Vulnerability index

Browse CVEs

4,342 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
HIGH 7.5 CVE-2023-39415 Improper authentication vulnerability in Proself Enterprise/Standard Edition Ver5.61 and earlier, Proself Gateway Edition Ver1.62 and earlier, and Pr… Proself after 5.61 Fix from $1,9502023-08-18 HIGH 8.8 CVE-2023-33237 TN-5900 Series firmware version v3.3 and prior is vulnerable to improper-authentication vulnerability. This vulnerability arises from inadequate auth… Tn 5900 Firmware after 3.3 Fix from $1,9502023-08-17 CRITICAL 9.8 CVE-2023-39846 An issue in Konga v0.14.9 allows attackers to bypass authentication via a crafted JWT token. Konga No fix yet Fix from $2,3002023-08-16 CRITICAL 9.8 CVE-2023-35082 KEVEPSS 100% An authentication bypass vulnerability in Ivanti EPMM 11.10 and older, allows unauthorized users to access restricted functionality or resources of t… Endpoint Manager Mobile 11.11.0+ Fix from $2,3002023-08-15 HIGH 8.3 CVE-2023-40020 PrivateUploader is an open source image hosting server written in Vue and TypeScript. In affected versions `app/routes/v3/admin.controller.ts` did no… Privateuploader 3.2.49+ Fix from $1,9502023-08-14 HIGH 7.5 CVE-2023-3263 The Dataprobe iBoot PDU running firmware version 1.43.03312023 or earlier is vulnerable to authentication bypass in the REST API due to the mishandli… Iboot Pdu4a C10 Firmware 1.44.0804202+ Fix from $1,9502023-08-14 HIGH 7.5 CVE-2023-39380 Permission control vulnerability in the audio module. Successful exploitation of this vulnerability may cause audio devices to perform abnormally. Emui No fix yet Fix from $1,9502023-08-13 CRITICAL 9.8 CVE-2023-40253 Improper Authentication vulnerability in Genians Genian NAC V4.0, Genians Genian NAC V5.0, Genians Genian NAC Suite V5.0, Genians Genian ZTNA allows … Genian Nac 4.0.156 / 5.0.55+ Fix from $2,3002023-08-11 CRITICAL 9.1 CVE-2023-40260 EmpowerID before 7.205.0.1 allows an attacker to bypass an MFA (multi factor authentication) requirement if the first factor (username and password) … Empowerid 7.205.0.1+ Fix from $2,3002023-08-11 MEDIUM 6.8 CVE-2023-39531 Sentry is an error tracking and performance monitoring platform. Starting in version 10.0.0 and prior to version 23.7.2, an attacker with sufficient … Sentry 23.7.2+ Fix from $1,6002023-08-09 HIGH 7.1 CVE-2023-21626 Cryptographic issue in HLOS due to improper authentication while performing key velocity checks using more than one key. Apq8009 Firmware Mitigation only Fix from $1,9502023-08-08 MEDIUM 5.3 CVE-2023-36926 Due to missing authentication check in SAP Host Agent - version 7.22, an unauthenticated attacker can set an undocumented parameter to a particular c… Host Agent Mitigation only Fix from $1,6002023-08-08 HIGH 8.1 CVE-2023-39349 Sentry is an error tracking and performance monitoring platform. Starting in version 22.1.0 and prior to version 23.7.2, an attacker with access to a… Sentry 23.7.2+ Fix from $1,9502023-08-07 CRITICAL 9.8 CVE-2023-32090 Pega platform clients who are using versions 6.1 through 7.3.1 may be utilizing default credentials Pega Platform after 7.3.1 Fix from $2,3002023-08-07 MEDIUM 5.0 CVE-2023-0264 A flaw was found in Keycloaks OpenID Connect user authentication, which may incorrectly authenticate requests. An authenticated attacker who could ob… Keycloak 7.6.2 / 18.0.6+ Fix from $1,6002023-08-04 MEDIUM 6.5 CVE-2023-38691 matrix-appservice-bridge provides an API for setting up bridges. Starting in version 4.0.0 and prior to versions 8.1.2 and 9.0.1, a malicious Matrix … Matrix Appservice Bridge 8.1.2+ Fix from $1,6002023-08-04 MEDIUM 6.5 CVE-2023-39112 ECShop v4.1.16 contains an arbitrary file deletion vulnerability in the Admin Panel. Ecshop No fix yet Fix from $1,6002023-08-04 CRITICAL 9.1 CVE-2023-20214 A vulnerability in the request authentication validation for the REST API of Cisco SD-WAN vManage software could allow an unauthenticated, remote att… Catalyst Sd Wan Manager 20.6.4.2 / 20.6.5.5+ Fix from $2,3002023-08-03 HIGH 7.5 CVE-2023-33363 An authentication bypass vulnerability exists in Suprema BioStar 2 before 2.9.1, which allows unauthenticated users to access some functionality on B… Biostar 2 2.9.1+ Fix from $1,9502023-08-03 HIGH 8.2 CVE-2023-34196 In the Keyfactor EJBCA before 8.0.0, the RA web certificate distribution servlet /ejbca/ra/cert allows partial denial of service due to an authentica… Ejbca 8.0.0+ Fix from $1,9502023-08-03 CRITICAL 9.4 CVE-2023-1935 ROC800-Series RTU devices are vulnerable to an authentication bypass, which could allow an attacker to gain unauthorized access to data or control of… Roc809 Firmware Mitigation only Fix from $2,3002023-08-02 MEDIUM 6.1 CVE-2023-3470 Specific F5 BIG-IP platforms with Cavium Nitrox FIPS HSM cards generate a deterministic password for the Crypto User account.  The predictable nature… Big Ip Access Policy Manager 13.1.4 / 14.1.4+ Fix from $1,6002023-08-02 HIGH 8.8 CVE-2023-33563 In PHP Jabbers Time Slots Booking Calendar 3.3 , lack of verification when changing an email address and/or password (on the Profile Page) allows rem… Time Slots Booking Calendar Mitigation only Fix from $1,9502023-08-01 HIGH 8.8 CVE-2023-38555 Authentication bypass vulnerability in Fujitsu network devices Si-R series and SR-M series allows a network-adjacent unauthenticated attacker to obta… Si R 30b Firmware after 02.54 Fix from $1,9502023-07-26 HIGH 8.8 CVE-2023-2626 There exists an authentication bypass vulnerability in OpenThread border router devices and implementations. This issue allows unauthenticated nodes … Nest Hub Max Firmware 1.56.368671 / 1.63.355999+ Fix from $1,9502023-07-25 CRITICAL 9.8 CVE-2023-35078 KEVEPSS 100% An authentication bypass vulnerability in Ivanti EPMM allows unauthorized users to access restricted functionality or resources of the application wi… Endpoint Manager Mobile 11.8.1.1 / 11.9.1.1+ Fix from $2,3002023-07-25 HIGH 7.5 CVE-2023-37918 Dapr is a portable, event-driven, runtime for building distributed applications across cloud and edge. A vulnerability has been found in Dapr that al… Dapr 1.10.9 / 1.11.2+ Fix from $1,9502023-07-21 CRITICAL 9.8 CVE-2023-37471 Open Access Management (OpenAM) is an access management solution that includes Authentication, SSO, Authorization, Federation, Entitlements and Web S… Openam 14.7.3+ Fix from $2,3002023-07-20 CRITICAL 9.8 CVE-2023-3638 In GeoVision GV-ADR2701 cameras, an attacker could edit the login response to access the web application. Gv Adr2701 Firmware No fix yet Fix from $2,3002023-07-19 HIGH 7.5 CVE-2023-27877 IBM Planning Analytics Cartridge for Cloud Pak for Data 4.0 connects to a CouchDB server. An attacker can exploit an insecure password policy to the … Cloud Pak For Data Patch available Fix from $1,9502023-07-19