Vulnerability index

Browse CVEs

4,337 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
HIGH 7.5 CVE-2024-13528 The Customer Email Verification for WooCommerce plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 2.9… Customer Email Verification For Woocommerce 2.9.6+ Fix from $1,9502025-02-12 CRITICAL 9.8 CVE-2025-1044EPSS 75% Logsign Unified SecOps Platform Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected … Unified Secops Platform 6.4.32+ Fix from $2,3002025-02-11 MEDIUM 6.8 CVE-2025-21349 Windows Remote Desktop Configuration Service Tampering Vulnerability Windows 10 1507 10.0.10240.20915 / 10.0.14393.7785+ Fix from $1,6002025-02-11 HIGH 8.4 CVE-2024-52968 An improper authentication in Fortinet FortiClientMac 7.0.11 through 7.2.4 allows attacker to gain improper access to MacOS via empty password. Forticlient 7.0.13 / 7.2.5+ Fix from $1,9502025-02-11 MEDIUM 5.4 CVE-2025-1231 Improper password reset in PAM Module in Devolutions Server 2024.3.10.0 and earlier allows an authenticated user to reuse the oracle user password af… Devolutions Server 2024.3.11.0+ Fix from $1,6002025-02-11 HIGH 8.8 CVE-2024-46434 Tenda W18E V16.01.0.8(1625) suffers from authentication bypass in the web management portal allowing an unauthorized remote attacker to gain administ… W18e Firmware No fix yet Fix from $1,9502025-02-10 CRITICAL 9.2 CVE-2025-24032 PAM-PKCS#11 is a Linux-PAM login module that allows a X.509 certificate based user login. Prior to version 0.6.13, if cert_policy is set to none (the… Patch available Fix from $2,3002025-02-10 CRITICAL 9.8 CVE-2025-1104 A vulnerability has been found in D-Link DHP-W310AV 1.04 and classified as critical. This vulnerability affects unknown code. The manipulation leads … Dhp W310av Firmware No fix yet Fix from $2,3002025-02-07 CRITICAL 9.8 CVE-2024-48445 An issue in compop.ca ONLINE MALL v.3.5.3 allows a remote attacker to execute arbitrary code via the rid, tid, et, and ts parameters. Mitigation only Fix from $2,3002025-02-04 MEDIUM 5.3 CVE-2024-27137 In Apache Cassandra it is possible for a local attacker without access to the Apache Cassandra process or configuration files to manipulate the RMI… Cassandra 4.0.15 / 4.1.8+ Fix from $1,6002025-02-04 CRITICAL 9.8 CVE-2025-0890EPSS 14% **UNSUPPORTED WHEN ASSIGNED** Insecure default credentials for the Telnet function in the legacy DSL CPE Zyxel VMG4325-B10A firmware version 1.00(AAF… Vmg4325 B10a Firmware Mitigation only Fix from $2,3002025-02-04 MEDIUM 6.7 CVE-2024-12510 If LDAP settings are accessed, authentication could be redirected to another server, potentially exposing credentials. This requires admin access and… Mitigation only Fix from $1,6002025-02-03 HIGH 7.5 CVE-2024-57432 macrozheng mall-tiny 1.0.1 suffers from Insecure Permissions. The application's JWT signing keys are hardcoded and do not change. User information is… Mall Tiny No fix yet Fix from $1,9502025-01-31 CRITICAL 9.8 CVE-2025-0637 It has been found that the Beta10 software does not provide for proper authorisation control in multiple areas of the application. This deficiency co… Mitigation only Fix from $2,3002025-01-23 MEDIUM 5.4 CVE-2025-0604 A flaw was found in Keycloak. When an Active Directory user resets their password, the system updates it without performing an LDAP bind to validate … Mitigation only Fix from $1,6002025-01-22 MEDIUM 5.3 CVE-2024-36402 Matrix Media Repo (MMR) is a highly configurable multi-homeserver media repository for Matrix. MMR before version 1.3.5 allows, by design, unauthenti… Matrix Media Repo 1.3.5+ Fix from $1,6002025-01-16 HIGH 8.7 CVE-2024-55954 OpenObserve is a cloud-native observability platform. A vulnerability in the user management endpoint `/api/{org_id}/users/{email_id}` allows an "Adm… Mitigation only Fix from $1,9502025-01-16 CRITICAL 9.1 CVE-2025-22146 Sentry is a developer-first error tracking and performance monitoring tool. A critical vulnerability was discovered in the SAML SSO implementation of… Patch available Fix from $2,3002025-01-15 HIGH 7.5 CVE-2024-11322 A denial-of-service vulnerability exists in CyberPower PowerPanel Business (PPB) 4.11.0. An unauthenticated remote attacker can restart the ppbd.exe… Mitigation only Fix from $1,9502025-01-15 CRITICAL 9.8 CVE-2024-12919 The Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction plugin for WordPress is vulnerable to Authentica… Membership \& Content Restriction Paid Member Subscriptions 2.13.8+ Fix from $2,3002025-01-14 CRITICAL 9.9 CVE-2025-0070 SAP NetWeaver Application Server for ABAP and ABAP Platform allows an authenticated attacker to obtain illegitimate access to the system by exploitin… Mitigation only Fix from $2,3002025-01-14 CRITICAL 9.8 CVE-2024-42172 HCL MyXalytics is affected by broken authentication. It allows attackers to compromise keys, passwords, and session tokens, potentially leading to i… Dryice Myxalytics Mitigation only Fix from $2,3002025-01-11 MEDIUM 5.6 CVE-2024-9133 A user with administrator privileges is able to retrieve authentication tokens Ng Firewall after 17.1.1 Fix from $1,6002025-01-10 MEDIUM 5.4 CVE-2024-13309 Improper Authentication vulnerability in Drupal Login Disable allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affe… Login Disable 2.1.1+ Fix from $1,6002025-01-09 CRITICAL 9.8 CVE-2024-53704 KEVEPSS 95% An Improper Authentication vulnerability in the SSLVPN authentication mechanism allows a remote attacker to bypass authentication. Sonicos after 7.1.1-7058 Fix from $2,3002025-01-09 MEDIUM 5.3 CVE-2024-56445 Instruction authentication bypass vulnerability in the Findnetwork module Impact: Successful exploitation of this vulnerability may cause features to… Harmonyos No fix yet Fix from $1,6002025-01-08 HIGH 7.5 CVE-2023-52955 Vulnerability of improper authentication in the ANS system service module Impact: Successful exploitation of this vulnerability may cause features to… Emui No fix yet Fix from $1,9502025-01-08 CRITICAL 9.8 CVE-2024-12264 The PayU CommercePro Plugin plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 3.8.3. This is due to /w… Mitigation only Fix from $2,3002025-01-07 HIGH 7.5 CVE-2025-21618 NiceGUI is an easy-to-use, Python-based UI framework. Prior to 2.9.1, authenticating with NiceGUI logged in the user for all browsers, including brow… Patch available Fix from $1,9502025-01-06 HIGH 8.1 CVE-2024-13111 A vulnerability classified as critical was found in Beijing Yunfan Internet Technology Yunfan Learning Examination System 1.9.2. Affected by this vul… Yunfan Learning Examination System No fix yet Fix from $1,9502025-01-02