Vulnerability index

Browse CVEs

2,893 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthenticationCWE-306 × clear
CRITICAL 9.8 CVE-2024-3701 The system application (com.transsion.kolun.aiservice) component does not perform an authentication check, which allows attackers to perform maliciou… Hios Mitigation only Fix from $2,3002024-04-15 CRITICAL 9.8 CVE-2024-3777 The password reset feature of Ai3 QbiBot lacks proper access control, allowing unauthenticated remote attackers to reset any user's password. Qbibot Mitigation only Fix from $2,3002024-04-15 MEDIUM 5.3 CVE-2024-3774 aEnrich Technology a+HRD's functionality for front-end retrieval of system configuration values lacks proper restrictions on a specific parameter, al… A\+hrd Mitigation only Fix from $1,6002024-04-15 HIGH 7.8 CVE-2024-26235 Windows Update Stack Elevation of Privilege Vulnerability Windows Server 2022 23h2 10.0.25398.830+ Fix from $1,9502024-04-09 HIGH 8.8 CVE-2024-3281 A vulnerability was discovered in the firmware builds after 8.0.2.3267 and prior to 8.1.3.1301 in CCX devices. A flaw in the firmware build process d… Poly Ccx 350 8.1.3.1301 / 8.1.1301+ Fix from $1,9502024-04-09 CRITICAL 9.8 CVE-2023-1083 An unauthenticated remote attacker who is aware of a MQTT topic name can send and receive messages, including GET/SET configuration commands, reboot… Mitigation only Fix from $2,3002024-04-09 MEDIUM 6.7 CVE-2023-25493 A potential vulnerability was reported in the BIOS update tool driver for some Desktop, Smart Edge, Smart Office, and ThinkStation products that coul… Mitigation only Fix from $1,6002024-04-05 CRITICAL 10.0 CVE-2023-48426 u-boot bug that allows for u-boot shell and interrupt over UART Chromecast Firmware Mitigation only Fix from $2,3002024-04-05 CRITICAL 9.8 CVE-2024-31218 Webhood is a self-hosted URL scanner used analyzing phishing and malicious sites. Webhood's backend container images in versions 0.9.0 and earlier ar… Patch available Fix from $2,3002024-04-05 MEDIUM 5.2 CVE-2023-6949 A Missing Authentication for Critical Function issue affecting the HTTP service running on the DJI Mavic Mini 3 Pro on the standard port 80 could all… Mitigation only Fix from $1,6002024-04-02 HIGH 7.5 CVE-2023-51571 Voltronic Power ViewPower Pro SocketService Missing Authentication Denial-of-Service Vulnerability. This vulnerability allows remote attackers to cre… Viewpower Mitigation only Fix from $1,9502024-04-01 CRITICAL 9.8 CVE-2024-2921 Improper access control in PAM vault permissions in Devolutions Server 2024.1.10.0 and earlier allows an authenticated user with access to the PAM to… Devolutions Server 2024.1.8.0+ Fix from $2,3002024-03-26 CRITICAL 9.8 CVE-2022-38057 Missing Authorization vulnerability in ThemeHunk Advance WordPress Search Plugin.This issue affects Advance WordPress Search Plugin: from n/a through… Th Advance Product Search 1.2.2+ Fix from $2,3002024-03-25 CRITICAL 9.1 CVE-2020-26942 An issue discovered in Axigen Mail Server 10.3.x before 10.3.1.27 and 10.3.2.x before 10.3.3.1 allows unauthenticated attackers to submit a setAdminP… Axigen Mail Server 10.3.1.27 / 10.3.3.1+ Fix from $2,3002024-03-21 CRITICAL 9.8 CVE-2024-28179 Jupyter Server Proxy allows users to run arbitrary external processes alongside their Jupyter notebook servers and provides authenticated web access.… Jupyter Server Proxy 3.2.3 / 4.1.1+ Fix from $2,3002024-03-20 CRITICAL 9.8 CVE-2024-24578EPSS 9% RaspberryMatic is an open-source operating system for HomeMatic internet-of-things devices. RaspberryMatic / OCCU prior to version 3.75.6.20240316 co… Raspberrymatic 3.75.6.20240316+ Fix from $2,3002024-03-18 MEDIUM 5.3 CVE-2024-21824 Improper authentication vulnerability in exists in multiple printers and scanners which implement Web Based Management provided by BROTHER INDUSTRIES… Mitigation only Fix from $1,6002024-03-18 MEDIUM 5.5 CVE-2024-22513 djangorestframework-simplejwt version 5.3.1 and before is vulnerable to information disclosure. A user can access web application resources even afte… Mitigation only Fix from $1,6002024-03-16 HIGH 8.8 CVE-2024-2450 Mattermost versions 8.1.x before 8.1.10, 9.2.x before 9.2.6, 9.3.x before 9.3.2, and 9.4.x before 9.4.3 fail to correctly verify account ownership wh… Mattermost Server 8.1.10 / 9.2.6+ Fix from $1,9502024-03-15 HIGH 8.2 CVE-2022-34321 Improper Authentication vulnerability in Apache Pulsar Proxy allows an attacker to connect to the /proxy-stats endpoint without authentication. The v… Pulsar 2.10.6 / 2.11.3+ Fix from $1,9502024-03-12 HIGH 8.4 CVE-2024-27758 In RPyC before 6.0.0, when a server exposes a method that calls the attribute named __array__ for a client-provided netref (e.g., np.array(client_net… Mitigation only Fix from $1,9502024-03-12 HIGH 7.5 CVE-2024-2076 A vulnerability was found in CodeAstro House Rental Management System 1.0. It has been rated as problematic. Affected by this issue is some unknown f… House Rental Management System Mitigation only Fix from $1,9502024-03-01 MEDIUM 5.9 CVE-2023-37495 Internet passwords stored in Person documents in the Domino® Directory created using the "Add Person" action on the People & Groups tab in the Domino… Domino 14.0+ Fix from $1,6002024-02-29 HIGH 7.5 CVE-2022-48621 Vulnerability of missing authentication for critical functions in the Wi-Fi module.Successful exploitation of this vulnerability may affect service c… Emui Mitigation only Fix from $1,9502024-02-18 HIGH 7.5 CVE-2024-26263 EBM Technologies RISWEB's specific URL path is not properly controlled by permission, allowing attackers to browse specific pages and query sensitive… Risweb 3.0+ Fix from $1,9502024-02-15 HIGH 7.4 CVE-2024-25618 Mastodon is a free, open-source social network server based on ActivityPub. Mastodon allows new identities from configured authentication providers (… Mastodon 3.5.18 / 4.0.14+ Fix from $1,9502024-02-14 HIGH 8.8 CVE-2024-23783 Improper authentication vulnerability in Energy Management Controller with Cloud Services JH-RVB1 /JH-RV11 Ver.B0.1.9.1 and earlier allows a network-… Jh Rvb1 Firmware Mitigation only Fix from $1,9502024-02-14 CRITICAL 9.8 CVE-2023-40545 Authentication bypass when an OAuth2 Client is using client_secret_jwt as its authentication method on affected 11.3 versions via specially crafted r… Pingfederate Mitigation only Fix from $2,3002024-02-06 CRITICAL 9.8 CVE-2024-23917EPSS 54% In JetBrains TeamCity before 2023.11.3 authentication bypass leading to RCE was possible Teamcity 2023.11.3+ Fix from $2,3002024-02-06 CRITICAL 9.1 CVE-2023-49617 The MachineSense application programmable interface (API) is improperly protected and can be accessed without authentication. A remote attacker could… Feverwarn Firmware Mitigation only Fix from $2,3002024-02-01