Vulnerability index

Browse CVEs

4,337 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
Dgnd3700 Firmware CRITICAL 9.8
CVE-2025-4978EPSS 18%

A vulnerability, which was classified as very critical, was found in Netgear DGND3700 1.1.00.15_1.00.15NA. This affects an unknown part of the file /…

No fix yet
Fix from $2,300 2025-05-20
Nextcloud Server MEDIUM 6.4
CVE-2025-47790

Nextcloud Server is a self hosted personal cloud system. Nextcloud Server prior to 29.0.15, 30.0.9, and 31.0.3 and Nextcloud Enterprise Server prior …

Fix: 26.0.13.15 / 27.1.11.15+
Fix from $1,600 2025-05-16
Di 7003g Firmware MEDIUM 5.3
CVE-2025-4755EPSS 7%

A vulnerability was found in D-Link DI-7003GV2 24.04.18D1 R(68125). It has been classified as critical. This affects the function sub_497DE4 of the f…

No fix yet
Fix from $1,600 2025-05-16
Unclassified CRITICAL 9.1
CVE-2025-47275

Auth0-PHP provides the PHP SDK for Auth0 Authentication and Management APIs. Starting in version 8.0.0-BETA1 and prior to version 8.14.0, session coo…

Patch available
Fix from $2,300 2025-05-15
Wso2 Oauth CRITICAL 9.8
CVE-2025-47889

In Jenkins WSO2 Oauth Plugin 1.0 and earlier, authentication claims are accepted without validation by the "WSO2 Oauth" security realm, allowing unau…

Fix: after 1.0
Fix from $2,300 2025-05-14
Unclassified HIGH 7.5
CVE-2025-20083

Improper authentication in the firmware for the Intel(R) Slim Bootloader may allow a privileged user to potentially enable escalation of privilege vi…

Mitigation only
Fix from $1,950 2025-05-13
Defender For Identity MEDIUM 6.5
CVE-2025-26685

Improper authentication in Microsoft Defender for Identity allows an unauthorized attacker to perform spoofing over an adjacent network.

Mitigation only
Fix from $1,600 2025-05-13
Ipados MEDIUM 6.8
CVE-2025-31228

The issue was addressed with improved authentication. This issue is fixed in iOS 18.5 and iPadOS 18.5, iPadOS 17.7.7. An attacker with physical acces…

Fix: 17.7.7 / 18.5+
Fix from $1,600 2025-05-12
Unclassified CRITICAL 9.4
CVE-2025-3659

Improper authentication handling was identified in a set of HTTP POST requests affecting the following product families: * Digi PortServer TS - …

Mitigation only
Fix from $2,300 2025-05-12
Jadmin CRITICAL 9.8
CVE-2025-4494

A vulnerability, which was classified as critical, was found in JAdmin-JAVA JAdmin 1.0. Affected is the function toLogin of the file NoNeedLoginContr…

No fix yet
Fix from $2,300 2025-05-09
Azure Devops CRITICAL 9.8
CVE-2025-29813

Authentication bypass by assumed-immutable data in Azure DevOps allows an unauthorized attacker to elevate privileges over a network.

Mitigation only
Fix from $2,300 2025-05-08
Unclassified CRITICAL 10.0
CVE-2024-11186

On affected versions of the CloudVision Portal, improper access controls could enable a malicious authenticated user to take broader actions on manag…

Mitigation only
Fix from $2,300 2025-05-08
Unclassified CRITICAL 9.3
CVE-2025-46572

passport-wsfed-saml2 provides passport strategy for both WS-fed and SAML2 protocol. A vulnerability present starting in version 3.0.5 up to and inclu…

Patch available
Fix from $2,300 2025-05-06
Unclassified HIGH 8.6
CVE-2025-46573

passport-wsfed-saml2 provides passport strategy for both WS-fed and SAML2 protocol. A vulnerability present starting in version 3.0.5 up to and inclu…

Patch available
Fix from $1,950 2025-05-06
Storage Manager HIGH 8.8
CVE-2025-22477

Dell Storage Center - Dell Storage Manager, version(s) 20.1.20, contain(s) an Improper Authentication vulnerability. An unauthenticated attacker with…

Mitigation only
Fix from $1,950 2025-05-06
Harmonyos MEDIUM 6.5
CVE-2025-46590

Bypass vulnerability in the network search instruction authentication module Impact: Successful exploitation of this vulnerability can bypass authent…

No fix yet
Fix from $1,600 2025-05-06
Privileged Remote Access HIGH 7.8
CVE-2025-0217

BeyondTrust Privileged Remote Access (PRA) versions prior to 25.1 are vulnerable to a local authentication bypass. A local authenticated attacker can…

Fix: 25.1+
Fix from $1,950 2025-05-05
Gefen Webfwc MEDIUM 6.5
CVE-2025-25504

An issue in the /usr/local/bin/jncs.sh script of Gefen WebFWC (In AV over IP products) v1.85h, v1.86v, and v1.70 allows attackers with network access…

No fix yet
Fix from $1,600 2025-05-05
A720r Firmware MEDIUM 5.3
CVE-2025-4268

A vulnerability has been found in TOTOLINK A720R 4.1.5cu.374 and classified as critical. This vulnerability affects unknown code of the file /cgi-bin…

No fix yet
Fix from $1,600 2025-05-05
Rx2 Pro Firmware MEDIUM 6.5
CVE-2025-46631EPSS 7%

Improper access controls in the web management portal of the Tenda RX2 Pro 16.03.30.14 allows an unauthenticated remote attacker to enable telnet acc…

No fix yet
Fix from $1,600 2025-05-01
Rx2 Pro Firmware MEDIUM 6.5
CVE-2025-46630

Improper access controls in the web management portal of the Tenda RX2 Pro 16.03.30.14 allows an unauthenticated remote attacker to enable 'ate' (a r…

No fix yet
Fix from $1,600 2025-05-01
Workers Oauth Provider CRITICAL 9.8
CVE-2025-4144

PKCE was implemented in the OAuth implementation in workers-oauth-provider that is part of MCP framework https://github.com/cloudflare/workers-mcp .…

Patch available
Fix from $2,300 2025-05-01
Unclassified HIGH 8.6
CVE-2025-29906

Finit is a fast init for Linux systems. Versions starting from 3.0-rc1 and prior to version 4.11 bundle an implementation of getty for the `tty` conf…

Patch available
Fix from $1,950 2025-04-29
Yeswiki CRITICAL 9.8
CVE-2025-46348

YesWiki is a wiki system written in PHP. Prior to version 4.5.4, the request to commence a site backup can be performed and downloaded without authen…

Fix: 4.5.4+
Fix from $2,300 2025-04-29
Build Of Keycloak MEDIUM 5.4
CVE-2025-3910

A flaw was found in Keycloak. The org.keycloak.authorization package may be vulnerable to circumventing required actions, allowing users to circumven…

Fix: 26.0.11+
Fix from $1,600 2025-04-29
Novel Plus CRITICAL 9.8
CVE-2025-4019

A vulnerability, which was classified as critical, was found in 20120630 Novel-Plus up to 0e156c04b4b7ce0563bef6c97af4476fcda8f160. Affected is the f…

Fix: 5.1.1+
Fix from $2,300 2025-04-28
Novel Plus HIGH 7.5
CVE-2025-4018

A vulnerability, which was classified as critical, has been found in 20120630 Novel-Plus up to 0e156c04b4b7ce0563bef6c97af4476fcda8f160. This issue a…

Fix: 5.1.1+
Fix from $1,950 2025-04-28
Novel Plus HIGH 7.5
CVE-2025-4015

A vulnerability was found in 20120630 Novel-Plus up to 0e156c04b4b7ce0563bef6c97af4476fcda8f160. It has been rated as critical. Affected by this issu…

Fix: 5.1.1+
Fix from $1,950 2025-04-28
Unclassified HIGH 8.1
CVE-2024-11917

The JobSearch WP Job Board plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 2.9.2. This is due to im…

Mitigation only
Fix from $1,950 2025-04-25
Router Firmware MEDIUM 5.3
CVE-2025-2771

BEC Technologies Multiple Routers Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affecte…

Mitigation only
Fix from $1,600 2025-04-23