Vulnerability index

Browse CVEs

4,342 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
Alarm System MEDIUM 5.9
CVE-2023-50127

Hozard alarm system (Alarmsysteem) v1.0 is vulnerable to Improper Authentication. Commands sent via the SMS functionality are accepted from random ph…

No fix yet
Fix from $1,600 2024-01-11
Azure Ipam CRITICAL 9.8
CVE-2024-21638

Azure IPAM (IP Address Management) is a lightweight solution developed on top of the Azure platform designed to help Azure customers manage their IP …

Fix: 3.0.0+
Fix from $2,300 2024-01-10
Nexo Os HIGH 8.8
CVE-2023-48257

The vulnerability allows a remote attacker to access sensitive data inside exported packages or obtain up to Remote Code Execution (RCE) with root pr…

Fix: after 1500-sp2
Fix from $1,950 2024-01-10
Jetnet 5310g Firmware CRITICAL 9.1
CVE-2023-5376

An Improper Authentication vulnerability in Korenix JetNet TFTP allows abuse of this service. This issue affects JetNet devices older than firmware v…

No fix yet
Fix from $2,300 2024-01-09
Data Science Studio CRITICAL 9.8
CVE-2023-51717

Dataiku DSS before 11.4.5 and 12.4.1 has Incorrect Access Control that could lead to a full authentication bypass.

Fix: 11.4.5 / 12.4.1+
Fix from $2,300 2024-01-09
Onenav CRITICAL 9.8
CVE-2023-7210

A vulnerability was found in OneNav up to 0.9.33. It has been classified as critical. This affects an unknown part of the file /index.php?c=api of th…

Fix: after 0.9.33
Fix from $2,300 2024-01-07
Uw 302vp Firmware HIGH 8.1
CVE-2023-7211

A vulnerability was found in Uniway Router 2.0. It has been declared as critical. This vulnerability affects unknown code of the component Administra…

Fix: after 2.0
Fix from $1,950 2024-01-07
Android MEDIUM 6.5
CVE-2024-20803

Improper authentication vulnerability in Bluetooth pairing process prior to SMR Jan-2024 Release 1 allows remote attackers to establish pairing proce…

Mitigation only
Fix from $1,600 2024-01-04
Omniauth\ CRITICAL 9.8
CVE-2024-21632

omniauth-microsoft_graph provides an Omniauth strategy for the Microsoft Graph API. Prior to versions 2.0.0, the implementation did not validate the …

Fix: 2.0.0+
Fix from $2,300 2024-01-02
Wrangler MEDIUM 5.7
CVE-2023-7079

Sending specially crafted HTTP requests and inspector messages to Wrangler's dev server could result in any file on the user's computer being accessi…

Fix: 3.19.0+
Fix from $1,600 2023-12-29
Cash Point \& Transport Optimizer MEDIUM 5.5
CVE-2023-31292

An issue was discovered in Sesami Cash Point & Transport Optimizer (CPTO) 6.3.8.6 (#718), allows local attackers to obtain sensitive information and …

Mitigation only
Fix from $1,600 2023-12-29
Dg860a Firmware HIGH 8.8
CVE-2023-40038

Arris DG860A and DG1670A devices have predictable default WPA2 PSKs that could lead to unauthorized remote access. (They use the first 6 characters o…

Mitigation only
Fix from $1,950 2023-12-27
Codeready Linux Builder MEDIUM 5.5
CVE-2023-4641

A flaw was found in shadow-utils. When asking for a new password, shadow-utils asks the password twice. If the password fails on the second attempt, …

Mitigation only
Fix from $1,600 2023-12-27
Quiz Maker MEDIUM 5.3
CVE-2023-6155

The Quiz Maker WordPress plugin before 6.4.9.5 does not adequately authorize the `ays_quiz_author_user_search` AJAX action, allowing an unauthenticat…

Fix: 6.4.9.5+
Fix from $1,600 2023-12-26
Worldserver CRITICAL 9.8
CVE-2022-34267EPSS 42%

An issue was discovered in RWS WorldServer before 11.7.3. Adding a token parameter with the value of 02 bypasses all authentication requirements. Arb…

Fix: 11.7.3+
Fix from $2,300 2023-12-25
Jamf CRITICAL 9.8
CVE-2023-31224

There is broken access control during authentication in Jamf Pro Server before 10.46.1.

Fix: 10.47.0+
Fix from $2,300 2023-12-25
Yii2 Authclient HIGH 8.8
CVE-2023-50714

yii2-authclient is an extension that adds OpenID, OAuth, OAuth2 and OpenId Connect consumers for the Yii framework 2.0. In yii2-authclient prior to v…

Fix: 2.2.15+
Fix from $1,950 2023-12-22
Nextcloud Server MEDIUM 5.4
CVE-2023-49791

Nextcloud Server provides data storage for Nextcloud, an open source cloud platform. In Nextcloud Server prior to versions 26.0.9 and 27.1.4; as well…

Fix: 23.0.12.13 / 24.0.12.9+
Fix from $1,600 2023-12-22
Assetwise Alim For Transportation HIGH 8.6
CVE-2023-51708

Bentley eB System Management Console applications within Assetwise Integrity Information Server allow an unauthenticated user to view configuration o…

Fix: 23.00.01.25 / 23.00.02.03+
Fix from $1,950 2023-12-22
Enterprise Server HIGH 7.5
CVE-2023-6847

An improper authentication vulnerability was identified in GitHub Enterprise Server that allowed a bypass of Private Mode by using a specially crafte…

Fix: 3.9.7 / 3.10.4+
Fix from $1,950 2023-12-21
Navidrome HIGH 8.6
CVE-2023-51442

Navidrome is an open source web-based music collection server and streamer. A security vulnerability has been identified in navidrome's subsonic endp…

Fix: 0.50.2+
Fix from $1,950 2023-12-21
Amazing Little Poll CRITICAL 9.8
CVE-2023-6768

Authentication bypass vulnerability in Amazing Little Poll affecting versions 1.3 and 1.4. This vulnerability could allow an unauthenticated user to …

Mitigation only
Fix from $2,300 2023-12-20
Pulsar HIGH 7.5
CVE-2023-37544

Improper Authentication vulnerability in Apache Pulsar WebSocket Proxy allows an attacker to connect to the /pingpong endpoint without authentication…

Fix: 2.10.5 / 2.11.2+
Fix from $1,950 2023-12-20
Allied Digital Integrated Tool As A Service CRITICAL 9.8
CVE-2023-6483

The vulnerability exists in ADiTaaS (Allied Digital Integrated Tool-as-a-Service) version 5.1 due to an improper authentication vulnerability in the …

Mitigation only
Fix from $2,300 2023-12-18
Stupid Simple Cms CRITICAL 9.1
CVE-2023-6907

A vulnerability has been found in codelyfe Stupid Simple CMS up to 1.2.4 and classified as critical. Affected by this vulnerability is an unknown fun…

Fix: after 1.2.4
Fix from $2,300 2023-12-18
Meeting Software Development Kit MEDIUM 6.5
CVE-2023-49646

Improper authentication in some Zoom clients before version 5.16.5 may allow an authenticated user to conduct a denial of service via network access.

Fix: 5.14.14 / 5.15.12+
Fix from $1,600 2023-12-13
Fortiwan HIGH 8.8
CVE-2023-44252

** UNSUPPORTED WHEN ASSIGNED **An improper authentication vulnerability [CWE-287] in Fortinet FortiWAN version 5.2.0 through 5.2.1 and version 5.1.1 …

Mitigation only
Fix from $1,950 2023-12-13
At 0402r Firmware HIGH 7.5
CVE-2023-45801

Improper Authentication vulnerability in Nadatel DVR allows Information Elicitation.This issue affects DVR: from 3.0.0 before 9.9.0.

Fix: 9.9.0+
Fix from $1,950 2023-12-13
Windows 10 1507 HIGH 7.5
CVE-2023-36004

Windows DPAPI (Data Protection Application Programming Interface) Spoofing Vulnerability

Fix: 10.0.10240.20345 / 10.0.14393.6529+
Fix from $1,950 2023-12-12
Cryptospike HIGH 8.2
CVE-2023-36648

Missing authentication in the internal data streaming system in ProLion CryptoSpike 3.0.15P2 allows remote unauthenticated users to read potentially …

No fix yet
Fix from $1,950 2023-12-12