Top technology
Linux 13140
Google 12530
Microsoft 12379
Oracle 6737
Apple 6692
Adobe 6387
Ibm 6330
Cisco 5757
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 6.5
CVE-2024-25106
OpenObserve is a observability platform built specifically for logs, metrics, traces, analytics, designed to work at petabyte scale. A critical vulne…
Openobserve
0.8.0+
CRITICAL 9.8
CVE-2024-24496EPSS 20%
An issue in Daily Habit Tracker v.1.0 allows a remote attacker to manipulate trackers via the home.php, add-tracker.php, delete-tracker.php, update-t…
Daily Habit Tracker
No fix yet
CRITICAL 9.8
CVE-2024-22394
An improper authentication vulnerability has been identified in SonicWall SonicOS SSL-VPN feature, which in specific conditions could allow a remote …
Sonicos
Mitigation only
MEDIUM 5.3
CVE-2024-23806
Sensitive data can be extracted from HID iCLASS SE reader configuration cards. This could include credential and device administrator keys.
Omnikey Secure Elements Reader Configuration Cards Firmware
Mitigation only
MEDIUM 5.9
CVE-2024-24771
Open Forms allows users create and publish smart forms. Versions prior to 2.2.9, 2.3.7, 2.4.5, and 2.5.2 contain a non-exploitable multi-factor authe…
Open Forms
2.2.9 / 2.3.7+
MEDIUM 5.3
CVE-2023-39196
Improper Authentication vulnerability in Apache Ozone.
The vulnerability allows an attacker to download metadata internal to the Storage Container M…
Ozone
after 1.3.0
CRITICAL 9.8
CVE-2024-24592
Lack of authentication in all versions of the fileserver component of Allegro AI’s ClearML platform allows a remote attacker to arbitrarily access, c…
Clearml
No fix yet
MEDIUM 6.5
CVE-2024-20815
Improper authentication vulnerability in onCharacteristicReadRequest in Auto Hotspot prior to SMR Feb-2024 Release 1 allows adjacent attackers connec…
Android
Mitigation only
MEDIUM 6.5
CVE-2024-20816
Improper authentication vulnerability in onCharacteristicWriteRequest in Auto Hotspot prior to SMR Feb-2024 Release 1 allows adjacent attackers conne…
Android
Mitigation only
CRITICAL 9.8
CVE-2023-39303
An improper authentication vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could al…
Qts
Mitigation only
MEDIUM 5.3
CVE-2023-50934
IBM PowerSC 1.3, 2.0, and 2.1 uses single-factor authentication which can lead to unnecessary risk of compromise when compared with the benefits of a…
Powersc
Patch available
MEDIUM 5.5
CVE-2023-47256
ConnectWise ScreenConnect through 23.8.4 allows local users to connect to arbitrary relay servers via implicit trust of proxy settings
Automate
23.8.5+
CRITICAL 9.8
CVE-2024-1039
Gessler GmbH WEB-MASTER has a restoration account that uses weak hard coded credentials and if exploited could allow an attacker control over the web…
Web Master Firmware
Mitigation only
HIGH 8.8
CVE-2024-23647
Authentik is an open-source Identity Provider. There is a bug in our implementation of PKCE that allows an attacker to circumvent the protection that…
Authentik
2023.8.7 / 2023.10.7+
CRITICAL 9.8
CVE-2023-51982
CrateDB 5.5.1 is contains an authentication bypass vulnerability in the Admin UI component. After configuring password authentication and_ Local_ In …
Cratedb
No fix yet
MEDIUM 5.3
CVE-2024-1006
A vulnerability was found in Shanxi Diankeyun Technology NODERP up to 6.0.2 and classified as critical. This issue affects some unknown processing of…
Noderp
6.0.2+
MEDIUM 6.5
CVE-2024-23792
When adding attachments to ticket comments,
another user can add attachments as well impersonating the orginal user. The attack requires a
logged-i…
Otrs
7.0.49 / 2024.1.1+
CRITICAL 9.8
CVE-2024-0988
A vulnerability classified as critical was found in Sichuan Yougou Technology KuERP up to 1.0.4. Affected by this vulnerability is the function check…
Kuerp
after 1.0.4
HIGH 7.5
CVE-2024-23629
An authentication bypass vulnerability exists in the web component of the Motorola MR2600. An attacker can exploit this vulnerability to access prote…
Mr2600 Firmware
Mitigation only
HIGH 7.5
CVE-2024-0822
An authentication bypass vulnerability was found in overt-engine. This flaw allows the creation of users in the system without authentication due to …
Ovirt Engine
Patch available
HIGH 7.5
CVE-2023-50275
HPE OneView may allow clusterService Authentication Bypass resulting in denial of service.
Oneview
8.70+
MEDIUM 6.2
CVE-2024-23219
The issue was addressed with improved authentication. This issue is fixed in iOS 17.3 and iPadOS 17.3. Stolen Device Protection may be unexpectedly d…
Ipados
17.3+
MEDIUM 5.5
CVE-2023-42935
An authentication issue was addressed with improved state management. This issue is fixed in macOS Ventura 13.6.4. A local attacker may be able to vi…
macOS
13.6.4 / 14.1+
HIGH 7.5
CVE-2023-52111
Authorization vulnerability in the BootLoader module. Successful exploitation of this vulnerability may affect service integrity.
Emui
No fix yet
HIGH 7.5
CVE-2023-46942
Lack of authentication in NPM's package @evershop/evershop before version 1.0.0-rc.8, allows remote attackers to obtain sensitive information via imp…
Evershop
Mitigation only
CRITICAL 9.8
CVE-2024-21654
Rubygems.org is the Ruby community's gem hosting service. Rubygems.org users with MFA enabled would normally be protected from account takeover in th…
Rubygems.org
2024-01-08+
CRITICAL 9.8
CVE-2024-22206
Clerk helps developers build user management. Unauthorized access or privilege escalation due to a logic flaw in auth() in the App Router or getAuth(…
Javascript
4.29.3+
HIGH 8.2
CVE-2023-46805 KEVEPSS 100%
An authentication bypass vulnerability in the web component of Ivanti ICS 9.x, 22.x and Ivanti Policy Secure allows a remote attacker to access restr…
Connect Secure
Mitigation only
CRITICAL 9.8
CVE-2023-49262
The authentication mechanism can be bypassed by overflowing the value of the Cookie "authentication" field, provided there is an active user session.
H8951 4g Esp Firmware
2310271149+
CRITICAL 9.8
CVE-2023-50919EPSS 48%
An issue was discovered on GL.iNet devices before version 4.5.0. There is an NGINX authentication bypass via Lua string pattern matching. This affect…
Gl Ax1800 Firmware
No fix yet