Vulnerability index

Browse CVEs

4,342 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
MEDIUM 5.3 CVE-2024-44821 ZZCMS 2023 contains a vulnerability in the captcha reuse logic located in /inc/function.php. The checkyzm function does not properly refresh the capt… Zzcms after 2023 Fix from $1,6002024-09-04 CRITICAL 9.8 CVE-2024-7012 An authentication bypass vulnerability has been identified in Foreman when deployed with External Authentication, due to the puppet-foreman configura… Satellite Mitigation only Fix from $2,3002024-09-04 CRITICAL 9.8 CVE-2024-7923 An authentication bypass vulnerability has been identified in Pulpcore when deployed with Gunicorn versions prior to 22.0, due to the puppet-pulpcore… Satellite Mitigation only Fix from $2,3002024-09-04 HIGH 7.5 CVE-2024-7870 The PixelYourSite – Your smart PIXEL (TAG) & API Manager and the PixelYourSite PRO plugins for WordPress are vulnerable to Sensitive Information Expo… Pixelyoursite 9.7.2 / 10.4.3+ Fix from $1,9502024-09-04 HIGH 8.1 CVE-2024-7745 In WS_FTP Server versions before 8.8.8 (2022.0.8), a Missing Critical Step in Multi-Factor Authentication of the Web Transfer Module allows users to … Ws Ftp Server 8.8.8+ Fix from $1,9502024-08-28 HIGH 8.8 CVE-2024-45346 The Xiaomi Security Center expresses heartfelt thanks to Ken Gannon and Ilyes Beghdadi of NCC Group working with Trend Micro Zero Day Initiative! At … No fix yet Fix from $1,9502024-08-28 HIGH 8.1 CVE-2024-8181EPSS 45% An Authentication Bypass vulnerability exists in Flowise version 1.8.2. This could allow a remote, unauthenticated attacker to access API endpoints a… Flowise Mitigation only Fix from $1,9502024-08-27 HIGH 7.5 CVE-2024-7401 Netskope was notified about a security gap in Netskope Client enrollment process where NSClient is using a static token “Orgkey” as authentication pa… Netskope Mitigation only Fix from $1,9502024-08-26 HIGH 8.1 CVE-2024-36444 cgi-bin/fdmcgiwebv2.cgi on Swissphone DiCal-RED 4009 devices allows an unauthenticated attacker to gain access to device logs. Mitigation only Fix from $1,9502024-08-22 MEDIUM 6.5 CVE-2024-43409 Ghost is a Node.js content management system. Improper authentication on some endpoints used for member actions would allow an attacker to perform me… Ghost 5.89.5+ Fix from $1,6002024-08-20 CRITICAL 9.8 CVE-2024-42336 Servision - CWE-287: Improper Authentication Ivg Webmax Mitigation only Fix from $2,3002024-08-20 HIGH 7.5 CVE-2024-38810 Missing Authorization When Using @AuthorizeReturnObject in Spring Security 6.3.0 and 6.3.1 allows attacker to render security annotations inaffective. Spring Security 6.3.2+ Fix from $1,9502024-08-20 CRITICAL 9.8 CVE-2024-43240 Improper Authentication vulnerability in azzaroco Ultimate Membership Pro indeed-membership-pro.This issue affects Ultimate Membership Pro: from n/a … Ultimate Membership Pro after 12.6 Fix from $2,3002024-08-19 CRITICAL 9.8 CVE-2024-42462 Improper Authentication vulnerability in upKeeper Solutions product upKeeper Manager allows Authentication Bypass.This issue affects upKeeper Manager… Upkeeper Manager 5.1.10+ Fix from $2,3002024-08-16 MEDIUM 6.8 CVE-2024-31800 Authentication Bypass in GNCC's GC2 Indoor Security Camera 1080P allows an attacker with physical access to gain a privileged command shell via the U… Gncc C2 Firmware No fix yet Fix from $1,6002024-08-15 HIGH 8.6 CVE-2024-6078 CVE-2024-6078 IMPACT An improper authentication vulnerability exists in the affected product, which could allow a malicious user to generate cookies… Mitigation only Fix from $1,9502024-08-14 MEDIUM 5.3 CVE-2024-37028 BIG-IP Next Central Manager may allow an attacker to lock out an account that has never been logged in.  Note: Software versions which have reached E… Big Ip Next Central Manager 20.2.1+ Fix from $1,6002024-08-14 MEDIUM 6.5 CVE-2024-25157 An authentication bypass vulnerability in GoAnywhere MFT prior to 7.6.0 allows Admin Users with access to the Agent Console to circumvent some permis… Goanywhere Managed File Transfer 7.6.0+ Fix from $1,6002024-08-14 CRITICAL 9.8 CVE-2024-7593 KEVEPSS 100% Incorrect implementation of an authentication algorithm in Ivanti vTM other than versions 22.2R1 or 22.7R2 allows a remote unauthenticated attacker t… Virtual Traffic Manager Patch available Fix from $2,3002024-08-13 CRITICAL 9.8 CVE-2024-7746 Use of Default Credentials vulnerability in Tananaev Solutions Traccar Server on Administrator Panel modules allows Authentication Abuse.This issue a… Traccar after 6.0 Fix from $2,3002024-08-13 MEDIUM 5.9 CVE-2024-35775 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting'), Improper Authentication vulnerability in Soliloquy Team … Mitigation only Fix from $1,6002024-08-12 MEDIUM 5.4 CVE-2024-4784 An issue was discovered in GitLab EE starting from version 16.7 before 17.0.6, version 17.1 before 17.1.4 and 17.2 before 17.2.2 that allowed bypassi… GitLab 17.0.6 / 17.1.4+ Fix from $1,6002024-08-08 HIGH 7.8 CVE-2024-42038 Vulnerability of PIN enhancement failures in the screen lock module Impact: Successful exploitation of this vulnerability may affect service confiden… Emui Mitigation only Fix from $1,9502024-08-08 HIGH 7.5 CVE-2024-36132 Insufficient verification of authentication controls in EPMM prior to 12.1.0.1 allows a remote attacker to bypass authentication and access sensitive… Endpoint Manager Mobile 12.1.0.1+ Fix from $1,9502024-08-07 MEDIUM 6.5 CVE-2024-34788 An improper authentication vulnerability in web component of EPMM prior to 12.1.0.1 allows a remote malicious user to access potentially sensitive in… Endpoint Manager Mobile 12.1.0.1+ Fix from $1,6002024-08-07 CRITICAL 9.8 CVE-2024-36130 An insufficient authorization vulnerability in web component of EPMM prior to 12.1.0.1 allows an unauthorized attacker within the network to execute … Endpoint Manager Mobile 12.1.0.1+ Fix from $2,3002024-08-07 CRITICAL 9.3 CVE-2024-7395 An authentication bypass vulnerability in Korenix JetPort 5601v3 allows an attacker to access functionality on the device without specifying a passwo… Mitigation only Fix from $2,3002024-08-05 HIGH 7.3 CVE-2022-4001 An authentication bypass vulnerability could allow an attacker to access API functions without authentication. Mitigation only Fix from $1,9502024-07-31 HIGH 7.2 CVE-2022-4002 A command injection vulnerability could allow an authenticated user to execute operating system commands as root via a specially crafted API request. Q14 Firmware 1.5.0.16+ Fix from $1,9502024-07-31 HIGH 7.8 CVE-2019-6197 A vulnerability was reported in Lenovo PC Manager prior to version 2.8.90.11211 that could allow a local attacker to escalate privileges. Pcmanager 2.8.90.11211+ Fix from $1,9502024-07-31