Top technology
Linux 13140
Google 12530
Microsoft 12379
Oracle 6737
Apple 6692
Adobe 6387
Ibm 6330
Cisco 5757
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 6.4
CVE-2023-50430
The Goodix Fingerprint Device, as shipped in Dell Inspiron 15 computers, does not follow the Secure Device Connection Protocol (SDCP) when enrolling …
Fingerprint Sensor Firmware
No fix yet
MEDIUM 6.3
CVE-2023-45866EPSS 8%
Bluetooth HID Hosts in BlueZ may permit an unauthenticated Peripheral role HID Device to initiate and establish an encrypted connection, and accept H…
Ubuntu Linux
14.2 / 17.2+
CRITICAL 9.8
CVE-2023-43742
An authentication bypass in Zultys MX-SE, MX-SE II, MX-E, MX-Virtual, MX250, and MX30 with firmware versions prior to 17.0.10 patch 17161 and 16.04 p…
Mx Se Firmware
16.0.4 / 17.0.10+
CRITICAL 9.8
CVE-2023-36655
The login REST API in ProLion CryptoSpike 3.0.15P2 (when LDAP or Active Directory is used as the users store) allows a remote blocked user to login a…
Cryptospike
No fix yet
HIGH 8.8
CVE-2023-6514
The Bluetooth module of some Huawei Smart Screen products has an identity authentication bypass vulnerability. Successful exploitation of this vulner…
Ajmd 370s Firmware
Mitigation only
HIGH 8.8
CVE-2023-5970
Improper authentication in the SMA100 SSL-VPN virtual office portal allows a remote authenticated attacker to create an identical external domain use…
Sma 200 Firmware
after 10.2.1.9-57sv
HIGH 7.8
CVE-2023-47304
An issue was discovered in Vonage Box Telephone Adapter VDV23 version VDV21-3.2.11-0.5.1, allows local attackers to bypass UART authentication contro…
Vdv23 Firmware
No fix yet
MEDIUM 6.8
CVE-2023-42576
Improper Authentication vulnerability in Samsung Pass prior to version 4.3.00.17 allows physical attackers to bypass authentication due to invalid ex…
Pass
4.3.00.17+
MEDIUM 5.5
CVE-2023-33070
Transient DOS in Automotive OS due to improper authentication to the secure IO calls.
Aqt1000 Firmware
Patch available
CRITICAL 9.1
CVE-2023-33054
Cryptographic issue in GPS HLOS Driver while downloading Qualcomm GNSS assistance data.
315 5g Iot Modem Firmware
Mitigation only
MEDIUM 6.5
CVE-2023-5808
SMU versions prior to 14.8.7825.01 are susceptible to unintended information disclosure, through URL manipulation. Authenticated users in a Storage a…
Vantara Hitachi Network Attached Storage
after 14.8.7825.01
CRITICAL 9.8
CVE-2023-44302
Dell DM5500 5.14.0.0 and prior contain an improper authentication vulnerability. A remote unauthenticated attacker could potentially exploit this vul…
Powerprotect Data Manager Dm5500 Firmware
after 5.14.0.0
CRITICAL 9.4
CVE-2023-6353
Tyler Technologies Civil and Criminal Electronic Filing allows an unauthenticated, remote attacker to upload, delete, and view files by manipulating …
Court Case Management Plus
Mitigation only
CRITICAL 9.4
CVE-2023-6354
Tyler Technologies Magistrate Court Case Management Plus allows an unauthenticated, remote attacker to upload, delete, and view files by manipulating…
Court Case Management Plus
Mitigation only
CRITICAL 9.8
CVE-2023-6342
Tyler Technologies Court Case Management Plus allows a remote attacker to authenticate as any user by manipulating at least the 'CmWebSearchPfp/Login…
Court Case Management Plus
Mitigation only
MEDIUM 5.3
CVE-2023-6343
Tyler Technologies Court Case Management Plus allows a remote, unauthenticated attacker to enumerate and access sensitive files using the tiffserver/…
Court Case Management Plus
Mitigation only
MEDIUM 5.3
CVE-2023-6344
Tyler Technologies Court Case Management Plus allows a remote, unauthenticated attacker to enumerate directories using the tiffserver/te003.aspx or t…
Court Case Management Plus
Mitigation only
CRITICAL 9.8
CVE-2023-34388
An Improper Authentication vulnerability in the Schweitzer Engineering Laboratories SEL-451 could allow a remote unauthenticated attacker to potentia…
Sel 451 Firmware
Mitigation only
HIGH 7.5
CVE-2023-35137
An improper authentication vulnerability in the authentication module of the Zyxel NAS326 firmware version V5.21(AAZF.14)C0 and NAS542 firmware versi…
Nas326 Firmware
after 5.21
MEDIUM 5.3
CVE-2023-48121
An authentication bypass vulnerability in the Direct Connection Module in Ezviz CS-C6N-xxx prior to v5.3.x build 20230401, Ezviz CS-CV310-xxx prior t…
Cs C6n A0 1c2wfr Firmware
Mitigation only
CRITICAL 9.8
CVE-2023-41264
Netwrix Usercube before 6.0.215, in certain misconfigured on-premises installations, allows authentication bypass on deployment endpoints, leading to…
Usercube
6.0.215+
HIGH 8.8
CVE-2022-41678EPSS 86%
Once an user is authenticated on Jolokia, he can potentially trigger arbitrary code execution.
In details, in ActiveMQ configurations, jetty allows…
Activemq
5.16.6 / 5.17.4+
CRITICAL 9.8
CVE-2023-6329EPSS 65%
An authentication bypass vulnerability exists in Control iD iDSecure v4.7.32.0. The login routine used by iDS-Core.dll contains a "passwordCustom" op…
Idsecure
No fix yet
CRITICAL 9.8
CVE-2023-41999
An authentication bypass exists in Arcserve UDP prior to version 9.2. An unauthenticated, remote attacker can obtain a valid authentication identifie…
Udp
9.2+
CRITICAL 9.8
CVE-2023-48312
capsule-proxy is a reverse proxy for the capsule operator project. Affected versions are subject to a privilege escalation vulnerability which is bas…
Capsule Proxy
after 0.4.5
CRITICAL 9.8
CVE-2023-4677
Cron log backup files contain administrator session IDs. It is trivial for any attacker who can reach the Pandora FMS Console to scrape the cron logs…
Pandora Fms
773+
HIGH 8.1
CVE-2023-2437EPSS 7%
The UserPro plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 5.1.1. This is due to insufficient verifica…
Userpro
after 5.1.1
CRITICAL 9.8
CVE-2023-49105EPSS 11%
An issue was discovered in ownCloud owncloud/core before 10.13.1. An attacker can access, modify, or delete any file without authentication if the us…
Owncloud Server
10.13.1+
CRITICAL 9.8
CVE-2023-6248
The Syrus4 IoT gateway utilizes an unsecured MQTT server to download and execute arbitrary commands, allowing a remote unauthenticated attacker to ex…
Syrus 4g Iot Telematics Gateway Firmware
Mitigation only
CRITICAL 9.8
CVE-2023-48228
authentik is an open-source identity provider. When initialising a oauth2 flow with a `code_challenge` and `code_method` (thus requesting PKCE), the …
Authentik
2023.8.5 / 2023.10.4+