Vulnerability index

Browse CVEs

4,342 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
HIGH 8.2 CVE-2024-24554 Bludit uses predictable methods in combination with the MD5 hashing algorithm to generate sensitive tokens such as the API token and the user token. … Bludit after 3.15.0 Fix from $1,9502024-06-24 MEDIUM 5.4 CVE-2024-37897 SFTPGo is a full-featured and highly configurable SFTP, HTTP/S, FTP/S and WebDAV server - S3, Google Cloud Storage, Azure Blob. SFTPGo WebAdmin and W… Patch available Fix from $1,6002024-06-20 CRITICAL 9.8 CVE-2024-5432 The Lifeline Donation plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.2.6. This is due to insufficien… Lifeline Donation after 1.2.6 Fix from $2,3002024-06-20 MEDIUM 5.4 CVE-2024-38351 Pocketbase is an open source web backend written in go. In affected versions a malicious user may be able to compromise other user accounts. In order… Mitigation only Fix from $1,6002024-06-18 MEDIUM 5.9 CVE-2024-37893 Firefly III is a free and open source personal finance manager. In affected versions an MFA bypass in the Firefly III OAuth flow may allow malicious … Mitigation only Fix from $1,6002024-06-17 CRITICAL 9.8 CVE-2024-6057 Improper authentication in the vault password feature in Devolutions Remote Desktop Manager 2024.1.31.0 and earlier allows an attacker that has compr… Remote Desktop Manager 2024.1.32.0+ Fix from $2,3002024-06-17 HIGH 7.8 CVE-2024-27275 IBM i 7.2, 7.3, 7.4, and 7.5 contains a local privilege escalation vulnerability caused by an insufficient authority requirement. A local user withou… I Mitigation only Fix from $1,9502024-06-15 HIGH 7.5 CVE-2024-37368 A user authentication vulnerability exists in the Rockwell Automation FactoryTalk® View SE. The vulnerability allows a user from a remote system with… Factorytalk View 14.0+ Fix from $1,9502024-06-14 HIGH 7.5 CVE-2024-37313 Nextcloud server is a self hosted personal cloud system. Under some circumstance it was possible to bypass the second factor of 2FA after successfull… Nextcloud Server 21.0.9.17 / 22.2.10.22+ Fix from $1,9502024-06-14 HIGH 7.5 CVE-2024-37367 A user authentication vulnerability exists in the Rockwell Automation FactoryTalk® View SE v12. The vulnerability allows a user from a remote system … Factorytalk View 14.0+ Fix from $1,9502024-06-14 CRITICAL 9.8 CVE-2024-3080EPSS 43% Certain ASUS router models have authentication bypass vulnerability, allowing unauthenticated remote attackers to log in the device. Mitigation only Fix from $2,3002024-06-14 CRITICAL 9.8 CVE-2024-22441 HPE Cray Parallel Application Launch Service (PALS) is subject to an authentication bypass. Cray Parallel Application Launch Service 1.2.14 / 1.3.3+ Fix from $2,3002024-06-13 CRITICAL 9.8 CVE-2024-30299 Adobe Framemaker Publishing Server versions 2020.3, 2022.2 and earlier are affected by an Improper Authentication vulnerability that could result in … Framemaker Publishing Server 2020+ Fix from $2,3002024-06-13 HIGH 8.1 CVE-2024-34103 Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by an Improper Authentication vulnerability that could result in… Commerce after 1.4.0 Fix from $1,9502024-06-13 HIGH 7.5 CVE-2024-5798 Vault and Vault Enterprise did not properly validate the JSON Web Token (JWT) role-bound audience claim when using the Vault JWT auth method. This ma… Vault 1.15.9 / 1.16.3+ Fix from $1,9502024-06-12 CRITICAL 9.8 CVE-2024-36264 ** UNSUPPORTED WHEN ASSIGNED ** Improper Authentication vulnerability in Apache Submarine Commons Utils. If the user doesn't explicitly set `submari… Submarine Patch available Fix from $2,3002024-06-12 HIGH 7.3 CVE-2024-35248 Microsoft Dynamics 365 Business Central Elevation of Privilege Vulnerability Dynamics 365 Business Central Patch available Fix from $1,9502024-06-11 HIGH 7.8 CVE-2024-36266 A vulnerability has been identified in PowerSys (All versions < V3.11). The affected application insufficiently protects responses to authentication … Powersys 3.11+ Fix from $1,9502024-06-11 MEDIUM 6.5 CVE-2022-45168 An issue was discovered in LIVEBOX Collaboration vDesk through v018. A Bypass of Two-Factor Authentication can occur under the /login/backup_code end… Vdesk after 018 Fix from $1,6002024-06-10 HIGH 7.3 CVE-2024-37408 fprintd through 1.94.3 lacks a security attention mechanism, and thus unexpected actions might be authorized by "auth sufficient pam_fprintd.so" for … Mitigation only Fix from $1,9502024-06-08 CRITICAL 9.8 CVE-2024-5732 A vulnerability was found in Clash up to 0.20.1 on Windows. It has been declared as critical. This vulnerability affects unknown code of the componen… Clash after 0.20.1 Fix from $2,3002024-06-07 HIGH 7.5 CVE-2024-37152 Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. The vulnerability allows unauthorized access to the sensitive settings expo… Argo Cd 2.9.17 / 2.10.12+ Fix from $1,9502024-06-06 MEDIUM 6.5 CVE-2024-5658 The CraftCMS plugin Two-Factor Authentication through 3.3.3 allows reuse of TOTP tokens multiple times within the validity period. Two Factor Authentication 3.3.4+ Fix from $1,6002024-06-06 MEDIUM 5.3 CVE-2023-50804 An issue was discovered in Samsung Mobile Processor, and Modem Exynos 9820, Exynos 9825, Exynos 980, Exynos 990, Exynos 850, Exynos 1080, Exynos 2100… Exynos 9820 Firmware Mitigation only Fix from $1,6002024-06-05 CRITICAL 9.8 CVE-2024-35670 Broken Authentication vulnerability in SoftLab Integrate Google Drive.This issue affects Integrate Google Drive: from n/a through 1.3.93. Integrate Google Drive 1.3.94+ Fix from $2,3002024-06-04 MEDIUM 6.5 CVE-2023-51511 Improper Authentication vulnerability in Pluggabl LLC Booster Elite for WooCommerce allows Accessing Functionality Not Properly Constrained by ACLs.T… Booster For Woocommerce 7.1.3+ Fix from $1,6002024-06-04 HIGH 8.8 CVE-2023-48747 Improper Authentication vulnerability in Pluggabl LLC Booster for WooCommerce allows Accessing Functionality Not Properly Constrained by ACLs.This is… Booster For Woocommerce 7.1.3+ Fix from $1,9502024-06-04 CRITICAL 9.8 CVE-2023-47189 Improper Authentication vulnerability in WPMU DEV Defender Security allows Accessing Functionality Not Properly Constrained by ACLs.This issue affect… Defender 4.2.1+ Fix from $2,3002024-06-04 HIGH 7.5 CVE-2023-46630 Improper Authentication vulnerability in wpase Admin and Site Enhancements (ASE) allows Accessing Functionality Not Properly Constrained by ACLs.This… Mitigation only Fix from $1,9502024-06-04 CRITICAL 9.8 CVE-2024-37019 Northern.tech Mender Enterprise before 3.6.4 and 3.7.x before 3.7.4 has Weak Authentication. Mitigation only Fix from $2,3002024-06-03