Vulnerability index

Browse CVEs

4,342 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
Oauth Single Sign On HIGH 8.8
CVE-2022-34155

Improper Authentication vulnerability in miniOrange OAuth Single Sign On – SSO (OAuth Client) plugin allows Authentication Bypass.This issue affects …

Fix: 6.23.4+
Fix from $1,950 2023-07-18
Casaos CRITICAL 9.8
CVE-2023-37266EPSS 7%

CasaOS is an open-source Personal Cloud system. Unauthenticated attackers can craft arbitrary JWTs and access features that usually require authentic…

Fix: 0.4.4+
Fix from $2,300 2023-07-17
Mattermost Server HIGH 8.2
CVE-2023-3591

Mattermost fails to invalidate previously generated password reset tokens when a new reset token was created.

Fix: 7.8.7 / 7.9.5+
Fix from $1,950 2023-07-17
Oliva Ekspertiz HIGH 7.5
CVE-2023-2959

Authentication Bypass by Primary Weakness vulnerability in Oliva Expertise Oliva Expertise EKS allows Collect Data as Provided by Users. This issue …

Fix: 1.2+
Fix from $1,950 2023-07-17
Robotic Process Automation MEDIUM 5.3
CVE-2023-35901

IBM Robotic Process Automation 21.0.0 through 21.0.7.6 and 23.0.0 through 23.0.6 is vulnerable to client side validation bypass which could allow inv…

Fix: after 23.0.6
Fix from $1,600 2023-07-17
Warpgate HIGH 8.8
CVE-2023-37268

Warpgate is an SSH, HTTPS and MySQL bastion host for Linux that doesn't need special client apps. When logging in as a user with SSO enabled an attac…

Patch available
Fix from $1,950 2023-07-14
OpenSSL MEDIUM 5.3
CVE-2023-2975

Issue summary: The AES-SIV cipher implementation contains a bug that causes it to ignore empty associated data entries which are unauthenticated as a…

Fix: after 3.1.1
Fix from $1,600 2023-07-14
Alaris 8015 Pcu Firmware MEDIUM 6.8
CVE-2023-30560

The configuration from the PCU can be modified without authentication using physical connection to the PCU.

Fix: after 12.1.3
Fix from $1,600 2023-07-13
Alaris 8015 Pcu Firmware MEDIUM 5.7
CVE-2023-30559

The firmware update package for the wireless card is not properly signed and can be modified.

Fix: after 12.1.3
Fix from $1,600 2023-07-13
Analytics CRITICAL 9.8
CVE-2023-34137

SonicWall GMS and Analytics CAS Web Services application use static values for authentication without proper checks leading to authentication bypass …

Fix: 9.3.2+
Fix from $2,300 2023-07-13
Analytics CRITICAL 9.8
CVE-2023-34124EPSS 46%

The authentication mechanism in SonicWall GMS and Analytics Web Services had insufficient checks, allowing authentication bypass. This issue affects …

Fix: 9.3.2+
Fix from $2,300 2023-07-13
Snmp Web Pro CRITICAL 9.8
CVE-2023-33274

The authentication mechanism in PowerShield SNMP Web Pro 1.1 contains a vulnerability that allows unauthenticated users to directly access Common Gat…

No fix yet
Fix from $2,300 2023-07-12
Pulsar MEDIUM 6.5
CVE-2023-31007

Improper Authentication vulnerability in Apache Software Foundation Apache Pulsar Broker allows a client to stay connected to a broker after authenti…

Fix: 2.9.5+
Fix from $1,600 2023-07-12
Istar Ultra Firmware CRITICAL 9.8
CVE-2023-3127

An unauthenticated user could log into iSTAR Ultra, iSTAR Ultra LT, iSTAR Ultra G2, and iSTAR Edge G2 with administrator rights.

Fix: 6.9.2+
Fix from $2,300 2023-07-11
Dronescout Ds230 Firmware HIGH 8.1
CVE-2023-31190

DroneScout ds230 Remote ID receiver from BlueMark Innovations is affected by an Improper Authentication vulnerability during the firmware update proc…

Fix: after 20230329-1042
Fix from $1,950 2023-07-11
Pass MEDIUM 5.5
CVE-2023-30675

Improper authentication in Samsung Pass prior to version 4.2.03.1 allows local attacker to access stored account information when Samsung Wallet is n…

Fix: 4.2.03.1+
Fix from $1,600 2023-07-06
Glpi HIGH 7.5
CVE-2023-35940

GLPI is a free asset and IT management software package. Starting in version 9.5.0 and prior to version 10.0.8, an incorrect rights check on a file a…

Fix: 10.0.8+
Fix from $1,950 2023-07-05
Wl Wn531ax2 Firmware MEDIUM 6.5
CVE-2023-32620

Improper authentication vulnerability in WL-WN531AX2 firmware versions prior to 2023526 allows a network-adjacent attacker to obtain a password for t…

Fix: 2023526+
Fix from $1,600 2023-06-30
Sealos CRITICAL 9.8
CVE-2023-33190

Sealos is an open source cloud operating system distribution based on the Kubernetes kernel. In versions of Sealos prior to 4.2.1-rc4 an improper con…

Fix: 4.2.1+
Fix from $2,300 2023-06-29
Dsl G256dg Firmware CRITICAL 9.8
CVE-2023-32222

D-Link DSL-G256DG version vBZ_1.00.27 web management interface allows authentication bypass via an unspecified method.

Mitigation only
Fix from $2,300 2023-06-28
Duo MEDIUM 6.6
CVE-2023-20199

A vulnerability in Cisco Duo Two-Factor Authentication for macOS could allow an authenticated, physical attacker to bypass secondary authentication a…

Fix: 2.0.2+
Fix from $1,600 2023-06-28
Clips2 CRITICAL 9.8
CVE-2023-30945

Multiple Services such as VHS(Video History Server) and VCD(Video Clip Distributor) and Clips2 were discovered to be vulnerable to an unauthenticated…

Fix: 0.24.10 / 0.111.2+
Fix from $2,300 2023-06-26
Mobile Security HIGH 8.8
CVE-2023-32523

Affected versions of Trend Micro Mobile Security (Enterprise) 9.8 SP5 contain some widgets that would allow a remote user to bypass authentication an…

Patch available
Fix from $1,950 2023-06-26
Mobile Security HIGH 8.8
CVE-2023-32524

Affected versions of Trend Micro Mobile Security (Enterprise) 9.8 SP5 contain some widgets that would allow a remote user to bypass authentication an…

Patch available
Fix from $1,950 2023-06-26
Knowage MEDIUM 6.5
CVE-2023-35154

Knowage is an open source analytics and business intelligence suite. Starting in version 6.0.0 and prior to version 8.1.8, an attacker can register a…

Fix: 8.1.8+
Fix from $1,600 2023-06-23
Precision 3570 Firmware HIGH 7.8
CVE-2023-28073

Dell BIOS contains an improper authentication vulnerability. A locally authenticated malicious user may potentially exploit this vulnerability by byp…

Fix: 1.13.2+
Fix from $1,950 2023-06-23
FreeBSD CRITICAL 9.8
CVE-2023-3326

pam_krb5 authenticates a user by essentially running kinit with the password, getting a ticket-granting ticket (tgt) from the Kerberos KDC (Key Distr…

Fix: 12.4 / 13.1+
Fix from $2,300 2023-06-22
Accumulo CRITICAL 9.8
CVE-2023-34340

Improper Authentication vulnerability in Apache Software Foundation Apache Accumulo. This issue affects Apache Accumulo: 2.1.0. Accumulo 2.1.0 conta…

Mitigation only
Fix from $2,300 2023-06-21
Online Shopping System Advanced CRITICAL 9.8
CVE-2023-3337

A vulnerability was found in PuneethReddyHC Online Shopping System Advanced 1.0. It has been declared as critical. Affected by this vulnerability is …

Mitigation only
Fix from $2,300 2023-06-20
Emui HIGH 7.5
CVE-2022-48494

Vulnerability of lax app identity verification in the pre-authorization function.Successful exploitation of this vulnerability will cause malicious a…

No fix yet
Fix from $1,950 2023-06-19