Vulnerability index

Browse CVEs

4,342 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
CRITICAL 9.8 CVE-2023-37283 Under a very specific and highly unrecommended configuration, authentication bypass is possible in the PingFederate Identifier First Adapter Pingfederate after 11.2.6 Fix from $2,3002023-10-25 HIGH 7.5 CVE-2023-27377 Missing authentication in the StudentPopupDetails_EmergencyContactDetails method in IDAttend’s IDWeb application 3.1.052 and earlier allows ex… Idweb after 3.1.052 Fix from $1,9502023-10-25 HIGH 8.8 CVE-2023-5246 Authentication Bypass by Capture-replay in SICK Flexi Soft Gateways with Partnumbers 1044073, 1127717, 1130282, 1044074, 1121597, 1099832, 1051432, 1… Fx0 Gent00000 Firmware Mitigation only Fix from $1,9502023-10-23 MEDIUM 6.5 CVE-2023-38735 IBM Cognos Dashboards on Cloud Pak for Data 4.7.0 could allow a remote attacker to bypass security restrictions, caused by a reverse tabnabbing flaw.… Cognos Dashboards On Cloud Pak For Data Patch available Fix from $1,6002023-10-22 MEDIUM 5.3 CVE-2023-4939 The SALESmanago plugin for WordPress is vulnerable to Log Injection in versions up to, and including, 3.2.4. This is due to the use of a weak authent… Salesmanago after 3.2.4 Fix from $1,6002023-10-21 HIGH 8.8 CVE-2023-41089 The affected product is vulnerable to an improper authentication vulnerability, which may allow an attacker to impersonate a legitimate user as long … Dexgate Mitigation only Fix from $1,9502023-10-19 MEDIUM 5.3 CVE-2023-45669 WebAuthn4J Spring Security provides Web Authentication specification support for Spring applications. Affected versions are subject to improper signa… Spring Security 0.9.1+ Fix from $1,6002023-10-16 CRITICAL 9.1 CVE-2023-4562 Improper Authentication vulnerability in Mitsubishi Electric Corporation MELSEC-F Series main modules allows a remote unauthenticated attacker to obt… Fx3g 14 Mr\/ds Firmware Mitigation only Fix from $2,3002023-10-13 MEDIUM 5.3 CVE-2023-41261 An issue was discovered in /fcgi/scrut_fcgi.fcgi in Plixer Scrutinizer before 19.3.1. The csvExportReport endpoint action generateCSV does not requir… Scrutinizer 19.3.1+ Fix from $1,6002023-10-12 HIGH 7.8 CVE-2023-23632 BeyondTrust Privileged Remote Access (PRA) versions 22.2.x to 22.4.x are vulnerable to a local authentication bypass. Attackers can exploit a flawed … Privileged Remote Access 22.3.3+ Fix from $1,9502023-10-12 CRITICAL 9.8 CVE-2023-24479 An authentication bypass vulnerability exists in the httpd nvram.cgi functionality of Yifan YF325 v1.0_20221108. A specially crafted network request … Yf325 Firmware Mitigation only Fix from $2,3002023-10-11 HIGH 7.5 CVE-2023-44096 Vulnerability of brute-force attacks on the device authentication module.Successful exploitation of this vulnerability may affect service confidentia… Harmonyos No fix yet Fix from $1,9502023-10-11 MEDIUM 5.5 CVE-2023-36724 Windows Power Management Service Information Disclosure Vulnerability Windows 10 1507 10.0.10240.20232 / 10.0.14393.6351+ Fix from $1,6002023-10-10 HIGH 7.5 CVE-2023-43793 Misskey is an open source, decentralized social media platform. Prior to version 2023.9.0, by editing the URL, a user can bypass the authentication o… Misskey 2023.9.0+ Fix from $1,9502023-10-04 HIGH 7.5 CVE-2023-43805 Nexkey is a fork of Misskey, an open source, decentralized social media platform. Prior to version 12.121.9, incomplete URL validation can allow user… Nexkey 12.121.9+ Fix from $1,9502023-10-04 HIGH 7.5 CVE-2023-43809 Soft Serve is a self-hostable Git server for the command line. Prior to version 0.6.2, a security vulnerability in Soft Serve could allow an unauthen… Soft Serve 0.6.2+ Fix from $1,9502023-10-04 HIGH 7.0 CVE-2021-3784 Garuda Linux performs an insecure user creation and authentication that allows any user to impersonate the created account. By creating users from th… Garuda Linux Mitigation only Fix from $1,9502023-10-04 MEDIUM 6.5 CVE-2023-40376 IBM UrbanCode Deploy (UCD) 7.1 - 7.1.2.12, 7.2 through 7.2.3.5, and 7.3 through 7.3.2.0 under certain configurations could allow an authenticated use… Urbancode Deploy after 7.3.2.0 Fix from $1,6002023-10-04 HIGH 7.5 CVE-2023-28540 Cryptographic issue in Data Modem due to improper authentication during TLS handshake. 315 5g Iot Modem Firmware Mitigation only Fix from $1,9502023-10-03 HIGH 7.5 CVE-2023-26150 Versions of the package asyncua before 0.9.96 are vulnerable to Improper Authentication such that it is possible to access Address Space without encr… Opcua Asyncio 0.9.96+ Fix from $1,9502023-10-03 HIGH 8.8 CVE-2023-42771 Authentication bypass vulnerability in ACERA 1320 firmware ver.01.26 and earlier, and ACERA 1310 firmware ver.01.26 and earlier allows a network-adja… Acera 1310 Firmware after 01.26 Fix from $1,9502023-10-03 HIGH 8.8 CVE-2023-5328 A vulnerability classified as critical has been found in SATO CL4NX-J Plus 1.13.2-u455_r2. This affects an unknown part of the component Cookie Handl… Cl4nx J Plus Firmware Mitigation only Fix from $1,9502023-10-02 HIGH 7.5 CVE-2023-5329 A vulnerability classified as problematic was found in Field Logic DataCube4 up to 20231001. This vulnerability affects unknown code of the file /api… Datacube4 Firmware after 2023-10-01 Fix from $1,9502023-10-02 HIGH 8.8 CVE-2023-5326 A vulnerability was found in SATO CL4NX-J Plus 1.13.2-u455_r2. It has been declared as critical. Affected by this vulnerability is an unknown functio… Cl4nx J Plus Firmware Mitigation only Fix from $1,9502023-10-01 HIGH 8.1 CVE-2023-43660 Warpgate is a smart SSH, HTTPS and MySQL bastion host for Linux that doesn't need special client apps. The SSH key verification for a user can be byp… Warpgate 0.8.1+ Fix from $1,9502023-09-27 CRITICAL 9.8 CVE-2023-42818 JumpServer is an open source bastion host. When users enable MFA and use a public key for authentication, the Koko SSH server does not verify the cor… Jumpserver 3.5.6 / 3.6.5+ Fix from $2,3002023-09-27 CRITICAL 9.8 CVE-2023-20252 A vulnerability in the Security Assertion Markup Language (SAML) APIs of Cisco Catalyst SD-WAN Manager Software could allow an unauthenticated, remot… Catalyst Sd Wan Manager Mitigation only Fix from $2,3002023-09-27 CRITICAL 9.1 CVE-2023-44152 Sensitive information disclosure and manipulation due to improper authentication. The following products are affected: Acronis Cyber Protect 15 (Linu… Cyber Protect 15+ Fix from $2,3002023-09-27 MEDIUM 5.4 CVE-2023-41904 Zoho ManageEngine ADManager Plus before 7203 allows 2FA bypass (for AuthToken generation) in REST APIs. Manageengine Admanager Plus 7.2+ Fix from $1,6002023-09-27 HIGH 7.8 CVE-2023-31015 NVIDIA DGX H100 BMC contains a vulnerability in the REST service where a host user may cause as improper authentication issue. A successful exploit o… Dgx H100 Firmware 23.08.18+ Fix from $1,9502023-09-20