Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 8.8
CVE-2024-41589
DrayTek Vigor310 devices through 4.3.2.6 use unencrypted HTTP for authentication requests.
Vigor3910 Firmware
after 4.3.2.6
HIGH 8.1
CVE-2024-47806
Jenkins OpenId Connect Authentication Plugin 4.354.v321ce67a_1de8 and earlier does not check the `aud` (Audience) claim of an ID Token, allowing atta…
Openid Connect Authentication
4.355.v3a_fb_fca_b_96d4+
HIGH 8.1
CVE-2024-47807
Jenkins OpenId Connect Authentication Plugin 4.354.v321ce67a_1de8 and earlier does not check the `iss` (Issuer) claim of an ID Token, allowing attack…
Openid Connect Authentication
4.355.v3a_fb_fca_b_96d4+
CRITICAL 9.0
CVE-2024-47070
authentik is an open-source identity provider. A vulnerability that exists in versions prior to 2024.8.3 and 2024.6.5 allows bypassing password login…
Authentik
2024.6.5 / 2024.8.3+
MEDIUM 5.9
CVE-2024-47174
Nix is a package manager for Linux and other Unix systems. Starting in version 1.11 and prior to versions 2.18.8 and 2.24.8, `<nix/fetchurl.nix>` did…
Patch available
MEDIUM 5.4
CVE-2024-47125
The goTenna Pro App does not authenticate public keys which allows an
unauthenticated attacker to manipulate messages. It is advised to update
your…
Gotenna Pro
2.0.3+
HIGH 7.3
CVE-2024-45750
An issue in TheGreenBow Windows Standard VPN Client 6.87.108 (and older), Windows Enterprise VPN Client 6.87.109 (and older), Windows Enterprise VPN …
Mitigation only
CRITICAL 9.8
CVE-2024-47078
Meshtastic is an open source, off-grid, decentralized, mesh network. Meshtastic uses MQTT to communicate over an internet connection to a shared or p…
Meshtastic Firmware
2.5.1+
CRITICAL 9.8
CVE-2024-0002
A condition exists in FlashArray Purity whereby an attacker can employ a privileged account allowing remote access to the array.
Purity\/\/fa
after 6.4.10
CRITICAL 9.8
CVE-2024-47218
An issue was discovered in vesoft NebulaGraph through 3.8.0. It allows bypassing authentication.
Nebulagraph Database
after 3.8.0
MEDIUM 6.5
CVE-2022-25768
The logic in place to facilitate the update process via the user interface lacks access control to verify if permission exists to perform the tasks. …
Mautic
4.4.13 / 5.1.1+
CRITICAL 9.8
CVE-2024-34399
**UNSUPPORTED WHEN ASSIGNED** An issue was discovered in BMC Remedy Mid Tier 7.6.04. An unauthenticated remote attacker is able to access any user ac…
Remedy Mid Tier
Mitigation only
HIGH 8.8
CVE-2024-41929
Improper authentication vulnerability in multiple digital video recorders provided by TAKENAKA ENGINEERING CO., LTD. allows a remote authenticated at…
Mitigation only
CRITICAL 9.1
CVE-2024-8956 KEVEPSS 61%
PTZOptics PT30X-SDI/NDI-xx before firmware 6.3.40 is vulnerable to an insufficient authentication issue. The camera does not properly enforce authent…
Pt30x Sdi Firmware
6.3.40+
MEDIUM 5.3
CVE-2024-44202
An authentication issue was addressed with improved state management. This issue is fixed in Safari 18, iOS 18 and iPadOS 18. Private Browsing tabs m…
Ipados
18.0+
MEDIUM 5.3
CVE-2024-44127
This issue was addressed through improved state management. This issue is fixed in iOS 17.7 and iPadOS 17.7, iOS 18 and iPadOS 18. Private Browsing t…
Ipados
17.7+
HIGH 7.5
CVE-2024-45113
ColdFusion versions 2023.6, 2021.12 and earlier are affected by an Improper Authentication vulnerability that could result in privilege escalation. A…
Coldfusion
Mitigation only
CRITICAL 9.8
CVE-2024-45823
CVE-2024-45823 IMPACT
An
authentication bypass vulnerability exists in the affected product. The
vulnerability exists due to shared secrets across…
Factorytalk Batch View
Mitigation only
HIGH 8.1
CVE-2024-8642
In Eclipse Dataspace Components, from version 0.5.0 and before version 0.9.0, the ConsumerPullTransferTokenValidationApiController does not check for…
Eclipse Dataspace Components
0.9.0+
CRITICAL 9.8
CVE-2024-38225
Microsoft Dynamics 365 Business Central Elevation of Privilege Vulnerability
Dynamics 365 Business Central
Patch available
CRITICAL 9.8
CVE-2023-37226
Loftware Spectrum before 4.6 HF14 has Missing Authentication for a Critical Function.
Spectrum
4.6+
HIGH 7.8
CVE-2024-40713
A vulnerability that allows a user who has been assigned a low-privileged role within Veeam Backup & Replication to alter Multi-Factor Authentication…
Veeam Backup \& Replication
12.2.0.334+
HIGH 8.8
CVE-2023-45038
An improper authentication vulnerability has been reported to affect Music Station. If exploited, the vulnerability could allow users to compromise t…
Music Station
5.4.0+
MEDIUM 5.3
CVE-2024-5956
This vulnerability allows unauthenticated remote attackers to bypass authentication and gain partial data access to the vulnerable Trellix IPS Manage…
Intrusion Prevention System Manager
Mitigation only
HIGH 7.5
CVE-2024-5957
This vulnerability allows unauthenticated remote attackers to bypass authentication and gain APIs access of the Manager.
Intrusion Prevention System Manager
11.1.7.97+
MEDIUM 5.3
CVE-2024-44821
ZZCMS 2023 contains a vulnerability in the captcha reuse logic located in /inc/function.php. The checkyzm function does not properly refresh the capt…
Zzcms
after 2023
CRITICAL 9.8
CVE-2024-7012
An authentication bypass vulnerability has been identified in Foreman when deployed with External Authentication, due to the puppet-foreman configura…
Satellite
Mitigation only
CRITICAL 9.8
CVE-2024-7923
An authentication bypass vulnerability has been identified in Pulpcore when deployed with Gunicorn versions prior to 22.0, due to the puppet-pulpcore…
Satellite
Mitigation only
HIGH 7.5
CVE-2024-7870
The PixelYourSite – Your smart PIXEL (TAG) & API Manager and the PixelYourSite PRO plugins for WordPress are vulnerable to Sensitive Information Expo…
Pixelyoursite
9.7.2 / 10.4.3+
HIGH 8.1
CVE-2024-7745
In WS_FTP Server versions before 8.8.8 (2022.0.8), a Missing Critical Step in Multi-Factor Authentication of the Web Transfer Module allows users to …
Ws Ftp Server
8.8.8+