Top technology
Linux 13140
Google 12530
Microsoft 12379
Oracle 6737
Apple 6692
Adobe 6387
Ibm 6330
Cisco 5757
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.8
CVE-2019-6198
A vulnerability was reported in Lenovo PC Manager prior to version 2.8.90.11211 that could allow a local attacker to escalate privileges.
Pcmanager
2.8.90.11211+
MEDIUM 5.3
CVE-2024-40794
This issue was addressed through improved state management. This issue is fixed in Safari 17.6, iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6. Private …
Safari
14.6 / 17.6+
CRITICAL 9.8
CVE-2024-6576
Improper Authentication vulnerability in Progress MOVEit Transfer (SFTP module) can lead to Privilege Escalation.This issue affects MOVEit Transfer: …
Moveit Transfer
2023.0.12 / 2023.1.7+
HIGH 8.3
CVE-2024-7050
Improper Authentication vulnerability in OpenText OpenText Directory Services may allow Multi-factor Authentication Bypass in particular scenarios.Th…
Mitigation only
HIGH 7.5
CVE-2024-41800
Craft is a content management system (CMS). Craft CMS 5 allows reuse of TOTP tokens multiple times within the validity period. An attacker is able to…
Craft Cms
5.2.3+
HIGH 7.5
CVE-2024-41829
In JetBrains TeamCity before 2024.07 an OAuth code for JetBrains Space could be stolen via Space Application connection
Teamcity
2024.07+
MEDIUM 5.4
CVE-2024-40648
matrix-rust-sdk is an implementation of a Matrix client-server library in Rust. The `UserIdentity::is_verified()` method in the matrix-sdk-crypto cra…
Patch available
HIGH 8.3
CVE-2024-28992
The SolarWinds Access Rights Manager was susceptible to a Directory Traversal and Information Disclosure Vulnerability. This vulnerability allows an …
Access Rights Manager
after 2023.2.4
HIGH 8.8
CVE-2024-23470
The SolarWinds Access Rights Manager was found to be susceptible to a pre-authentication remote code execution vulnerability. If exploited, this vuln…
Access Rights Manager
after 2023.2.4
HIGH 8.8
CVE-2024-23471
The SolarWinds Access Rights Manager was found to be susceptible to a Remote Code Execution Vulnerability. If exploited, this vulnerability allows an…
Access Rights Manager
after 2023.2.4
HIGH 8.8
CVE-2024-23465
The SolarWinds Access Rights Manager was found to be susceptible to an authentication bypass vulnerability. This vulnerability allows an unauthentica…
Access Rights Manager
after 2023.2.4
MEDIUM 5.3
CVE-2024-6535
A flaw was found in Skupper. When Skupper is initialized with the console-enabled and with console-auth set to Openshift, it configures the openshift…
Service Interconnect
Mitigation only
CRITICAL 9.8
CVE-2024-22442
The vulnerability could be remotely exploited to bypass authentication.
3par Service Processor Firmware
5.1.2.0+
MEDIUM 6.5
CVE-2024-39767
Mattermost Mobile Apps versions <=2.16.0 fail to validate that the push notifications received for a server actually came from this serve that which …
Mattermost Mobile
2.17.0+
HIGH 8.8
CVE-2024-39340
The authentication system of Securepoint UTM mishandles OTP keys. This allows the bypassing of second-factor verification (when OTP is enabled) in bo…
Mitigation only
MEDIUM 6.7
CVE-2024-38433
Nuvoton - CWE-305: Authentication Bypass by Primary Weakness
An attacker with write access to the SPI-Flash on an NPCM7xx BMC subsystem that uses th…
Npcm750r Firmware
10.10.19+
CRITICAL 9.8
CVE-2024-6397
The InstaWP Connect – 1-click WP Staging & Migration plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including…
Instawp Connect
0.1.0.45+
HIGH 8.8
CVE-2024-6235EPSS 21%
Sensitive information disclosure in NetScaler Console
Netscaler Console
14.1-25.53+
MEDIUM 5.9
CVE-2024-38099
Windows Remote Desktop Licensing Service Denial of Service Vulnerability
Windows Server 2008
10.0.14393.7159 / 10.0.17763.6054+
MEDIUM 5.9
CVE-2024-39830
Mattermost versions 9.8.x <= 9.8.0, 9.7.x <= 9.7.4, 9.6.x <= 9.6.2 and 9.5.x <= 9.5.5, when shared channels are enabled, fail to use constant time co…
Mattermost
9.5.6 / 9.6.3+
HIGH 8.6
CVE-2024-3826
In versions of Akana in versions prior to and including 2022.1.3 validation is broken when using the SAML Single Sign-On (SSO) functionality.
No fix yet
HIGH 7.5
CVE-2024-34596
Improper authentication in SmartThings prior to version 1.8.17 allows remote attackers to bypass the expiration date for members set by the owner.
Smartthings
1.8.17+
HIGH 8.8
CVE-2024-20890
Improper input validation in BLE prior to SMR Jul-2024 Release 1 allows adjacent attackers to trigger abnormal behavior.
Android
Mitigation only
CRITICAL 9.8
CVE-2024-28200
The N-central server is vulnerable to an authentication bypass of the user interface. This vulnerability is present in all deployments of N-central p…
N Central
2024.2+
HIGH 7.5
CVE-2024-38523
Hush Line is a free and open-source, anonymous-tip-line-as-a-service for organizations or individuals. The TOTP authentication flow has multiple issu…
Patch available
HIGH 8.8
CVE-2024-23767
An issue was discovered on HMS Anybus X-Gateway AB7832-F firmware version 3. The HICP protocol allows unauthenticated changes to a device's network c…
Mitigation only
HIGH 8.6
CVE-2024-5012
In WhatsUp Gold versions released before 2023.1.3, there is a missing authentication vulnerability in WUGDataAccess.Credentials. This vulnerability a…
Whatsup Gold
23.1.3+
CRITICAL 9.1
CVE-2024-5805EPSS 8%
Improper Authentication vulnerability in Progress MOVEit Gateway (SFTP modules) allows Authentication Bypass.This issue affects MOVEit Gateway: 2024.…
Moveit Gateway
Mitigation only
CRITICAL 9.8
CVE-2024-5806EPSS 81%
Improper Authentication vulnerability in Progress MOVEit Transfer (SFTP module) can lead to Authentication Bypass.This issue affects MOVEit Transfer:…
Moveit Transfer
2023.0.11 / 2023.1.6+
HIGH 7.2
CVE-2024-37085 KEVEPSS 26%
VMware ESXi contains an authentication bypass vulnerability. A malicious actor with sufficient Active Directory (AD) permissions can gain full access…
Cloud Foundation
5.2+