Top technology
Linux 13140
Google 12530
Microsoft 12379
Oracle 6737
Apple 6692
Adobe 6387
Ibm 6330
Cisco 5757
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 8.8
CVE-2022-34155
Improper Authentication vulnerability in miniOrange OAuth Single Sign On – SSO (OAuth Client) plugin allows Authentication Bypass.This issue affects …
Oauth Single Sign On
6.23.4+
CRITICAL 9.8
CVE-2023-37266EPSS 7%
CasaOS is an open-source Personal Cloud system. Unauthenticated attackers can craft arbitrary JWTs and access features that usually require authentic…
Casaos
0.4.4+
HIGH 8.2
CVE-2023-3591
Mattermost fails to invalidate previously generated password reset tokens when a new reset token was created.
Mattermost Server
7.8.7 / 7.9.5+
HIGH 7.5
CVE-2023-2959
Authentication Bypass by Primary Weakness vulnerability in Oliva Expertise Oliva Expertise EKS allows Collect Data as Provided by Users.
This issue …
Oliva Ekspertiz
1.2+
MEDIUM 5.3
CVE-2023-35901
IBM Robotic Process Automation 21.0.0 through 21.0.7.6 and 23.0.0 through 23.0.6 is vulnerable to client side validation bypass which could allow inv…
Robotic Process Automation
after 23.0.6
HIGH 8.8
CVE-2023-37268
Warpgate is an SSH, HTTPS and MySQL bastion host for Linux that doesn't need special client apps. When logging in as a user with SSO enabled an attac…
Warpgate
Patch available
MEDIUM 5.3
CVE-2023-2975
Issue summary: The AES-SIV cipher implementation contains a bug that causes
it to ignore empty associated data entries which are unauthenticated as
a…
OpenSSL
after 3.1.1
MEDIUM 6.8
CVE-2023-30560
The configuration from the PCU can be modified without authentication using physical connection to the PCU.
Alaris 8015 Pcu Firmware
after 12.1.3
MEDIUM 5.7
CVE-2023-30559
The firmware update package for the wireless card is not properly signed and can be modified.
Alaris 8015 Pcu Firmware
after 12.1.3
CRITICAL 9.8
CVE-2023-34137
SonicWall GMS and Analytics CAS Web Services application use static values for authentication without proper checks leading to authentication bypass …
Analytics
9.3.2+
CRITICAL 9.8
CVE-2023-34124EPSS 46%
The authentication mechanism in SonicWall GMS and Analytics Web Services had insufficient checks, allowing authentication bypass. This issue affects …
Analytics
9.3.2+
CRITICAL 9.8
CVE-2023-33274
The authentication mechanism in PowerShield SNMP Web Pro 1.1 contains a vulnerability that allows unauthenticated users to directly access Common Gat…
Snmp Web Pro
No fix yet
MEDIUM 6.5
CVE-2023-31007
Improper Authentication vulnerability in Apache Software Foundation Apache Pulsar Broker allows a client to stay connected to a broker after authenti…
Pulsar
2.9.5+
CRITICAL 9.8
CVE-2023-3127
An unauthenticated user could log into iSTAR Ultra, iSTAR Ultra LT, iSTAR Ultra G2, and iSTAR Edge G2 with administrator rights.
Istar Ultra Firmware
6.9.2+
HIGH 8.1
CVE-2023-31190
DroneScout ds230 Remote ID receiver from BlueMark Innovations is affected by an Improper Authentication vulnerability during the firmware update proc…
Dronescout Ds230 Firmware
after 20230329-1042
MEDIUM 5.5
CVE-2023-30675
Improper authentication in Samsung Pass prior to version 4.2.03.1 allows local attacker to access stored account information when Samsung Wallet is n…
Pass
4.2.03.1+
HIGH 7.5
CVE-2023-35940
GLPI is a free asset and IT management software package. Starting in version 9.5.0 and prior to version 10.0.8, an incorrect rights check on a file a…
Glpi
10.0.8+
MEDIUM 6.5
CVE-2023-32620
Improper authentication vulnerability in WL-WN531AX2 firmware versions prior to 2023526 allows a network-adjacent attacker to obtain a password for t…
Wl Wn531ax2 Firmware
2023526+
CRITICAL 9.8
CVE-2023-33190
Sealos is an open source cloud operating system distribution based on the Kubernetes kernel. In versions of Sealos prior to 4.2.1-rc4 an improper con…
Sealos
4.2.1+
CRITICAL 9.8
CVE-2023-32222
D-Link DSL-G256DG version vBZ_1.00.27 web management interface allows authentication bypass via an unspecified method.
Dsl G256dg Firmware
Mitigation only
MEDIUM 6.6
CVE-2023-20199
A vulnerability in Cisco Duo Two-Factor Authentication for macOS could allow an authenticated, physical attacker to bypass secondary authentication a…
Duo
2.0.2+
CRITICAL 9.8
CVE-2023-30945
Multiple Services such as VHS(Video History Server) and VCD(Video Clip Distributor) and Clips2 were discovered to be vulnerable to an unauthenticated…
Clips2
0.24.10 / 0.111.2+
HIGH 8.8
CVE-2023-32523
Affected versions of Trend Micro Mobile Security (Enterprise) 9.8 SP5 contain some widgets that would allow a remote user to bypass authentication an…
Mobile Security
Patch available
HIGH 8.8
CVE-2023-32524
Affected versions of Trend Micro Mobile Security (Enterprise) 9.8 SP5 contain some widgets that would allow a remote user to bypass authentication an…
Mobile Security
Patch available
MEDIUM 6.5
CVE-2023-35154
Knowage is an open source analytics and business intelligence suite. Starting in version 6.0.0 and prior to version 8.1.8, an attacker can register a…
Knowage
8.1.8+
HIGH 7.8
CVE-2023-28073
Dell BIOS contains an improper authentication vulnerability. A locally authenticated malicious user may potentially exploit this vulnerability by byp…
Precision 3570 Firmware
1.13.2+
CRITICAL 9.8
CVE-2023-3326
pam_krb5 authenticates a user by essentially running kinit with the password, getting a ticket-granting ticket (tgt) from the Kerberos KDC (Key Distr…
FreeBSD
12.4 / 13.1+
CRITICAL 9.8
CVE-2023-34340
Improper Authentication vulnerability in Apache Software Foundation Apache Accumulo.
This issue affects Apache Accumulo: 2.1.0.
Accumulo 2.1.0 conta…
Accumulo
Mitigation only
CRITICAL 9.8
CVE-2023-3337
A vulnerability was found in PuneethReddyHC Online Shopping System Advanced 1.0. It has been declared as critical. Affected by this vulnerability is …
Online Shopping System Advanced
Mitigation only
HIGH 7.5
CVE-2022-48494
Vulnerability of lax app identity verification in the pre-authorization function.Successful exploitation of this vulnerability will cause malicious a…
Emui
No fix yet