Top technology
Linux 13140
Google 12530
Microsoft 12379
Oracle 6737
Apple 6692
Adobe 6387
Ibm 6330
Cisco 5757
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 5.9
CVE-2023-50127
Hozard alarm system (Alarmsysteem) v1.0 is vulnerable to Improper Authentication. Commands sent via the SMS functionality are accepted from random ph…
Alarm System
No fix yet
CRITICAL 9.8
CVE-2024-21638
Azure IPAM (IP Address Management) is a lightweight solution developed on top of the Azure platform designed to help Azure customers manage their IP …
Azure Ipam
3.0.0+
HIGH 8.8
CVE-2023-48257
The vulnerability allows a remote attacker to access sensitive data inside exported packages or obtain up to Remote Code Execution (RCE) with root pr…
Nexo Os
after 1500-sp2
CRITICAL 9.1
CVE-2023-5376
An Improper Authentication vulnerability in Korenix JetNet TFTP allows abuse of this service. This issue affects JetNet devices older than firmware v…
Jetnet 5310g Firmware
No fix yet
CRITICAL 9.8
CVE-2023-51717
Dataiku DSS before 11.4.5 and 12.4.1 has Incorrect Access Control that could lead to a full authentication bypass.
Data Science Studio
11.4.5 / 12.4.1+
CRITICAL 9.8
CVE-2023-7210
A vulnerability was found in OneNav up to 0.9.33. It has been classified as critical. This affects an unknown part of the file /index.php?c=api of th…
Onenav
after 0.9.33
HIGH 8.1
CVE-2023-7211
A vulnerability was found in Uniway Router 2.0. It has been declared as critical. This vulnerability affects unknown code of the component Administra…
Uw 302vp Firmware
after 2.0
MEDIUM 6.5
CVE-2024-20803
Improper authentication vulnerability in Bluetooth pairing process prior to SMR Jan-2024 Release 1 allows remote attackers to establish pairing proce…
Android
Mitigation only
CRITICAL 9.8
CVE-2024-21632
omniauth-microsoft_graph provides an Omniauth strategy for the Microsoft Graph API. Prior to versions 2.0.0, the implementation did not validate the …
Omniauth\
2.0.0+
MEDIUM 5.7
CVE-2023-7079
Sending specially crafted HTTP requests and inspector messages to Wrangler's dev server could result in any file on the user's computer being accessi…
Wrangler
3.19.0+
MEDIUM 5.5
CVE-2023-31292
An issue was discovered in Sesami Cash Point & Transport Optimizer (CPTO) 6.3.8.6 (#718), allows local attackers to obtain sensitive information and …
Cash Point \& Transport Optimizer
Mitigation only
HIGH 8.8
CVE-2023-40038
Arris DG860A and DG1670A devices have predictable default WPA2 PSKs that could lead to unauthorized remote access. (They use the first 6 characters o…
Dg860a Firmware
Mitigation only
MEDIUM 5.5
CVE-2023-4641
A flaw was found in shadow-utils. When asking for a new password, shadow-utils asks the password twice. If the password fails on the second attempt, …
Codeready Linux Builder
Mitigation only
MEDIUM 5.3
CVE-2023-6155
The Quiz Maker WordPress plugin before 6.4.9.5 does not adequately authorize the `ays_quiz_author_user_search` AJAX action, allowing an unauthenticat…
Quiz Maker
6.4.9.5+
CRITICAL 9.8
CVE-2022-34267EPSS 42%
An issue was discovered in RWS WorldServer before 11.7.3. Adding a token parameter with the value of 02 bypasses all authentication requirements. Arb…
Worldserver
11.7.3+
CRITICAL 9.8
CVE-2023-31224
There is broken access control during authentication in Jamf Pro Server before 10.46.1.
Jamf
10.47.0+
HIGH 8.8
CVE-2023-50714
yii2-authclient is an extension that adds OpenID, OAuth, OAuth2 and OpenId Connect consumers for the Yii framework 2.0. In yii2-authclient prior to v…
Yii2 Authclient
2.2.15+
MEDIUM 5.4
CVE-2023-49791
Nextcloud Server provides data storage for Nextcloud, an open source cloud platform. In Nextcloud Server prior to versions 26.0.9 and 27.1.4; as well…
Nextcloud Server
23.0.12.13 / 24.0.12.9+
HIGH 8.6
CVE-2023-51708
Bentley eB System Management Console applications within Assetwise Integrity Information Server allow an unauthenticated user to view configuration o…
Assetwise Alim For Transportation
23.00.01.25 / 23.00.02.03+
HIGH 7.5
CVE-2023-6847
An improper authentication vulnerability was identified in GitHub Enterprise Server that allowed a bypass of Private Mode by using a specially crafte…
Enterprise Server
3.9.7 / 3.10.4+
HIGH 8.6
CVE-2023-51442
Navidrome is an open source web-based music collection server and streamer. A security vulnerability has been identified in navidrome's subsonic endp…
Navidrome
0.50.2+
CRITICAL 9.8
CVE-2023-6768
Authentication bypass vulnerability in Amazing Little Poll affecting versions 1.3 and 1.4. This vulnerability could allow an unauthenticated user to …
Amazing Little Poll
Mitigation only
HIGH 7.5
CVE-2023-37544
Improper Authentication vulnerability in Apache Pulsar WebSocket Proxy allows an attacker to connect to the /pingpong endpoint without authentication…
Pulsar
2.10.5 / 2.11.2+
CRITICAL 9.8
CVE-2023-6483
The vulnerability exists in ADiTaaS (Allied Digital Integrated Tool-as-a-Service) version 5.1 due to an improper authentication vulnerability in the …
Allied Digital Integrated Tool As A Service
Mitigation only
CRITICAL 9.1
CVE-2023-6907
A vulnerability has been found in codelyfe Stupid Simple CMS up to 1.2.4 and classified as critical. Affected by this vulnerability is an unknown fun…
Stupid Simple Cms
after 1.2.4
MEDIUM 6.5
CVE-2023-49646
Improper authentication in some Zoom clients before version 5.16.5 may allow an authenticated user to conduct a denial of service via network access.
Meeting Software Development Kit
5.14.14 / 5.15.12+
HIGH 8.8
CVE-2023-44252
** UNSUPPORTED WHEN ASSIGNED **An improper authentication vulnerability [CWE-287] in Fortinet FortiWAN version 5.2.0 through 5.2.1 and version 5.1.1 …
Fortiwan
Mitigation only
HIGH 7.5
CVE-2023-45801
Improper Authentication vulnerability in Nadatel DVR allows Information Elicitation.This issue affects DVR: from 3.0.0 before 9.9.0.
At 0402r Firmware
9.9.0+
HIGH 7.5
CVE-2023-36004
Windows DPAPI (Data Protection Application Programming Interface) Spoofing Vulnerability
Windows 10 1507
10.0.10240.20345 / 10.0.14393.6529+
HIGH 8.2
CVE-2023-36648
Missing authentication in the internal data streaming system in ProLion CryptoSpike 3.0.15P2 allows remote unauthenticated users to read potentially …
Cryptospike
No fix yet