Top technology
Linux 13140
Google 12530
Microsoft 12379
Oracle 6737
Apple 6692
Adobe 6387
Ibm 6330
Cisco 5757
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.8
CVE-2023-37283
Under a very specific and highly unrecommended configuration, authentication bypass is possible in the PingFederate Identifier First Adapter
Pingfederate
after 11.2.6
HIGH 7.5
CVE-2023-27377
Missing authentication in the StudentPopupDetails_EmergencyContactDetails method in IDAttend’s IDWeb application 3.1.052 and earlier allows ex…
Idweb
after 3.1.052
HIGH 8.8
CVE-2023-5246
Authentication Bypass by Capture-replay in SICK Flexi Soft Gateways with Partnumbers 1044073, 1127717, 1130282, 1044074, 1121597, 1099832, 1051432, 1…
Fx0 Gent00000 Firmware
Mitigation only
MEDIUM 6.5
CVE-2023-38735
IBM Cognos Dashboards on Cloud Pak for Data 4.7.0 could allow a remote attacker to bypass security restrictions, caused by a reverse tabnabbing flaw.…
Cognos Dashboards On Cloud Pak For Data
Patch available
MEDIUM 5.3
CVE-2023-4939
The SALESmanago plugin for WordPress is vulnerable to Log Injection in versions up to, and including, 3.2.4. This is due to the use of a weak authent…
Salesmanago
after 3.2.4
HIGH 8.8
CVE-2023-41089
The affected product is vulnerable to an improper authentication vulnerability, which may allow an attacker to impersonate a legitimate user as long …
Dexgate
Mitigation only
MEDIUM 5.3
CVE-2023-45669
WebAuthn4J Spring Security provides Web Authentication specification support for Spring applications. Affected versions are subject to improper signa…
Spring Security
0.9.1+
CRITICAL 9.1
CVE-2023-4562
Improper Authentication vulnerability in Mitsubishi Electric Corporation MELSEC-F Series main modules allows a remote unauthenticated attacker to obt…
Fx3g 14 Mr\/ds Firmware
Mitigation only
MEDIUM 5.3
CVE-2023-41261
An issue was discovered in /fcgi/scrut_fcgi.fcgi in Plixer Scrutinizer before 19.3.1. The csvExportReport endpoint action generateCSV does not requir…
Scrutinizer
19.3.1+
HIGH 7.8
CVE-2023-23632
BeyondTrust Privileged Remote Access (PRA) versions 22.2.x to 22.4.x are vulnerable to a local authentication bypass. Attackers can exploit a flawed …
Privileged Remote Access
22.3.3+
CRITICAL 9.8
CVE-2023-24479
An authentication bypass vulnerability exists in the httpd nvram.cgi functionality of Yifan YF325 v1.0_20221108. A specially crafted network request …
Yf325 Firmware
Mitigation only
HIGH 7.5
CVE-2023-44096
Vulnerability of brute-force attacks on the device authentication module.Successful exploitation of this vulnerability may affect service confidentia…
Harmonyos
No fix yet
MEDIUM 5.5
CVE-2023-36724
Windows Power Management Service Information Disclosure Vulnerability
Windows 10 1507
10.0.10240.20232 / 10.0.14393.6351+
HIGH 7.5
CVE-2023-43793
Misskey is an open source, decentralized social media platform. Prior to version 2023.9.0, by editing the URL, a user can bypass the authentication o…
Misskey
2023.9.0+
HIGH 7.5
CVE-2023-43805
Nexkey is a fork of Misskey, an open source, decentralized social media platform. Prior to version 12.121.9, incomplete URL validation can allow user…
Nexkey
12.121.9+
HIGH 7.5
CVE-2023-43809
Soft Serve is a self-hostable Git server for the command line. Prior to version 0.6.2, a security vulnerability in Soft Serve could allow an unauthen…
Soft Serve
0.6.2+
HIGH 7.0
CVE-2021-3784
Garuda Linux performs an insecure user creation and authentication that allows any user to impersonate the created account. By creating users from th…
Garuda Linux
Mitigation only
MEDIUM 6.5
CVE-2023-40376
IBM UrbanCode Deploy (UCD) 7.1 - 7.1.2.12, 7.2 through 7.2.3.5, and 7.3 through 7.3.2.0 under certain configurations could allow an authenticated use…
Urbancode Deploy
after 7.3.2.0
HIGH 7.5
CVE-2023-28540
Cryptographic issue in Data Modem due to improper authentication during TLS handshake.
315 5g Iot Modem Firmware
Mitigation only
HIGH 7.5
CVE-2023-26150
Versions of the package asyncua before 0.9.96 are vulnerable to Improper Authentication such that it is possible to access Address Space without encr…
Opcua Asyncio
0.9.96+
HIGH 8.8
CVE-2023-42771
Authentication bypass vulnerability in ACERA 1320 firmware ver.01.26 and earlier, and ACERA 1310 firmware ver.01.26 and earlier allows a network-adja…
Acera 1310 Firmware
after 01.26
HIGH 8.8
CVE-2023-5328
A vulnerability classified as critical has been found in SATO CL4NX-J Plus 1.13.2-u455_r2. This affects an unknown part of the component Cookie Handl…
Cl4nx J Plus Firmware
Mitigation only
HIGH 7.5
CVE-2023-5329
A vulnerability classified as problematic was found in Field Logic DataCube4 up to 20231001. This vulnerability affects unknown code of the file /api…
Datacube4 Firmware
after 2023-10-01
HIGH 8.8
CVE-2023-5326
A vulnerability was found in SATO CL4NX-J Plus 1.13.2-u455_r2. It has been declared as critical. Affected by this vulnerability is an unknown functio…
Cl4nx J Plus Firmware
Mitigation only
HIGH 8.1
CVE-2023-43660
Warpgate is a smart SSH, HTTPS and MySQL bastion host for Linux that doesn't need special client apps. The SSH key verification for a user can be byp…
Warpgate
0.8.1+
CRITICAL 9.8
CVE-2023-42818
JumpServer is an open source bastion host. When users enable MFA and use a public key for authentication, the Koko SSH server does not verify the cor…
Jumpserver
3.5.6 / 3.6.5+
CRITICAL 9.8
CVE-2023-20252
A vulnerability in the Security Assertion Markup Language (SAML) APIs of Cisco Catalyst SD-WAN Manager Software could allow an unauthenticated, remot…
Catalyst Sd Wan Manager
Mitigation only
CRITICAL 9.1
CVE-2023-44152
Sensitive information disclosure and manipulation due to improper authentication. The following products are affected: Acronis Cyber Protect 15 (Linu…
Cyber Protect
15+
MEDIUM 5.4
CVE-2023-41904
Zoho ManageEngine ADManager Plus before 7203 allows 2FA bypass (for AuthToken generation) in REST APIs.
Manageengine Admanager Plus
7.2+
HIGH 7.8
CVE-2023-31015
NVIDIA DGX H100 BMC contains a vulnerability in the REST service where a host user may cause as improper authentication issue. A successful exploit o…
Dgx H100 Firmware
23.08.18+