Vulnerability index

Browse CVEs

4,342 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
Mf642cdw Firmware MEDIUM 5.3
CVE-2023-0858

Improper Authentication of RemoteUI of Office / Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network …

Fix: after 11.04
Fix from $1,600 2023-05-11
Sel 2241 Rtac Module Firmware HIGH 8.8
CVE-2023-31152

An Authentication Bypass Using an Alternate Path or Channel vulnerability in the Schweitzer Engineering Laboratories Real-Time Automation Controller …

Mitigation only
Fix from $1,950 2023-05-10
Uc Ftps HIGH 7.5
CVE-2022-41985

An authentication bypass vulnerability exists in the Authentication functionality of Weston Embedded uC-FTPs v 1.98.00. A specially crafted set of ne…

Patch available
Fix from $1,950 2023-05-10
Data Center Manager HIGH 8.8
CVE-2022-44610

Improper authentication in the Intel(R) DCM software before version 5.1 may allow an authenticated user to potentially enable escalation of privilege…

Fix: 5.1+
Fix from $1,950 2023-05-10
Next Engine Integration MEDIUM 5.3
CVE-2023-27919

Authentication bypass vulnerability in NEXT ENGINE Integration Plugin (for EC-CUBE 2.0 series) all versions allows a remote unauthenticated attacker …

Mitigation only
Fix from $1,600 2023-05-10
Avalanche MEDIUM 5.9
CVE-2023-28125

An improper authentication vulnerability exists in Avalanche Premise versions 6.3.x and below that could allow an attacker to gain access to the serv…

Fix: after 6.3.4.153
Fix from $1,600 2023-05-09
Tripreporter CRITICAL 9.1
CVE-2023-31123

`effectindex/tripreporter` is a community-powered, universal platform for submitting and analyzing trip reports. Prior to commit bd80ba833b9023d39ca2…

Fix: 2023-04-30+
Fix from $2,300 2023-05-08
Libspdm HIGH 8.8
CVE-2023-31127

libspdm is a sample implementation that follows the DMTF SPDM specifications. A vulnerability has been identified in SPDM session establishment in li…

Fix: 2.3.2+
Fix from $1,950 2023-05-08
Ipados MEDIUM 6.5
CVE-2023-28182

The issue was addressed with improved authentication. This issue is fixed in macOS Ventura 13.3, iOS 16.4 and iPadOS 16.4, iOS 15.7.4 and iPadOS 15.7…

Fix: 11.7.5 / 12.6.4+
Fix from $1,600 2023-05-08
Shimo CRITICAL 9.8
CVE-2023-30328

An issue in the helper tool of Mailbutler GmbH Shimo VPN Client for macOS v5.0.4 allows attackers to bypass authentication via PID re-use.

No fix yet
Fix from $2,300 2023-05-04
Android HIGH 7.8
CVE-2023-21484

Improper access control vulnerability in AppLock prior to SMR May-2023 Release 1 allows local attackers without proper permission to execute a privil…

Mitigation only
Fix from $1,950 2023-05-04
Fortinac HIGH 7.5
CVE-2022-45860

A weak authentication vulnerability [CWE-1390] in FortiNAC-F version 7.2.0, FortiNAC version 9.4.2 and below, 9.2 all versions, 9.1 all versions, 8.8…

Fix: 9.4.2+
Fix from $1,950 2023-05-03
Cyber Backup HIGH 7.5
CVE-2022-30995

Sensitive information disclosure due to improper authentication. The following products are affected: Acronis Cyber Protect 15 (Windows, Linux) befor…

Mitigation only
Fix from $1,950 2023-05-03
Easy Digital Downloads CRITICAL 9.8
CVE-2023-30869

Improper Authentication vulnerability in Easy Digital Downloads plugin allows unauth. Privilege Escalation. This issue affects Easy Digital Downloads…

Fix: 3.1.1.4.2+
Fix from $2,300 2023-05-02
Bizmanager CRITICAL 9.8
CVE-2022-35898

OpenText BizManager before 16.6.0.1 does not perform proper validation during the change-password operation. This allows any authenticated user to ch…

Fix: 16.6.0.1+
Fix from $2,300 2023-05-01
Dir 879 Firmware HIGH 7.5
CVE-2023-30061

D-Link DIR-879 v105A1 is vulnerable to Authentication Bypass via phpcgi.

No fix yet
Fix from $1,950 2023-05-01
Dir 890l Firmware HIGH 7.5
CVE-2023-30063

D-Link DIR-890L FW1.10 A1 is vulnerable to Authentication bypass.

No fix yet
Fix from $1,950 2023-05-01
Keycloak Authenticator HIGH 8.8
CVE-2023-1477

Improper Authentication vulnerability in HYPR Keycloak Authenticator Extension allows Authentication Abuse.This issue affects HYPR Keycloak Authentic…

Fix: 7.10.2 / 8.0.3+
Fix from $1,950 2023-04-28
Data Security Firewall Firmware CRITICAL 9.8
CVE-2023-1778

This vulnerability exists in GajShield Data Security Firewall firmware versions prior to v4.28 (except v4.21) due to insecure default credentials whi…

Fix: 4.21 / 4.28+
Fix from $2,300 2023-04-27
Profile Builder HIGH 8.1
CVE-2023-2297

The Profile Builder – User Profile & User Registration Forms plugin for WordPress is vulnerable to unauthorized password resets in versions up to, a…

Fix: after 3.9.0
Fix from $1,950 2023-04-27
Espv2 CRITICAL 9.8
CVE-2023-30845

ESPv2 is a service proxy that provides API management capabilities using Google Service Infrastructure. ESPv2 2.20.0 through 2.42.0 contains an authe…

Fix: 2.43.0+
Fix from $2,300 2023-04-26
Agent HIGH 7.5
CVE-2022-45456

Denial of service due to unauthenticated API endpoint. The following products are affected: Acronis Agent (Windows, macOS, Linux) before build 30161.

Mitigation only
Fix from $1,950 2023-04-26
Pingfederate MEDIUM 6.5
CVE-2022-40723

The PingID RADIUS PCV adapter for PingFederate, which supports RADIUS authentication with PingID MFA, is vulnerable to MFA bypass under certain confi…

Fix: 2.24 / 3.0.2+
Fix from $1,600 2023-04-25
Powerpanel CRITICAL 9.8
CVE-2023-25131

Use of default password vulnerability in PowerPanel Business Local/Remote for Windows v4.8.6 and earlier, PowerPanel Business Management for Windows …

Fix: after 4.8.6
Fix from $2,300 2023-04-24
Sbios HIGH 7.8
CVE-2023-0209

NVIDIA DGX-1 SBIOS contains a vulnerability in the Uncore PEI module, where authentication of the code executed by SSA is missing, which may lead to …

Fix: 52w_3a13+
Fix from $1,950 2023-04-22
Papercut Mf HIGH 7.5
CVE-2023-27351 KEVEPSS 77%

This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Build 63914). Authentication is …

Fix: 20.1.7 / 21.2.11+
Fix from $1,950 2023-04-20
Strapi HIGH 7.5
CVE-2023-22893

Strapi through 4.5.5 does not verify the access or ID tokens issued during the OAuth flow when the AWS Cognito login provider is used for authenticat…

Fix: 4.6.0+
Fix from $1,950 2023-04-19
Merten Instabus Tastermodul 1fach System M Firmware HIGH 8.8
CVE-2023-25556

A CWE-287: Improper Authentication vulnerability exists that could allow a device to be compromised when a key of less than seven digits is entered a…

Mitigation only
Fix from $1,950 2023-04-18
Or1200 Firmware CRITICAL 9.8
CVE-2021-40506

An issue was discovered in the ALU unit of the OR1200 (aka OpenRISC 1200) processor 2011-09-10 through 2015-11-11. The overflow flag is not being upd…

Fix: after 2015-11-11
Fix from $2,300 2023-04-18
Or1200 Firmware CRITICAL 9.8
CVE-2021-40507

An issue was discovered in the ALU unit of the OR1200 (aka OpenRISC 1200) processor 2011-09-10 through 2015-11-11. The overflow flag is not being upd…

Fix: after 2015-11-11
Fix from $2,300 2023-04-18