Vulnerability index

Browse CVEs

4,342 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
MEDIUM 6.4 CVE-2023-50430 The Goodix Fingerprint Device, as shipped in Dell Inspiron 15 computers, does not follow the Secure Device Connection Protocol (SDCP) when enrolling … Fingerprint Sensor Firmware No fix yet Fix from $1,6002023-12-09 MEDIUM 6.3 CVE-2023-45866EPSS 8% Bluetooth HID Hosts in BlueZ may permit an unauthenticated Peripheral role HID Device to initiate and establish an encrypted connection, and accept H… Ubuntu Linux 14.2 / 17.2+ Fix from $1,6002023-12-08 CRITICAL 9.8 CVE-2023-43742 An authentication bypass in Zultys MX-SE, MX-SE II, MX-E, MX-Virtual, MX250, and MX30 with firmware versions prior to 17.0.10 patch 17161 and 16.04 p… Mx Se Firmware 16.0.4 / 17.0.10+ Fix from $2,3002023-12-08 CRITICAL 9.8 CVE-2023-36655 The login REST API in ProLion CryptoSpike 3.0.15P2 (when LDAP or Active Directory is used as the users store) allows a remote blocked user to login a… Cryptospike No fix yet Fix from $2,3002023-12-06 HIGH 8.8 CVE-2023-6514 The Bluetooth module of some Huawei Smart Screen products has an identity authentication bypass vulnerability. Successful exploitation of this vulner… Ajmd 370s Firmware Mitigation only Fix from $1,9502023-12-06 HIGH 8.8 CVE-2023-5970 Improper authentication in the SMA100 SSL-VPN virtual office portal allows a remote authenticated attacker to create an identical external domain use… Sma 200 Firmware after 10.2.1.9-57sv Fix from $1,9502023-12-05 HIGH 7.8 CVE-2023-47304 An issue was discovered in Vonage Box Telephone Adapter VDV23 version VDV21-3.2.11-0.5.1, allows local attackers to bypass UART authentication contro… Vdv23 Firmware No fix yet Fix from $1,9502023-12-05 MEDIUM 6.8 CVE-2023-42576 Improper Authentication vulnerability in Samsung Pass prior to version 4.3.00.17 allows physical attackers to bypass authentication due to invalid ex… Pass 4.3.00.17+ Fix from $1,6002023-12-05 MEDIUM 5.5 CVE-2023-33070 Transient DOS in Automotive OS due to improper authentication to the secure IO calls. Aqt1000 Firmware Patch available Fix from $1,6002023-12-05 CRITICAL 9.1 CVE-2023-33054 Cryptographic issue in GPS HLOS Driver while downloading Qualcomm GNSS assistance data. 315 5g Iot Modem Firmware Mitigation only Fix from $2,3002023-12-05 MEDIUM 6.5 CVE-2023-5808 SMU versions prior to 14.8.7825.01 are susceptible to unintended information disclosure, through URL manipulation. Authenticated users in a Storage a… Vantara Hitachi Network Attached Storage after 14.8.7825.01 Fix from $1,6002023-12-05 CRITICAL 9.8 CVE-2023-44302 Dell DM5500 5.14.0.0 and prior contain an improper authentication vulnerability. A remote unauthenticated attacker could potentially exploit this vul… Powerprotect Data Manager Dm5500 Firmware after 5.14.0.0 Fix from $2,3002023-12-04 CRITICAL 9.4 CVE-2023-6353 Tyler Technologies Civil and Criminal Electronic Filing allows an unauthenticated, remote attacker to upload, delete, and view files by manipulating … Court Case Management Plus Mitigation only Fix from $2,3002023-11-30 CRITICAL 9.4 CVE-2023-6354 Tyler Technologies Magistrate Court Case Management Plus allows an unauthenticated, remote attacker to upload, delete, and view files by manipulating… Court Case Management Plus Mitigation only Fix from $2,3002023-11-30 CRITICAL 9.8 CVE-2023-6342 Tyler Technologies Court Case Management Plus allows a remote attacker to authenticate as any user by manipulating at least the 'CmWebSearchPfp/Login… Court Case Management Plus Mitigation only Fix from $2,3002023-11-30 MEDIUM 5.3 CVE-2023-6343 Tyler Technologies Court Case Management Plus allows a remote, unauthenticated attacker to enumerate and access sensitive files using the tiffserver/… Court Case Management Plus Mitigation only Fix from $1,6002023-11-30 MEDIUM 5.3 CVE-2023-6344 Tyler Technologies Court Case Management Plus allows a remote, unauthenticated attacker to enumerate directories using the tiffserver/te003.aspx or t… Court Case Management Plus Mitigation only Fix from $1,6002023-11-30 CRITICAL 9.8 CVE-2023-34388 An Improper Authentication vulnerability in the Schweitzer Engineering Laboratories SEL-451 could allow a remote unauthenticated attacker to potentia… Sel 451 Firmware Mitigation only Fix from $2,3002023-11-30 HIGH 7.5 CVE-2023-35137 An improper authentication vulnerability in the authentication module of the Zyxel NAS326 firmware version V5.21(AAZF.14)C0 and NAS542 firmware versi… Nas326 Firmware after 5.21 Fix from $1,9502023-11-30 MEDIUM 5.3 CVE-2023-48121 An authentication bypass vulnerability in the Direct Connection Module in Ezviz CS-C6N-xxx prior to v5.3.x build 20230401, Ezviz CS-CV310-xxx prior t… Cs C6n A0 1c2wfr Firmware Mitigation only Fix from $1,6002023-11-28 CRITICAL 9.8 CVE-2023-41264 Netwrix Usercube before 6.0.215, in certain misconfigured on-premises installations, allows authentication bypass on deployment endpoints, leading to… Usercube 6.0.215+ Fix from $2,3002023-11-28 HIGH 8.8 CVE-2022-41678EPSS 86% Once an user is authenticated on Jolokia, he can potentially trigger arbitrary code execution.  In details, in ActiveMQ configurations, jetty allows… Activemq 5.16.6 / 5.17.4+ Fix from $1,9502023-11-28 CRITICAL 9.8 CVE-2023-6329EPSS 65% An authentication bypass vulnerability exists in Control iD iDSecure v4.7.32.0. The login routine used by iDS-Core.dll contains a "passwordCustom" op… Idsecure No fix yet Fix from $2,3002023-11-27 CRITICAL 9.8 CVE-2023-41999 An authentication bypass exists in Arcserve UDP prior to version 9.2. An unauthenticated, remote attacker can obtain a valid authentication identifie… Udp 9.2+ Fix from $2,3002023-11-27 CRITICAL 9.8 CVE-2023-48312 capsule-proxy is a reverse proxy for the capsule operator project. Affected versions are subject to a privilege escalation vulnerability which is bas… Capsule Proxy after 0.4.5 Fix from $2,3002023-11-24 CRITICAL 9.8 CVE-2023-4677 Cron log backup files contain administrator session IDs. It is trivial for any attacker who can reach the Pandora FMS Console to scrape the cron logs… Pandora Fms 773+ Fix from $2,3002023-11-23 HIGH 8.1 CVE-2023-2437EPSS 7% The UserPro plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 5.1.1. This is due to insufficient verifica… Userpro after 5.1.1 Fix from $1,9502023-11-22 CRITICAL 9.8 CVE-2023-49105EPSS 11% An issue was discovered in ownCloud owncloud/core before 10.13.1. An attacker can access, modify, or delete any file without authentication if the us… Owncloud Server 10.13.1+ Fix from $2,3002023-11-21 CRITICAL 9.8 CVE-2023-6248 The Syrus4 IoT gateway utilizes an unsecured MQTT server to download and execute arbitrary commands, allowing a remote unauthenticated attacker to ex… Syrus 4g Iot Telematics Gateway Firmware Mitigation only Fix from $2,3002023-11-21 CRITICAL 9.8 CVE-2023-48228 authentik is an open-source identity provider. When initialising a oauth2 flow with a `code_challenge` and `code_method` (thus requesting PKCE), the … Authentik 2023.8.5 / 2023.10.4+ Fix from $2,3002023-11-21