Vulnerability index

Browse CVEs

4,342 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
Windows Server 2012 HIGH 7.5
CVE-2024-21427

Windows Kerberos Security Feature Bypass Vulnerability

Fix: 10.0.14393.6897 / 10.0.17763.5696+
Fix from $1,950 2024-03-12
Authenticator HIGH 7.1
CVE-2024-21390

Microsoft Authenticator Elevation of Privilege Vulnerability

Fix: 6.2401.0617+
Fix from $1,950 2024-03-12
Fortios HIGH 8.8
CVE-2023-46717

An improper authentication vulnerability [CWE-287] in FortiOS versions 7.4.1 and below, versions 7.2.6 and below, and versions 7.0.12 and below when …

Fix: 7.0.13 / 7.2.7+
Fix from $1,950 2024-03-12
Unclassified CRITICAL 9.8
CVE-2023-49340

An issue was discovered in Newland Nquire 1000 Interactive Kiosk version NQ1000-II_G_V1.00.011, allows remote attackers to escalate privileges and by…

Mitigation only
Fix from $2,300 2024-03-09
Qts CRITICAL 9.8
CVE-2024-21899EPSS 24%

An improper authentication vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could al…

Fix: 4.5.4.2627 / 5.1.3.2578+
Fix from $2,300 2024-03-08
Ds8900f Firmware CRITICAL 9.8
CVE-2023-46172

IBM DS8900F HMC 89.21.19.0, 89.21.31.0, 89.30.68.0, 89.32.40.0, and 89.33.48.0 could allow a remote attacker to bypass authentication restrictions fo…

Mitigation only
Fix from $2,300 2024-03-07
Artifactory MEDIUM 6.5
CVE-2023-42662

JFrog Artifactory versions 7.59 and above, but below 7.59.18, 7.63.18, 7.68.19, 7.71.8 are vulnerable to an issue whereby user interaction with speci…

Fix: 7.59.18 / 7.63.18+
Fix from $1,600 2024-03-07
Go Saml HIGH 7.5
CVE-2023-48703

RobotsAndPencils go-saml, a SAML client library written in Go, contains an authentication bypass vulnerability in all known versions. This is due to …

No fix yet
Fix from $1,950 2024-03-06
Duo Authentication For Windows Logon And Rdp MEDIUM 6.2
CVE-2024-20301

A vulnerability in Cisco Duo Authentication for Windows Logon and RDP could allow an authenticated, physical attacker to bypass secondary authenticat…

Fix: 4.3.0+
Fix from $1,600 2024-03-06
Cloud Pak For Business Automation MEDIUM 6.5
CVE-2023-38367

IBM Cloud Pak Foundational Services Identity Provider (idP) API (IBM Cloud Pak for Automation 18.0.0, 18.0.1, 18.0.2, 19.0.1, 19.0.2, 19.0.3, 20.0.1,…

Mitigation only
Fix from $1,600 2024-02-29
Flask Appbuilder CRITICAL 9.1
CVE-2024-25128

Flask-AppBuilder is an application development framework, built on top of Flask. When Flask-AppBuilder is set to AUTH_TYPE AUTH_OID, it allows an att…

Fix: 4.3.11+
Fix from $2,300 2024-02-29
Watson Iot Platform HIGH 7.5
CVE-2023-38372

An unauthorized attacker who has obtained an IBM Watson IoT Platform 1.0 security authentication token can use it to impersonate an authorized platfo…

Mitigation only
Fix from $1,950 2024-02-29
Armeria CRITICAL 9.1
CVE-2024-1735

A vulnerability has been identified in armeria-saml versions less than 1.27.2, allowing the use of malicious SAML messages to bypass authentication. …

Fix: 1.27.2+
Fix from $2,300 2024-02-26
Sma 200 Firmware MEDIUM 6.3
CVE-2024-22395

Improper access control vulnerability has been identified in the SMA100 SSL-VPN virtual office portal, which in specific conditions could potentially…

Fix: 10.2.1.11-65sv+
Fix from $1,600 2024-02-24
Dm Enterprise Website Building System CRITICAL 9.8
CVE-2024-1817

A vulnerability has been found in Demososo DM Enterprise Website Building System up to 2022.8 and classified as critical. Affected by this vulnerabil…

Fix: after 2022.8
Fix from $2,300 2024-02-23
Debian Linux MEDIUM 6.5
CVE-2023-52160

The implementation of PEAP in wpa_supplicant through 2.10 allows authentication bypass. For a successful attack, wpa_supplicant must be configured to…

Fix: after 2.10
Fix from $1,600 2024-02-22
Inet Wireless Daemon HIGH 7.5
CVE-2023-52161

The Access Point functionality in eapol_auth_key_handle in eapol.c in iNet wireless daemon (IWD) before 2.14 allows attackers to gain unauthorized ac…

Fix: 2.14+
Fix from $1,950 2024-02-22
Unclassified CRITICAL 9.6
CVE-2024-22245

Arbitrary Authentication Relay and Session Hijack vulnerabilities in the deprecated VMware Enhanced Authentication Plug-in (EAP) could allow a malici…

Mitigation only
Fix from $2,300 2024-02-20
Spectrum Scale Container Native Storage Access MEDIUM 6.5
CVE-2022-41737

IBM Storage Scale Container Native Storage Access 5.1.2.1 through 5.1.7.0 could allow a local attacker to initiate connections from a container outsi…

Fix: after 5.1.7.0
Fix from $1,600 2024-02-17
Spectrum Scale Container Native Storage Access HIGH 7.5
CVE-2022-41738

IBM Storage Scale Container Native Storage Access 5.1.2.1 -through 5.1.7.0 could allow an attacker to initiate connections to containers from externa…

Fix: after 5.1.7.0
Fix from $1,950 2024-02-17
Procura HIGH 7.5
CVE-2023-6451

Publicly known cryptographic machine key in AlayaCare's Procura Portal before 9.0.1.2 allows attackers to forge their own authentication cookies and …

Fix: 9.0.1.2+
Fix from $1,950 2024-02-16
Framemaker Publishing Server CRITICAL 9.8
CVE-2024-20738

Adobe FrameMaker Publishing Server versions 2022.1 and earlier are affected by an Improper Authentication vulnerability that could result in a Securi…

Fix: 2022+
Fix from $2,300 2024-02-15
Mastodon HIGH 7.4
CVE-2024-25618

Mastodon is a free, open-source social network server based on ActivityPub. Mastodon allows new identities from configured authentication providers (…

Fix: 3.5.18 / 4.0.14+
Fix from $1,950 2024-02-14
Rmnf22tb30 Firmware HIGH 8.8
CVE-2024-0568

CWE-287: Improper Authentication vulnerability exists that could cause unauthorized tampering of device configuration over NFC communication.

Mitigation only
Fix from $1,950 2024-02-14
Openbmc HIGH 8.8
CVE-2023-31189

Improper authentication in some Intel(R) Server Product OpenBMC firmware before version egs-1.09 may allow an authenticated user to enable escalation…

Mitigation only
Fix from $1,950 2024-02-14
Exchange Server CRITICAL 9.8
CVE-2024-21410 KEVEPSS 13%

Microsoft Exchange Server Elevation of Privilege Vulnerability

Patch available
Fix from $2,300 2024-02-13
Polarion Alm CRITICAL 9.8
CVE-2024-23813

A vulnerability has been identified in Polarion ALM (All versions < V2404.0). The REST API endpoints of doorsconnector of the affected product lacks …

Fix: 2404.0+
Fix from $2,300 2024-02-13
Simple School Management System HIGH 8.8
CVE-2024-25313

Code-projects Simple School Managment System 1.0 allows Authentication Bypass via the username and password parameters at School/teacher_login.php.

No fix yet
Fix from $1,950 2024-02-09
Gc370xa Firmware HIGH 8.1
CVE-2023-51761

In Emerson Rosemount GC370XA, GC700XA, and GC1500XA products, an unauthenticated user with network access could bypass authentication and acquire adm…

Mitigation only
Fix from $1,950 2024-02-09
Openobserve HIGH 8.8
CVE-2024-24830

OpenObserve is a observability platform built specifically for logs, metrics, traces, analytics, designed to work at petabyte scale. A vulnerability …

Fix: 0.8.0+
Fix from $1,950 2024-02-08