Vulnerability index

Browse CVEs

4,337 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
CRITICAL 9.8 CVE-2025-4978EPSS 18% A vulnerability, which was classified as very critical, was found in Netgear DGND3700 1.1.00.15_1.00.15NA. This affects an unknown part of the file /… Dgnd3700 Firmware No fix yet Fix from $2,3002025-05-20 MEDIUM 6.4 CVE-2025-47790 Nextcloud Server is a self hosted personal cloud system. Nextcloud Server prior to 29.0.15, 30.0.9, and 31.0.3 and Nextcloud Enterprise Server prior … Nextcloud Server 26.0.13.15 / 27.1.11.15+ Fix from $1,6002025-05-16 MEDIUM 5.3 CVE-2025-4755EPSS 7% A vulnerability was found in D-Link DI-7003GV2 24.04.18D1 R(68125). It has been classified as critical. This affects the function sub_497DE4 of the f… Di 7003g Firmware No fix yet Fix from $1,6002025-05-16 CRITICAL 9.1 CVE-2025-47275 Auth0-PHP provides the PHP SDK for Auth0 Authentication and Management APIs. Starting in version 8.0.0-BETA1 and prior to version 8.14.0, session coo… Patch available Fix from $2,3002025-05-15 CRITICAL 9.8 CVE-2025-47889 In Jenkins WSO2 Oauth Plugin 1.0 and earlier, authentication claims are accepted without validation by the "WSO2 Oauth" security realm, allowing unau… Wso2 Oauth after 1.0 Fix from $2,3002025-05-14 HIGH 7.5 CVE-2025-20083 Improper authentication in the firmware for the Intel(R) Slim Bootloader may allow a privileged user to potentially enable escalation of privilege vi… Mitigation only Fix from $1,9502025-05-13 MEDIUM 6.5 CVE-2025-26685 Improper authentication in Microsoft Defender for Identity allows an unauthorized attacker to perform spoofing over an adjacent network. Defender For Identity Mitigation only Fix from $1,6002025-05-13 MEDIUM 6.8 CVE-2025-31228 The issue was addressed with improved authentication. This issue is fixed in iOS 18.5 and iPadOS 18.5, iPadOS 17.7.7. An attacker with physical acces… Ipados 17.7.7 / 18.5+ Fix from $1,6002025-05-12 CRITICAL 9.4 CVE-2025-3659 Improper authentication handling was identified in a set of HTTP POST requests affecting the following product families: * Digi PortServer TS - … Mitigation only Fix from $2,3002025-05-12 CRITICAL 9.8 CVE-2025-4494 A vulnerability, which was classified as critical, was found in JAdmin-JAVA JAdmin 1.0. Affected is the function toLogin of the file NoNeedLoginContr… Jadmin No fix yet Fix from $2,3002025-05-09 CRITICAL 9.8 CVE-2025-29813 Authentication bypass by assumed-immutable data in Azure DevOps allows an unauthorized attacker to elevate privileges over a network. Azure Devops Mitigation only Fix from $2,3002025-05-08 CRITICAL 10.0 CVE-2024-11186 On affected versions of the CloudVision Portal, improper access controls could enable a malicious authenticated user to take broader actions on manag… Mitigation only Fix from $2,3002025-05-08 CRITICAL 9.3 CVE-2025-46572 passport-wsfed-saml2 provides passport strategy for both WS-fed and SAML2 protocol. A vulnerability present starting in version 3.0.5 up to and inclu… Patch available Fix from $2,3002025-05-06 HIGH 8.6 CVE-2025-46573 passport-wsfed-saml2 provides passport strategy for both WS-fed and SAML2 protocol. A vulnerability present starting in version 3.0.5 up to and inclu… Patch available Fix from $1,9502025-05-06 HIGH 8.8 CVE-2025-22477 Dell Storage Center - Dell Storage Manager, version(s) 20.1.20, contain(s) an Improper Authentication vulnerability. An unauthenticated attacker with… Storage Manager Mitigation only Fix from $1,9502025-05-06 MEDIUM 6.5 CVE-2025-46590 Bypass vulnerability in the network search instruction authentication module Impact: Successful exploitation of this vulnerability can bypass authent… Harmonyos No fix yet Fix from $1,6002025-05-06 HIGH 7.8 CVE-2025-0217 BeyondTrust Privileged Remote Access (PRA) versions prior to 25.1 are vulnerable to a local authentication bypass. A local authenticated attacker can… Privileged Remote Access 25.1+ Fix from $1,9502025-05-05 MEDIUM 6.5 CVE-2025-25504 An issue in the /usr/local/bin/jncs.sh script of Gefen WebFWC (In AV over IP products) v1.85h, v1.86v, and v1.70 allows attackers with network access… Gefen Webfwc No fix yet Fix from $1,6002025-05-05 MEDIUM 5.3 CVE-2025-4268 A vulnerability has been found in TOTOLINK A720R 4.1.5cu.374 and classified as critical. This vulnerability affects unknown code of the file /cgi-bin… A720r Firmware No fix yet Fix from $1,6002025-05-05 MEDIUM 6.5 CVE-2025-46631EPSS 7% Improper access controls in the web management portal of the Tenda RX2 Pro 16.03.30.14 allows an unauthenticated remote attacker to enable telnet acc… Rx2 Pro Firmware No fix yet Fix from $1,6002025-05-01 MEDIUM 6.5 CVE-2025-46630 Improper access controls in the web management portal of the Tenda RX2 Pro 16.03.30.14 allows an unauthenticated remote attacker to enable 'ate' (a r… Rx2 Pro Firmware No fix yet Fix from $1,6002025-05-01 CRITICAL 9.8 CVE-2025-4144 PKCE was implemented in the OAuth implementation in workers-oauth-provider that is part of MCP framework https://github.com/cloudflare/workers-mcp .… Workers Oauth Provider Patch available Fix from $2,3002025-05-01 HIGH 8.6 CVE-2025-29906 Finit is a fast init for Linux systems. Versions starting from 3.0-rc1 and prior to version 4.11 bundle an implementation of getty for the `tty` conf… Patch available Fix from $1,9502025-04-29 CRITICAL 9.8 CVE-2025-46348 YesWiki is a wiki system written in PHP. Prior to version 4.5.4, the request to commence a site backup can be performed and downloaded without authen… Yeswiki 4.5.4+ Fix from $2,3002025-04-29 MEDIUM 5.4 CVE-2025-3910 A flaw was found in Keycloak. The org.keycloak.authorization package may be vulnerable to circumventing required actions, allowing users to circumven… Build Of Keycloak 26.0.11+ Fix from $1,6002025-04-29 CRITICAL 9.8 CVE-2025-4019 A vulnerability, which was classified as critical, was found in 20120630 Novel-Plus up to 0e156c04b4b7ce0563bef6c97af4476fcda8f160. Affected is the f… Novel Plus 5.1.1+ Fix from $2,3002025-04-28 HIGH 7.5 CVE-2025-4018 A vulnerability, which was classified as critical, has been found in 20120630 Novel-Plus up to 0e156c04b4b7ce0563bef6c97af4476fcda8f160. This issue a… Novel Plus 5.1.1+ Fix from $1,9502025-04-28 HIGH 7.5 CVE-2025-4015 A vulnerability was found in 20120630 Novel-Plus up to 0e156c04b4b7ce0563bef6c97af4476fcda8f160. It has been rated as critical. Affected by this issu… Novel Plus 5.1.1+ Fix from $1,9502025-04-28 HIGH 8.1 CVE-2024-11917 The JobSearch WP Job Board plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 2.9.2. This is due to im… Mitigation only Fix from $1,9502025-04-25 MEDIUM 5.3 CVE-2025-2771 BEC Technologies Multiple Routers Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affecte… Router Firmware Mitigation only Fix from $1,6002025-04-23