Vulnerability index

Browse CVEs

4,342 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
HIGH 7.5 CVE-2024-21427 Windows Kerberos Security Feature Bypass Vulnerability Windows Server 2012 10.0.14393.6897 / 10.0.17763.5696+ Fix from $1,9502024-03-12 HIGH 7.1 CVE-2024-21390 Microsoft Authenticator Elevation of Privilege Vulnerability Authenticator 6.2401.0617+ Fix from $1,9502024-03-12 HIGH 8.8 CVE-2023-46717 An improper authentication vulnerability [CWE-287] in FortiOS versions 7.4.1 and below, versions 7.2.6 and below, and versions 7.0.12 and below when … Fortios 7.0.13 / 7.2.7+ Fix from $1,9502024-03-12 CRITICAL 9.8 CVE-2023-49340 An issue was discovered in Newland Nquire 1000 Interactive Kiosk version NQ1000-II_G_V1.00.011, allows remote attackers to escalate privileges and by… Mitigation only Fix from $2,3002024-03-09 CRITICAL 9.8 CVE-2024-21899EPSS 24% An improper authentication vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could al… Qts 4.5.4.2627 / 5.1.3.2578+ Fix from $2,3002024-03-08 CRITICAL 9.8 CVE-2023-46172 IBM DS8900F HMC 89.21.19.0, 89.21.31.0, 89.30.68.0, 89.32.40.0, and 89.33.48.0 could allow a remote attacker to bypass authentication restrictions fo… Ds8900f Firmware Mitigation only Fix from $2,3002024-03-07 MEDIUM 6.5 CVE-2023-42662 JFrog Artifactory versions 7.59 and above, but below 7.59.18, 7.63.18, 7.68.19, 7.71.8 are vulnerable to an issue whereby user interaction with speci… Artifactory 7.59.18 / 7.63.18+ Fix from $1,6002024-03-07 HIGH 7.5 CVE-2023-48703 RobotsAndPencils go-saml, a SAML client library written in Go, contains an authentication bypass vulnerability in all known versions. This is due to … Go Saml No fix yet Fix from $1,9502024-03-06 MEDIUM 6.2 CVE-2024-20301 A vulnerability in Cisco Duo Authentication for Windows Logon and RDP could allow an authenticated, physical attacker to bypass secondary authenticat… Duo Authentication For Windows Logon And Rdp 4.3.0+ Fix from $1,6002024-03-06 MEDIUM 6.5 CVE-2023-38367 IBM Cloud Pak Foundational Services Identity Provider (idP) API (IBM Cloud Pak for Automation 18.0.0, 18.0.1, 18.0.2, 19.0.1, 19.0.2, 19.0.3, 20.0.1,… Cloud Pak For Business Automation Mitigation only Fix from $1,6002024-02-29 CRITICAL 9.1 CVE-2024-25128 Flask-AppBuilder is an application development framework, built on top of Flask. When Flask-AppBuilder is set to AUTH_TYPE AUTH_OID, it allows an att… Flask Appbuilder 4.3.11+ Fix from $2,3002024-02-29 HIGH 7.5 CVE-2023-38372 An unauthorized attacker who has obtained an IBM Watson IoT Platform 1.0 security authentication token can use it to impersonate an authorized platfo… Watson Iot Platform Mitigation only Fix from $1,9502024-02-29 CRITICAL 9.1 CVE-2024-1735 A vulnerability has been identified in armeria-saml versions less than 1.27.2, allowing the use of malicious SAML messages to bypass authentication. … Armeria 1.27.2+ Fix from $2,3002024-02-26 MEDIUM 6.3 CVE-2024-22395 Improper access control vulnerability has been identified in the SMA100 SSL-VPN virtual office portal, which in specific conditions could potentially… Sma 200 Firmware 10.2.1.11-65sv+ Fix from $1,6002024-02-24 CRITICAL 9.8 CVE-2024-1817 A vulnerability has been found in Demososo DM Enterprise Website Building System up to 2022.8 and classified as critical. Affected by this vulnerabil… Dm Enterprise Website Building System after 2022.8 Fix from $2,3002024-02-23 MEDIUM 6.5 CVE-2023-52160 The implementation of PEAP in wpa_supplicant through 2.10 allows authentication bypass. For a successful attack, wpa_supplicant must be configured to… Debian Linux after 2.10 Fix from $1,6002024-02-22 HIGH 7.5 CVE-2023-52161 The Access Point functionality in eapol_auth_key_handle in eapol.c in iNet wireless daemon (IWD) before 2.14 allows attackers to gain unauthorized ac… Inet Wireless Daemon 2.14+ Fix from $1,9502024-02-22 CRITICAL 9.6 CVE-2024-22245 Arbitrary Authentication Relay and Session Hijack vulnerabilities in the deprecated VMware Enhanced Authentication Plug-in (EAP) could allow a malici… Mitigation only Fix from $2,3002024-02-20 MEDIUM 6.5 CVE-2022-41737 IBM Storage Scale Container Native Storage Access 5.1.2.1 through 5.1.7.0 could allow a local attacker to initiate connections from a container outsi… Spectrum Scale Container Native Storage Access after 5.1.7.0 Fix from $1,6002024-02-17 HIGH 7.5 CVE-2022-41738 IBM Storage Scale Container Native Storage Access 5.1.2.1 -through 5.1.7.0 could allow an attacker to initiate connections to containers from externa… Spectrum Scale Container Native Storage Access after 5.1.7.0 Fix from $1,9502024-02-17 HIGH 7.5 CVE-2023-6451 Publicly known cryptographic machine key in AlayaCare's Procura Portal before 9.0.1.2 allows attackers to forge their own authentication cookies and … Procura 9.0.1.2+ Fix from $1,9502024-02-16 CRITICAL 9.8 CVE-2024-20738 Adobe FrameMaker Publishing Server versions 2022.1 and earlier are affected by an Improper Authentication vulnerability that could result in a Securi… Framemaker Publishing Server 2022+ Fix from $2,3002024-02-15 HIGH 7.4 CVE-2024-25618 Mastodon is a free, open-source social network server based on ActivityPub. Mastodon allows new identities from configured authentication providers (… Mastodon 3.5.18 / 4.0.14+ Fix from $1,9502024-02-14 HIGH 8.8 CVE-2024-0568 CWE-287: Improper Authentication vulnerability exists that could cause unauthorized tampering of device configuration over NFC communication. Rmnf22tb30 Firmware Mitigation only Fix from $1,9502024-02-14 HIGH 8.8 CVE-2023-31189 Improper authentication in some Intel(R) Server Product OpenBMC firmware before version egs-1.09 may allow an authenticated user to enable escalation… Openbmc Mitigation only Fix from $1,9502024-02-14 CRITICAL 9.8 CVE-2024-21410 KEVEPSS 13% Microsoft Exchange Server Elevation of Privilege Vulnerability Exchange Server Patch available Fix from $2,3002024-02-13 CRITICAL 9.8 CVE-2024-23813 A vulnerability has been identified in Polarion ALM (All versions < V2404.0). The REST API endpoints of doorsconnector of the affected product lacks … Polarion Alm 2404.0+ Fix from $2,3002024-02-13 HIGH 8.8 CVE-2024-25313 Code-projects Simple School Managment System 1.0 allows Authentication Bypass via the username and password parameters at School/teacher_login.php. Simple School Management System No fix yet Fix from $1,9502024-02-09 HIGH 8.1 CVE-2023-51761 In Emerson Rosemount GC370XA, GC700XA, and GC1500XA products, an unauthenticated user with network access could bypass authentication and acquire adm… Gc370xa Firmware Mitigation only Fix from $1,9502024-02-09 HIGH 8.8 CVE-2024-24830 OpenObserve is a observability platform built specifically for logs, metrics, traces, analytics, designed to work at petabyte scale. A vulnerability … Openobserve 0.8.0+ Fix from $1,9502024-02-08