Vulnerability index

Browse CVEs

4,342 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
HIGH 8.8 CVE-2022-34155 Improper Authentication vulnerability in miniOrange OAuth Single Sign On – SSO (OAuth Client) plugin allows Authentication Bypass.This issue affects … Oauth Single Sign On 6.23.4+ Fix from $1,9502023-07-18 CRITICAL 9.8 CVE-2023-37266EPSS 7% CasaOS is an open-source Personal Cloud system. Unauthenticated attackers can craft arbitrary JWTs and access features that usually require authentic… Casaos 0.4.4+ Fix from $2,3002023-07-17 HIGH 8.2 CVE-2023-3591 Mattermost fails to invalidate previously generated password reset tokens when a new reset token was created. Mattermost Server 7.8.7 / 7.9.5+ Fix from $1,9502023-07-17 HIGH 7.5 CVE-2023-2959 Authentication Bypass by Primary Weakness vulnerability in Oliva Expertise Oliva Expertise EKS allows Collect Data as Provided by Users. This issue … Oliva Ekspertiz 1.2+ Fix from $1,9502023-07-17 MEDIUM 5.3 CVE-2023-35901 IBM Robotic Process Automation 21.0.0 through 21.0.7.6 and 23.0.0 through 23.0.6 is vulnerable to client side validation bypass which could allow inv… Robotic Process Automation after 23.0.6 Fix from $1,6002023-07-17 HIGH 8.8 CVE-2023-37268 Warpgate is an SSH, HTTPS and MySQL bastion host for Linux that doesn't need special client apps. When logging in as a user with SSO enabled an attac… Warpgate Patch available Fix from $1,9502023-07-14 MEDIUM 5.3 CVE-2023-2975 Issue summary: The AES-SIV cipher implementation contains a bug that causes it to ignore empty associated data entries which are unauthenticated as a… OpenSSL after 3.1.1 Fix from $1,6002023-07-14 MEDIUM 6.8 CVE-2023-30560 The configuration from the PCU can be modified without authentication using physical connection to the PCU. Alaris 8015 Pcu Firmware after 12.1.3 Fix from $1,6002023-07-13 MEDIUM 5.7 CVE-2023-30559 The firmware update package for the wireless card is not properly signed and can be modified. Alaris 8015 Pcu Firmware after 12.1.3 Fix from $1,6002023-07-13 CRITICAL 9.8 CVE-2023-34137 SonicWall GMS and Analytics CAS Web Services application use static values for authentication without proper checks leading to authentication bypass … Analytics 9.3.2+ Fix from $2,3002023-07-13 CRITICAL 9.8 CVE-2023-34124EPSS 46% The authentication mechanism in SonicWall GMS and Analytics Web Services had insufficient checks, allowing authentication bypass. This issue affects … Analytics 9.3.2+ Fix from $2,3002023-07-13 CRITICAL 9.8 CVE-2023-33274 The authentication mechanism in PowerShield SNMP Web Pro 1.1 contains a vulnerability that allows unauthenticated users to directly access Common Gat… Snmp Web Pro No fix yet Fix from $2,3002023-07-12 MEDIUM 6.5 CVE-2023-31007 Improper Authentication vulnerability in Apache Software Foundation Apache Pulsar Broker allows a client to stay connected to a broker after authenti… Pulsar 2.9.5+ Fix from $1,6002023-07-12 CRITICAL 9.8 CVE-2023-3127 An unauthenticated user could log into iSTAR Ultra, iSTAR Ultra LT, iSTAR Ultra G2, and iSTAR Edge G2 with administrator rights. Istar Ultra Firmware 6.9.2+ Fix from $2,3002023-07-11 HIGH 8.1 CVE-2023-31190 DroneScout ds230 Remote ID receiver from BlueMark Innovations is affected by an Improper Authentication vulnerability during the firmware update proc… Dronescout Ds230 Firmware after 20230329-1042 Fix from $1,9502023-07-11 MEDIUM 5.5 CVE-2023-30675 Improper authentication in Samsung Pass prior to version 4.2.03.1 allows local attacker to access stored account information when Samsung Wallet is n… Pass 4.2.03.1+ Fix from $1,6002023-07-06 HIGH 7.5 CVE-2023-35940 GLPI is a free asset and IT management software package. Starting in version 9.5.0 and prior to version 10.0.8, an incorrect rights check on a file a… Glpi 10.0.8+ Fix from $1,9502023-07-05 MEDIUM 6.5 CVE-2023-32620 Improper authentication vulnerability in WL-WN531AX2 firmware versions prior to 2023526 allows a network-adjacent attacker to obtain a password for t… Wl Wn531ax2 Firmware 2023526+ Fix from $1,6002023-06-30 CRITICAL 9.8 CVE-2023-33190 Sealos is an open source cloud operating system distribution based on the Kubernetes kernel. In versions of Sealos prior to 4.2.1-rc4 an improper con… Sealos 4.2.1+ Fix from $2,3002023-06-29 CRITICAL 9.8 CVE-2023-32222 D-Link DSL-G256DG version vBZ_1.00.27 web management interface allows authentication bypass via an unspecified method. Dsl G256dg Firmware Mitigation only Fix from $2,3002023-06-28 MEDIUM 6.6 CVE-2023-20199 A vulnerability in Cisco Duo Two-Factor Authentication for macOS could allow an authenticated, physical attacker to bypass secondary authentication a… Duo 2.0.2+ Fix from $1,6002023-06-28 CRITICAL 9.8 CVE-2023-30945 Multiple Services such as VHS(Video History Server) and VCD(Video Clip Distributor) and Clips2 were discovered to be vulnerable to an unauthenticated… Clips2 0.24.10 / 0.111.2+ Fix from $2,3002023-06-26 HIGH 8.8 CVE-2023-32523 Affected versions of Trend Micro Mobile Security (Enterprise) 9.8 SP5 contain some widgets that would allow a remote user to bypass authentication an… Mobile Security Patch available Fix from $1,9502023-06-26 HIGH 8.8 CVE-2023-32524 Affected versions of Trend Micro Mobile Security (Enterprise) 9.8 SP5 contain some widgets that would allow a remote user to bypass authentication an… Mobile Security Patch available Fix from $1,9502023-06-26 MEDIUM 6.5 CVE-2023-35154 Knowage is an open source analytics and business intelligence suite. Starting in version 6.0.0 and prior to version 8.1.8, an attacker can register a… Knowage 8.1.8+ Fix from $1,6002023-06-23 HIGH 7.8 CVE-2023-28073 Dell BIOS contains an improper authentication vulnerability. A locally authenticated malicious user may potentially exploit this vulnerability by byp… Precision 3570 Firmware 1.13.2+ Fix from $1,9502023-06-23 CRITICAL 9.8 CVE-2023-3326 pam_krb5 authenticates a user by essentially running kinit with the password, getting a ticket-granting ticket (tgt) from the Kerberos KDC (Key Distr… FreeBSD 12.4 / 13.1+ Fix from $2,3002023-06-22 CRITICAL 9.8 CVE-2023-34340 Improper Authentication vulnerability in Apache Software Foundation Apache Accumulo. This issue affects Apache Accumulo: 2.1.0. Accumulo 2.1.0 conta… Accumulo Mitigation only Fix from $2,3002023-06-21 CRITICAL 9.8 CVE-2023-3337 A vulnerability was found in PuneethReddyHC Online Shopping System Advanced 1.0. It has been declared as critical. Affected by this vulnerability is … Online Shopping System Advanced Mitigation only Fix from $2,3002023-06-20 HIGH 7.5 CVE-2022-48494 Vulnerability of lax app identity verification in the pre-authorization function.Successful exploitation of this vulnerability will cause malicious a… Emui No fix yet Fix from $1,9502023-06-19