Vulnerability index

Browse CVEs

4,337 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
Customer Email Verification For Woocommerce HIGH 7.5
CVE-2024-13528

The Customer Email Verification for WooCommerce plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 2.9…

Fix: 2.9.6+
Fix from $1,950 2025-02-12
Unified Secops Platform CRITICAL 9.8
CVE-2025-1044EPSS 75%

Logsign Unified SecOps Platform Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected …

Fix: 6.4.32+
Fix from $2,300 2025-02-11
Windows 10 1507 MEDIUM 6.8
CVE-2025-21349

Windows Remote Desktop Configuration Service Tampering Vulnerability

Fix: 10.0.10240.20915 / 10.0.14393.7785+
Fix from $1,600 2025-02-11
Forticlient HIGH 8.4
CVE-2024-52968

An improper authentication in Fortinet FortiClientMac 7.0.11 through 7.2.4 allows attacker to gain improper access to MacOS via empty password.

Fix: 7.0.13 / 7.2.5+
Fix from $1,950 2025-02-11
Devolutions Server MEDIUM 5.4
CVE-2025-1231

Improper password reset in PAM Module in Devolutions Server 2024.3.10.0 and earlier allows an authenticated user to reuse the oracle user password af…

Fix: 2024.3.11.0+
Fix from $1,600 2025-02-11
W18e Firmware HIGH 8.8
CVE-2024-46434

Tenda W18E V16.01.0.8(1625) suffers from authentication bypass in the web management portal allowing an unauthorized remote attacker to gain administ…

No fix yet
Fix from $1,950 2025-02-10
Unclassified CRITICAL 9.2
CVE-2025-24032

PAM-PKCS#11 is a Linux-PAM login module that allows a X.509 certificate based user login. Prior to version 0.6.13, if cert_policy is set to none (the…

Patch available
Fix from $2,300 2025-02-10
Dhp W310av Firmware CRITICAL 9.8
CVE-2025-1104

A vulnerability has been found in D-Link DHP-W310AV 1.04 and classified as critical. This vulnerability affects unknown code. The manipulation leads …

No fix yet
Fix from $2,300 2025-02-07
Unclassified CRITICAL 9.8
CVE-2024-48445

An issue in compop.ca ONLINE MALL v.3.5.3 allows a remote attacker to execute arbitrary code via the rid, tid, et, and ts parameters.

Mitigation only
Fix from $2,300 2025-02-04
Cassandra MEDIUM 5.3
CVE-2024-27137

In Apache Cassandra it is possible for a local attacker without access to the Apache Cassandra process or configuration files to manipulate the RMI…

Fix: 4.0.15 / 4.1.8+
Fix from $1,600 2025-02-04
Vmg4325 B10a Firmware CRITICAL 9.8
CVE-2025-0890EPSS 14%

**UNSUPPORTED WHEN ASSIGNED** Insecure default credentials for the Telnet function in the legacy DSL CPE Zyxel VMG4325-B10A firmware version 1.00(AAF…

Mitigation only
Fix from $2,300 2025-02-04
Unclassified MEDIUM 6.7
CVE-2024-12510

If LDAP settings are accessed, authentication could be redirected to another server, potentially exposing credentials. This requires admin access and…

Mitigation only
Fix from $1,600 2025-02-03
Mall Tiny HIGH 7.5
CVE-2024-57432

macrozheng mall-tiny 1.0.1 suffers from Insecure Permissions. The application's JWT signing keys are hardcoded and do not change. User information is…

No fix yet
Fix from $1,950 2025-01-31
Unclassified CRITICAL 9.8
CVE-2025-0637

It has been found that the Beta10 software does not provide for proper authorisation control in multiple areas of the application. This deficiency co…

Mitigation only
Fix from $2,300 2025-01-23
Unclassified MEDIUM 5.4
CVE-2025-0604

A flaw was found in Keycloak. When an Active Directory user resets their password, the system updates it without performing an LDAP bind to validate …

Mitigation only
Fix from $1,600 2025-01-22
Matrix Media Repo MEDIUM 5.3
CVE-2024-36402

Matrix Media Repo (MMR) is a highly configurable multi-homeserver media repository for Matrix. MMR before version 1.3.5 allows, by design, unauthenti…

Fix: 1.3.5+
Fix from $1,600 2025-01-16
Unclassified HIGH 8.7
CVE-2024-55954

OpenObserve is a cloud-native observability platform. A vulnerability in the user management endpoint `/api/{org_id}/users/{email_id}` allows an "Adm…

Mitigation only
Fix from $1,950 2025-01-16
Unclassified CRITICAL 9.1
CVE-2025-22146

Sentry is a developer-first error tracking and performance monitoring tool. A critical vulnerability was discovered in the SAML SSO implementation of…

Patch available
Fix from $2,300 2025-01-15
Unclassified HIGH 7.5
CVE-2024-11322

A denial-of-service vulnerability exists in CyberPower PowerPanel Business (PPB) 4.11.0. An unauthenticated remote attacker can restart the ppbd.exe…

Mitigation only
Fix from $1,950 2025-01-15
Membership \& Content Restriction Paid Member Subscriptions CRITICAL 9.8
CVE-2024-12919

The Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction plugin for WordPress is vulnerable to Authentica…

Fix: 2.13.8+
Fix from $2,300 2025-01-14
Unclassified CRITICAL 9.9
CVE-2025-0070

SAP NetWeaver Application Server for ABAP and ABAP Platform allows an authenticated attacker to obtain illegitimate access to the system by exploitin…

Mitigation only
Fix from $2,300 2025-01-14
Dryice Myxalytics CRITICAL 9.8
CVE-2024-42172

HCL MyXalytics is affected by broken authentication. It allows attackers to compromise keys, passwords, and session tokens, potentially leading to i…

Mitigation only
Fix from $2,300 2025-01-11
Ng Firewall MEDIUM 5.6
CVE-2024-9133

A user with administrator privileges is able to retrieve authentication tokens

Fix: after 17.1.1
Fix from $1,600 2025-01-10
Login Disable MEDIUM 5.4
CVE-2024-13309

Improper Authentication vulnerability in Drupal Login Disable allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affe…

Fix: 2.1.1+
Fix from $1,600 2025-01-09
Sonicos CRITICAL 9.8
CVE-2024-53704 KEVEPSS 95%

An Improper Authentication vulnerability in the SSLVPN authentication mechanism allows a remote attacker to bypass authentication.

Fix: after 7.1.1-7058
Fix from $2,300 2025-01-09
Harmonyos MEDIUM 5.3
CVE-2024-56445

Instruction authentication bypass vulnerability in the Findnetwork module Impact: Successful exploitation of this vulnerability may cause features to…

No fix yet
Fix from $1,600 2025-01-08
Emui HIGH 7.5
CVE-2023-52955

Vulnerability of improper authentication in the ANS system service module Impact: Successful exploitation of this vulnerability may cause features to…

No fix yet
Fix from $1,950 2025-01-08
Unclassified CRITICAL 9.8
CVE-2024-12264

The PayU CommercePro Plugin plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 3.8.3. This is due to /w…

Mitigation only
Fix from $2,300 2025-01-07
Unclassified HIGH 7.5
CVE-2025-21618

NiceGUI is an easy-to-use, Python-based UI framework. Prior to 2.9.1, authenticating with NiceGUI logged in the user for all browsers, including brow…

Patch available
Fix from $1,950 2025-01-06
Yunfan Learning Examination System HIGH 8.1
CVE-2024-13111

A vulnerability classified as critical was found in Beijing Yunfan Internet Technology Yunfan Learning Examination System 1.9.2. Affected by this vul…

No fix yet
Fix from $1,950 2025-01-02