Vulnerability index

Browse CVEs

4,342 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
HIGH 7.8 CVE-2019-6198 A vulnerability was reported in Lenovo PC Manager prior to version 2.8.90.11211 that could allow a local attacker to escalate privileges. Pcmanager 2.8.90.11211+ Fix from $1,9502024-07-31 MEDIUM 5.3 CVE-2024-40794 This issue was addressed through improved state management. This issue is fixed in Safari 17.6, iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6. Private … Safari 14.6 / 17.6+ Fix from $1,6002024-07-29 CRITICAL 9.8 CVE-2024-6576 Improper Authentication vulnerability in Progress MOVEit Transfer (SFTP module) can lead to Privilege Escalation.This issue affects MOVEit Transfer: … Moveit Transfer 2023.0.12 / 2023.1.7+ Fix from $2,3002024-07-29 HIGH 8.3 CVE-2024-7050 Improper Authentication vulnerability in OpenText OpenText Directory Services may allow Multi-factor Authentication Bypass in particular scenarios.Th… Mitigation only Fix from $1,9502024-07-26 HIGH 7.5 CVE-2024-41800 Craft is a content management system (CMS). Craft CMS 5 allows reuse of TOTP tokens multiple times within the validity period. An attacker is able to… Craft Cms 5.2.3+ Fix from $1,9502024-07-25 HIGH 7.5 CVE-2024-41829 In JetBrains TeamCity before 2024.07 an OAuth code for JetBrains Space could be stolen via Space Application connection Teamcity 2024.07+ Fix from $1,9502024-07-22 MEDIUM 5.4 CVE-2024-40648 matrix-rust-sdk is an implementation of a Matrix client-server library in Rust. The `UserIdentity::is_verified()` method in the matrix-sdk-crypto cra… Patch available Fix from $1,6002024-07-18 HIGH 8.3 CVE-2024-28992 The SolarWinds Access Rights Manager was susceptible to a Directory Traversal and Information Disclosure Vulnerability. This vulnerability allows an … Access Rights Manager after 2023.2.4 Fix from $1,9502024-07-17 HIGH 8.8 CVE-2024-23470 The SolarWinds Access Rights Manager was found to be susceptible to a pre-authentication remote code execution vulnerability. If exploited, this vuln… Access Rights Manager after 2023.2.4 Fix from $1,9502024-07-17 HIGH 8.8 CVE-2024-23471 The SolarWinds Access Rights Manager was found to be susceptible to a Remote Code Execution Vulnerability. If exploited, this vulnerability allows an… Access Rights Manager after 2023.2.4 Fix from $1,9502024-07-17 HIGH 8.8 CVE-2024-23465 The SolarWinds Access Rights Manager was found to be susceptible to an authentication bypass vulnerability. This vulnerability allows an unauthentica… Access Rights Manager after 2023.2.4 Fix from $1,9502024-07-17 MEDIUM 5.3 CVE-2024-6535 A flaw was found in Skupper. When Skupper is initialized with the console-enabled and with console-auth set to Openshift, it configures the openshift… Service Interconnect Mitigation only Fix from $1,6002024-07-17 CRITICAL 9.8 CVE-2024-22442 The vulnerability could be remotely exploited to bypass authentication. 3par Service Processor Firmware 5.1.2.0+ Fix from $2,3002024-07-16 MEDIUM 6.5 CVE-2024-39767 Mattermost Mobile Apps versions <=2.16.0 fail to validate that the push notifications received for a server actually came from this serve that which … Mattermost Mobile 2.17.0+ Fix from $1,6002024-07-15 HIGH 8.8 CVE-2024-39340 The authentication system of Securepoint UTM mishandles OTP keys. This allows the bypassing of second-factor verification (when OTP is enabled) in bo… Mitigation only Fix from $1,9502024-07-12 MEDIUM 6.7 CVE-2024-38433 Nuvoton - CWE-305: Authentication Bypass by Primary Weakness An attacker with write access to the SPI-Flash on an NPCM7xx BMC subsystem that uses th… Npcm750r Firmware 10.10.19+ Fix from $1,6002024-07-11 CRITICAL 9.8 CVE-2024-6397 The InstaWP Connect – 1-click WP Staging & Migration plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including… Instawp Connect 0.1.0.45+ Fix from $2,3002024-07-11 HIGH 8.8 CVE-2024-6235EPSS 21% Sensitive information disclosure in NetScaler Console Netscaler Console 14.1-25.53+ Fix from $1,9502024-07-10 MEDIUM 5.9 CVE-2024-38099 Windows Remote Desktop Licensing Service Denial of Service Vulnerability Windows Server 2008 10.0.14393.7159 / 10.0.17763.6054+ Fix from $1,6002024-07-09 MEDIUM 5.9 CVE-2024-39830 Mattermost versions 9.8.x <= 9.8.0, 9.7.x <= 9.7.4, 9.6.x <= 9.6.2 and 9.5.x <= 9.5.5, when shared channels are enabled, fail to use constant time co… Mattermost 9.5.6 / 9.6.3+ Fix from $1,6002024-07-03 HIGH 8.6 CVE-2024-3826 In versions of Akana in versions prior to and including 2022.1.3 validation is broken when using the SAML Single Sign-On (SSO) functionality. No fix yet Fix from $1,9502024-07-02 HIGH 7.5 CVE-2024-34596 Improper authentication in SmartThings prior to version 1.8.17 allows remote attackers to bypass the expiration date for members set by the owner. Smartthings 1.8.17+ Fix from $1,9502024-07-02 HIGH 8.8 CVE-2024-20890 Improper input validation in BLE prior to SMR Jul-2024 Release 1 allows adjacent attackers to trigger abnormal behavior. Android Mitigation only Fix from $1,9502024-07-02 CRITICAL 9.8 CVE-2024-28200 The N-central server is vulnerable to an authentication bypass of the user interface. This vulnerability is present in all deployments of N-central p… N Central 2024.2+ Fix from $2,3002024-07-01 HIGH 7.5 CVE-2024-38523 Hush Line is a free and open-source, anonymous-tip-line-as-a-service for organizations or individuals. The TOTP authentication flow has multiple issu… Patch available Fix from $1,9502024-06-27 HIGH 8.8 CVE-2024-23767 An issue was discovered on HMS Anybus X-Gateway AB7832-F firmware version 3. The HICP protocol allows unauthenticated changes to a device's network c… Mitigation only Fix from $1,9502024-06-26 HIGH 8.6 CVE-2024-5012 In WhatsUp Gold versions released before 2023.1.3, there is a missing authentication vulnerability in WUGDataAccess.Credentials. This vulnerability a… Whatsup Gold 23.1.3+ Fix from $1,9502024-06-25 CRITICAL 9.1 CVE-2024-5805EPSS 8% Improper Authentication vulnerability in Progress MOVEit Gateway (SFTP modules) allows Authentication Bypass.This issue affects MOVEit Gateway: 2024.… Moveit Gateway Mitigation only Fix from $2,3002024-06-25 CRITICAL 9.8 CVE-2024-5806EPSS 81% Improper Authentication vulnerability in Progress MOVEit Transfer (SFTP module) can lead to Authentication Bypass.This issue affects MOVEit Transfer:… Moveit Transfer 2023.0.11 / 2023.1.6+ Fix from $2,3002024-06-25 HIGH 7.2 CVE-2024-37085 KEVEPSS 26% VMware ESXi contains an authentication bypass vulnerability. A malicious actor with sufficient Active Directory (AD) permissions can gain full access… Cloud Foundation 5.2+ Fix from $1,9502024-06-25