Vulnerability index

Browse CVEs

4,342 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
Junos Os Evolved HIGH 7.1
CVE-2023-28973

An Improper Authorization vulnerability in the 'sysmanctl' shell command of Juniper Networks Junos OS Evolved allows a local, authenticated attacker …

Fix: 20.4+
Fix from $1,950 2023-04-17
Junos CRITICAL 9.8
CVE-2023-28962

An Improper Authentication vulnerability in upload-file.php, used by the J-Web component of Juniper Networks Junos OS allows an unauthenticated, netw…

Fix: 19.4+
Fix from $2,300 2023-04-17
Junos MEDIUM 5.3
CVE-2023-28963

An Improper Authentication vulnerability in cert-mgmt.php, used by the J-Web component of Juniper Networks Junos OS allows an unauthenticated, networ…

Fix: 19.4+
Fix from $1,600 2023-04-17
Iotdb CRITICAL 9.8
CVE-2023-24831

Improper Authentication vulnerability in Apache Software Foundation Apache IoTDB.This issue affects Apache IoTDB Grafana Connector: from 0.13.0 throu…

Fix: after 0.13.3
Fix from $2,300 2023-04-17
Emui MEDIUM 6.5
CVE-2022-48314

The Bluetooth module has a vulnerability of bypassing the user confirmation in the pairing process. Successful exploitation of this vulnerability may…

No fix yet
Fix from $1,600 2023-04-16
Zm Ajax Login \& Register CRITICAL 9.8
CVE-2023-2027

The ZM Ajax Login & Register plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.0.2. This is due to insu…

Fix: after 2.0.2
Fix from $2,300 2023-04-15
Micollab MEDIUM 5.9
CVE-2023-25597

A vulnerability in the web conferencing component of Mitel MiCollab through 9.6.2.9 could allow an unauthenticated attacker to download a shared file…

Fix: 9.7+
Fix from $1,600 2023-04-14
Vdesk CRITICAL 9.8
CVE-2022-45173

An issue was discovered in LIVEBOX Collaboration vDesk through v018. A Bypass of Two-Factor Authentication can occur under the /api/v1/vdeskintegrati…

Fix: after 018
Fix from $2,300 2023-04-14
Vdesk CRITICAL 9.8
CVE-2022-45174

An issue was discovered in LIVEBOX Collaboration vDesk through v018. A Bypass of Two-Factor Authentication for SAML Users can occur under the /login/…

Fix: after 018
Fix from $2,300 2023-04-14
Router Firmware CRITICAL 9.8
CVE-2023-1803

Authentication Bypass by Alternate Name vulnerability in DTS Electronics Redline Router firmware allows Authentication Bypass. This issue affects Re…

Fix: 7.17+
Fix from $2,300 2023-04-14
Router Firmware CRITICAL 9.8
CVE-2023-1833

Authentication Bypass by Primary Weakness vulnerability in DTS Electronics Redline Router firmware allows Authentication Bypass. This issue affects …

Fix: 7.17+
Fix from $2,300 2023-04-14
Vc4 CRITICAL 9.8
CVE-2023-1617

Improper Authentication vulnerability in B&R Industrial Automation B&R VC4 (VNC-Server modules).  This vulnerability may allow an unauthenticated net…

Fix: 3.96.8 / 4.34.7+
Fix from $2,300 2023-04-14
Woocommerce Payments CRITICAL 9.8
CVE-2023-28121EPSS 87%

An issue in WooCommerce Payments plugin for WordPress (versions 5.6.1 and lower) allows an unauthenticated attacker to send requests on behalf of an …

Fix: 4.8.2 / 5.0.4+
Fix from $2,300 2023-04-12
Remote Desktop Manager MEDIUM 6.5
CVE-2023-1980

Two factor authentication bypass on login in Devolutions Remote Desktop Manager 2022.3.35 and earlier allow user to cancel the two factor authenti…

Fix: after 2022.3.35
Fix from $1,600 2023-04-11
Enterprise Server MEDIUM 5.3
CVE-2023-23761

An improper authentication vulnerability was identified in GitHub Enterprise Server that allowed an unauthorized actor to modify other users' secret …

Fix: 3.4.18 / 3.5.15+
Fix from $1,600 2023-04-07
Teacms HIGH 7.2
CVE-2023-27091

An unauthorized access issue found in XiaoBingby TeaCMS 2.3.3 allows attackers to escalate privileges via the id and keywords parameter(s).

No fix yet
Fix from $1,950 2023-04-04
Etcd CRITICAL 9.8
CVE-2021-28235

Authentication vulnerability found in Etcd-io v.3.4.10 allows remote attackers to escalate privileges via the debug function.

Patch available
Fix from $2,300 2023-04-04
Jeecg Boot CRITICAL 9.8
CVE-2023-1784

A vulnerability was found in jeecg-boot 3.5.0 and classified as critical. This issue affects some unknown processing of the component API Documentati…

Mitigation only
Fix from $2,300 2023-03-31
Lemonldap\ CRITICAL 9.8
CVE-2023-28862

An issue was discovered in LemonLDAP::NG before 2.16.1. Weak session ID generation in the AuthBasic handler and incorrect failure handling during a p…

Fix: 2.16.1+
Fix from $2,300 2023-03-31
Aiseg2 Firmware HIGH 8.8
CVE-2023-28727

Panasonic AiSEG2 versions 2.00J through 2.93A allows adjacent attackers bypass authentication due to mishandling of X-Forwarded-For headers.

Fix: after 2.93a
Fix from $1,950 2023-03-31
Fedora MEDIUM 5.9
CVE-2023-27535

An authentication bypass vulnerability exists in libcurl <8.0.0 in the FTP connection reuse feature that can result in wrong credentials being used d…

Fix: after 7.88.1
Fix from $1,600 2023-03-30
Fedora MEDIUM 5.9
CVE-2023-27536

An authentication bypass vulnerability exists libcurl <8.0.0 in the connection reuse feature which can reuse previously established connections with …

Fix: after 7.88.1
Fix from $1,600 2023-03-30
Fedora MEDIUM 5.5
CVE-2023-27538

An authentication bypass vulnerability exists in libcurl prior to v8.0.0 where it reuses a previously established SSH connection despite the fact tha…

Fix: 8.0.0+
Fix from $1,600 2023-03-30
Nextcloud MEDIUM 6.8
CVE-2023-28647

Nextcloud iOS is an ios application used to interface with the nextcloud home cloud ecosystem. In versions prior to 4.7.0 when an attacker has physic…

Fix: 4.7.0+
Fix from $1,600 2023-03-30
Unidata CRITICAL 9.8
CVE-2023-28503EPSS 62%

Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 suffer from an authe…

Fix: after 12.2.1
Fix from $2,300 2023-03-29
Dir 1935 Firmware HIGH 8.8
CVE-2022-43620

This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of D-Link DIR-1935 1.03 routers. Authenticati…

Fix: after 1.02
Fix from $1,950 2023-03-29
Osprey Pump Controller Firmware CRITICAL 9.8
CVE-2023-28398

Osprey Pump Controller version 1.01 could allow an unauthenticated user to create an account and bypass authentication, thereby gaining unauthorized …

Mitigation only
Fix from $2,300 2023-03-28
Rccmd CRITICAL 9.8
CVE-2022-4126

Use of Default Password vulnerability in ABB RCCMD on Windows, Linux, MacOS allows Try Common or Default Usernames and Passwords.This issue affects R…

Fix: 4.40_230207+
Fix from $2,300 2023-03-27
Android HIGH 7.5
CVE-2023-21027

In multiple functions of PasspointXmlUtils.java, there is a possible authentication misconfiguration due to a logic error in the code. This could lea…

Mitigation only
Fix from $1,950 2023-03-24
Kinghistorian HIGH 7.5
CVE-2022-45124EPSS 13%

An information disclosure vulnerability exists in the User authentication functionality of WellinTech KingHistorian 35.01.00.05. A specially crafted …

No fix yet
Fix from $1,950 2023-03-20