Vulnerability index

Browse CVEs

4,342 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
Me Rtu Firmware CRITICAL 9.8
CVE-2023-29155

Versions of INEA ME RTU firmware 3.36b and prior do not require authentication to the "root" account on the host system of the device. This could all…

Fix: 3.37+
Fix from $2,300 2023-11-20
Framemaker Publishing Server CRITICAL 9.8
CVE-2023-44324

Adobe FrameMaker Publishing Server versions 2022 and earlier are affected by an Improper Authentication vulnerability that could result in a Security…

Fix: 2022+
Fix from $2,300 2023-11-17
Tor Loco Min CRITICAL 9.8
CVE-2023-41442

An issue in Kloudq Technologies Limited Tor Equip 1.0, Tor Loco Mini 1.0 through 3.1 allows a remote attacker to execute arbitrary code via a crafted…

Fix: after 3.1
Fix from $2,300 2023-11-15
Meetings HIGH 8.8
CVE-2023-43582

Improper authorization in some Zoom clients may allow an authorized user to conduct an escalation of privilege via network access.

Fix: 5.14.13 / 5.15.11+
Fix from $1,950 2023-11-15
TYPO3 MEDIUM 5.4
CVE-2023-47127

TYPO3 is an open source PHP based web content management system released under the GNU GPL. In typo3 installations there are always at least two diff…

Fix: 8.7.55 / 9.5.44+
Fix from $1,600 2023-11-14
Realtek Sd Card Reader Driver HIGH 7.8
CVE-2023-32661

Improper authentication in some Intel(R) NUC Kits NUC7PJYH and NUC7CJYH Realtek* SD Card Reader Driver installation software before version 10.0.1904…

Fix: 10.0.19041.29098+
Fix from $1,950 2023-11-14
Usb Firmware HIGH 7.8
CVE-2023-28377

Improper authentication in some Intel(R) NUC Kit NUC11PH USB firmware installation software before version 1.1 for Windows may allow an authenticated…

Fix: 1.1+
Fix from $1,950 2023-11-14
Unison Software HIGH 8.8
CVE-2023-22663

Improper authentication for some Intel Unison software may allow an authenticated user to potentially enable escalation of privilege via network acce…

Fix: 20.14.2.3053 / 20.14.4244+
Fix from $1,950 2023-11-14
Pfsense HIGH 7.2
CVE-2023-29975

An issue discovered in Pfsense CE version 2.6.0 allows attackers to change the password of any user without verification.

Mitigation only
Fix from $1,950 2023-11-09
Central Authentication Service CRITICAL 9.8
CVE-2023-4612

Improper Authentication vulnerability in Apereo CAS in jakarta.servlet.http.HttpServletRequest.getRemoteAddr method allows Multi-Factor Authenticatio…

Fix: 7.0.0+
Fix from $2,300 2023-11-09
Pass MEDIUM 6.8
CVE-2023-42554

Improper Authentication vulnerabiity in Samsung Pass prior to version 4.3.00.17 allows physical attackers to bypass authentication.

Fix: 4.3.00.17+
Fix from $1,600 2023-11-07
Android HIGH 7.1
CVE-2023-42531

Improper access control vulnerability in SmsController prior to SMR Nov-2023 Release1 allows local attackers to bypass restrictions on starting activ…

Mitigation only
Fix from $1,950 2023-11-07
315 5g Iot Modem Firmware HIGH 7.8
CVE-2023-24852

Memory Corruption in Core due to secure memory access by user while loading modem image.

Mitigation only
Fix from $1,950 2023-11-07
Strapi HIGH 7.5
CVE-2023-39345

strapi is an open-source headless CMS. Versions prior to 4.13.1 did not properly restrict write access to fielded marked as private in the user regis…

Fix: 4.13.1+
Fix from $1,950 2023-11-06
Enterprise Linux MEDIUM 6.6
CVE-2023-40660

A flaw was found in OpenSC packages that allow a potential PIN bypass. When a token/card is authenticated by one process, it can perform cryptographi…

Fix: after 0.23.0
Fix from $1,600 2023-11-06
Yunfan Learning Examination System MEDIUM 5.3
CVE-2023-46963

An issue in Beijing Yunfan Internet Technology Co., Ltd, Yunfan Learning Examination System v.6.5 allows a remote attacker to obtain sensitive inform…

No fix yet
Fix from $1,600 2023-11-04
Automation HIGH 7.8
CVE-2022-44569

A locally authenticated attacker with low privileges can bypass authentication due to insecure inter-process communication.

Fix: 2023.4+
Fix from $1,950 2023-11-03
Open Xchange Appsuite HIGH 7.8
CVE-2023-26455

RMI was not requiring authentication when calling ChronosRMIService:setEventOrganizer. Attackers with local or adjacent network access could abuse th…

Fix: 7.10.6+
Fix from $1,950 2023-11-02
Primelink C9065 Firmware MEDIUM 5.9
CVE-2023-46327

Multiple MFPs (multifunction printers) provided by FUJIFILM Business Innovation Corp. and Xerox Corporation provide a facility to export the contents…

Fix: 68.81.41 / 85.40.31+
Fix from $1,600 2023-11-02
Nport 6150 T Firmware HIGH 7.5
CVE-2023-5627

A vulnerability has been identified in NPort 6000 Series, making the authentication mechanism vulnerable. This vulnerability arises from the incorrec…

Fix: after 1.21
Fix from $1,950 2023-11-01
Authentik CRITICAL 9.8
CVE-2023-46249

authentik is an open-source Identity Provider. Prior to versions 2023.8.4 and 2023.10.2, when the default admin user has been deleted, it is potentia…

Fix: 2023.8.4 / 2023.10.2+
Fix from $2,300 2023-10-31
Cloudexplorer Lite CRITICAL 9.8
CVE-2023-44397

CloudExplorer Lite is an open source, lightweight cloud management platform. Prior to version 1.4.1, the gateway filter of CloudExplorer Lite uses a …

Fix: 1.4.1+
Fix from $2,300 2023-10-30
Android MEDIUM 5.0
CVE-2023-21307

In Bluetooth, there is a possible way for a paired Bluetooth device to access a long term identifier for an Android device due to a permissions bypas…

Fix: 14.0+
Fix from $1,600 2023-10-30
Admin Classic Bundle HIGH 7.2
CVE-2023-5844

Unverified Password Change in GitHub repository pimcore/admin-ui-classic-bundle prior to 1.2.0.

Fix: after 1.1.4
Fix from $1,950 2023-10-30
Document Locator CRITICAL 9.8
CVE-2023-5830EPSS 61%

A vulnerability classified as critical has been found in ColumbiaSoft Document Locator. This affects an unknown part of the file /api/authentication/…

Fix: 7.2+
Fix from $2,300 2023-10-27
Access Controller HIGH 8.8
CVE-2023-35794

An issue was discovered in Cassia Access Controller 2.1.1.2303271039. The Web SSH terminal endpoint (spawned console) can be accessed without authent…

No fix yet
Fix from $1,950 2023-10-27
Mr2600 MEDIUM 6.5
CVE-2022-3681

A vulnerability has been identified in the MR2600 router v1.0.18 and earlier that could allow an attacker within range of the wireless network to suc…

Fix: after 1.0.18
Fix from $1,600 2023-10-27
Factorytalk Services Platform HIGH 8.1
CVE-2023-46290

Due to inadequate code logic, a previously unauthenticated threat actor could potentially obtain a local Windows OS user token through the FactoryTal…

Fix: 2.80+
Fix from $1,950 2023-10-27
Gm265dn Firmware MEDIUM 5.4
CVE-2022-34887

Standard users can directly operate and set printer configuration information , such as IP, in some Lenovo Printers without having to authenticate wi…

Fix: 02.06.00.04.00+
Fix from $1,600 2023-10-27
Orbital Simulator HIGH 7.5
CVE-2023-30967

Gotham Orbital-Simulator service prior to 0.692.0 was found to be vulnerable to a Path traversal issue allowing an unauthenticated user to read arbit…

Fix: 0.692.0+
Fix from $1,950 2023-10-26