Vulnerability index

Browse CVEs

4,337 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
MEDIUM 5.3 CVE-2025-2344 A vulnerability, which was classified as critical, has been found in IROAD Dash Cam X5 and Dash Cam X6 up to 20250308. Affected by this issue is some… Mitigation only Fix from $1,6002025-03-16 HIGH 7.5 CVE-2025-2339 A vulnerability was found in otale Tale Blog 2.0.5. It has been classified as problematic. This affects an unknown part of the file /%61dmin/api/logs… Tale Blog No fix yet Fix from $1,9502025-03-16 HIGH 7.7 CVE-2025-2230 A flaw exists in the Windows login flow where an AuthContext token can be exploited for replay attacks and authentication bypass. Mitigation only Fix from $1,9502025-03-13 CRITICAL 9.8 CVE-2025-27138 DataEase is an open source business intelligence and data visualization tool. Prior to version 2.10.6, there is a flaw in the authentication in the i… Dataease 2.10.6+ Fix from $2,3002025-03-13 HIGH 7.8 CVE-2025-29773 Froxlor is open-source server administration software. A vulnerability in versions prior to 2.2.6 allows users (such as resellers or customers) to cr… Froxlor Patch available Fix from $1,9502025-03-13 MEDIUM 6.8 CVE-2025-0813 CWE-287: Improper Authentication vulnerability exists that could cause an Authentication Bypass when an unauthorized user without permission rights h… Mitigation only Fix from $1,6002025-03-12 HIGH 7.2 CVE-2025-27403 Ratify is a verification engine as a binary executable and on Kubernetes which enables verification of artifact security metadata and admits for depl… Patch available Fix from $1,9502025-03-11 CRITICAL 9.8 CVE-2024-56336 A vulnerability has been identified in SINAMICS S200 (All versions with serial number beginning with SZVS8, SZVS9, SZVS0 or SZVSN and the FS number i… Mitigation only Fix from $2,3002025-03-11 CRITICAL 9.8 CVE-2024-11087 The miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) Pro Addon plugin for WordPress is vulnerable to authentication bypass i… Social Login after 200.3.9 Fix from $2,3002025-03-08 CRITICAL 9.8 CVE-2025-1475 The WPCOM Member plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1.7.5. This is due to insufficient… Mitigation only Fix from $2,3002025-03-07 MEDIUM 5.1 CVE-2025-25450 An issue in TAAGSOLUTIONS GmbH MyTaag v.2024-11-24 and before allows a remote attacker to escalate privileges via the deactivation of the activated s… Mytaag after 2024-11-24 Fix from $1,6002025-03-06 MEDIUM 5.1 CVE-2025-25451 An issue in TAAGSOLUTIONS GmbH MyTaag v.2024-11-24 and before allows a physically proximate attacker to escalate privileges via the "2fa_authorized" … Mytaag after 2024-11-24 Fix from $1,6002025-03-06 MEDIUM 5.1 CVE-2025-25452 An issue in TAAGSOLUTIONS GmbH MyTaag v.2024-11-24 and before allows a remote attacker to escalate privileges via the "/user" endpoint Mytaag after 2024-11-24 Fix from $1,6002025-03-06 CRITICAL 9.8 CVE-2025-27672 Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.843 Application 20.0.1923 allows OAUTH Security Bypass OVE-20230524-0016. Vasion Print 20.0.1923 / 22.0.843+ Fix from $2,3002025-03-05 CRITICAL 9.8 CVE-2025-27641 Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.951 Application 20.0.2368 allows Unauthenticated APIs for Single-Sign On V-20… Vasion Print 20.0.2368 / 22.0.951+ Fix from $2,3002025-03-05 HIGH 7.5 CVE-2025-27422 FACTION is a PenTesting Report Generation and Collaboration Framework. Authentication is bypassed when an attacker registers a new user with admin pr… Patch available Fix from $1,9502025-03-03 MEDIUM 5.3 CVE-2024-38426 While processing the authentication message in UE, improper authentication may lead to information disclosure. 315 5g Iot Firmware Mitigation only Fix from $1,6002025-03-03 HIGH 8.1 CVE-2025-1723 Zohocorp ManageEngine ADSelfService Plus versions 6510 and below are vulnerable to account takeover due to the session mishandling. Valid account hol… Manageengine Adselfservice Plus 6.5+ Fix from $1,9502025-03-03 CRITICAL 9.6 CVE-2025-23116 An Authentication Bypass vulnerability on UniFi Protect Application with Auto-Adopt Bridge Devices enabled could allow a malicious actor with access … Mitigation only Fix from $2,3002025-03-01 MEDIUM 5.9 CVE-2025-27416 Scratch-Coding-Hut.github.io is the website for Coding Hut. The website as of 28 February 2025 contained a sign in with scratch username and password… Mitigation only Fix from $1,6002025-03-01 HIGH 8.8 CVE-2025-26326 A vulnerability was identified in the NVDA Remote (version 2.6.4) and Tele NVDA Remote (version 2025.3.3) remote connection add-ons, which allows an … Mitigation only Fix from $1,9502025-02-28 MEDIUM 6.5 CVE-2025-27112 Navidrome is an open source web-based music collection server and streamer. Starting in version 0.52.0 and prior to version 0.54.5, in certain Subson… Navidrome 0.54.5+ Fix from $1,6002025-02-24 MEDIUM 5.3 CVE-2024-5174 A flaw in Gliffy results in broken authentication through the reset functionality of the application. No fix yet Fix from $1,6002025-02-24 CRITICAL 9.1 CVE-2025-24894 SPID.AspNetCore.Authentication is an AspNetCore Remote Authenticator for SPID. Authentication using Spid and CIE is based on the SAML2 standard which… Mitigation only Fix from $2,3002025-02-18 CRITICAL 9.1 CVE-2025-24895 CIE.AspNetCore.Authentication is an AspNetCore Remote Authenticator for CIE 3.0. Authentication using Spid and CIE is based on the SAML2 standard whi… Mitigation only Fix from $2,3002025-02-18 CRITICAL 9.8 CVE-2024-57045EPSS 32% A vulnerability in the D-Link DIR-859 router with firmware version A3 1.05 and earlier permits unauthorized individuals to bypass the authentication.… Dir 859 A3 Firmware 1.05+ Fix from $2,3002025-02-18 HIGH 8.8 CVE-2024-57046 A vulnerability in the Netgear DGN2200 router with firmware version v1.0.0.46 and earlier permits unauthorized individuals to bypass the authenticati… Dgn2200 Firmware after 1.0.0.46 Fix from $1,9502025-02-18 MEDIUM 6.1 CVE-2025-0981 A vulnerability exists in ChurchCRM 5.13.0 and prior that allows an attacker to hijack a user's session by exploiting a Stored Cross Site Scripting (… Churchcrm after 5.13.0 Fix from $1,6002025-02-18 HIGH 8.5 CVE-2025-24904 libsignal-service-rs is a Rust version of the libsignal-service-java library which implements the core functionality to communicate with Signal serve… Patch available Fix from $1,9502025-02-13 HIGH 8.2 CVE-2025-25205 Audiobookshelf is a self-hosted audiobook and podcast server. Starting in version 2.17.0 and prior to version 2.19.1, a flaw in the authentication by… Audiobookshelf 2.19.1+ Fix from $1,9502025-02-12