fix yet
Fix from $1,950 2024-04-08
Android HIGH 7.3
CVE-2024-29757

there is a possible permission bypass due to Debug certs being allowlisted. This could lead to local escalation of privilege with no additional execu…

Mitigation only
Fix from $1,950 2024-04-05
Portal For Arcgis HIGH 8.5
CVE-2024-25699

There is a difficult‑to‑exploit improper authentication issue in the Home application for Esri Portal for ArcGIS versions 11.2 and below on Windows a…

Fix: after 11.2
Fix from $1,950 2024-04-04
Veridiumad CRITICAL 9.1
CVE-2023-44039

In VeridiumID before 3.5.0, the WebAuthn API allows an internal unauthenticated attacker (who can pass enrollment verifications and is allowed to enr…

Fix: 3.5.0+
Fix from $2,300 2024-04-03
Aterm Wg1800hp4 Firmware MEDIUM 5.3
CVE-2024-28006

Improper authentication vulnerability in NEC Corporation Aterm WG1800HP4, WG1200HS3, WG1900HP2, WG1200HP3, WG1800HP3, WG1200HS2, WG1900HP, WG1200HP2,…

Mitigation only
Fix from $1,600 2024-03-28
Aterm Wg1800hp4 Firmware CRITICAL 9.8
CVE-2024-28007

Improper authentication vulnerability in NEC Corporation Aterm WG1800HP4, WG1200HS3, WG1900HP2, WG1200HP3, WG1800HP3, WG1200HS2, WG1900HP, WG1200HP2,…

Mitigation only
Fix from $2,300 2024-03-28
Aterm Wg1800hp4 Firmware CRITICAL 9.8
CVE-2024-28009

Improper authentication vulnerability in NEC Corporation Aterm WG1800HP4, WG1200HS3, WG1900HP2, WG1200HP3, WG1800HP3, WG1200HS2, WG1900HP, WG1200HP2,…

Mitigation only
Fix from $2,300 2024-03-28
Aterm Wg1800hp4 Firmware CRITICAL 9.8
CVE-2024-28012

Improper authentication vulnerability in NEC Corporation Aterm WG1800HP4, WG1200HS3, WG1900HP2, WG1200HP3, WG1800HP3, WG1200HS2, WG1900HP, WG1200HP2,…

Mitigation only
Fix from $2,300 2024-03-28
Teslamate CRITICAL 9.8
CVE-2023-31634

In TeslaMate before 1.27.2, there is unauthorized access to port 4000 for remote viewing and operation of user data. After accessing the IP address f…

Fix: 1.27.2+
Fix from $2,300 2024-03-27
Unclassified MEDIUM 5.3
CVE-2024-2244

REST service authentication anomaly with “valid username/no password” credential combination for batch job processing resulting in successful service…

Mitigation only
Fix from $1,600 2024-03-27
Wolfssh CRITICAL 9.1
CVE-2024-2873

A vulnerability was found in wolfSSH's server-side state machine before versions 1.4.17. A malicious client could create channels without first perfo…

Fix: 1.4.17+
Fix from $2,300 2024-03-25
Lg Led Assistant CRITICAL 9.8
CVE-2024-2862EPSS 51%

This vulnerability allows remote attackers to reset the password of anonymous users without authorization on the affected LG LED Assistant.

Mitigation only
Fix from $2,300 2024-03-25
Wp 2fa MEDIUM 5.3
CVE-2022-44595

Improper Authentication vulnerability in Melapress WP 2FA allows Authentication Bypass.This issue affects WP 2FA: from n/a through 2.2.0.

Fix: after 2.2.0
Fix from $1,600 2024-03-21
Unclassified CRITICAL 9.8
CVE-2024-1147

Weak access control in OpenText PVCS Version Manager allows potential bypassing of authentication and download of files.

Mitigation only
Fix from $2,300 2024-03-21
Unclassified CRITICAL 9.8
CVE-2024-1148

Weak access control in OpenText PVCS Version Manager allows potential bypassing of authentication and uploading of files.

Mitigation only
Fix from $2,300 2024-03-21
Grav HIGH 8.8
CVE-2024-27923

Grav is a content management system (CMS). Prior to version 1.7.43, users who may write a page may use the `frontmatter` feature due to insufficient …

Fix: 1.7.43+
Fix from $1,950 2024-03-21
Financials By Coda HIGH 8.1
CVE-2024-28735

Unit4 Financials by Coda versions prior to 2023Q4 suffer from an incorrect access control authorization bypass vulnerability which allows an authenti…

Fix: 2023q4+
Fix from $1,950 2024-03-20
Unilogic CRITICAL 9.8
CVE-2024-27767

CWE-287: Improper Authentication may allow Authentication Bypass

Fix: 1.35.227+
Fix from $2,300 2024-03-18
Openmetadata CRITICAL 9.8
CVE-2024-28255EPSS 73%

OpenMetadata is a unified platform for discovery, observability, and governance powered by a central metadata repository, in-depth lineage, and seaml…

Fix: 1.2.4+
Fix from $2,300 2024-03-15
Mattermost Server HIGH 8.8
CVE-2024-2450

Mattermost versions 8.1.x before 8.1.10, 9.2.x before 9.2.6, 9.3.x before 9.3.2, and 9.4.x before 9.4.3 fail to correctly verify account ownership wh…

Fix: 8.1.10 / 9.2.6+
Fix from $1,950 2024-03-15
Secret Server HIGH 8.4
CVE-2024-25652

In Delinea PAM Secret Server 11.4, it is possible for a user assigned "Administer Reports" permission and/or with access to Report functionality via …

Mitigation only
Fix from $1,950 2024-03-14
Exceed Turbox HIGH 7.5
CVE-2023-38534

Improper authentication vulnerability in OpenText™ Exceed Turbo X affecting versions 12.5.0 and 12.5.1. The vulnerability could allow disclosure of r…

Mitigation only
Fix from $1,950 2024-03-13
Udp CRITICAL 9.8
CVE-2024-0799

An authentication bypass vulnerability exists in Arcserve Unified Data Protection 9.2 and 8.1 in the edge-app-base-webui.jar!com.ca.arcserve.edge.app…

No fix yet
Fix from $2,300 2024-03-13