Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 8.7
CVE-2024-1609
In OPPOStore iOS App, there's a possible escalation of privilege due to improper input validation.
No fix yet
HIGH 8.1
CVE-2023-31279
The AirVantage platform is vulnerable to an unauthorized attacker registering previously unregistered
devices on the AirVantage platform when the ow…
Mitigation only
HIGH 7.5
CVE-2024-56335
vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. In affected versions an attacker is capable…
Vaultwarden
1.32.7+
HIGH 8.9
CVE-2024-56329
Socialstream is a third-party package for Laravel Jetstream. It replaces the published authentication and profile scaffolding provided by Laravel Jet…
Patch available
CRITICAL 9.8
CVE-2024-12287
The Biagiotti Membership plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1.0.2. This is due to the …
Mitigation only
CRITICAL 9.8
CVE-2024-1610
In OPPO Store APP, there's a possible escalation of privilege due to improper input validation.
Mitigation only
HIGH 7.1
CVE-2024-21543
Versions of the package djoser before 2.3.0 are vulnerable to Authentication Bypass when the authenticate() function fails. This is because the syste…
Patch available
MEDIUM 6.9
CVE-2024-55886
OpenSearch Data Prepper is a component of the OpenSearch project that accepts, filters, transforms, enriches, and routes data at scale. A vulnerabili…
Opensearch Data Prepper
2.10.2+
HIGH 8.1
CVE-2024-10111
The OAuth Single Sign On – SSO (OAuth Client) plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 6.26.…
Mitigation only
CRITICAL 9.8
CVE-2024-11015
The Sign In With Google plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1.8.0. This is due to the '…
Mitigation only
MEDIUM 5.3
CVE-2024-50339EPSS 20%
GLPI is a free asset and IT management software package. Starting in version 9.5.0 and prior to version 10.0.17, an unauthenticated user can retrieve…
Glpi
10.0.17+
HIGH 7.8
CVE-2024-49076
Windows Virtualization-Based Security (VBS) Enclave Elevation of Privilege Vulnerability
Windows 10 1809
10.0.17763.6659 / 10.0.19044.5247+
HIGH 8.1
CVE-2024-45404
OpenCTI is an open-source cyber threat intelligence platform. In versions below 6.2.18, because the function to limit the rate of OTP does not exist,…
Opencti
6.2.18+
HIGH 7.2
CVE-2024-47761
GLPI is a free asset and IT management software package. Starting in version 0.80 and prior to version 10.0.17, an administrator with access to the s…
Glpi
10.0.17+
MEDIUM 5.3
CVE-2024-10511
CWE-287: Improper Authentication vulnerability exists that could cause Denial of access to the web interface
when someone on the local network repeat…
No fix yet
HIGH 8.8
CVE-2024-0130
NVIDIA UFM Enterprise, UFM Appliance, and UFM CyberAI contain a vulnerability where an attacker can cause an improper authentication issue by sending…
No fix yet
CRITICAL 9.1
CVE-2024-48859
An improper authentication vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could al…
Qts
Mitigation only
HIGH 8.1
CVE-2024-11293
The Registration Forms – User Registration Forms, Invitation-Based Registrations, Front-end User Profile, Login Form & Content Restriction Social Si…
Mitigation only
HIGH 8.1
CVE-2024-45106
Improper authentication of an HTTP endpoint in the S3 Gateway of Apache Ozone 1.4.0 allows any authenticated Kerberos user to revoke and regenerate t…
Ozone
Mitigation only
CRITICAL 9.2
CVE-2024-53990
The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. When making any…
Patch available
HIGH 7.8
CVE-2018-11952
An image with a version lower than the fuse version may potentially be booted lead to improper authentication.
Mdm9206 Firmware
No fix yet
HIGH 7.8
CVE-2016-10394
Initial xbl_sec revision does not have all the debug policy features and critical checks.
Mdm9206 Firmware
No fix yet
MEDIUM 5.4
CVE-2024-11671
Improper authentication in SQL data source MFA validation in Devolutions Remote Desktop Manager 2024.3.17 and earlier on Windows allows an authentica…
Remote Desktop Manager
2024.3.18.0+
MEDIUM 6.7
CVE-2022-33862
IPP software prior to v1.71 is vulnerable to default credential vulnerability. This could
lead attackers to identify and access vulnerable systems.
Mitigation only
HIGH 8.1
CVE-2024-45369
The web application uses a weak authentication mechanism to verify that a request is coming from an authenticated and authorized resource.
Mitigation only
HIGH 7.5
CVE-2024-6248
Wyze Cam v3 Cloud Infrastructure Improper Authentication Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to…
Cam V3 Firmware
4.36.11.8391+
HIGH 7.5
CVE-2024-11494
**UNSUPPORTED WHEN ASSIGNED** The improper authentication vulnerability in the Zyxel P-6101C ADSL modem firmware version P-6101CSA6AP_20140331 could …
P6101c Firmware
No fix yet
CRITICAL 9.8
CVE-2024-47533
Cobbler, a Linux installation server that allows for rapid setup of network installation environments, has an improper authentication vulnerability s…
Patch available
MEDIUM 5.4
CVE-2024-52518
Nextcloud Server is a self hosted personal cloud system. After an attacker got access to the session of a user or administrator, the attacker would b…
Nextcloud Server
28.0.12 / 29.0.9+
CRITICAL 9.8
CVE-2024-11209
A vulnerability was found in Apereo CAS 6.6. It has been classified as critical. This affects an unknown part of the file /login?service of the compo…
Central Authentication Service
No fix yet