Vulnerability index

Browse CVEs

4,337 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
HIGH 7.5 CVE-2024-51996 Symphony process is a module for the Symphony PHP framework which executes commands in sub-processes. When consuming a persisted remember-me cookie, … Patch available Fix from $1,9502024-11-13 HIGH 8.8 CVE-2024-49039 KEVEPSS 14% Windows Task Scheduler Elevation of Privilege Vulnerability Windows 10 1507 10.0.10240.20826 / 10.0.14393.7515+ Fix from $1,9502024-11-12 HIGH 8.1 CVE-2024-51997 Trustee is a set of tools and components for attesting confidential guests and providing secrets to them. The ART (**Attestation Results Token**) tok… Mitigation only Fix from $1,9502024-11-08 HIGH 7.4 CVE-2024-10963 A flaw was found in pam_access, where certain rules in its configuration file are mistakenly treated as hostnames. This vulnerability allows attacker… Patch available Fix from $1,9502024-11-07 HIGH 8.1 CVE-2024-9946 The Social Share, Social Login and Social Comments Plugin – Super Socializer plugin for WordPress is vulnerable to authentication bypass in all versi… Super Socializer 7.14+ Fix from $1,9502024-11-06 HIGH 8.1 CVE-2024-10020 The Heateor Social Login WordPress plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1.1.35. This is … Social Login 1.1.36+ Fix from $1,9502024-11-06 HIGH 8.8 CVE-2023-29117 Waybox Enel X web management API authentication could be bypassed and provide administrator’s privileges over the Waybox system. Waybox Pro Firmware 2.1.1.0_jb3vu096a+ Fix from $1,9502024-11-05 HIGH 8.1 CVE-2024-10114 The WooCommerce - Social Login plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 2.7.7. This is due t… Woocommerce Social Login 2.7.8+ Fix from $1,9502024-11-05 HIGH 8.1 CVE-2024-10097 The Loginizer Security and Loginizer plugins for WordPress are vulnerable to authentication bypass in all versions up to, and including, 1.9.2. This … Loginizer 1.9.3+ Fix from $1,9502024-11-05 MEDIUM 5.3 CVE-2024-10620 A vulnerability was found in knightliao Disconf 2.6.36. It has been classified as critical. This affects an unknown part of the file /api/config/list… Mitigation only Fix from $1,6002024-11-01 MEDIUM 6.5 CVE-2024-10474 Focus was incorrectly allowing internal links to utilize the app scheme used for deeplinking, which could result in links potentially circumventing s… Firefox Focus 132.0+ Fix from $1,6002024-10-29 CRITICAL 9.8 CVE-2024-50478 Authentication Bypass by Primary Weakness vulnerability in Swoop 1-Click Login: Passwordless Authentication allows Authentication Bypass.This issue a… 1 Click Login\ Mitigation only Fix from $2,3002024-10-28 HIGH 8.8 CVE-2024-49376 Autolab, a course management service that enables auto-graded programming assignments, has misconfigured reset password permissions in version 3.0.0.… Autolab Patch available Fix from $1,9502024-10-25 HIGH 7.5 CVE-2024-7763 In WhatsUp Gold versions released before 2024.0.0,  an Authentication Bypass issue exists which allows an attacker to obtain encrypted user credenti… Whatsup Gold 24.0+ Fix from $1,9502024-10-24 HIGH 8.1 CVE-2024-10327 A vulnerability in Okta Verify for iOS versions 9.25.1 (beta) and 9.27.0 (including beta) allows push notification responses through the iOS ContextE… Mitigation only Fix from $1,9502024-10-24 CRITICAL 9.8 CVE-2024-9947 The ProfilePress Pro plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 4.11.1. This is due to insuffi… Profilepress 4.11.2+ Fix from $2,3002024-10-23 HIGH 7.2 CVE-2024-9927 The WooCommerce Order Proposal plugin for WordPress is vulnerable to privilege escalation via order proposal in all versions up to and including 2.0.… Woocommerce Order Proposal 2.0.6+ Fix from $1,9502024-10-23 HIGH 7.5 CVE-2024-10173 A vulnerability has been found in didi DDMQ 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the compone… Ddmq No fix yet Fix from $1,9502024-10-20 MEDIUM 5.3 CVE-2024-9683 A vulnerability was found in Quay, which allows successful authentication even when a truncated password version is provided. This flaw affects the a… Quay Mitigation only Fix from $1,6002024-10-17 HIGH 8.8 CVE-2023-22650 A vulnerability has been identified in which Rancher does not automatically clean up a user which has been deleted from the configured authentication… Mitigation only Fix from $1,9502024-10-16 CRITICAL 9.8 CVE-2024-45216EPSS 91% Improper Authentication vulnerability in Apache Solr. Solr instances using the PKIAuthenticationPlugin, which is enabled by default when Solr Authen… Solr 8.11.4 / 9.7.0+ Fix from $2,3002024-10-16 CRITICAL 9.8 CVE-2020-36832 The Ultimate Membership Pro plugin for WordPress is vulnerable to Authentication Bypass in versions between, and including, 7.3 to 8.6. This makes it… Mitigation only Fix from $2,3002024-10-16 HIGH 8.8 CVE-2024-38139 Improper authentication in Microsoft Dataverse allows an authorized attacker to elevate privileges over a network. Dataverse Patch available Fix from $1,9502024-10-15 HIGH 8.7 CVE-2024-47080 matrix-js-sdk is the Matrix Client-Server SDK for JavaScript and TypeScript. In matrix-js-sdk versions versions 9.11.0 through 34.7.0, the method `Ma… Patch available Fix from $1,9502024-10-15 HIGH 8.8 CVE-2024-45148 Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Authentication vulnerability that could resul… Commerce Mitigation only Fix from $1,9502024-10-10 CRITICAL 9.8 CVE-2024-45115 Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Authentication vulnerability that could resul… Commerce Mitigation only Fix from $2,3002024-10-10 CRITICAL 9.0 CVE-2024-38124 Windows Netlogon Elevation of Privilege Vulnerability Windows Server 2008 10.0.14393.7428 / 10.0.17763.6414+ Fix from $2,3002024-10-08 CRITICAL 9.8 CVE-2024-41798 A vulnerability has been identified in SENTRON 7KM PAC3200 (All versions). Affected devices only provide a 4-digit PIN to protect from administrative… Mitigation only Fix from $2,3002024-10-08 HIGH 8.2 CVE-2024-45051 Discourse is an open source platform for community discussion. A maliciously crafted email address could allow an attacker to bypass domain-based res… Discourse 3.3.2 / 3.4.0+ Fix from $1,9502024-10-07 HIGH 8.1 CVE-2024-47768 Lif Authentication Server is a server used by Lif to do various tasks regarding Lif accounts. This vulnerability has to do with the account recovery … Lif Authentication Server 1.7.3+ Fix from $1,9502024-10-04