Vulnerability index

Browse CVEs

4,342 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
CRITICAL 9.8 CVE-2023-28609 api/auth.go in Ansible Semaphore before 2.8.89 mishandles authentication. Ansible Semaphore 2.8.89+ Fix from $2,3002023-03-18 CRITICAL 9.8 CVE-2023-1464 A vulnerability, which was classified as critical, was found in SourceCodester Medicine Tracker System 1.0. This affects an unknown part of the file … Medicine Tracker System Mitigation only Fix from $2,3002023-03-17 CRITICAL 9.8 CVE-2023-1460 A vulnerability was found in SourceCodester Online Pizza Ordering System 1.0. It has been classified as critical. This affects an unknown part of the… Online Pizza Ordering System Mitigation only Fix from $2,3002023-03-17 CRITICAL 9.1 CVE-2023-21455 Improper authorization implementation in Exynos baseband prior to SMR Mar-2023 Release 1 allows incorrect handling of unencrypted message. Exynos Firmware Mitigation only Fix from $2,3002023-03-16 CRITICAL 9.8 CVE-2023-28461 KEVEPSS 68% Array Networks Array AG Series and vxAG (9.4.0.481 and earlier) allow remote code execution. An attacker can browse the filesystem on the SSL VPN gat… Arrayos Ag after 9.4.0.481 Fix from $2,3002023-03-15 MEDIUM 6.5 CVE-2022-46773 IBM Robotic Process Automation 21.0.0 - 21.0.7 and 23.0.0 is vulnerable to client-side validation bypass for credential pools. Invalid credential poo… Robotic Process Automation 21.0.7.1 / 23.0.1+ Fix from $1,6002023-03-15 MEDIUM 6.5 CVE-2022-46774 IBM Manage Application 8.8.0 and 8.9.0 in the IBM Maximo Application Suite is vulnerable to incorrect default permissions which could give access to … Manage Application Mitigation only Fix from $1,6002023-03-15 CRITICAL 9.8 CVE-2023-1327 Netgear RAX30 (AX2400), prior to version 1.0.6.74, was affected by an authentication bypass vulnerability, allowing an unauthenticated attacker to ga… Rax30 Firmware 1.0.6.74+ Fix from $2,3002023-03-14 HIGH 7.5 CVE-2023-25957 A vulnerability has been identified in Mendix SAML (Mendix 7 compatible) (All versions >= V1.16.4 < V1.17.3), Mendix SAML (Mendix 8 compatible) (All … Saml 1.17.2 / 2.2.3+ Fix from $1,9502023-03-14 HIGH 8.6 CVE-2023-23857 Due to missing authentication check, SAP NetWeaver AS for Java - version 7.50, allows an unauthenticated attacker to attach to an open interface and … Netweaver Application Server For Java Mitigation only Fix from $1,9502023-03-14 CRITICAL 9.8 CVE-2023-27582 maddy is a composable, all-in-one mail server. Starting with version 0.2.0 and prior to version 0.6.3, maddy allows a full authentication bypass if S… Maddy 0.6.3+ Fix from $2,3002023-03-13 HIGH 7.5 CVE-2022-44574EPSS 65% An improper authentication vulnerability exists in Avalanche version 6.3.x and below allows unauthenticated attacker to modify properties on specific… Avalanche 6.4.0+ Fix from $1,9502023-03-10 HIGH 7.8 CVE-2022-33242 Memory corruption due to improper authentication in Qualcomm IPC while loading unsigned lib in audio PD. Aqt1000 Firmware Mitigation only Fix from $1,9502023-03-10 CRITICAL 10.0 CVE-2023-27482EPSS 72% homeassistant is an open source home automation tool. A remotely exploitable vulnerability bypassing authentication for accessing the Supervisor API … Home Assistant 2023.3.0 / 2023.03.1+ Fix from $2,3002023-03-08 HIGH 8.8 CVE-2023-0228 Improper Authentication vulnerability in ABB Symphony Plus S+ Operations.This issue affects Symphony Plus S+ Operations: from 2.X through 2.1 SP2, 2.… Symphony Plus S\+ Operations 2.1 / 3.3+ Fix from $1,9502023-03-02 MEDIUM 6.8 CVE-2023-25931 Medtronic identified that the Pelvic Health clinician apps, which are installed on the Smart Programmer mobile device, have a password vulnerability … Interstim X Clinician Mitigation only Fix from $1,6002023-03-01 MEDIUM 5.3 CVE-2023-1065 This vulnerability in the Snyk Kubernetes Monitor can result in irrelevant data being posted to a Snyk Organization, which could in turn obfuscate ot… Kubernetes Monitor 2.0.0+ Fix from $1,6002023-02-28 HIGH 7.5 CVE-2023-25264 An issue was discovered in Docmosis Tornado prior to version 2.9.5. An unauthenticated attacker can bypass the authentication check filter completely… Tornado 2.9.5+ Fix from $1,9502023-02-28 MEDIUM 5.5 CVE-2022-48305 There is an identity authentication bypass vulnerability in Huawei Children Smart Watch (Simba-AL00) 1.1.1.274. Successful exploitation of this vulne… Simba Al00 Firmware Mitigation only Fix from $1,6002023-02-27 HIGH 7.5 CVE-2022-34908 An issue was discovered in the A4N (Aremis 4 Nomad) application 1.5.0 for Android. It possesses an authentication mechanism; however, some features d… Aremis 4 Nomads 1.5.1+ Fix from $1,9502023-02-27 CRITICAL 9.8 CVE-2023-24093 An access control issue in H3C A210-G A210-GV100R005 allows attackers to authenticate without a password. A210 G Firmware No fix yet Fix from $2,3002023-02-22 CRITICAL 9.8 CVE-2015-10083 A vulnerability has been found in harrystech Dynosaur-Rails and classified as critical. Affected by this vulnerability is the function basic_auth of … Dynosaur Rails 2015-09-15+ Fix from $2,3002023-02-21 HIGH 7.5 CVE-2023-0905 A vulnerability classified as critical has been found in SourceCodester Employee Task Management System 1.0. Affected is an unknown function of the f… Employee Task Management System No fix yet Fix from $1,9502023-02-18 HIGH 7.2 CVE-2022-32971 Improper authentication in the Intel(R) SUR software before version 2.4.8902 may allow a privileged user to potentially enable escalation of privileg… System Usage Report 2.4.8902+ Fix from $1,9502023-02-16 HIGH 7.8 CVE-2022-33946 Improper authentication in the Intel(R) SUR software before version 2.4.8902 may allow an authenticated user to potentially enable escalation of priv… System Usage Report 2.4.8902+ Fix from $1,9502023-02-16 HIGH 7.8 CVE-2022-32570 Improper authentication in the Intel(R) Quartus Prime Pro and Standard edition software may allow an authenticated user to potentially enable escalat… Quartus Prime 22.1 / 22.2+ Fix from $1,9502023-02-16 HIGH 7.5 CVE-2022-47508 Customers who had configured their polling to occur via Kerberos did not expect NTLM Traffic on their environment, but since we were querying for dat… Server And Application Monitor Mitigation only Fix from $1,9502023-02-15 CRITICAL 9.8 CVE-2023-23460 Priority Web version 19.1.0.68, parameter manipulation on an unspecified end-point may allow authentication bypass. Priority No fix yet Fix from $2,3002023-02-15 HIGH 7.8 CVE-2023-21817 Windows Kerberos Elevation of Privilege Vulnerability Windows 10 10.0.10240.19747 / 10.0.14393.5717+ Fix from $1,9502023-02-14 MEDIUM 6.5 CVE-2023-21721 Microsoft OneNote Elevation of Privilege Vulnerability Onenote 16.0.16026.20158+ Fix from $1,6002023-02-14