Vulnerability index

Browse CVEs

4,342 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
Openobserve MEDIUM 6.5
CVE-2024-25106

OpenObserve is a observability platform built specifically for logs, metrics, traces, analytics, designed to work at petabyte scale. A critical vulne…

Fix: 0.8.0+
Fix from $1,600 2024-02-08
Daily Habit Tracker CRITICAL 9.8
CVE-2024-24496EPSS 20%

An issue in Daily Habit Tracker v.1.0 allows a remote attacker to manipulate trackers via the home.php, add-tracker.php, delete-tracker.php, update-t…

No fix yet
Fix from $2,300 2024-02-08
Sonicos CRITICAL 9.8
CVE-2024-22394

An improper authentication vulnerability has been identified in SonicWall SonicOS SSL-VPN feature, which in specific conditions could allow a remote …

Mitigation only
Fix from $2,300 2024-02-08
Omnikey Secure Elements Reader Configuration Cards Firmware MEDIUM 5.3
CVE-2024-23806

Sensitive data can be extracted from HID iCLASS SE reader configuration cards. This could include credential and device administrator keys.

Mitigation only
Fix from $1,600 2024-02-07
Open Forms MEDIUM 5.9
CVE-2024-24771

Open Forms allows users create and publish smart forms. Versions prior to 2.2.9, 2.3.7, 2.4.5, and 2.5.2 contain a non-exploitable multi-factor authe…

Fix: 2.2.9 / 2.3.7+
Fix from $1,600 2024-02-07
Ozone MEDIUM 5.3
CVE-2023-39196

Improper Authentication vulnerability in Apache Ozone. The vulnerability allows an attacker to download metadata internal to the Storage Container M…

Fix: after 1.3.0
Fix from $1,600 2024-02-07
Clearml CRITICAL 9.8
CVE-2024-24592

Lack of authentication in all versions of the fileserver component of Allegro AI’s ClearML platform allows a remote attacker to arbitrarily access, c…

No fix yet
Fix from $2,300 2024-02-06
Android MEDIUM 6.5
CVE-2024-20815

Improper authentication vulnerability in onCharacteristicReadRequest in Auto Hotspot prior to SMR Feb-2024 Release 1 allows adjacent attackers connec…

Mitigation only
Fix from $1,600 2024-02-06
Android MEDIUM 6.5
CVE-2024-20816

Improper authentication vulnerability in onCharacteristicWriteRequest in Auto Hotspot prior to SMR Feb-2024 Release 1 allows adjacent attackers conne…

Mitigation only
Fix from $1,600 2024-02-06
Qts CRITICAL 9.8
CVE-2023-39303

An improper authentication vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could al…

Mitigation only
Fix from $2,300 2024-02-02
Powersc MEDIUM 5.3
CVE-2023-50934

IBM PowerSC 1.3, 2.0, and 2.1 uses single-factor authentication which can lead to unnecessary risk of compromise when compared with the benefits of a…

Patch available
Fix from $1,600 2024-02-02
Automate MEDIUM 5.5
CVE-2023-47256

ConnectWise ScreenConnect through 23.8.4 allows local users to connect to arbitrary relay servers via implicit trust of proxy settings

Fix: 23.8.5+
Fix from $1,600 2024-02-01
Web Master Firmware CRITICAL 9.8
CVE-2024-1039

Gessler GmbH WEB-MASTER has a restoration account that uses weak hard coded credentials and if exploited could allow an attacker control over the web…

Mitigation only
Fix from $2,300 2024-02-01
Authentik HIGH 8.8
CVE-2024-23647

Authentik is an open-source Identity Provider. There is a bug in our implementation of PKCE that allows an attacker to circumvent the protection that…

Fix: 2023.8.7 / 2023.10.7+
Fix from $1,950 2024-01-30
Cratedb CRITICAL 9.8
CVE-2023-51982

CrateDB 5.5.1 is contains an authentication bypass vulnerability in the Admin UI component. After configuring password authentication and_ Local_ In …

No fix yet
Fix from $2,300 2024-01-30
Noderp MEDIUM 5.3
CVE-2024-1006

A vulnerability was found in Shanxi Diankeyun Technology NODERP up to 6.0.2 and classified as critical. This issue affects some unknown processing of…

Fix: 6.0.2+
Fix from $1,600 2024-01-29
Otrs MEDIUM 6.5
CVE-2024-23792

When adding attachments to ticket comments, another user can add attachments as well impersonating the orginal user. The attack requires a logged-i…

Fix: 7.0.49 / 2024.1.1+
Fix from $1,600 2024-01-29
Kuerp CRITICAL 9.8
CVE-2024-0988

A vulnerability classified as critical was found in Sichuan Yougou Technology KuERP up to 1.0.4. Affected by this vulnerability is the function check…

Fix: after 1.0.4
Fix from $2,300 2024-01-29
Mr2600 Firmware HIGH 7.5
CVE-2024-23629

An authentication bypass vulnerability exists in the web component of the Motorola MR2600. An attacker can exploit this vulnerability to access prote…

Mitigation only
Fix from $1,950 2024-01-26
Ovirt Engine HIGH 7.5
CVE-2024-0822

An authentication bypass vulnerability was found in overt-engine. This flaw allows the creation of users in the system without authentication due to …

Patch available
Fix from $1,950 2024-01-25
Oneview HIGH 7.5
CVE-2023-50275

HPE OneView may allow clusterService Authentication Bypass resulting in denial of service.

Fix: 8.70+
Fix from $1,950 2024-01-23
Ipados MEDIUM 6.2
CVE-2024-23219

The issue was addressed with improved authentication. This issue is fixed in iOS 17.3 and iPadOS 17.3. Stolen Device Protection may be unexpectedly d…

Fix: 17.3+
Fix from $1,600 2024-01-23
macOS MEDIUM 5.5
CVE-2023-42935

An authentication issue was addressed with improved state management. This issue is fixed in macOS Ventura 13.6.4. A local attacker may be able to vi…

Fix: 13.6.4 / 14.1+
Fix from $1,600 2024-01-23
Emui HIGH 7.5
CVE-2023-52111

Authorization vulnerability in the BootLoader module. Successful exploitation of this vulnerability may affect service integrity.

No fix yet
Fix from $1,950 2024-01-16
Evershop HIGH 7.5
CVE-2023-46942

Lack of authentication in NPM's package @evershop/evershop before version 1.0.0-rc.8, allows remote attackers to obtain sensitive information via imp…

Mitigation only
Fix from $1,950 2024-01-13
Rubygems.org CRITICAL 9.8
CVE-2024-21654

Rubygems.org is the Ruby community's gem hosting service. Rubygems.org users with MFA enabled would normally be protected from account takeover in th…

Fix: 2024-01-08+
Fix from $2,300 2024-01-12
Javascript CRITICAL 9.8
CVE-2024-22206

Clerk helps developers build user management. Unauthorized access or privilege escalation due to a logic flaw in auth() in the App Router or getAuth(…

Fix: 4.29.3+
Fix from $2,300 2024-01-12
Connect Secure HIGH 8.2
CVE-2023-46805 KEVEPSS 100%

An authentication bypass vulnerability in the web component of Ivanti ICS 9.x, 22.x and Ivanti Policy Secure allows a remote attacker to access restr…

Mitigation only
Fix from $1,950 2024-01-12
H8951 4g Esp Firmware CRITICAL 9.8
CVE-2023-49262

The authentication mechanism can be bypassed by overflowing the value of the Cookie "authentication" field, provided there is an active user session.

Fix: 2310271149+
Fix from $2,300 2024-01-12
Gl Ax1800 Firmware CRITICAL 9.8
CVE-2023-50919EPSS 48%

An issue was discovered on GL.iNet devices before version 4.5.0. There is an NGINX authentication bypass via Lua string pattern matching. This affect…

No fix yet
Fix from $2,300 2024-01-12