Vulnerability index

Browse CVEs

4,342 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
CRITICAL 9.8 CVE-2023-29155 Versions of INEA ME RTU firmware 3.36b and prior do not require authentication to the "root" account on the host system of the device. This could all… Me Rtu Firmware 3.37+ Fix from $2,3002023-11-20 CRITICAL 9.8 CVE-2023-44324 Adobe FrameMaker Publishing Server versions 2022 and earlier are affected by an Improper Authentication vulnerability that could result in a Security… Framemaker Publishing Server 2022+ Fix from $2,3002023-11-17 CRITICAL 9.8 CVE-2023-41442 An issue in Kloudq Technologies Limited Tor Equip 1.0, Tor Loco Mini 1.0 through 3.1 allows a remote attacker to execute arbitrary code via a crafted… Tor Loco Min after 3.1 Fix from $2,3002023-11-15 HIGH 8.8 CVE-2023-43582 Improper authorization in some Zoom clients may allow an authorized user to conduct an escalation of privilege via network access. Meetings 5.14.13 / 5.15.11+ Fix from $1,9502023-11-15 MEDIUM 5.4 CVE-2023-47127 TYPO3 is an open source PHP based web content management system released under the GNU GPL. In typo3 installations there are always at least two diff… TYPO3 8.7.55 / 9.5.44+ Fix from $1,6002023-11-14 HIGH 7.8 CVE-2023-32661 Improper authentication in some Intel(R) NUC Kits NUC7PJYH and NUC7CJYH Realtek* SD Card Reader Driver installation software before version 10.0.1904… Realtek Sd Card Reader Driver 10.0.19041.29098+ Fix from $1,9502023-11-14 HIGH 7.8 CVE-2023-28377 Improper authentication in some Intel(R) NUC Kit NUC11PH USB firmware installation software before version 1.1 for Windows may allow an authenticated… Usb Firmware 1.1+ Fix from $1,9502023-11-14 HIGH 8.8 CVE-2023-22663 Improper authentication for some Intel Unison software may allow an authenticated user to potentially enable escalation of privilege via network acce… Unison Software 20.14.2.3053 / 20.14.4244+ Fix from $1,9502023-11-14 HIGH 7.2 CVE-2023-29975 An issue discovered in Pfsense CE version 2.6.0 allows attackers to change the password of any user without verification. Pfsense Mitigation only Fix from $1,9502023-11-09 CRITICAL 9.8 CVE-2023-4612 Improper Authentication vulnerability in Apereo CAS in jakarta.servlet.http.HttpServletRequest.getRemoteAddr method allows Multi-Factor Authenticatio… Central Authentication Service 7.0.0+ Fix from $2,3002023-11-09 MEDIUM 6.8 CVE-2023-42554 Improper Authentication vulnerabiity in Samsung Pass prior to version 4.3.00.17 allows physical attackers to bypass authentication. Pass 4.3.00.17+ Fix from $1,6002023-11-07 HIGH 7.1 CVE-2023-42531 Improper access control vulnerability in SmsController prior to SMR Nov-2023 Release1 allows local attackers to bypass restrictions on starting activ… Android Mitigation only Fix from $1,9502023-11-07 HIGH 7.8 CVE-2023-24852 Memory Corruption in Core due to secure memory access by user while loading modem image. 315 5g Iot Modem Firmware Mitigation only Fix from $1,9502023-11-07 HIGH 7.5 CVE-2023-39345 strapi is an open-source headless CMS. Versions prior to 4.13.1 did not properly restrict write access to fielded marked as private in the user regis… Strapi 4.13.1+ Fix from $1,9502023-11-06 MEDIUM 6.6 CVE-2023-40660 A flaw was found in OpenSC packages that allow a potential PIN bypass. When a token/card is authenticated by one process, it can perform cryptographi… Enterprise Linux after 0.23.0 Fix from $1,6002023-11-06 MEDIUM 5.3 CVE-2023-46963 An issue in Beijing Yunfan Internet Technology Co., Ltd, Yunfan Learning Examination System v.6.5 allows a remote attacker to obtain sensitive inform… Yunfan Learning Examination System No fix yet Fix from $1,6002023-11-04 HIGH 7.8 CVE-2022-44569 A locally authenticated attacker with low privileges can bypass authentication due to insecure inter-process communication. Automation 2023.4+ Fix from $1,9502023-11-03 HIGH 7.8 CVE-2023-26455 RMI was not requiring authentication when calling ChronosRMIService:setEventOrganizer. Attackers with local or adjacent network access could abuse th… Open Xchange Appsuite 7.10.6+ Fix from $1,9502023-11-02 MEDIUM 5.9 CVE-2023-46327 Multiple MFPs (multifunction printers) provided by FUJIFILM Business Innovation Corp. and Xerox Corporation provide a facility to export the contents… Primelink C9065 Firmware 68.81.41 / 85.40.31+ Fix from $1,6002023-11-02 HIGH 7.5 CVE-2023-5627 A vulnerability has been identified in NPort 6000 Series, making the authentication mechanism vulnerable. This vulnerability arises from the incorrec… Nport 6150 T Firmware after 1.21 Fix from $1,9502023-11-01 CRITICAL 9.8 CVE-2023-46249 authentik is an open-source Identity Provider. Prior to versions 2023.8.4 and 2023.10.2, when the default admin user has been deleted, it is potentia… Authentik 2023.8.4 / 2023.10.2+ Fix from $2,3002023-10-31 CRITICAL 9.8 CVE-2023-44397 CloudExplorer Lite is an open source, lightweight cloud management platform. Prior to version 1.4.1, the gateway filter of CloudExplorer Lite uses a … Cloudexplorer Lite 1.4.1+ Fix from $2,3002023-10-30 MEDIUM 5.0 CVE-2023-21307 In Bluetooth, there is a possible way for a paired Bluetooth device to access a long term identifier for an Android device due to a permissions bypas… Android 14.0+ Fix from $1,6002023-10-30 HIGH 7.2 CVE-2023-5844 Unverified Password Change in GitHub repository pimcore/admin-ui-classic-bundle prior to 1.2.0. Admin Classic Bundle after 1.1.4 Fix from $1,9502023-10-30 CRITICAL 9.8 CVE-2023-5830EPSS 61% A vulnerability classified as critical has been found in ColumbiaSoft Document Locator. This affects an unknown part of the file /api/authentication/… Document Locator 7.2+ Fix from $2,3002023-10-27 HIGH 8.8 CVE-2023-35794 An issue was discovered in Cassia Access Controller 2.1.1.2303271039. The Web SSH terminal endpoint (spawned console) can be accessed without authent… Access Controller No fix yet Fix from $1,9502023-10-27 MEDIUM 6.5 CVE-2022-3681 A vulnerability has been identified in the MR2600 router v1.0.18 and earlier that could allow an attacker within range of the wireless network to suc… Mr2600 after 1.0.18 Fix from $1,6002023-10-27 HIGH 8.1 CVE-2023-46290 Due to inadequate code logic, a previously unauthenticated threat actor could potentially obtain a local Windows OS user token through the FactoryTal… Factorytalk Services Platform 2.80+ Fix from $1,9502023-10-27 MEDIUM 5.4 CVE-2022-34887 Standard users can directly operate and set printer configuration information , such as IP, in some Lenovo Printers without having to authenticate wi… Gm265dn Firmware 02.06.00.04.00+ Fix from $1,6002023-10-27 HIGH 7.5 CVE-2023-30967 Gotham Orbital-Simulator service prior to 0.692.0 was found to be vulnerable to a Path traversal issue allowing an unauthenticated user to read arbit… Orbital Simulator 0.692.0+ Fix from $1,9502023-10-26