Top technology
Linux 13140
Google 12530
Microsoft 12379
Oracle 6737
Apple 6692
Adobe 6387
Ibm 6330
Cisco 5757
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 8.2
CVE-2024-24554
Bludit uses predictable methods in combination with the MD5 hashing algorithm to generate sensitive tokens such as the API token and the user token. …
Bludit
after 3.15.0
MEDIUM 5.4
CVE-2024-37897
SFTPGo is a full-featured and highly configurable SFTP, HTTP/S, FTP/S and WebDAV server - S3, Google Cloud Storage, Azure Blob. SFTPGo WebAdmin and W…
Patch available
CRITICAL 9.8
CVE-2024-5432
The Lifeline Donation plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.2.6. This is due to insufficien…
Lifeline Donation
after 1.2.6
MEDIUM 5.4
CVE-2024-38351
Pocketbase is an open source web backend written in go. In affected versions a malicious user may be able to compromise other user accounts. In order…
Mitigation only
MEDIUM 5.9
CVE-2024-37893
Firefly III is a free and open source personal finance manager. In affected versions an MFA bypass in the Firefly III OAuth flow may allow malicious …
Mitigation only
CRITICAL 9.8
CVE-2024-6057
Improper authentication in the vault password feature in Devolutions Remote Desktop Manager 2024.1.31.0 and earlier allows an attacker that has compr…
Remote Desktop Manager
2024.1.32.0+
HIGH 7.8
CVE-2024-27275
IBM i 7.2, 7.3, 7.4, and 7.5 contains a local privilege escalation vulnerability caused by an insufficient authority requirement. A local user withou…
I
Mitigation only
HIGH 7.5
CVE-2024-37368
A user authentication vulnerability exists in the Rockwell Automation FactoryTalk® View SE. The vulnerability allows a user from a remote system with…
Factorytalk View
14.0+
HIGH 7.5
CVE-2024-37313
Nextcloud server is a self hosted personal cloud system. Under some circumstance it was possible to bypass the second factor of 2FA after successfull…
Nextcloud Server
21.0.9.17 / 22.2.10.22+
HIGH 7.5
CVE-2024-37367
A user authentication vulnerability exists in the Rockwell Automation FactoryTalk® View SE v12. The vulnerability allows a user from a remote system …
Factorytalk View
14.0+
CRITICAL 9.8
CVE-2024-3080EPSS 43%
Certain ASUS router models have authentication bypass vulnerability, allowing unauthenticated remote attackers to log in the device.
Mitigation only
CRITICAL 9.8
CVE-2024-22441
HPE Cray Parallel Application Launch Service (PALS) is subject to an authentication bypass.
Cray Parallel Application Launch Service
1.2.14 / 1.3.3+
CRITICAL 9.8
CVE-2024-30299
Adobe Framemaker Publishing Server versions 2020.3, 2022.2 and earlier are affected by an Improper Authentication vulnerability that could result in …
Framemaker Publishing Server
2020+
HIGH 8.1
CVE-2024-34103
Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by an Improper Authentication vulnerability that could result in…
Commerce
after 1.4.0
HIGH 7.5
CVE-2024-5798
Vault and Vault Enterprise did not properly validate the JSON Web Token (JWT) role-bound audience claim when using the Vault JWT auth method. This ma…
Vault
1.15.9 / 1.16.3+
CRITICAL 9.8
CVE-2024-36264
** UNSUPPORTED WHEN ASSIGNED ** Improper Authentication vulnerability in Apache Submarine Commons Utils.
If the user doesn't explicitly set `submari…
Submarine
Patch available
HIGH 7.3
CVE-2024-35248
Microsoft Dynamics 365 Business Central Elevation of Privilege Vulnerability
Dynamics 365 Business Central
Patch available
HIGH 7.8
CVE-2024-36266
A vulnerability has been identified in PowerSys (All versions < V3.11). The affected application insufficiently protects responses to authentication …
Powersys
3.11+
MEDIUM 6.5
CVE-2022-45168
An issue was discovered in LIVEBOX Collaboration vDesk through v018. A Bypass of Two-Factor Authentication can occur under the /login/backup_code end…
Vdesk
after 018
HIGH 7.3
CVE-2024-37408
fprintd through 1.94.3 lacks a security attention mechanism, and thus unexpected actions might be authorized by "auth sufficient pam_fprintd.so" for …
Mitigation only
CRITICAL 9.8
CVE-2024-5732
A vulnerability was found in Clash up to 0.20.1 on Windows. It has been declared as critical. This vulnerability affects unknown code of the componen…
Clash
after 0.20.1
HIGH 7.5
CVE-2024-37152
Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. The vulnerability allows unauthorized access to the sensitive settings expo…
Argo Cd
2.9.17 / 2.10.12+
MEDIUM 6.5
CVE-2024-5658
The CraftCMS plugin Two-Factor Authentication through 3.3.3 allows reuse of TOTP tokens multiple times within the validity period.
Two Factor Authentication
3.3.4+
MEDIUM 5.3
CVE-2023-50804
An issue was discovered in Samsung Mobile Processor, and Modem Exynos 9820, Exynos 9825, Exynos 980, Exynos 990, Exynos 850, Exynos 1080, Exynos 2100…
Exynos 9820 Firmware
Mitigation only
CRITICAL 9.8
CVE-2024-35670
Broken Authentication vulnerability in SoftLab Integrate Google Drive.This issue affects Integrate Google Drive: from n/a through 1.3.93.
Integrate Google Drive
1.3.94+
MEDIUM 6.5
CVE-2023-51511
Improper Authentication vulnerability in Pluggabl LLC Booster Elite for WooCommerce allows Accessing Functionality Not Properly Constrained by ACLs.T…
Booster For Woocommerce
7.1.3+
HIGH 8.8
CVE-2023-48747
Improper Authentication vulnerability in Pluggabl LLC Booster for WooCommerce allows Accessing Functionality Not Properly Constrained by ACLs.This is…
Booster For Woocommerce
7.1.3+
CRITICAL 9.8
CVE-2023-47189
Improper Authentication vulnerability in WPMU DEV Defender Security allows Accessing Functionality Not Properly Constrained by ACLs.This issue affect…
Defender
4.2.1+
HIGH 7.5
CVE-2023-46630
Improper Authentication vulnerability in wpase Admin and Site Enhancements (ASE) allows Accessing Functionality Not Properly Constrained by ACLs.This…
Mitigation only
CRITICAL 9.8
CVE-2024-37019
Northern.tech Mender Enterprise before 3.6.4 and 3.7.x before 3.7.4 has Weak Authentication.
Mitigation only