Vulnerability index

Browse CVEs

4,342 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
MEDIUM 5.9 CVE-2023-50127 Hozard alarm system (Alarmsysteem) v1.0 is vulnerable to Improper Authentication. Commands sent via the SMS functionality are accepted from random ph… Alarm System No fix yet Fix from $1,6002024-01-11 CRITICAL 9.8 CVE-2024-21638 Azure IPAM (IP Address Management) is a lightweight solution developed on top of the Azure platform designed to help Azure customers manage their IP … Azure Ipam 3.0.0+ Fix from $2,3002024-01-10 HIGH 8.8 CVE-2023-48257 The vulnerability allows a remote attacker to access sensitive data inside exported packages or obtain up to Remote Code Execution (RCE) with root pr… Nexo Os after 1500-sp2 Fix from $1,9502024-01-10 CRITICAL 9.1 CVE-2023-5376 An Improper Authentication vulnerability in Korenix JetNet TFTP allows abuse of this service. This issue affects JetNet devices older than firmware v… Jetnet 5310g Firmware No fix yet Fix from $2,3002024-01-09 CRITICAL 9.8 CVE-2023-51717 Dataiku DSS before 11.4.5 and 12.4.1 has Incorrect Access Control that could lead to a full authentication bypass. Data Science Studio 11.4.5 / 12.4.1+ Fix from $2,3002024-01-09 CRITICAL 9.8 CVE-2023-7210 A vulnerability was found in OneNav up to 0.9.33. It has been classified as critical. This affects an unknown part of the file /index.php?c=api of th… Onenav after 0.9.33 Fix from $2,3002024-01-07 HIGH 8.1 CVE-2023-7211 A vulnerability was found in Uniway Router 2.0. It has been declared as critical. This vulnerability affects unknown code of the component Administra… Uw 302vp Firmware after 2.0 Fix from $1,9502024-01-07 MEDIUM 6.5 CVE-2024-20803 Improper authentication vulnerability in Bluetooth pairing process prior to SMR Jan-2024 Release 1 allows remote attackers to establish pairing proce… Android Mitigation only Fix from $1,6002024-01-04 CRITICAL 9.8 CVE-2024-21632 omniauth-microsoft_graph provides an Omniauth strategy for the Microsoft Graph API. Prior to versions 2.0.0, the implementation did not validate the … Omniauth\ 2.0.0+ Fix from $2,3002024-01-02 MEDIUM 5.7 CVE-2023-7079 Sending specially crafted HTTP requests and inspector messages to Wrangler's dev server could result in any file on the user's computer being accessi… Wrangler 3.19.0+ Fix from $1,6002023-12-29 MEDIUM 5.5 CVE-2023-31292 An issue was discovered in Sesami Cash Point & Transport Optimizer (CPTO) 6.3.8.6 (#718), allows local attackers to obtain sensitive information and … Cash Point \& Transport Optimizer Mitigation only Fix from $1,6002023-12-29 HIGH 8.8 CVE-2023-40038 Arris DG860A and DG1670A devices have predictable default WPA2 PSKs that could lead to unauthorized remote access. (They use the first 6 characters o… Dg860a Firmware Mitigation only Fix from $1,9502023-12-27 MEDIUM 5.5 CVE-2023-4641 A flaw was found in shadow-utils. When asking for a new password, shadow-utils asks the password twice. If the password fails on the second attempt, … Codeready Linux Builder Mitigation only Fix from $1,6002023-12-27 MEDIUM 5.3 CVE-2023-6155 The Quiz Maker WordPress plugin before 6.4.9.5 does not adequately authorize the `ays_quiz_author_user_search` AJAX action, allowing an unauthenticat… Quiz Maker 6.4.9.5+ Fix from $1,6002023-12-26 CRITICAL 9.8 CVE-2022-34267EPSS 42% An issue was discovered in RWS WorldServer before 11.7.3. Adding a token parameter with the value of 02 bypasses all authentication requirements. Arb… Worldserver 11.7.3+ Fix from $2,3002023-12-25 CRITICAL 9.8 CVE-2023-31224 There is broken access control during authentication in Jamf Pro Server before 10.46.1. Jamf 10.47.0+ Fix from $2,3002023-12-25 HIGH 8.8 CVE-2023-50714 yii2-authclient is an extension that adds OpenID, OAuth, OAuth2 and OpenId Connect consumers for the Yii framework 2.0. In yii2-authclient prior to v… Yii2 Authclient 2.2.15+ Fix from $1,9502023-12-22 MEDIUM 5.4 CVE-2023-49791 Nextcloud Server provides data storage for Nextcloud, an open source cloud platform. In Nextcloud Server prior to versions 26.0.9 and 27.1.4; as well… Nextcloud Server 23.0.12.13 / 24.0.12.9+ Fix from $1,6002023-12-22 HIGH 8.6 CVE-2023-51708 Bentley eB System Management Console applications within Assetwise Integrity Information Server allow an unauthenticated user to view configuration o… Assetwise Alim For Transportation 23.00.01.25 / 23.00.02.03+ Fix from $1,9502023-12-22 HIGH 7.5 CVE-2023-6847 An improper authentication vulnerability was identified in GitHub Enterprise Server that allowed a bypass of Private Mode by using a specially crafte… Enterprise Server 3.9.7 / 3.10.4+ Fix from $1,9502023-12-21 HIGH 8.6 CVE-2023-51442 Navidrome is an open source web-based music collection server and streamer. A security vulnerability has been identified in navidrome's subsonic endp… Navidrome 0.50.2+ Fix from $1,9502023-12-21 CRITICAL 9.8 CVE-2023-6768 Authentication bypass vulnerability in Amazing Little Poll affecting versions 1.3 and 1.4. This vulnerability could allow an unauthenticated user to … Amazing Little Poll Mitigation only Fix from $2,3002023-12-20 HIGH 7.5 CVE-2023-37544 Improper Authentication vulnerability in Apache Pulsar WebSocket Proxy allows an attacker to connect to the /pingpong endpoint without authentication… Pulsar 2.10.5 / 2.11.2+ Fix from $1,9502023-12-20 CRITICAL 9.8 CVE-2023-6483 The vulnerability exists in ADiTaaS (Allied Digital Integrated Tool-as-a-Service) version 5.1 due to an improper authentication vulnerability in the … Allied Digital Integrated Tool As A Service Mitigation only Fix from $2,3002023-12-18 CRITICAL 9.1 CVE-2023-6907 A vulnerability has been found in codelyfe Stupid Simple CMS up to 1.2.4 and classified as critical. Affected by this vulnerability is an unknown fun… Stupid Simple Cms after 1.2.4 Fix from $2,3002023-12-18 MEDIUM 6.5 CVE-2023-49646 Improper authentication in some Zoom clients before version 5.16.5 may allow an authenticated user to conduct a denial of service via network access. Meeting Software Development Kit 5.14.14 / 5.15.12+ Fix from $1,6002023-12-13 HIGH 8.8 CVE-2023-44252 ** UNSUPPORTED WHEN ASSIGNED **An improper authentication vulnerability [CWE-287] in Fortinet FortiWAN version 5.2.0 through 5.2.1 and version 5.1.1 … Fortiwan Mitigation only Fix from $1,9502023-12-13 HIGH 7.5 CVE-2023-45801 Improper Authentication vulnerability in Nadatel DVR allows Information Elicitation.This issue affects DVR: from 3.0.0 before 9.9.0. At 0402r Firmware 9.9.0+ Fix from $1,9502023-12-13 HIGH 7.5 CVE-2023-36004 Windows DPAPI (Data Protection Application Programming Interface) Spoofing Vulnerability Windows 10 1507 10.0.10240.20345 / 10.0.14393.6529+ Fix from $1,9502023-12-12 HIGH 8.2 CVE-2023-36648 Missing authentication in the internal data streaming system in ProLion CryptoSpike 3.0.15P2 allows remote unauthenticated users to read potentially … Cryptospike No fix yet Fix from $1,9502023-12-12