Vulnerability index

Browse CVEs

4,342 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
Proself HIGH 7.5
CVE-2023-39415

Improper authentication vulnerability in Proself Enterprise/Standard Edition Ver5.61 and earlier, Proself Gateway Edition Ver1.62 and earlier, and Pr…

Fix: after 5.61
Fix from $1,950 2023-08-18
Tn 5900 Firmware HIGH 8.8
CVE-2023-33237

TN-5900 Series firmware version v3.3 and prior is vulnerable to improper-authentication vulnerability. This vulnerability arises from inadequate auth…

Fix: after 3.3
Fix from $1,950 2023-08-17
Konga CRITICAL 9.8
CVE-2023-39846

An issue in Konga v0.14.9 allows attackers to bypass authentication via a crafted JWT token.

No fix yet
Fix from $2,300 2023-08-16
Endpoint Manager Mobile CRITICAL 9.8
CVE-2023-35082 KEVEPSS 100%

An authentication bypass vulnerability in Ivanti EPMM 11.10 and older, allows unauthorized users to access restricted functionality or resources of t…

Fix: 11.11.0+
Fix from $2,300 2023-08-15
Privateuploader HIGH 8.3
CVE-2023-40020

PrivateUploader is an open source image hosting server written in Vue and TypeScript. In affected versions `app/routes/v3/admin.controller.ts` did no…

Fix: 3.2.49+
Fix from $1,950 2023-08-14
Iboot Pdu4a C10 Firmware HIGH 7.5
CVE-2023-3263

The Dataprobe iBoot PDU running firmware version 1.43.03312023 or earlier is vulnerable to authentication bypass in the REST API due to the mishandli…

Fix: 1.44.0804202+
Fix from $1,950 2023-08-14
Emui HIGH 7.5
CVE-2023-39380

Permission control vulnerability in the audio module. Successful exploitation of this vulnerability may cause audio devices to perform abnormally.

No fix yet
Fix from $1,950 2023-08-13
Genian Nac CRITICAL 9.8
CVE-2023-40253

Improper Authentication vulnerability in Genians Genian NAC V4.0, Genians Genian NAC V5.0, Genians Genian NAC Suite V5.0, Genians Genian ZTNA allows …

Fix: 4.0.156 / 5.0.55+
Fix from $2,300 2023-08-11
Empowerid CRITICAL 9.1
CVE-2023-40260

EmpowerID before 7.205.0.1 allows an attacker to bypass an MFA (multi factor authentication) requirement if the first factor (username and password) …

Fix: 7.205.0.1+
Fix from $2,300 2023-08-11
Sentry MEDIUM 6.8
CVE-2023-39531

Sentry is an error tracking and performance monitoring platform. Starting in version 10.0.0 and prior to version 23.7.2, an attacker with sufficient …

Fix: 23.7.2+
Fix from $1,600 2023-08-09
Apq8009 Firmware HIGH 7.1
CVE-2023-21626

Cryptographic issue in HLOS due to improper authentication while performing key velocity checks using more than one key.

Mitigation only
Fix from $1,950 2023-08-08
Host Agent MEDIUM 5.3
CVE-2023-36926

Due to missing authentication check in SAP Host Agent - version 7.22, an unauthenticated attacker can set an undocumented parameter to a particular c…

Mitigation only
Fix from $1,600 2023-08-08
Sentry HIGH 8.1
CVE-2023-39349

Sentry is an error tracking and performance monitoring platform. Starting in version 22.1.0 and prior to version 23.7.2, an attacker with access to a…

Fix: 23.7.2+
Fix from $1,950 2023-08-07
Pega Platform CRITICAL 9.8
CVE-2023-32090

Pega platform clients who are using versions 6.1 through 7.3.1 may be utilizing default credentials

Fix: after 7.3.1
Fix from $2,300 2023-08-07
Keycloak MEDIUM 5.0
CVE-2023-0264

A flaw was found in Keycloaks OpenID Connect user authentication, which may incorrectly authenticate requests. An authenticated attacker who could ob…

Fix: 7.6.2 / 18.0.6+
Fix from $1,600 2023-08-04
Matrix Appservice Bridge MEDIUM 6.5
CVE-2023-38691

matrix-appservice-bridge provides an API for setting up bridges. Starting in version 4.0.0 and prior to versions 8.1.2 and 9.0.1, a malicious Matrix …

Fix: 8.1.2+
Fix from $1,600 2023-08-04
Ecshop MEDIUM 6.5
CVE-2023-39112

ECShop v4.1.16 contains an arbitrary file deletion vulnerability in the Admin Panel.

No fix yet
Fix from $1,600 2023-08-04
Catalyst Sd Wan Manager CRITICAL 9.1
CVE-2023-20214

A vulnerability in the request authentication validation for the REST API of Cisco SD-WAN vManage software could allow an unauthenticated, remote att…

Fix: 20.6.4.2 / 20.6.5.5+
Fix from $2,300 2023-08-03
Biostar 2 HIGH 7.5
CVE-2023-33363

An authentication bypass vulnerability exists in Suprema BioStar 2 before 2.9.1, which allows unauthenticated users to access some functionality on B…

Fix: 2.9.1+
Fix from $1,950 2023-08-03
Ejbca HIGH 8.2
CVE-2023-34196

In the Keyfactor EJBCA before 8.0.0, the RA web certificate distribution servlet /ejbca/ra/cert allows partial denial of service due to an authentica…

Fix: 8.0.0+
Fix from $1,950 2023-08-03
Roc809 Firmware CRITICAL 9.4
CVE-2023-1935

ROC800-Series RTU devices are vulnerable to an authentication bypass, which could allow an attacker to gain unauthorized access to data or control of…

Mitigation only
Fix from $2,300 2023-08-02
Big Ip Access Policy Manager MEDIUM 6.1
CVE-2023-3470

Specific F5 BIG-IP platforms with Cavium Nitrox FIPS HSM cards generate a deterministic password for the Crypto User account.  The predictable nature…

Fix: 13.1.4 / 14.1.4+
Fix from $1,600 2023-08-02
Time Slots Booking Calendar HIGH 8.8
CVE-2023-33563

In PHP Jabbers Time Slots Booking Calendar 3.3 , lack of verification when changing an email address and/or password (on the Profile Page) allows rem…

Mitigation only
Fix from $1,950 2023-08-01
Si R 30b Firmware HIGH 8.8
CVE-2023-38555

Authentication bypass vulnerability in Fujitsu network devices Si-R series and SR-M series allows a network-adjacent unauthenticated attacker to obta…

Fix: after 02.54
Fix from $1,950 2023-07-26
Nest Hub Max Firmware HIGH 8.8
CVE-2023-2626

There exists an authentication bypass vulnerability in OpenThread border router devices and implementations. This issue allows unauthenticated nodes …

Fix: 1.56.368671 / 1.63.355999+
Fix from $1,950 2023-07-25
Endpoint Manager Mobile CRITICAL 9.8
CVE-2023-35078 KEVEPSS 100%

An authentication bypass vulnerability in Ivanti EPMM allows unauthorized users to access restricted functionality or resources of the application wi…

Fix: 11.8.1.1 / 11.9.1.1+
Fix from $2,300 2023-07-25
Dapr HIGH 7.5
CVE-2023-37918

Dapr is a portable, event-driven, runtime for building distributed applications across cloud and edge. A vulnerability has been found in Dapr that al…

Fix: 1.10.9 / 1.11.2+
Fix from $1,950 2023-07-21
Openam CRITICAL 9.8
CVE-2023-37471

Open Access Management (OpenAM) is an access management solution that includes Authentication, SSO, Authorization, Federation, Entitlements and Web S…

Fix: 14.7.3+
Fix from $2,300 2023-07-20
Gv Adr2701 Firmware CRITICAL 9.8
CVE-2023-3638

In GeoVision GV-ADR2701 cameras, an attacker could edit the login response to access the web application.

No fix yet
Fix from $2,300 2023-07-19
Cloud Pak For Data HIGH 7.5
CVE-2023-27877

IBM Planning Analytics Cartridge for Cloud Pak for Data 4.0 connects to a CouchDB server. An attacker can exploit an insecure password policy to the …

Patch available
Fix from $1,950 2023-07-19