Top technology
Linux 13140
Google 12530
Microsoft 12379
Oracle 6737
Apple 6692
Adobe 6387
Ibm 6330
Cisco 5757
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 5.3
CVE-2024-44821
ZZCMS 2023 contains a vulnerability in the captcha reuse logic located in /inc/function.php. The checkyzm function does not properly refresh the capt…
Zzcms
after 2023
CRITICAL 9.8
CVE-2024-7012
An authentication bypass vulnerability has been identified in Foreman when deployed with External Authentication, due to the puppet-foreman configura…
Satellite
Mitigation only
CRITICAL 9.8
CVE-2024-7923
An authentication bypass vulnerability has been identified in Pulpcore when deployed with Gunicorn versions prior to 22.0, due to the puppet-pulpcore…
Satellite
Mitigation only
HIGH 7.5
CVE-2024-7870
The PixelYourSite – Your smart PIXEL (TAG) & API Manager and the PixelYourSite PRO plugins for WordPress are vulnerable to Sensitive Information Expo…
Pixelyoursite
9.7.2 / 10.4.3+
HIGH 8.1
CVE-2024-7745
In WS_FTP Server versions before 8.8.8 (2022.0.8), a Missing Critical Step in Multi-Factor Authentication of the Web Transfer Module allows users to …
Ws Ftp Server
8.8.8+
HIGH 8.8
CVE-2024-45346
The Xiaomi Security Center expresses heartfelt thanks to Ken Gannon and Ilyes Beghdadi of NCC Group working with Trend Micro Zero Day Initiative! At …
No fix yet
HIGH 8.1
CVE-2024-8181EPSS 45%
An Authentication Bypass vulnerability exists in Flowise version 1.8.2. This could allow a remote, unauthenticated attacker to access API endpoints a…
Flowise
Mitigation only
HIGH 7.5
CVE-2024-7401
Netskope was notified about a security gap in Netskope Client enrollment process where NSClient is using a static token “Orgkey” as authentication pa…
Netskope
Mitigation only
HIGH 8.1
CVE-2024-36444
cgi-bin/fdmcgiwebv2.cgi on Swissphone DiCal-RED 4009 devices allows an unauthenticated attacker to gain access to device logs.
Mitigation only
MEDIUM 6.5
CVE-2024-43409
Ghost is a Node.js content management system. Improper authentication on some endpoints used for member actions would allow an attacker to perform me…
Ghost
5.89.5+
CRITICAL 9.8
CVE-2024-42336
Servision - CWE-287: Improper Authentication
Ivg Webmax
Mitigation only
HIGH 7.5
CVE-2024-38810
Missing Authorization When Using @AuthorizeReturnObject in Spring Security 6.3.0 and 6.3.1 allows attacker to render security annotations inaffective.
Spring Security
6.3.2+
CRITICAL 9.8
CVE-2024-43240
Improper Authentication vulnerability in azzaroco Ultimate Membership Pro indeed-membership-pro.This issue affects Ultimate Membership Pro: from n/a …
Ultimate Membership Pro
after 12.6
CRITICAL 9.8
CVE-2024-42462
Improper Authentication vulnerability in upKeeper Solutions product upKeeper Manager allows Authentication Bypass.This issue affects upKeeper Manager…
Upkeeper Manager
5.1.10+
MEDIUM 6.8
CVE-2024-31800
Authentication Bypass in GNCC's GC2 Indoor Security Camera 1080P allows an attacker with physical access to gain a privileged command shell via the U…
Gncc C2 Firmware
No fix yet
HIGH 8.6
CVE-2024-6078
CVE-2024-6078 IMPACT
An improper authentication vulnerability exists in the affected product, which could allow a malicious user to generate cookies…
Mitigation only
MEDIUM 5.3
CVE-2024-37028
BIG-IP Next Central Manager may allow an attacker to lock out an account that has never been logged in. Note: Software versions which have reached E…
Big Ip Next Central Manager
20.2.1+
MEDIUM 6.5
CVE-2024-25157
An authentication bypass vulnerability in GoAnywhere MFT prior to 7.6.0 allows Admin Users with access to the Agent Console to circumvent some permis…
Goanywhere Managed File Transfer
7.6.0+
CRITICAL 9.8
CVE-2024-7593 KEVEPSS 100%
Incorrect implementation of an authentication algorithm in Ivanti vTM other than versions 22.2R1 or 22.7R2 allows a remote unauthenticated attacker t…
Virtual Traffic Manager
Patch available
CRITICAL 9.8
CVE-2024-7746
Use of Default Credentials vulnerability in Tananaev Solutions Traccar Server on Administrator Panel modules allows Authentication Abuse.This issue a…
Traccar
after 6.0
MEDIUM 5.9
CVE-2024-35775
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting'), Improper Authentication vulnerability in Soliloquy Team …
Mitigation only
MEDIUM 5.4
CVE-2024-4784
An issue was discovered in GitLab EE starting from version 16.7 before 17.0.6, version 17.1 before 17.1.4 and 17.2 before 17.2.2 that allowed bypassi…
GitLab
17.0.6 / 17.1.4+
HIGH 7.8
CVE-2024-42038
Vulnerability of PIN enhancement failures in the screen lock module
Impact: Successful exploitation of this vulnerability may affect service confiden…
Emui
Mitigation only
HIGH 7.5
CVE-2024-36132
Insufficient verification of authentication controls in EPMM prior to 12.1.0.1 allows a remote attacker to bypass authentication and access sensitive…
Endpoint Manager Mobile
12.1.0.1+
MEDIUM 6.5
CVE-2024-34788
An improper authentication vulnerability in web component of EPMM prior to 12.1.0.1 allows a remote malicious user to access potentially sensitive in…
Endpoint Manager Mobile
12.1.0.1+
CRITICAL 9.8
CVE-2024-36130
An insufficient authorization vulnerability in web component of EPMM prior to 12.1.0.1 allows an unauthorized attacker within the network to execute …
Endpoint Manager Mobile
12.1.0.1+
CRITICAL 9.3
CVE-2024-7395
An authentication bypass vulnerability in Korenix JetPort 5601v3 allows an attacker to access functionality on the device without specifying a passwo…
Mitigation only
HIGH 7.3
CVE-2022-4001
An authentication bypass vulnerability could allow an attacker to access API functions without authentication.
Mitigation only
HIGH 7.2
CVE-2022-4002
A command injection vulnerability could allow an authenticated user to execute operating system commands as root via a specially crafted API request.
Q14 Firmware
1.5.0.16+
HIGH 7.8
CVE-2019-6197
A vulnerability was reported in Lenovo PC Manager prior to version 2.8.90.11211 that could allow a local attacker to escalate privileges.
Pcmanager
2.8.90.11211+