Vulnerability index

Browse CVEs

4,342 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
Arconte Aurea HIGH 8.2
CVE-2023-4094

ARCONTE Aurea's authentication system, in its 1.5.0.0 version, could allow an attacker to make incorrect access requests in order to block each legit…

Mitigation only
Fix from $1,950 2023-09-19
Ipc322lb Sf28 A Firmware CRITICAL 9.8
CVE-2023-0773

The vulnerability exists in Uniview IP Camera due to identification and authentication failure at its web-based management interface. A remote attack…

Mitigation only
Fix from $2,300 2023-09-19
Jumpserver MEDIUM 5.3
CVE-2023-42442EPSS 56%

JumpServer is an open source bastion host and a professional operation and maintenance security audit system. Starting in version 3.0.0 and prior to …

Fix: 3.5.5 / 3.6.4+
Fix from $1,600 2023-09-15
Network Observability HIGH 7.5
CVE-2023-0813

A flaw was found in the Network Observability plugin for OpenShift console. Unless the Loki authToken configuration is set to FORWARD mode, authentic…

Mitigation only
Fix from $1,950 2023-09-15
Vtech Nb403 Il Firmware HIGH 7.5
CVE-2022-47848

An issue was discovered in Bezeq Vtech NB403-IL version BZ_2.02.07.09.13.01 and Vtech IAD604-IL versions BZ_2.02.07.09.13.01, BZ_2.02.07.09.13T, and …

No fix yet
Fix from $1,950 2023-09-15
Inplant Scada HIGH 7.8
CVE-2023-4985

A vulnerability classified as critical has been found in Supcon InPlant SCADA up to 20230901. Affected is an unknown function of the file Project.xml…

Fix: after 20230901
Fix from $1,950 2023-09-15
Sysguard 3001 Firmware CRITICAL 9.8
CVE-2023-4669

Authentication Bypass by Assumed-Immutable Data vulnerability in Exagate SYSGuard 3001 allows Authentication Bypass. This issue affects SYSGuard 300…

Fix: 3.2.20.0+
Fix from $2,300 2023-09-14
Papercut Ng MEDIUM 6.5
CVE-2023-4568

PaperCut NG allows for unauthenticated XMLRPC commands to be run by default. Versions 22.0.12 and below are confirmed to be affected, but later versi…

Fix: after 22.0.12
Fix from $1,600 2023-09-13
Meeting Software Development Kit MEDIUM 6.5
CVE-2023-39215

Improper authentication in Zoom clients may allow an authenticated user to conduct a denial of service via network access.

Fix: 5.14.12 / 5.15.4+
Fix from $1,600 2023-09-12
Cobol Server CRITICAL 9.8
CVE-2023-4501

User authentication with username and password credentials is ineffective in OpenText (Micro Focus) Visual COBOL, COBOL Server, Enterprise Developer,…

Mitigation only
Fix from $2,300 2023-09-12
Pavilion8 MEDIUM 5.4
CVE-2023-29463

The JMX Console within the Rockwell Automation Pavilion8 is exposed to application users and does not require authentication. If exploited, a malicio…

Fix: 5.20+
Fix from $1,600 2023-09-12
Cortex CRITICAL 9.8
CVE-2023-39069

An issue in StrangeBee TheHive v.5.0.8, v.4.1.21 and Cortex v.3.1.6 allows a remote attacker to gain privileges via Active Directory authentication m…

Fix: 3.5.2+
Fix from $2,300 2023-09-11
Asset Suite HIGH 8.8
CVE-2023-4816

A vulnerability exists in the Equipment Tag Out authentication, when configured with Single Sign-On (SSO) with password validation in T214. This vuln…

Fix: after 9.6.3.11.1
Fix from $1,950 2023-09-11
Mofi4500 4gxelte V2 Firmware CRITICAL 9.8
CVE-2021-27715

An issue was discovered in MoFi Network MOFI4500-4GXeLTE-V2 3.5.6-xnet-5052 allows attackers to bypass the authentication and execute arbitrary code …

Mitigation only
Fix from $2,300 2023-09-08
Broadworks Application Delivery Platform CRITICAL 9.8
CVE-2023-20238EPSS 15%

A vulnerability in the single sign-on (SSO) implementation of Cisco BroadWorks Application Delivery Platform and Cisco BroadWorks Xtended Services Pl…

Fix: 23.0.1075.ap384245+
Fix from $2,300 2023-09-06
N300 Firmware MEDIUM 5.3
CVE-2023-4498

Tenda N300 Wireless N VDSL2 Modem Router allows unauthenticated access to pages that in turn should be accessible to authenticated users only

Mitigation only
Fix from $1,600 2023-09-06
Archer C20 Firmware HIGH 8.8
CVE-2023-37284

Improper authentication vulnerability in Archer C20 firmware versions prior to 'Archer C20(JP)_V1_230616' allows a network-adjacent unauthenticated a…

Fix: 230616+
Fix from $1,950 2023-09-06
Gallery MEDIUM 5.5
CVE-2023-30725

Improper authentication in LocalProvier of Gallery prior to version 14.5.01.2 allows attacker to access the data in content provider.

Fix: 14.5.01.2+
Fix from $1,600 2023-09-06
Android HIGH 7.5
CVE-2023-30708

Improper authentication in SecSettings prior to SMR Sep-2023 Release 1 allows attacker to access Captive Portal Wi-Fi in Reactivation Lock status.

Mitigation only
Fix from $1,950 2023-09-06
Oas Platform HIGH 8.1
CVE-2023-34998

An authentication bypass vulnerability exists in the OAS Engine functionality of Open Automation Software OAS Platform v18.00.0072. A specially craft…

Mitigation only
Fix from $1,950 2023-09-05
Oas Platform CRITICAL 9.8
CVE-2023-31242

An authentication bypass vulnerability exists in the OAS Engine functionality of Open Automation Software OAS Platform v18.00.0072. A specially-craft…

No fix yet
Fix from $2,300 2023-09-05
Mxsecurity HIGH 7.5
CVE-2023-39981

A vulnerability that allows for unauthorized access has been discovered in MXsecurity versions prior to v1.0.1. This vulnerability arises from inadeq…

Fix: after 1.0.1
Fix from $1,950 2023-09-02
Agent MEDIUM 5.5
CVE-2023-41751

Sensitive information disclosure due to improper token expiration validation. The following products are affected: Acronis Agent (Windows) before bui…

Mitigation only
Fix from $1,600 2023-08-31
Manageengine Ad360 HIGH 8.1
CVE-2023-35785

Zoho ManageEngine Active Directory 360 versions 4315 and below, ADAudit Plus 7202 and below, ADManager Plus 7200 and below, Asset Explorer 6993 and b…

Fix: 4.1 / 4.3+
Fix from $1,950 2023-08-28
Intuition 9 Firmware HIGH 8.8
CVE-2023-32202

Walchem Intuition 9 firmware versions prior to v4.21 are vulnerable to improper authentication. Login credentials are stored in a format that could a…

Fix: 4.21+
Fix from $1,950 2023-08-23
Wifi Pocket Firmware MEDIUM 5.4
CVE-2023-40282

Improper authentication vulnerability in Rakuten WiFi Pocket all versions allows a network-adjacent attacker to log in to the product's Management Sc…

Mitigation only
Fix from $1,600 2023-08-23
Nr4h Firmware HIGH 8.8
CVE-2023-38585

Improper authentication vulnerability in the CBC products allows a remote authenticated attacker to execute an arbitrary OS command on the device or …

Mitigation only
Fix from $1,950 2023-08-23
Ak Sm 800a Firmware HIGH 7.5
CVE-2023-25913

Because of an authentication flaw an attacker would be capable of generating a web report that discloses sensitive information such as internal IP ad…

Fix: after 3.3
Fix from $1,950 2023-08-21
Remote Desktop Manager CRITICAL 9.8
CVE-2023-4373

Inadequate validation of permissions when employing remote tools and macros within Devolutions Remote Desktop Manager versions 2023.2.19 and earlier …

Fix: after 2023.2.19
Fix from $2,300 2023-08-21
Rg Ew1200g Firmware HIGH 8.8
CVE-2023-4415EPSS 57%

A vulnerability was found in Ruijie RG-EW1200G 07161417 r483. It has been rated as critical. Affected by this issue is some unknown functionality of …

No fix yet
Fix from $1,950 2023-08-18