Vulnerability index

Browse CVEs

4,342 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
Ansible Semaphore CRITICAL 9.8
CVE-2023-28609

api/auth.go in Ansible Semaphore before 2.8.89 mishandles authentication.

Fix: 2.8.89+
Fix from $2,300 2023-03-18
Medicine Tracker System CRITICAL 9.8
CVE-2023-1464

A vulnerability, which was classified as critical, was found in SourceCodester Medicine Tracker System 1.0. This affects an unknown part of the file …

Mitigation only
Fix from $2,300 2023-03-17
Online Pizza Ordering System CRITICAL 9.8
CVE-2023-1460

A vulnerability was found in SourceCodester Online Pizza Ordering System 1.0. It has been classified as critical. This affects an unknown part of the…

Mitigation only
Fix from $2,300 2023-03-17
Exynos Firmware CRITICAL 9.1
CVE-2023-21455

Improper authorization implementation in Exynos baseband prior to SMR Mar-2023 Release 1 allows incorrect handling of unencrypted message.

Mitigation only
Fix from $2,300 2023-03-16
Arrayos Ag CRITICAL 9.8
CVE-2023-28461 KEVEPSS 68%

Array Networks Array AG Series and vxAG (9.4.0.481 and earlier) allow remote code execution. An attacker can browse the filesystem on the SSL VPN gat…

Fix: after 9.4.0.481
Fix from $2,300 2023-03-15
Robotic Process Automation MEDIUM 6.5
CVE-2022-46773

IBM Robotic Process Automation 21.0.0 - 21.0.7 and 23.0.0 is vulnerable to client-side validation bypass for credential pools. Invalid credential poo…

Fix: 21.0.7.1 / 23.0.1+
Fix from $1,600 2023-03-15
Manage Application MEDIUM 6.5
CVE-2022-46774

IBM Manage Application 8.8.0 and 8.9.0 in the IBM Maximo Application Suite is vulnerable to incorrect default permissions which could give access to …

Mitigation only
Fix from $1,600 2023-03-15
Rax30 Firmware CRITICAL 9.8
CVE-2023-1327

Netgear RAX30 (AX2400), prior to version 1.0.6.74, was affected by an authentication bypass vulnerability, allowing an unauthenticated attacker to ga…

Fix: 1.0.6.74+
Fix from $2,300 2023-03-14
Saml HIGH 7.5
CVE-2023-25957

A vulnerability has been identified in Mendix SAML (Mendix 7 compatible) (All versions >= V1.16.4 < V1.17.3), Mendix SAML (Mendix 8 compatible) (All …

Fix: 1.17.2 / 2.2.3+
Fix from $1,950 2023-03-14
Netweaver Application Server For Java HIGH 8.6
CVE-2023-23857

Due to missing authentication check, SAP NetWeaver AS for Java - version 7.50, allows an unauthenticated attacker to attach to an open interface and …

Mitigation only
Fix from $1,950 2023-03-14
Maddy CRITICAL 9.8
CVE-2023-27582

maddy is a composable, all-in-one mail server. Starting with version 0.2.0 and prior to version 0.6.3, maddy allows a full authentication bypass if S…

Fix: 0.6.3+
Fix from $2,300 2023-03-13
Avalanche HIGH 7.5
CVE-2022-44574EPSS 65%

An improper authentication vulnerability exists in Avalanche version 6.3.x and below allows unauthenticated attacker to modify properties on specific…

Fix: 6.4.0+
Fix from $1,950 2023-03-10
Aqt1000 Firmware HIGH 7.8
CVE-2022-33242

Memory corruption due to improper authentication in Qualcomm IPC while loading unsigned lib in audio PD.

Mitigation only
Fix from $1,950 2023-03-10
Home Assistant CRITICAL 10.0
CVE-2023-27482EPSS 72%

homeassistant is an open source home automation tool. A remotely exploitable vulnerability bypassing authentication for accessing the Supervisor API …

Fix: 2023.3.0 / 2023.03.1+
Fix from $2,300 2023-03-08
Symphony Plus S\+ Operations HIGH 8.8
CVE-2023-0228

Improper Authentication vulnerability in ABB Symphony Plus S+ Operations.This issue affects Symphony Plus S+ Operations: from 2.X through 2.1 SP2, 2.…

Fix: 2.1 / 3.3+
Fix from $1,950 2023-03-02
Interstim X Clinician MEDIUM 6.8
CVE-2023-25931

Medtronic identified that the Pelvic Health clinician apps, which are installed on the Smart Programmer mobile device, have a password vulnerability …

Mitigation only
Fix from $1,600 2023-03-01
Kubernetes Monitor MEDIUM 5.3
CVE-2023-1065

This vulnerability in the Snyk Kubernetes Monitor can result in irrelevant data being posted to a Snyk Organization, which could in turn obfuscate ot…

Fix: 2.0.0+
Fix from $1,600 2023-02-28
Tornado HIGH 7.5
CVE-2023-25264

An issue was discovered in Docmosis Tornado prior to version 2.9.5. An unauthenticated attacker can bypass the authentication check filter completely…

Fix: 2.9.5+
Fix from $1,950 2023-02-28
Simba Al00 Firmware MEDIUM 5.5
CVE-2022-48305

There is an identity authentication bypass vulnerability in Huawei Children Smart Watch (Simba-AL00) 1.1.1.274. Successful exploitation of this vulne…

Mitigation only
Fix from $1,600 2023-02-27
Aremis 4 Nomads HIGH 7.5
CVE-2022-34908

An issue was discovered in the A4N (Aremis 4 Nomad) application 1.5.0 for Android. It possesses an authentication mechanism; however, some features d…

Fix: 1.5.1+
Fix from $1,950 2023-02-27
A210 G Firmware CRITICAL 9.8
CVE-2023-24093

An access control issue in H3C A210-G A210-GV100R005 allows attackers to authenticate without a password.

No fix yet
Fix from $2,300 2023-02-22
Dynosaur Rails CRITICAL 9.8
CVE-2015-10083

A vulnerability has been found in harrystech Dynosaur-Rails and classified as critical. Affected by this vulnerability is the function basic_auth of …

Fix: 2015-09-15+
Fix from $2,300 2023-02-21
Employee Task Management System HIGH 7.5
CVE-2023-0905

A vulnerability classified as critical has been found in SourceCodester Employee Task Management System 1.0. Affected is an unknown function of the f…

No fix yet
Fix from $1,950 2023-02-18
System Usage Report HIGH 7.2
CVE-2022-32971

Improper authentication in the Intel(R) SUR software before version 2.4.8902 may allow a privileged user to potentially enable escalation of privileg…

Fix: 2.4.8902+
Fix from $1,950 2023-02-16
System Usage Report HIGH 7.8
CVE-2022-33946

Improper authentication in the Intel(R) SUR software before version 2.4.8902 may allow an authenticated user to potentially enable escalation of priv…

Fix: 2.4.8902+
Fix from $1,950 2023-02-16
Quartus Prime HIGH 7.8
CVE-2022-32570

Improper authentication in the Intel(R) Quartus Prime Pro and Standard edition software may allow an authenticated user to potentially enable escalat…

Fix: 22.1 / 22.2+
Fix from $1,950 2023-02-16
Server And Application Monitor HIGH 7.5
CVE-2022-47508

Customers who had configured their polling to occur via Kerberos did not expect NTLM Traffic on their environment, but since we were querying for dat…

Mitigation only
Fix from $1,950 2023-02-15
Priority CRITICAL 9.8
CVE-2023-23460

Priority Web version 19.1.0.68, parameter manipulation on an unspecified end-point may allow authentication bypass.

No fix yet
Fix from $2,300 2023-02-15
Windows 10 HIGH 7.8
CVE-2023-21817

Windows Kerberos Elevation of Privilege Vulnerability

Fix: 10.0.10240.19747 / 10.0.14393.5717+
Fix from $1,950 2023-02-14
Onenote MEDIUM 6.5
CVE-2023-21721

Microsoft OneNote Elevation of Privilege Vulnerability

Fix: 16.0.16026.20158+
Fix from $1,600 2023-02-14