Vulnerability index

Browse CVEs

2,893 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthenticationCWE-306 × clear
Hios CRITICAL 9.8
CVE-2024-3701

The system application (com.transsion.kolun.aiservice) component does not perform an authentication check, which allows attackers to perform maliciou…

Mitigation only
Fix from $2,300 2024-04-15
Qbibot CRITICAL 9.8
CVE-2024-3777

The password reset feature of Ai3 QbiBot lacks proper access control, allowing unauthenticated remote attackers to reset any user's password.

Mitigation only
Fix from $2,300 2024-04-15
A\+hrd MEDIUM 5.3
CVE-2024-3774

aEnrich Technology a+HRD's functionality for front-end retrieval of system configuration values lacks proper restrictions on a specific parameter, al…

Mitigation only
Fix from $1,600 2024-04-15
Windows Server 2022 23h2 HIGH 7.8
CVE-2024-26235

Windows Update Stack Elevation of Privilege Vulnerability

Fix: 10.0.25398.830+
Fix from $1,950 2024-04-09
Poly Ccx 350 HIGH 8.8
CVE-2024-3281

A vulnerability was discovered in the firmware builds after 8.0.2.3267 and prior to 8.1.3.1301 in CCX devices. A flaw in the firmware build process d…

Fix: 8.1.3.1301 / 8.1.1301+
Fix from $1,950 2024-04-09
Unclassified CRITICAL 9.8
CVE-2023-1083

An unauthenticated remote attacker who is aware of a MQTT topic name can send and receive messages, including GET/SET configuration commands, reboot…

Mitigation only
Fix from $2,300 2024-04-09
Unclassified MEDIUM 6.7
CVE-2023-25493

A potential vulnerability was reported in the BIOS update tool driver for some Desktop, Smart Edge, Smart Office, and ThinkStation products that coul…

Mitigation only
Fix from $1,600 2024-04-05
Chromecast Firmware CRITICAL 10.0
CVE-2023-48426

u-boot bug that allows for u-boot shell and interrupt over UART

Mitigation only
Fix from $2,300 2024-04-05
Unclassified CRITICAL 9.8
CVE-2024-31218

Webhood is a self-hosted URL scanner used analyzing phishing and malicious sites. Webhood's backend container images in versions 0.9.0 and earlier ar…

Patch available
Fix from $2,300 2024-04-05
Unclassified MEDIUM 5.2
CVE-2023-6949

A Missing Authentication for Critical Function issue affecting the HTTP service running on the DJI Mavic Mini 3 Pro on the standard port 80 could all…

Mitigation only
Fix from $1,600 2024-04-02
Viewpower HIGH 7.5
CVE-2023-51571

Voltronic Power ViewPower Pro SocketService Missing Authentication Denial-of-Service Vulnerability. This vulnerability allows remote attackers to cre…

Mitigation only
Fix from $1,950 2024-04-01
Devolutions Server CRITICAL 9.8
CVE-2024-2921

Improper access control in PAM vault permissions in Devolutions Server 2024.1.10.0 and earlier allows an authenticated user with access to the PAM to…

Fix: 2024.1.8.0+
Fix from $2,300 2024-03-26
Th Advance Product Search CRITICAL 9.8
CVE-2022-38057

Missing Authorization vulnerability in ThemeHunk Advance WordPress Search Plugin.This issue affects Advance WordPress Search Plugin: from n/a through…

Fix: 1.2.2+
Fix from $2,300 2024-03-25
Axigen Mail Server CRITICAL 9.1
CVE-2020-26942

An issue discovered in Axigen Mail Server 10.3.x before 10.3.1.27 and 10.3.2.x before 10.3.3.1 allows unauthenticated attackers to submit a setAdminP…

Fix: 10.3.1.27 / 10.3.3.1+
Fix from $2,300 2024-03-21
Jupyter Server Proxy CRITICAL 9.8
CVE-2024-28179

Jupyter Server Proxy allows users to run arbitrary external processes alongside their Jupyter notebook servers and provides authenticated web access.…

Fix: 3.2.3 / 4.1.1+
Fix from $2,300 2024-03-20
Raspberrymatic CRITICAL 9.8
CVE-2024-24578EPSS 9%

RaspberryMatic is an open-source operating system for HomeMatic internet-of-things devices. RaspberryMatic / OCCU prior to version 3.75.6.20240316 co…

Fix: 3.75.6.20240316+
Fix from $2,300 2024-03-18
Unclassified MEDIUM 5.3
CVE-2024-21824

Improper authentication vulnerability in exists in multiple printers and scanners which implement Web Based Management provided by BROTHER INDUSTRIES…

Mitigation only
Fix from $1,600 2024-03-18
Unclassified MEDIUM 5.5
CVE-2024-22513

djangorestframework-simplejwt version 5.3.1 and before is vulnerable to information disclosure. A user can access web application resources even afte…

Mitigation only
Fix from $1,600 2024-03-16
Mattermost Server HIGH 8.8
CVE-2024-2450

Mattermost versions 8.1.x before 8.1.10, 9.2.x before 9.2.6, 9.3.x before 9.3.2, and 9.4.x before 9.4.3 fail to correctly verify account ownership wh…

Fix: 8.1.10 / 9.2.6+
Fix from $1,950 2024-03-15
Pulsar HIGH 8.2
CVE-2022-34321

Improper Authentication vulnerability in Apache Pulsar Proxy allows an attacker to connect to the /proxy-stats endpoint without authentication. The v…

Fix: 2.10.6 / 2.11.3+
Fix from $1,950 2024-03-12
Unclassified HIGH 8.4
CVE-2024-27758

In RPyC before 6.0.0, when a server exposes a method that calls the attribute named __array__ for a client-provided netref (e.g., np.array(client_net…

Mitigation only
Fix from $1,950 2024-03-12
House Rental Management System HIGH 7.5
CVE-2024-2076

A vulnerability was found in CodeAstro House Rental Management System 1.0. It has been rated as problematic. Affected by this issue is some unknown f…

Mitigation only
Fix from $1,950 2024-03-01
Domino MEDIUM 5.9
CVE-2023-37495

Internet passwords stored in Person documents in the Domino® Directory created using the "Add Person" action on the People & Groups tab in the Domino…

Fix: 14.0+
Fix from $1,600 2024-02-29
Emui HIGH 7.5
CVE-2022-48621

Vulnerability of missing authentication for critical functions in the Wi-Fi module.Successful exploitation of this vulnerability may affect service c…

Mitigation only
Fix from $1,950 2024-02-18
Risweb HIGH 7.5
CVE-2024-26263

EBM Technologies RISWEB's specific URL path is not properly controlled by permission, allowing attackers to browse specific pages and query sensitive…

Fix: 3.0+
Fix from $1,950 2024-02-15
Mastodon HIGH 7.4
CVE-2024-25618

Mastodon is a free, open-source social network server based on ActivityPub. Mastodon allows new identities from configured authentication providers (…

Fix: 3.5.18 / 4.0.14+
Fix from $1,950 2024-02-14
Jh Rvb1 Firmware HIGH 8.8
CVE-2024-23783

Improper authentication vulnerability in Energy Management Controller with Cloud Services JH-RVB1 /JH-RV11 Ver.B0.1.9.1 and earlier allows a network-…

Mitigation only
Fix from $1,950 2024-02-14
Pingfederate CRITICAL 9.8
CVE-2023-40545

Authentication bypass when an OAuth2 Client is using client_secret_jwt as its authentication method on affected 11.3 versions via specially crafted r…

Mitigation only
Fix from $2,300 2024-02-06
Teamcity CRITICAL 9.8
CVE-2024-23917EPSS 54%

In JetBrains TeamCity before 2023.11.3 authentication bypass leading to RCE was possible

Fix: 2023.11.3+
Fix from $2,300 2024-02-06
Feverwarn Firmware CRITICAL 9.1
CVE-2023-49617

The MachineSense application programmable interface (API) is improperly protected and can be accessed without authentication. A remote attacker could…

Mitigation only
Fix from $2,300 2024-02-01