Vulnerability index

Browse CVEs

4,342 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
HIGH 7.5 CVE-2022-48496 Vulnerability of lax app identity verification in the pre-authorization function.Successful exploitation of this vulnerability will cause malicious a… Emui No fix yet Fix from $1,9502023-06-19 HIGH 7.5 CVE-2023-30223 A broken authentication vulnerability in 4D SAS 4D Server software v17, v18, v19 R7, and earlier allows attackers to send crafted TCP packets contain… Server No fix yet Fix from $1,9502023-06-16 MEDIUM 5.0 CVE-2023-2638 Rockwell Automation's FactoryTalk System Services does not verify that a backup configuration archive is password protected.   Improper authorizati… Factorytalk Policy Manager Mitigation only Fix from $1,6002023-06-13 CRITICAL 9.8 CVE-2023-30762 Improper authentication vulnerability exists in KB-AHR series and KB-IRIP series. If this vulnerability is exploited, an arbitrary OS command may be … Kb Ahr04d Firmware 91110.1.101106.78 / 91210.1.101106.78+ Fix from $2,3002023-06-13 CRITICAL 9.8 CVE-2023-29129 A vulnerability has been identified in Mendix SAML (Mendix 7 compatible) (All versions >= V1.17.3 < V1.18.0), Mendix SAML (Mendix 7 compatible) (All … Saml 1.18.0 / 2.4.0+ Fix from $2,3002023-06-13 CRITICAL 9.8 CVE-2023-32220 Milesight NCR/camera version 71.8.0.6-r5 allows authentication bypass through an unspecified method. Ncr\/camera Firmware No fix yet Fix from $2,3002023-06-12 MEDIUM 6.5 CVE-2023-34246 Doorkeeper is an OAuth 2 provider for Ruby on Rails / Grape. Prior to version 5.6.6, Doorkeeper automatically processes authorization requests withou… Doorkeeper 5.6.6+ Fix from $1,6002023-06-12 CRITICAL 9.8 CVE-2023-33553 An issue in Planet Technologies WDRT-1800AX v1.01-CP21 allows attackers to bypass authentication and escalate privileges to root via manipulation of … Wdrt 1800ax Firmware No fix yet Fix from $2,3002023-06-07 MEDIUM 5.4 CVE-2023-32682 Synapse is a Matrix protocol homeserver written in Python with the Twisted framework. In affected versions it may be possible for a deactivated user … Synapse 1.85.0+ Fix from $1,6002023-06-06 HIGH 7.5 CVE-2022-40521 Transient DOS due to improper authorization in Modem 315 5g Iot Modem Firmware No fix yet Fix from $1,9502023-06-06 HIGH 7.5 CVE-2022-40536 Transient DOS due to improper authentication in modem while receiving plain TLB OTA request message from network. 315 5g Iot Modem Firmware Mitigation only Fix from $1,9502023-06-06 CRITICAL 9.1 CVE-2023-3065 Improper Authentication vulnerability in Mobatime mobile application AMXGT100 allows Authentication Bypass.This issue affects Mobatime mobile applica… Amxgt 100 after 1.3.20 Fix from $2,3002023-06-05 CRITICAL 9.8 CVE-2023-3069 Unverified Password Change in GitHub repository tsolucio/corebos prior to 8. Corebos 8.0+ Fix from $2,3002023-06-02 CRITICAL 9.8 CVE-2023-3028 Insufficient authentication in the MQTT backend (broker) allows an attacker to access and even manipulate the telemetry data of the entire fleet of v… Hqt401 Firmware Mitigation only Fix from $2,3002023-06-01 MEDIUM 6.5 CVE-2023-2283 A vulnerability was found in libssh, where the authentication check of the connecting client can be bypassed in the`pki_verify_data_signature` functi… Fedora after 0.10.4 Fix from $1,6002023-05-26 MEDIUM 5.3 CVE-2023-0117 The online authentication provided by the hwKitAssistant lacks strict identity verification of applications. Successful exploitation of this vulnerab… Emui No fix yet Fix from $1,6002023-05-26 HIGH 8.8 CVE-2023-25946 Authentication bypass vulnerability in Qrio Lock (Q-SL2) firmware version 2.0.9 and earlier allows a network-adjacent attacker to analyze the product… Q Sl2 Firmware after 2.0.9 Fix from $1,9502023-05-23 CRITICAL 9.8 CVE-2023-27388 Improper authentication vulnerability in T&D Corporation and ESPEC MIC CORP. data logger products allows a remote unauthenticated attacker to login t… Tr 71w Firmware Mitigation only Fix from $2,3002023-05-23 CRITICAL 9.8 CVE-2023-2586 Teltonika’s Remote Management System versions 4.14.0 is vulnerable to an unauthorized attacker registering previously unregistered devices through th… Remote Management System Mitigation only Fix from $2,3002023-05-22 CRITICAL 9.8 CVE-2023-32347 Teltonika’s Remote Management System versions prior to 4.10.0 use device serial numbers and MAC addresses to identify devices from the user perspecti… Remote Management System 4.10.0+ Fix from $2,3002023-05-22 HIGH 7.5 CVE-2023-2024 Improper authentication in OpenBlue Enterprise Manager Data Collector versions prior to 3.2.5.75 allow access to an unauthorized user under certain c… Openblue Enterprise Manager Data Collector 3.2.5.75+ Fix from $1,9502023-05-18 HIGH 8.8 CVE-2023-0863 Improper Authentication vulnerability in ABB Terra AC wallbox (UL40/80A), ABB Terra AC wallbox (UL32A), ABB Terra AC wallbox (CE) (Terra AC MID), ABB… Terra Ac Wallbox Ul40 Firmware 1.2.8 / 1.5.6+ Fix from $1,9502023-05-17 HIGH 8.1 CVE-2023-2706 The OTP Login Woocommerce & Gravity Forms plugin for WordPress is vulnerable to authentication bypass. This is due to the fact that when generating O… Otp Login Woocommerce \& Gravity Forms 2.3+ Fix from $1,9502023-05-17 CRITICAL 9.8 CVE-2023-2499 The RegistrationMagic plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 5.2.1.0. This is due to insuffici… Registrationmagic after 5.2.1.0 Fix from $2,3002023-05-16 CRITICAL 9.8 CVE-2023-23450 Use of Password Hash Instead of Password for Authentication in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116… Ftmg Esd20axx Firmware 2.0+ Fix from $2,3002023-05-15 MEDIUM 6.5 CVE-2023-32081 Vert.x STOMP is a vert.x implementation of the STOMP specification that provides a STOMP server and client. From versions 3.1.0 until 3.9.16 and 4.0.… Vert.x Stomp 3.9.16 / 4.4.2+ Fix from $1,6002023-05-12 CRITICAL 9.8 CVE-2023-27823EPSS 53% An authentication bypass in Optoma 1080PSTX C02 allows an attacker to access the administration console without valid credentials. 1080pstx Mitigation only Fix from $2,3002023-05-12 CRITICAL 9.8 CVE-2023-32243EPSS 76% Improper Authentication vulnerability in WPDeveloper Essential Addons for Elementor allows Privilege Escalation. This issue affects Essential Addons … Essential Addons For Elementor 5.7.1+ Fix from $2,3002023-05-12 HIGH 8.1 CVE-2023-29032 An attacker that has gained access to certain private information can use this to act as other user. Vendor: The Apache Software Foundation Version… Openmeetings 7.1.0+ Fix from $1,9502023-05-12 MEDIUM 6.5 CVE-2023-28325 An improper authorization vulnerability exists in Rocket.Chat <6.0 that could allow a hacker to manipulate the rid parameter and change the updateMes… Rocket.chat 6.0.0+ Fix from $1,6002023-05-11