Vulnerability index

Browse CVEs

4,342 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
MEDIUM 6.5 CVE-2024-25106 OpenObserve is a observability platform built specifically for logs, metrics, traces, analytics, designed to work at petabyte scale. A critical vulne… Openobserve 0.8.0+ Fix from $1,6002024-02-08 CRITICAL 9.8 CVE-2024-24496EPSS 20% An issue in Daily Habit Tracker v.1.0 allows a remote attacker to manipulate trackers via the home.php, add-tracker.php, delete-tracker.php, update-t… Daily Habit Tracker No fix yet Fix from $2,3002024-02-08 CRITICAL 9.8 CVE-2024-22394 An improper authentication vulnerability has been identified in SonicWall SonicOS SSL-VPN feature, which in specific conditions could allow a remote … Sonicos Mitigation only Fix from $2,3002024-02-08 MEDIUM 5.3 CVE-2024-23806 Sensitive data can be extracted from HID iCLASS SE reader configuration cards. This could include credential and device administrator keys. Omnikey Secure Elements Reader Configuration Cards Firmware Mitigation only Fix from $1,6002024-02-07 MEDIUM 5.9 CVE-2024-24771 Open Forms allows users create and publish smart forms. Versions prior to 2.2.9, 2.3.7, 2.4.5, and 2.5.2 contain a non-exploitable multi-factor authe… Open Forms 2.2.9 / 2.3.7+ Fix from $1,6002024-02-07 MEDIUM 5.3 CVE-2023-39196 Improper Authentication vulnerability in Apache Ozone. The vulnerability allows an attacker to download metadata internal to the Storage Container M… Ozone after 1.3.0 Fix from $1,6002024-02-07 CRITICAL 9.8 CVE-2024-24592 Lack of authentication in all versions of the fileserver component of Allegro AI’s ClearML platform allows a remote attacker to arbitrarily access, c… Clearml No fix yet Fix from $2,3002024-02-06 MEDIUM 6.5 CVE-2024-20815 Improper authentication vulnerability in onCharacteristicReadRequest in Auto Hotspot prior to SMR Feb-2024 Release 1 allows adjacent attackers connec… Android Mitigation only Fix from $1,6002024-02-06 MEDIUM 6.5 CVE-2024-20816 Improper authentication vulnerability in onCharacteristicWriteRequest in Auto Hotspot prior to SMR Feb-2024 Release 1 allows adjacent attackers conne… Android Mitigation only Fix from $1,6002024-02-06 CRITICAL 9.8 CVE-2023-39303 An improper authentication vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could al… Qts Mitigation only Fix from $2,3002024-02-02 MEDIUM 5.3 CVE-2023-50934 IBM PowerSC 1.3, 2.0, and 2.1 uses single-factor authentication which can lead to unnecessary risk of compromise when compared with the benefits of a… Powersc Patch available Fix from $1,6002024-02-02 MEDIUM 5.5 CVE-2023-47256 ConnectWise ScreenConnect through 23.8.4 allows local users to connect to arbitrary relay servers via implicit trust of proxy settings Automate 23.8.5+ Fix from $1,6002024-02-01 CRITICAL 9.8 CVE-2024-1039 Gessler GmbH WEB-MASTER has a restoration account that uses weak hard coded credentials and if exploited could allow an attacker control over the web… Web Master Firmware Mitigation only Fix from $2,3002024-02-01 HIGH 8.8 CVE-2024-23647 Authentik is an open-source Identity Provider. There is a bug in our implementation of PKCE that allows an attacker to circumvent the protection that… Authentik 2023.8.7 / 2023.10.7+ Fix from $1,9502024-01-30 CRITICAL 9.8 CVE-2023-51982 CrateDB 5.5.1 is contains an authentication bypass vulnerability in the Admin UI component. After configuring password authentication and_ Local_ In … Cratedb No fix yet Fix from $2,3002024-01-30 MEDIUM 5.3 CVE-2024-1006 A vulnerability was found in Shanxi Diankeyun Technology NODERP up to 6.0.2 and classified as critical. This issue affects some unknown processing of… Noderp 6.0.2+ Fix from $1,6002024-01-29 MEDIUM 6.5 CVE-2024-23792 When adding attachments to ticket comments, another user can add attachments as well impersonating the orginal user. The attack requires a logged-i… Otrs 7.0.49 / 2024.1.1+ Fix from $1,6002024-01-29 CRITICAL 9.8 CVE-2024-0988 A vulnerability classified as critical was found in Sichuan Yougou Technology KuERP up to 1.0.4. Affected by this vulnerability is the function check… Kuerp after 1.0.4 Fix from $2,3002024-01-29 HIGH 7.5 CVE-2024-23629 An authentication bypass vulnerability exists in the web component of the Motorola MR2600. An attacker can exploit this vulnerability to access prote… Mr2600 Firmware Mitigation only Fix from $1,9502024-01-26 HIGH 7.5 CVE-2024-0822 An authentication bypass vulnerability was found in overt-engine. This flaw allows the creation of users in the system without authentication due to … Ovirt Engine Patch available Fix from $1,9502024-01-25 HIGH 7.5 CVE-2023-50275 HPE OneView may allow clusterService Authentication Bypass resulting in denial of service. Oneview 8.70+ Fix from $1,9502024-01-23 MEDIUM 6.2 CVE-2024-23219 The issue was addressed with improved authentication. This issue is fixed in iOS 17.3 and iPadOS 17.3. Stolen Device Protection may be unexpectedly d… Ipados 17.3+ Fix from $1,6002024-01-23 MEDIUM 5.5 CVE-2023-42935 An authentication issue was addressed with improved state management. This issue is fixed in macOS Ventura 13.6.4. A local attacker may be able to vi… macOS 13.6.4 / 14.1+ Fix from $1,6002024-01-23 HIGH 7.5 CVE-2023-52111 Authorization vulnerability in the BootLoader module. Successful exploitation of this vulnerability may affect service integrity. Emui No fix yet Fix from $1,9502024-01-16 HIGH 7.5 CVE-2023-46942 Lack of authentication in NPM's package @evershop/evershop before version 1.0.0-rc.8, allows remote attackers to obtain sensitive information via imp… Evershop Mitigation only Fix from $1,9502024-01-13 CRITICAL 9.8 CVE-2024-21654 Rubygems.org is the Ruby community's gem hosting service. Rubygems.org users with MFA enabled would normally be protected from account takeover in th… Rubygems.org 2024-01-08+ Fix from $2,3002024-01-12 CRITICAL 9.8 CVE-2024-22206 Clerk helps developers build user management. Unauthorized access or privilege escalation due to a logic flaw in auth() in the App Router or getAuth(… Javascript 4.29.3+ Fix from $2,3002024-01-12 HIGH 8.2 CVE-2023-46805 KEVEPSS 100% An authentication bypass vulnerability in the web component of Ivanti ICS 9.x, 22.x and Ivanti Policy Secure allows a remote attacker to access restr… Connect Secure Mitigation only Fix from $1,9502024-01-12 CRITICAL 9.8 CVE-2023-49262 The authentication mechanism can be bypassed by overflowing the value of the Cookie "authentication" field, provided there is an active user session. H8951 4g Esp Firmware 2310271149+ Fix from $2,3002024-01-12 CRITICAL 9.8 CVE-2023-50919EPSS 48% An issue was discovered on GL.iNet devices before version 4.5.0. There is an NGINX authentication bypass via Lua string pattern matching. This affect… Gl Ax1800 Firmware No fix yet Fix from $2,3002024-01-12