Vulnerability index

Browse CVEs

4,337 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
Unclassified MEDIUM 5.3
CVE-2025-2344

A vulnerability, which was classified as critical, has been found in IROAD Dash Cam X5 and Dash Cam X6 up to 20250308. Affected by this issue is some…

Mitigation only
Fix from $1,600 2025-03-16
Tale Blog HIGH 7.5
CVE-2025-2339

A vulnerability was found in otale Tale Blog 2.0.5. It has been classified as problematic. This affects an unknown part of the file /%61dmin/api/logs…

No fix yet
Fix from $1,950 2025-03-16
Unclassified HIGH 7.7
CVE-2025-2230

A flaw exists in the Windows login flow where an AuthContext token can be exploited for replay attacks and authentication bypass.

Mitigation only
Fix from $1,950 2025-03-13
Dataease CRITICAL 9.8
CVE-2025-27138

DataEase is an open source business intelligence and data visualization tool. Prior to version 2.10.6, there is a flaw in the authentication in the i…

Fix: 2.10.6+
Fix from $2,300 2025-03-13
Froxlor HIGH 7.8
CVE-2025-29773

Froxlor is open-source server administration software. A vulnerability in versions prior to 2.2.6 allows users (such as resellers or customers) to cr…

Patch available
Fix from $1,950 2025-03-13
Unclassified MEDIUM 6.8
CVE-2025-0813

CWE-287: Improper Authentication vulnerability exists that could cause an Authentication Bypass when an unauthorized user without permission rights h…

Mitigation only
Fix from $1,600 2025-03-12
Unclassified HIGH 7.2
CVE-2025-27403

Ratify is a verification engine as a binary executable and on Kubernetes which enables verification of artifact security metadata and admits for depl…

Patch available
Fix from $1,950 2025-03-11
Unclassified CRITICAL 9.8
CVE-2024-56336

A vulnerability has been identified in SINAMICS S200 (All versions with serial number beginning with SZVS8, SZVS9, SZVS0 or SZVSN and the FS number i…

Mitigation only
Fix from $2,300 2025-03-11
Social Login CRITICAL 9.8
CVE-2024-11087

The miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) Pro Addon plugin for WordPress is vulnerable to authentication bypass i…

Fix: after 200.3.9
Fix from $2,300 2025-03-08
Unclassified CRITICAL 9.8
CVE-2025-1475

The WPCOM Member plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1.7.5. This is due to insufficient…

Mitigation only
Fix from $2,300 2025-03-07
Mytaag MEDIUM 5.1
CVE-2025-25450

An issue in TAAGSOLUTIONS GmbH MyTaag v.2024-11-24 and before allows a remote attacker to escalate privileges via the deactivation of the activated s…

Fix: after 2024-11-24
Fix from $1,600 2025-03-06
Mytaag MEDIUM 5.1
CVE-2025-25451

An issue in TAAGSOLUTIONS GmbH MyTaag v.2024-11-24 and before allows a physically proximate attacker to escalate privileges via the "2fa_authorized" …

Fix: after 2024-11-24
Fix from $1,600 2025-03-06
Mytaag MEDIUM 5.1
CVE-2025-25452

An issue in TAAGSOLUTIONS GmbH MyTaag v.2024-11-24 and before allows a remote attacker to escalate privileges via the "/user" endpoint

Fix: after 2024-11-24
Fix from $1,600 2025-03-06
Vasion Print CRITICAL 9.8
CVE-2025-27672

Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.843 Application 20.0.1923 allows OAUTH Security Bypass OVE-20230524-0016.

Fix: 20.0.1923 / 22.0.843+
Fix from $2,300 2025-03-05
Vasion Print CRITICAL 9.8
CVE-2025-27641

Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.951 Application 20.0.2368 allows Unauthenticated APIs for Single-Sign On V-20…

Fix: 20.0.2368 / 22.0.951+
Fix from $2,300 2025-03-05
Unclassified HIGH 7.5
CVE-2025-27422

FACTION is a PenTesting Report Generation and Collaboration Framework. Authentication is bypassed when an attacker registers a new user with admin pr…

Patch available
Fix from $1,950 2025-03-03
315 5g Iot Firmware MEDIUM 5.3
CVE-2024-38426

While processing the authentication message in UE, improper authentication may lead to information disclosure.

Mitigation only
Fix from $1,600 2025-03-03
Manageengine Adselfservice Plus HIGH 8.1
CVE-2025-1723

Zohocorp ManageEngine ADSelfService Plus versions 6510 and below are vulnerable to account takeover due to the session mishandling. Valid account hol…

Fix: 6.5+
Fix from $1,950 2025-03-03
Unclassified CRITICAL 9.6
CVE-2025-23116

An Authentication Bypass vulnerability on UniFi Protect Application with Auto-Adopt Bridge Devices enabled could allow a malicious actor with access …

Mitigation only
Fix from $2,300 2025-03-01
Unclassified MEDIUM 5.9
CVE-2025-27416

Scratch-Coding-Hut.github.io is the website for Coding Hut. The website as of 28 February 2025 contained a sign in with scratch username and password…

Mitigation only
Fix from $1,600 2025-03-01
Unclassified HIGH 8.8
CVE-2025-26326

A vulnerability was identified in the NVDA Remote (version 2.6.4) and Tele NVDA Remote (version 2025.3.3) remote connection add-ons, which allows an …

Mitigation only
Fix from $1,950 2025-02-28
Navidrome MEDIUM 6.5
CVE-2025-27112

Navidrome is an open source web-based music collection server and streamer. Starting in version 0.52.0 and prior to version 0.54.5, in certain Subson…

Fix: 0.54.5+
Fix from $1,600 2025-02-24
Unclassified MEDIUM 5.3
CVE-2024-5174

A flaw in Gliffy results in broken authentication through the reset functionality of the application.

No fix yet
Fix from $1,600 2025-02-24
Unclassified CRITICAL 9.1
CVE-2025-24894

SPID.AspNetCore.Authentication is an AspNetCore Remote Authenticator for SPID. Authentication using Spid and CIE is based on the SAML2 standard which…

Mitigation only
Fix from $2,300 2025-02-18
Unclassified CRITICAL 9.1
CVE-2025-24895

CIE.AspNetCore.Authentication is an AspNetCore Remote Authenticator for CIE 3.0. Authentication using Spid and CIE is based on the SAML2 standard whi…

Mitigation only
Fix from $2,300 2025-02-18
Dir 859 A3 Firmware CRITICAL 9.8
CVE-2024-57045EPSS 32%

A vulnerability in the D-Link DIR-859 router with firmware version A3 1.05 and earlier permits unauthorized individuals to bypass the authentication.…

Fix: 1.05+
Fix from $2,300 2025-02-18
Dgn2200 Firmware HIGH 8.8
CVE-2024-57046

A vulnerability in the Netgear DGN2200 router with firmware version v1.0.0.46 and earlier permits unauthorized individuals to bypass the authenticati…

Fix: after 1.0.0.46
Fix from $1,950 2025-02-18
Churchcrm MEDIUM 6.1
CVE-2025-0981

A vulnerability exists in ChurchCRM 5.13.0 and prior that allows an attacker to hijack a user's session by exploiting a Stored Cross Site Scripting (…

Fix: after 5.13.0
Fix from $1,600 2025-02-18
Unclassified HIGH 8.5
CVE-2025-24904

libsignal-service-rs is a Rust version of the libsignal-service-java library which implements the core functionality to communicate with Signal serve…

Patch available
Fix from $1,950 2025-02-13
Audiobookshelf HIGH 8.2
CVE-2025-25205

Audiobookshelf is a self-hosted audiobook and podcast server. Starting in version 2.17.0 and prior to version 2.19.1, a flaw in the authentication by…

Fix: 2.19.1+
Fix from $1,950 2025-02-12