Vulnerability index

Browse CVEs

4,342 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
Fingerprint Sensor Firmware MEDIUM 6.4
CVE-2023-50430

The Goodix Fingerprint Device, as shipped in Dell Inspiron 15 computers, does not follow the Secure Device Connection Protocol (SDCP) when enrolling …

No fix yet
Fix from $1,600 2023-12-09
Ubuntu Linux MEDIUM 6.3
CVE-2023-45866EPSS 8%

Bluetooth HID Hosts in BlueZ may permit an unauthenticated Peripheral role HID Device to initiate and establish an encrypted connection, and accept H…

Fix: 14.2 / 17.2+
Fix from $1,600 2023-12-08
Mx Se Firmware CRITICAL 9.8
CVE-2023-43742

An authentication bypass in Zultys MX-SE, MX-SE II, MX-E, MX-Virtual, MX250, and MX30 with firmware versions prior to 17.0.10 patch 17161 and 16.04 p…

Fix: 16.0.4 / 17.0.10+
Fix from $2,300 2023-12-08
Cryptospike CRITICAL 9.8
CVE-2023-36655

The login REST API in ProLion CryptoSpike 3.0.15P2 (when LDAP or Active Directory is used as the users store) allows a remote blocked user to login a…

No fix yet
Fix from $2,300 2023-12-06
Ajmd 370s Firmware HIGH 8.8
CVE-2023-6514

The Bluetooth module of some Huawei Smart Screen products has an identity authentication bypass vulnerability. Successful exploitation of this vulner…

Mitigation only
Fix from $1,950 2023-12-06
Sma 200 Firmware HIGH 8.8
CVE-2023-5970

Improper authentication in the SMA100 SSL-VPN virtual office portal allows a remote authenticated attacker to create an identical external domain use…

Fix: after 10.2.1.9-57sv
Fix from $1,950 2023-12-05
Vdv23 Firmware HIGH 7.8
CVE-2023-47304

An issue was discovered in Vonage Box Telephone Adapter VDV23 version VDV21-3.2.11-0.5.1, allows local attackers to bypass UART authentication contro…

No fix yet
Fix from $1,950 2023-12-05
Pass MEDIUM 6.8
CVE-2023-42576

Improper Authentication vulnerability in Samsung Pass prior to version 4.3.00.17 allows physical attackers to bypass authentication due to invalid ex…

Fix: 4.3.00.17+
Fix from $1,600 2023-12-05
Aqt1000 Firmware MEDIUM 5.5
CVE-2023-33070

Transient DOS in Automotive OS due to improper authentication to the secure IO calls.

Patch available
Fix from $1,600 2023-12-05
315 5g Iot Modem Firmware CRITICAL 9.1
CVE-2023-33054

Cryptographic issue in GPS HLOS Driver while downloading Qualcomm GNSS assistance data.

Mitigation only
Fix from $2,300 2023-12-05
Vantara Hitachi Network Attached Storage MEDIUM 6.5
CVE-2023-5808

SMU versions prior to 14.8.7825.01 are susceptible to unintended information disclosure, through URL manipulation. Authenticated users in a Storage a…

Fix: after 14.8.7825.01
Fix from $1,600 2023-12-05
Powerprotect Data Manager Dm5500 Firmware CRITICAL 9.8
CVE-2023-44302

Dell DM5500 5.14.0.0 and prior contain an improper authentication vulnerability. A remote unauthenticated attacker could potentially exploit this vul…

Fix: after 5.14.0.0
Fix from $2,300 2023-12-04
Court Case Management Plus CRITICAL 9.4
CVE-2023-6353

Tyler Technologies Civil and Criminal Electronic Filing allows an unauthenticated, remote attacker to upload, delete, and view files by manipulating …

Mitigation only
Fix from $2,300 2023-11-30
Court Case Management Plus CRITICAL 9.4
CVE-2023-6354

Tyler Technologies Magistrate Court Case Management Plus allows an unauthenticated, remote attacker to upload, delete, and view files by manipulating…

Mitigation only
Fix from $2,300 2023-11-30
Court Case Management Plus CRITICAL 9.8
CVE-2023-6342

Tyler Technologies Court Case Management Plus allows a remote attacker to authenticate as any user by manipulating at least the 'CmWebSearchPfp/Login…

Mitigation only
Fix from $2,300 2023-11-30
Court Case Management Plus MEDIUM 5.3
CVE-2023-6343

Tyler Technologies Court Case Management Plus allows a remote, unauthenticated attacker to enumerate and access sensitive files using the tiffserver/…

Mitigation only
Fix from $1,600 2023-11-30
Court Case Management Plus MEDIUM 5.3
CVE-2023-6344

Tyler Technologies Court Case Management Plus allows a remote, unauthenticated attacker to enumerate directories using the tiffserver/te003.aspx or t…

Mitigation only
Fix from $1,600 2023-11-30
Sel 451 Firmware CRITICAL 9.8
CVE-2023-34388

An Improper Authentication vulnerability in the Schweitzer Engineering Laboratories SEL-451 could allow a remote unauthenticated attacker to potentia…

Mitigation only
Fix from $2,300 2023-11-30
Nas326 Firmware HIGH 7.5
CVE-2023-35137

An improper authentication vulnerability in the authentication module of the Zyxel NAS326 firmware version V5.21(AAZF.14)C0 and NAS542 firmware versi…

Fix: after 5.21
Fix from $1,950 2023-11-30
Cs C6n A0 1c2wfr Firmware MEDIUM 5.3
CVE-2023-48121

An authentication bypass vulnerability in the Direct Connection Module in Ezviz CS-C6N-xxx prior to v5.3.x build 20230401, Ezviz CS-CV310-xxx prior t…

Mitigation only
Fix from $1,600 2023-11-28
Usercube CRITICAL 9.8
CVE-2023-41264

Netwrix Usercube before 6.0.215, in certain misconfigured on-premises installations, allows authentication bypass on deployment endpoints, leading to…

Fix: 6.0.215+
Fix from $2,300 2023-11-28
Activemq HIGH 8.8
CVE-2022-41678EPSS 86%

Once an user is authenticated on Jolokia, he can potentially trigger arbitrary code execution.  In details, in ActiveMQ configurations, jetty allows…

Fix: 5.16.6 / 5.17.4+
Fix from $1,950 2023-11-28
Idsecure CRITICAL 9.8
CVE-2023-6329EPSS 65%

An authentication bypass vulnerability exists in Control iD iDSecure v4.7.32.0. The login routine used by iDS-Core.dll contains a "passwordCustom" op…

No fix yet
Fix from $2,300 2023-11-27
Udp CRITICAL 9.8
CVE-2023-41999

An authentication bypass exists in Arcserve UDP prior to version 9.2. An unauthenticated, remote attacker can obtain a valid authentication identifie…

Fix: 9.2+
Fix from $2,300 2023-11-27
Capsule Proxy CRITICAL 9.8
CVE-2023-48312

capsule-proxy is a reverse proxy for the capsule operator project. Affected versions are subject to a privilege escalation vulnerability which is bas…

Fix: after 0.4.5
Fix from $2,300 2023-11-24
Pandora Fms CRITICAL 9.8
CVE-2023-4677

Cron log backup files contain administrator session IDs. It is trivial for any attacker who can reach the Pandora FMS Console to scrape the cron logs…

Fix: 773+
Fix from $2,300 2023-11-23
Userpro HIGH 8.1
CVE-2023-2437EPSS 7%

The UserPro plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 5.1.1. This is due to insufficient verifica…

Fix: after 5.1.1
Fix from $1,950 2023-11-22
Owncloud Server CRITICAL 9.8
CVE-2023-49105EPSS 11%

An issue was discovered in ownCloud owncloud/core before 10.13.1. An attacker can access, modify, or delete any file without authentication if the us…

Fix: 10.13.1+
Fix from $2,300 2023-11-21
Syrus 4g Iot Telematics Gateway Firmware CRITICAL 9.8
CVE-2023-6248

The Syrus4 IoT gateway utilizes an unsecured MQTT server to download and execute arbitrary commands, allowing a remote unauthenticated attacker to ex…

Mitigation only
Fix from $2,300 2023-11-21
Authentik CRITICAL 9.8
CVE-2023-48228

authentik is an open-source identity provider. When initialising a oauth2 flow with a `code_challenge` and `code_method` (thus requesting PKCE), the …

Fix: 2023.8.5 / 2023.10.4+
Fix from $2,300 2023-11-21