Vulnerability index

Browse CVEs

4,342 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
Emui HIGH 7.5
CVE-2022-48496

Vulnerability of lax app identity verification in the pre-authorization function.Successful exploitation of this vulnerability will cause malicious a…

No fix yet
Fix from $1,950 2023-06-19
Server HIGH 7.5
CVE-2023-30223

A broken authentication vulnerability in 4D SAS 4D Server software v17, v18, v19 R7, and earlier allows attackers to send crafted TCP packets contain…

No fix yet
Fix from $1,950 2023-06-16
Factorytalk Policy Manager MEDIUM 5.0
CVE-2023-2638

Rockwell Automation's FactoryTalk System Services does not verify that a backup configuration archive is password protected.   Improper authorizati…

Mitigation only
Fix from $1,600 2023-06-13
Kb Ahr04d Firmware CRITICAL 9.8
CVE-2023-30762

Improper authentication vulnerability exists in KB-AHR series and KB-IRIP series. If this vulnerability is exploited, an arbitrary OS command may be …

Fix: 91110.1.101106.78 / 91210.1.101106.78+
Fix from $2,300 2023-06-13
Saml CRITICAL 9.8
CVE-2023-29129

A vulnerability has been identified in Mendix SAML (Mendix 7 compatible) (All versions >= V1.17.3 < V1.18.0), Mendix SAML (Mendix 7 compatible) (All …

Fix: 1.18.0 / 2.4.0+
Fix from $2,300 2023-06-13
Ncr\/camera Firmware CRITICAL 9.8
CVE-2023-32220

Milesight NCR/camera version 71.8.0.6-r5 allows authentication bypass through an unspecified method.

No fix yet
Fix from $2,300 2023-06-12
Doorkeeper MEDIUM 6.5
CVE-2023-34246

Doorkeeper is an OAuth 2 provider for Ruby on Rails / Grape. Prior to version 5.6.6, Doorkeeper automatically processes authorization requests withou…

Fix: 5.6.6+
Fix from $1,600 2023-06-12
Wdrt 1800ax Firmware CRITICAL 9.8
CVE-2023-33553

An issue in Planet Technologies WDRT-1800AX v1.01-CP21 allows attackers to bypass authentication and escalate privileges to root via manipulation of …

No fix yet
Fix from $2,300 2023-06-07
Synapse MEDIUM 5.4
CVE-2023-32682

Synapse is a Matrix protocol homeserver written in Python with the Twisted framework. In affected versions it may be possible for a deactivated user …

Fix: 1.85.0+
Fix from $1,600 2023-06-06
315 5g Iot Modem Firmware HIGH 7.5
CVE-2022-40521

Transient DOS due to improper authorization in Modem

No fix yet
Fix from $1,950 2023-06-06
315 5g Iot Modem Firmware HIGH 7.5
CVE-2022-40536

Transient DOS due to improper authentication in modem while receiving plain TLB OTA request message from network.

Mitigation only
Fix from $1,950 2023-06-06
Amxgt 100 CRITICAL 9.1
CVE-2023-3065

Improper Authentication vulnerability in Mobatime mobile application AMXGT100 allows Authentication Bypass.This issue affects Mobatime mobile applica…

Fix: after 1.3.20
Fix from $2,300 2023-06-05
Corebos CRITICAL 9.8
CVE-2023-3069

Unverified Password Change in GitHub repository tsolucio/corebos prior to 8.

Fix: 8.0+
Fix from $2,300 2023-06-02
Hqt401 Firmware CRITICAL 9.8
CVE-2023-3028

Insufficient authentication in the MQTT backend (broker) allows an attacker to access and even manipulate the telemetry data of the entire fleet of v…

Mitigation only
Fix from $2,300 2023-06-01
Fedora MEDIUM 6.5
CVE-2023-2283

A vulnerability was found in libssh, where the authentication check of the connecting client can be bypassed in the`pki_verify_data_signature` functi…

Fix: after 0.10.4
Fix from $1,600 2023-05-26
Emui MEDIUM 5.3
CVE-2023-0117

The online authentication provided by the hwKitAssistant lacks strict identity verification of applications. Successful exploitation of this vulnerab…

No fix yet
Fix from $1,600 2023-05-26
Q Sl2 Firmware HIGH 8.8
CVE-2023-25946

Authentication bypass vulnerability in Qrio Lock (Q-SL2) firmware version 2.0.9 and earlier allows a network-adjacent attacker to analyze the product…

Fix: after 2.0.9
Fix from $1,950 2023-05-23
Tr 71w Firmware CRITICAL 9.8
CVE-2023-27388

Improper authentication vulnerability in T&D Corporation and ESPEC MIC CORP. data logger products allows a remote unauthenticated attacker to login t…

Mitigation only
Fix from $2,300 2023-05-23
Remote Management System CRITICAL 9.8
CVE-2023-2586

Teltonika’s Remote Management System versions 4.14.0 is vulnerable to an unauthorized attacker registering previously unregistered devices through th…

Mitigation only
Fix from $2,300 2023-05-22
Remote Management System CRITICAL 9.8
CVE-2023-32347

Teltonika’s Remote Management System versions prior to 4.10.0 use device serial numbers and MAC addresses to identify devices from the user perspecti…

Fix: 4.10.0+
Fix from $2,300 2023-05-22
Openblue Enterprise Manager Data Collector HIGH 7.5
CVE-2023-2024

Improper authentication in OpenBlue Enterprise Manager Data Collector versions prior to 3.2.5.75 allow access to an unauthorized user under certain c…

Fix: 3.2.5.75+
Fix from $1,950 2023-05-18
Terra Ac Wallbox Ul40 Firmware HIGH 8.8
CVE-2023-0863

Improper Authentication vulnerability in ABB Terra AC wallbox (UL40/80A), ABB Terra AC wallbox (UL32A), ABB Terra AC wallbox (CE) (Terra AC MID), ABB…

Fix: 1.2.8 / 1.5.6+
Fix from $1,950 2023-05-17
Otp Login Woocommerce \& Gravity Forms HIGH 8.1
CVE-2023-2706

The OTP Login Woocommerce & Gravity Forms plugin for WordPress is vulnerable to authentication bypass. This is due to the fact that when generating O…

Fix: 2.3+
Fix from $1,950 2023-05-17
Registrationmagic CRITICAL 9.8
CVE-2023-2499

The RegistrationMagic plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 5.2.1.0. This is due to insuffici…

Fix: after 5.2.1.0
Fix from $2,300 2023-05-16
Ftmg Esd20axx Firmware CRITICAL 9.8
CVE-2023-23450

Use of Password Hash Instead of Password for Authentication in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116…

Fix: 2.0+
Fix from $2,300 2023-05-15
Vert.x Stomp MEDIUM 6.5
CVE-2023-32081

Vert.x STOMP is a vert.x implementation of the STOMP specification that provides a STOMP server and client. From versions 3.1.0 until 3.9.16 and 4.0.…

Fix: 3.9.16 / 4.4.2+
Fix from $1,600 2023-05-12
1080pstx CRITICAL 9.8
CVE-2023-27823EPSS 53%

An authentication bypass in Optoma 1080PSTX C02 allows an attacker to access the administration console without valid credentials.

Mitigation only
Fix from $2,300 2023-05-12
Essential Addons For Elementor CRITICAL 9.8
CVE-2023-32243EPSS 76%

Improper Authentication vulnerability in WPDeveloper Essential Addons for Elementor allows Privilege Escalation. This issue affects Essential Addons …

Fix: 5.7.1+
Fix from $2,300 2023-05-12
Openmeetings HIGH 8.1
CVE-2023-29032

An attacker that has gained access to certain private information can use this to act as other user. Vendor: The Apache Software Foundation Version…

Fix: 7.1.0+
Fix from $1,950 2023-05-12
Rocket.chat MEDIUM 6.5
CVE-2023-28325

An improper authorization vulnerability exists in Rocket.Chat <6.0 that could allow a hacker to manipulate the rid parameter and change the updateMes…

Fix: 6.0.0+
Fix from $1,600 2023-05-11