Vulnerability index

Browse CVEs

4,342 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
MEDIUM 5.3 CVE-2023-25790 Improper Authentication, Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in xtemos WoodMart allows… Mitigation only Fix from $1,6002024-04-24 CRITICAL 9.8 CVE-2023-47504 Improper Authentication vulnerability in Elementor Elementor Website Builder allows Accessing Functionality Not Properly Constrained by ACLs.This iss… Website Builder 3.16.5+ Fix from $2,3002024-04-24 CRITICAL 9.8 CVE-2024-3701 The system application (com.transsion.kolun.aiservice) component does not perform an authentication check, which allows attackers to perform maliciou… Hios Mitigation only Fix from $2,3002024-04-15 HIGH 8.8 CVE-2024-29837 The Web interface of Evolution Controller Versions 2.04.560.31.03.2024 and below uses poor session management, allowing for an unauthenticated attack… Evolution after 2.04.560 Fix from $1,9502024-04-15 MEDIUM 6.5 CVE-2023-48865 An issue discovered in Reportico Till 8.1.0 allows attackers to obtain sensitive information via execute_mode parameter of the URL. Reportico No fix yet Fix from $1,6002024-04-11 HIGH 7.5 CVE-2024-2112 The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to Sensitive Information Exposure in al… Form Maker 1.15.23+ Fix from $1,9502024-04-09 HIGH 8.8 CVE-2024-24279 An issue in secdiskapp 1.5.1 (management program for NewQ Fingerprint Encryption Super Speed Flash Disk) allows attackers to gain escalated privilege… Secdiskapp No fix yet Fix from $1,9502024-04-08 HIGH 7.5 CVE-2023-52540 Vulnerability of improper authentication in the Iaware module. Impact: Successful exploitation of this vulnerability will affect availability. Emui No fix yet Fix from $1,9502024-04-08 HIGH 7.3 CVE-2024-29757 there is a possible permission bypass due to Debug certs being allowlisted. This could lead to local escalation of privilege with no additional execu… Android Mitigation only Fix from $1,9502024-04-05 HIGH 8.5 CVE-2024-25699 There is a difficult‑to‑exploit improper authentication issue in the Home application for Esri Portal for ArcGIS versions 11.2 and below on Windows a… Portal For Arcgis after 11.2 Fix from $1,9502024-04-04 CRITICAL 9.1 CVE-2023-44039 In VeridiumID before 3.5.0, the WebAuthn API allows an internal unauthenticated attacker (who can pass enrollment verifications and is allowed to enr… Veridiumad 3.5.0+ Fix from $2,3002024-04-03 MEDIUM 5.3 CVE-2024-28006 Improper authentication vulnerability in NEC Corporation Aterm WG1800HP4, WG1200HS3, WG1900HP2, WG1200HP3, WG1800HP3, WG1200HS2, WG1900HP, WG1200HP2,… Aterm Wg1800hp4 Firmware Mitigation only Fix from $1,6002024-03-28 CRITICAL 9.8 CVE-2024-28007 Improper authentication vulnerability in NEC Corporation Aterm WG1800HP4, WG1200HS3, WG1900HP2, WG1200HP3, WG1800HP3, WG1200HS2, WG1900HP, WG1200HP2,… Aterm Wg1800hp4 Firmware Mitigation only Fix from $2,3002024-03-28 CRITICAL 9.8 CVE-2024-28009 Improper authentication vulnerability in NEC Corporation Aterm WG1800HP4, WG1200HS3, WG1900HP2, WG1200HP3, WG1800HP3, WG1200HS2, WG1900HP, WG1200HP2,… Aterm Wg1800hp4 Firmware Mitigation only Fix from $2,3002024-03-28 CRITICAL 9.8 CVE-2024-28012 Improper authentication vulnerability in NEC Corporation Aterm WG1800HP4, WG1200HS3, WG1900HP2, WG1200HP3, WG1800HP3, WG1200HS2, WG1900HP, WG1200HP2,… Aterm Wg1800hp4 Firmware Mitigation only Fix from $2,3002024-03-28 CRITICAL 9.8 CVE-2023-31634 In TeslaMate before 1.27.2, there is unauthorized access to port 4000 for remote viewing and operation of user data. After accessing the IP address f… Teslamate 1.27.2+ Fix from $2,3002024-03-27 MEDIUM 5.3 CVE-2024-2244 REST service authentication anomaly with “valid username/no password” credential combination for batch job processing resulting in successful service… Mitigation only Fix from $1,6002024-03-27 CRITICAL 9.1 CVE-2024-2873 A vulnerability was found in wolfSSH's server-side state machine before versions 1.4.17. A malicious client could create channels without first perfo… Wolfssh 1.4.17+ Fix from $2,3002024-03-25 CRITICAL 9.8 CVE-2024-2862EPSS 51% This vulnerability allows remote attackers to reset the password of anonymous users without authorization on the affected LG LED Assistant. Lg Led Assistant Mitigation only Fix from $2,3002024-03-25 MEDIUM 5.3 CVE-2022-44595 Improper Authentication vulnerability in Melapress WP 2FA allows Authentication Bypass.This issue affects WP 2FA: from n/a through 2.2.0. Wp 2fa after 2.2.0 Fix from $1,6002024-03-21 CRITICAL 9.8 CVE-2024-1147 Weak access control in OpenText PVCS Version Manager allows potential bypassing of authentication and download of files. Mitigation only Fix from $2,3002024-03-21 CRITICAL 9.8 CVE-2024-1148 Weak access control in OpenText PVCS Version Manager allows potential bypassing of authentication and uploading of files. Mitigation only Fix from $2,3002024-03-21 HIGH 8.8 CVE-2024-27923 Grav is a content management system (CMS). Prior to version 1.7.43, users who may write a page may use the `frontmatter` feature due to insufficient … Grav 1.7.43+ Fix from $1,9502024-03-21 HIGH 8.1 CVE-2024-28735 Unit4 Financials by Coda versions prior to 2023Q4 suffer from an incorrect access control authorization bypass vulnerability which allows an authenti… Financials By Coda 2023q4+ Fix from $1,9502024-03-20 CRITICAL 9.8 CVE-2024-27767 CWE-287: Improper Authentication may allow Authentication Bypass Unilogic 1.35.227+ Fix from $2,3002024-03-18 CRITICAL 9.8 CVE-2024-28255EPSS 73% OpenMetadata is a unified platform for discovery, observability, and governance powered by a central metadata repository, in-depth lineage, and seaml… Openmetadata 1.2.4+ Fix from $2,3002024-03-15 HIGH 8.8 CVE-2024-2450 Mattermost versions 8.1.x before 8.1.10, 9.2.x before 9.2.6, 9.3.x before 9.3.2, and 9.4.x before 9.4.3 fail to correctly verify account ownership wh… Mattermost Server 8.1.10 / 9.2.6+ Fix from $1,9502024-03-15 HIGH 8.4 CVE-2024-25652 In Delinea PAM Secret Server 11.4, it is possible for a user assigned "Administer Reports" permission and/or with access to Report functionality via … Secret Server Mitigation only Fix from $1,9502024-03-14 HIGH 7.5 CVE-2023-38534 Improper authentication vulnerability in OpenText™ Exceed Turbo X affecting versions 12.5.0 and 12.5.1. The vulnerability could allow disclosure of r… Exceed Turbox Mitigation only Fix from $1,9502024-03-13 CRITICAL 9.8 CVE-2024-0799 An authentication bypass vulnerability exists in Arcserve Unified Data Protection 9.2 and 8.1 in the edge-app-base-webui.jar!com.ca.arcserve.edge.app… Udp No fix yet Fix from $2,3002024-03-13