Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 7.5
CVE-2024-13528
The Customer Email Verification for WooCommerce plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 2.9…
Customer Email Verification For Woocommerce
2.9.6+
CRITICAL 9.8
CVE-2025-1044EPSS 75%
Logsign Unified SecOps Platform Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected …
Unified Secops Platform
6.4.32+
MEDIUM 6.8
CVE-2025-21349
Windows Remote Desktop Configuration Service Tampering Vulnerability
Windows 10 1507
10.0.10240.20915 / 10.0.14393.7785+
HIGH 8.4
CVE-2024-52968
An improper authentication in Fortinet FortiClientMac 7.0.11 through 7.2.4 allows attacker to gain improper access to MacOS via empty password.
Forticlient
7.0.13 / 7.2.5+
MEDIUM 5.4
CVE-2025-1231
Improper password reset in PAM Module in Devolutions Server 2024.3.10.0 and earlier allows an authenticated user to reuse the oracle user password af…
Devolutions Server
2024.3.11.0+
HIGH 8.8
CVE-2024-46434
Tenda W18E V16.01.0.8(1625) suffers from authentication bypass in the web management portal allowing an unauthorized remote attacker to gain administ…
W18e Firmware
No fix yet
CRITICAL 9.2
CVE-2025-24032
PAM-PKCS#11 is a Linux-PAM login module that allows a X.509 certificate based user login. Prior to version 0.6.13, if cert_policy is set to none (the…
Patch available
CRITICAL 9.8
CVE-2025-1104
A vulnerability has been found in D-Link DHP-W310AV 1.04 and classified as critical. This vulnerability affects unknown code. The manipulation leads …
Dhp W310av Firmware
No fix yet
CRITICAL 9.8
CVE-2024-48445
An issue in compop.ca ONLINE MALL v.3.5.3 allows a remote attacker to execute arbitrary code via the rid, tid, et, and ts parameters.
Mitigation only
MEDIUM 5.3
CVE-2024-27137
In Apache Cassandra it is possible for a local attacker without access
to the Apache Cassandra process or configuration files to manipulate
the RMI…
Cassandra
4.0.15 / 4.1.8+
CRITICAL 9.8
CVE-2025-0890EPSS 14%
**UNSUPPORTED WHEN ASSIGNED**
Insecure default credentials for the Telnet function in the legacy DSL CPE Zyxel VMG4325-B10A firmware version 1.00(AAF…
Vmg4325 B10a Firmware
Mitigation only
MEDIUM 6.7
CVE-2024-12510
If LDAP settings are accessed, authentication could be redirected to another server, potentially exposing credentials. This requires admin access and…
Mitigation only
HIGH 7.5
CVE-2024-57432
macrozheng mall-tiny 1.0.1 suffers from Insecure Permissions. The application's JWT signing keys are hardcoded and do not change. User information is…
Mall Tiny
No fix yet
CRITICAL 9.8
CVE-2025-0637
It has been found that the Beta10 software does not provide for proper authorisation control in multiple areas of the application. This deficiency co…
Mitigation only
MEDIUM 5.4
CVE-2025-0604
A flaw was found in Keycloak. When an Active Directory user resets their password, the system updates it without performing an LDAP bind to validate …
Mitigation only
MEDIUM 5.3
CVE-2024-36402
Matrix Media Repo (MMR) is a highly configurable multi-homeserver media repository for Matrix. MMR before version 1.3.5 allows, by design, unauthenti…
Matrix Media Repo
1.3.5+
HIGH 8.7
CVE-2024-55954
OpenObserve is a cloud-native observability platform. A vulnerability in the user management endpoint `/api/{org_id}/users/{email_id}` allows an "Adm…
Mitigation only
CRITICAL 9.1
CVE-2025-22146
Sentry is a developer-first error tracking and performance monitoring tool. A critical vulnerability was discovered in the SAML SSO implementation of…
Patch available
HIGH 7.5
CVE-2024-11322
A denial-of-service vulnerability exists in CyberPower PowerPanel Business (PPB) 4.11.0.
An unauthenticated remote attacker can restart the ppbd.exe…
Mitigation only
CRITICAL 9.8
CVE-2024-12919
The Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction plugin for WordPress is vulnerable to Authentica…
Membership \& Content Restriction Paid Member Subscriptions
2.13.8+
CRITICAL 9.9
CVE-2025-0070
SAP NetWeaver Application Server for ABAP and ABAP Platform allows an authenticated attacker to obtain illegitimate access to the system by exploitin…
Mitigation only
CRITICAL 9.8
CVE-2024-42172
HCL MyXalytics is affected by broken authentication. It allows attackers to compromise keys, passwords, and session tokens, potentially leading to i…
Dryice Myxalytics
Mitigation only
MEDIUM 5.6
CVE-2024-9133
A user with administrator privileges is able to retrieve authentication tokens
Ng Firewall
after 17.1.1
MEDIUM 5.4
CVE-2024-13309
Improper Authentication vulnerability in Drupal Login Disable allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affe…
Login Disable
2.1.1+
CRITICAL 9.8
CVE-2024-53704 KEVEPSS 95%
An Improper Authentication vulnerability in the SSLVPN authentication mechanism allows a remote attacker to bypass authentication.
Sonicos
after 7.1.1-7058
MEDIUM 5.3
CVE-2024-56445
Instruction authentication bypass vulnerability in the Findnetwork module
Impact: Successful exploitation of this vulnerability may cause features to…
Harmonyos
No fix yet
HIGH 7.5
CVE-2023-52955
Vulnerability of improper authentication in the ANS system service module
Impact: Successful exploitation of this vulnerability may cause features to…
Emui
No fix yet
CRITICAL 9.8
CVE-2024-12264
The PayU CommercePro Plugin plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 3.8.3. This is due to /w…
Mitigation only
HIGH 7.5
CVE-2025-21618
NiceGUI is an easy-to-use, Python-based UI framework. Prior to 2.9.1, authenticating with NiceGUI logged in the user for all browsers, including brow…
Patch available
HIGH 8.1
CVE-2024-13111
A vulnerability classified as critical was found in Beijing Yunfan Internet Technology Yunfan Learning Examination System 1.9.2. Affected by this vul…
Yunfan Learning Examination System
No fix yet