Top technology
Linux 13140
Google 12530
Microsoft 12379
Oracle 6737
Apple 6692
Adobe 6387
Ibm 6330
Cisco 5757
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 5.3
CVE-2023-25790
Improper Authentication, Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in xtemos WoodMart allows…
Mitigation only
CRITICAL 9.8
CVE-2023-47504
Improper Authentication vulnerability in Elementor Elementor Website Builder allows Accessing Functionality Not Properly Constrained by ACLs.This iss…
Website Builder
3.16.5+
CRITICAL 9.8
CVE-2024-3701
The system application (com.transsion.kolun.aiservice) component does not perform an authentication check, which allows attackers to perform maliciou…
Hios
Mitigation only
HIGH 8.8
CVE-2024-29837
The Web interface of Evolution Controller Versions 2.04.560.31.03.2024 and below uses poor session management, allowing for an unauthenticated attack…
Evolution
after 2.04.560
MEDIUM 6.5
CVE-2023-48865
An issue discovered in Reportico Till 8.1.0 allows attackers to obtain sensitive information via execute_mode parameter of the URL.
Reportico
No fix yet
HIGH 7.5
CVE-2024-2112
The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to Sensitive Information Exposure in al…
Form Maker
1.15.23+
HIGH 8.8
CVE-2024-24279
An issue in secdiskapp 1.5.1 (management program for NewQ Fingerprint Encryption Super Speed Flash Disk) allows attackers to gain escalated privilege…
Secdiskapp
No fix yet
HIGH 7.5
CVE-2023-52540
Vulnerability of improper authentication in the Iaware module.
Impact: Successful exploitation of this vulnerability will affect availability.
Emui
No fix yet
HIGH 7.3
CVE-2024-29757
there is a possible permission bypass due to Debug certs being allowlisted. This could lead to local escalation of privilege with no additional execu…
Android
Mitigation only
HIGH 8.5
CVE-2024-25699
There is a difficult‑to‑exploit improper authentication issue in the Home application for Esri Portal for ArcGIS versions 11.2 and below on Windows a…
Portal For Arcgis
after 11.2
CRITICAL 9.1
CVE-2023-44039
In VeridiumID before 3.5.0, the WebAuthn API allows an internal unauthenticated attacker (who can pass enrollment verifications and is allowed to enr…
Veridiumad
3.5.0+
MEDIUM 5.3
CVE-2024-28006
Improper authentication vulnerability in NEC Corporation Aterm WG1800HP4, WG1200HS3, WG1900HP2, WG1200HP3, WG1800HP3, WG1200HS2, WG1900HP, WG1200HP2,…
Aterm Wg1800hp4 Firmware
Mitigation only
CRITICAL 9.8
CVE-2024-28007
Improper authentication vulnerability in NEC Corporation Aterm WG1800HP4, WG1200HS3, WG1900HP2, WG1200HP3, WG1800HP3, WG1200HS2, WG1900HP, WG1200HP2,…
Aterm Wg1800hp4 Firmware
Mitigation only
CRITICAL 9.8
CVE-2024-28009
Improper authentication vulnerability in NEC Corporation Aterm WG1800HP4, WG1200HS3, WG1900HP2, WG1200HP3, WG1800HP3, WG1200HS2, WG1900HP, WG1200HP2,…
Aterm Wg1800hp4 Firmware
Mitigation only
CRITICAL 9.8
CVE-2024-28012
Improper authentication vulnerability in NEC Corporation Aterm WG1800HP4, WG1200HS3, WG1900HP2, WG1200HP3, WG1800HP3, WG1200HS2, WG1900HP, WG1200HP2,…
Aterm Wg1800hp4 Firmware
Mitigation only
CRITICAL 9.8
CVE-2023-31634
In TeslaMate before 1.27.2, there is unauthorized access to port 4000 for remote viewing and operation of user data. After accessing the IP address f…
Teslamate
1.27.2+
MEDIUM 5.3
CVE-2024-2244
REST service authentication anomaly with “valid username/no password” credential combination for batch job processing resulting in successful service…
Mitigation only
CRITICAL 9.1
CVE-2024-2873
A vulnerability was found in wolfSSH's server-side state machine before versions 1.4.17. A malicious client could create channels without first perfo…
Wolfssh
1.4.17+
CRITICAL 9.8
CVE-2024-2862EPSS 51%
This vulnerability allows remote attackers to reset the password of anonymous users without authorization on the affected LG LED Assistant.
Lg Led Assistant
Mitigation only
MEDIUM 5.3
CVE-2022-44595
Improper Authentication vulnerability in Melapress WP 2FA allows Authentication Bypass.This issue affects WP 2FA: from n/a through 2.2.0.
Wp 2fa
after 2.2.0
CRITICAL 9.8
CVE-2024-1147
Weak access control in OpenText PVCS Version Manager allows potential bypassing of authentication and download of files.
Mitigation only
CRITICAL 9.8
CVE-2024-1148
Weak access control in OpenText PVCS Version Manager allows potential bypassing of authentication and uploading of files.
Mitigation only
HIGH 8.8
CVE-2024-27923
Grav is a content management system (CMS). Prior to version 1.7.43, users who may write a page may use the `frontmatter` feature due to insufficient …
Grav
1.7.43+
HIGH 8.1
CVE-2024-28735
Unit4 Financials by Coda versions prior to 2023Q4 suffer from an incorrect access control authorization bypass vulnerability which allows an authenti…
Financials By Coda
2023q4+
CRITICAL 9.8
CVE-2024-27767
CWE-287: Improper Authentication may allow Authentication Bypass
Unilogic
1.35.227+
CRITICAL 9.8
CVE-2024-28255EPSS 73%
OpenMetadata is a unified platform for discovery, observability, and governance powered by a central metadata repository, in-depth lineage, and seaml…
Openmetadata
1.2.4+
HIGH 8.8
CVE-2024-2450
Mattermost versions 8.1.x before 8.1.10, 9.2.x before 9.2.6, 9.3.x before 9.3.2, and 9.4.x before 9.4.3 fail to correctly verify account ownership wh…
Mattermost Server
8.1.10 / 9.2.6+
HIGH 8.4
CVE-2024-25652
In Delinea PAM Secret Server 11.4, it is possible for a user assigned "Administer Reports" permission and/or with access to Report functionality via …
Secret Server
Mitigation only
HIGH 7.5
CVE-2023-38534
Improper authentication vulnerability in OpenText™ Exceed Turbo X affecting versions 12.5.0 and 12.5.1. The vulnerability could allow disclosure of r…
Exceed Turbox
Mitigation only
CRITICAL 9.8
CVE-2024-0799
An authentication bypass vulnerability exists in Arcserve Unified Data Protection 9.2 and 8.1 in the edge-app-base-webui.jar!com.ca.arcserve.edge.app…
Udp
No fix yet