Vulnerability index

Browse CVEs

4,337 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
HIGH 8.8 CVE-2024-41589 DrayTek Vigor310 devices through 4.3.2.6 use unencrypted HTTP for authentication requests. Vigor3910 Firmware after 4.3.2.6 Fix from $1,9502024-10-03 HIGH 8.1 CVE-2024-47806 Jenkins OpenId Connect Authentication Plugin 4.354.v321ce67a_1de8 and earlier does not check the `aud` (Audience) claim of an ID Token, allowing atta… Openid Connect Authentication 4.355.v3a_fb_fca_b_96d4+ Fix from $1,9502024-10-02 HIGH 8.1 CVE-2024-47807 Jenkins OpenId Connect Authentication Plugin 4.354.v321ce67a_1de8 and earlier does not check the `iss` (Issuer) claim of an ID Token, allowing attack… Openid Connect Authentication 4.355.v3a_fb_fca_b_96d4+ Fix from $1,9502024-10-02 CRITICAL 9.0 CVE-2024-47070 authentik is an open-source identity provider. A vulnerability that exists in versions prior to 2024.8.3 and 2024.6.5 allows bypassing password login… Authentik 2024.6.5 / 2024.8.3+ Fix from $2,3002024-09-27 MEDIUM 5.9 CVE-2024-47174 Nix is a package manager for Linux and other Unix systems. Starting in version 1.11 and prior to versions 2.18.8 and 2.24.8, `<nix/fetchurl.nix>` did… Patch available Fix from $1,6002024-09-26 MEDIUM 5.4 CVE-2024-47125 The goTenna Pro App does not authenticate public keys which allows an unauthenticated attacker to manipulate messages. It is advised to update your… Gotenna Pro 2.0.3+ Fix from $1,6002024-09-26 HIGH 7.3 CVE-2024-45750 An issue in TheGreenBow Windows Standard VPN Client 6.87.108 (and older), Windows Enterprise VPN Client 6.87.109 (and older), Windows Enterprise VPN … Mitigation only Fix from $1,9502024-09-25 CRITICAL 9.8 CVE-2024-47078 Meshtastic is an open source, off-grid, decentralized, mesh network. Meshtastic uses MQTT to communicate over an internet connection to a shared or p… Meshtastic Firmware 2.5.1+ Fix from $2,3002024-09-25 CRITICAL 9.8 CVE-2024-0002 A condition exists in FlashArray Purity whereby an attacker can employ a privileged account allowing remote access to the array. Purity\/\/fa after 6.4.10 Fix from $2,3002024-09-23 CRITICAL 9.8 CVE-2024-47218 An issue was discovered in vesoft NebulaGraph through 3.8.0. It allows bypassing authentication. Nebulagraph Database after 3.8.0 Fix from $2,3002024-09-22 MEDIUM 6.5 CVE-2022-25768 The logic in place to facilitate the update process via the user interface lacks access control to verify if permission exists to perform the tasks. … Mautic 4.4.13 / 5.1.1+ Fix from $1,6002024-09-18 CRITICAL 9.8 CVE-2024-34399 **UNSUPPORTED WHEN ASSIGNED** An issue was discovered in BMC Remedy Mid Tier 7.6.04. An unauthenticated remote attacker is able to access any user ac… Remedy Mid Tier Mitigation only Fix from $2,3002024-09-18 HIGH 8.8 CVE-2024-41929 Improper authentication vulnerability in multiple digital video recorders provided by TAKENAKA ENGINEERING CO., LTD. allows a remote authenticated at… Mitigation only Fix from $1,9502024-09-18 CRITICAL 9.1 CVE-2024-8956 KEVEPSS 61% PTZOptics PT30X-SDI/NDI-xx before firmware 6.3.40 is vulnerable to an insufficient authentication issue. The camera does not properly enforce authent… Pt30x Sdi Firmware 6.3.40+ Fix from $2,3002024-09-17 MEDIUM 5.3 CVE-2024-44202 An authentication issue was addressed with improved state management. This issue is fixed in Safari 18, iOS 18 and iPadOS 18. Private Browsing tabs m… Ipados 18.0+ Fix from $1,6002024-09-17 MEDIUM 5.3 CVE-2024-44127 This issue was addressed through improved state management. This issue is fixed in iOS 17.7 and iPadOS 17.7, iOS 18 and iPadOS 18. Private Browsing t… Ipados 17.7+ Fix from $1,6002024-09-17 HIGH 7.5 CVE-2024-45113 ColdFusion versions 2023.6, 2021.12 and earlier are affected by an Improper Authentication vulnerability that could result in privilege escalation. A… Coldfusion Mitigation only Fix from $1,9502024-09-13 CRITICAL 9.8 CVE-2024-45823 CVE-2024-45823 IMPACT An authentication bypass vulnerability exists in the affected product. The vulnerability exists due to shared secrets across… Factorytalk Batch View Mitigation only Fix from $2,3002024-09-12 HIGH 8.1 CVE-2024-8642 In Eclipse Dataspace Components, from version 0.5.0 and before version 0.9.0, the ConsumerPullTransferTokenValidationApiController does not check for… Eclipse Dataspace Components 0.9.0+ Fix from $1,9502024-09-11 CRITICAL 9.8 CVE-2024-38225 Microsoft Dynamics 365 Business Central Elevation of Privilege Vulnerability Dynamics 365 Business Central Patch available Fix from $2,3002024-09-10 CRITICAL 9.8 CVE-2023-37226 Loftware Spectrum before 4.6 HF14 has Missing Authentication for a Critical Function. Spectrum 4.6+ Fix from $2,3002024-09-10 HIGH 7.8 CVE-2024-40713 A vulnerability that allows a user who has been assigned a low-privileged role within Veeam Backup & Replication to alter Multi-Factor Authentication… Veeam Backup \& Replication 12.2.0.334+ Fix from $1,9502024-09-07 HIGH 8.8 CVE-2023-45038 An improper authentication vulnerability has been reported to affect Music Station. If exploited, the vulnerability could allow users to compromise t… Music Station 5.4.0+ Fix from $1,9502024-09-06 MEDIUM 5.3 CVE-2024-5956 This vulnerability allows unauthenticated remote attackers to bypass authentication and gain partial data access to the vulnerable Trellix IPS Manage… Intrusion Prevention System Manager Mitigation only Fix from $1,6002024-09-05 HIGH 7.5 CVE-2024-5957 This vulnerability allows unauthenticated remote attackers to bypass authentication and gain APIs access of the Manager. Intrusion Prevention System Manager 11.1.7.97+ Fix from $1,9502024-09-05 MEDIUM 5.3 CVE-2024-44821 ZZCMS 2023 contains a vulnerability in the captcha reuse logic located in /inc/function.php. The checkyzm function does not properly refresh the capt… Zzcms after 2023 Fix from $1,6002024-09-04 CRITICAL 9.8 CVE-2024-7012 An authentication bypass vulnerability has been identified in Foreman when deployed with External Authentication, due to the puppet-foreman configura… Satellite Mitigation only Fix from $2,3002024-09-04 CRITICAL 9.8 CVE-2024-7923 An authentication bypass vulnerability has been identified in Pulpcore when deployed with Gunicorn versions prior to 22.0, due to the puppet-pulpcore… Satellite Mitigation only Fix from $2,3002024-09-04 HIGH 7.5 CVE-2024-7870 The PixelYourSite – Your smart PIXEL (TAG) & API Manager and the PixelYourSite PRO plugins for WordPress are vulnerable to Sensitive Information Expo… Pixelyoursite 9.7.2 / 10.4.3+ Fix from $1,9502024-09-04 HIGH 8.1 CVE-2024-7745 In WS_FTP Server versions before 8.8.8 (2022.0.8), a Missing Critical Step in Multi-Factor Authentication of the Web Transfer Module allows users to … Ws Ftp Server 8.8.8+ Fix from $1,9502024-08-28