Vulnerability index

Browse CVEs

2,893 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthenticationCWE-306 × clear
Drive Server HIGH 7.5
CVE-2024-50630EPSS 23%

Missing authentication for critical function vulnerability in the webapi component in Synology Drive Server before 3.0.4-12699, 3.2.1-23280, 3.5.0-26…

Fix: 3.0.4-12699 / 3.2.1-23280+
Fix from $1,950 2025-03-19
Unclassified HIGH 7.5
CVE-2025-30111

On IROAD v9 devices, one can Remotely Dump Video Footage and the Live Video Stream. The dashcam exposes endpoints that allow unauthorized users, who …

Mitigation only
Fix from $1,950 2025-03-18
Unclassified CRITICAL 9.1
CVE-2024-23943

An unauthenticated remote attacker can gain access to the cloud API due to a lack of authentication for a critical function in the affected devices. …

Mitigation only
Fix from $2,300 2025-03-18
Unclassified MEDIUM 5.3
CVE-2025-2344

A vulnerability, which was classified as critical, has been found in IROAD Dash Cam X5 and Dash Cam X6 up to 20250308. Affected by this issue is some…

Mitigation only
Fix from $1,600 2025-03-16
Civi MEDIUM 5.9
CVE-2024-13771

The Civi - Job Board & Freelance Marketplace WordPress Theme plugin for WordPress is vulnerable to authentication bypass in all versions up to, and i…

Fix: after 2.1.4
Fix from $1,600 2025-03-14
Civi MEDIUM 5.9
CVE-2024-13772

The Civi - Job Board & Freelance Marketplace WordPress Theme plugin for WordPress is vulnerable to authentication bypass in all versions up to, and i…

Fix: after 2.1.4
Fix from $1,600 2025-03-14
Unclassified MEDIUM 5.3
CVE-2024-52285

A vulnerability has been identified in SiPass integrated AC5102 (ACC-G2) (All versions < V6.4.8), SiPass integrated ACC-AP (All versions < V6.4.8). A…

Mitigation only
Fix from $1,600 2025-03-11
Unclassified MEDIUM 5.3
CVE-2025-23194

SAP NetWeaver Enterprise Portal OBN does not perform proper authentication check for a particular configuration setting. As result, a non-authenticat…

Mitigation only
Fix from $1,600 2025-03-11
Unclassified HIGH 8.3
CVE-2025-27256

Missing Authentication for Critical Function vulnerability in GE Vernova Enervista UR Setup application allows Authentication Bypass due to a missing…

Mitigation only
Fix from $1,950 2025-03-10
Injob CRITICAL 9.8
CVE-2025-1315

The InWave Jobs plugin for WordPress is vulnerable to privilege escalation via password reset in all versions up to, and including, 3.5.1. This is du…

Fix: after 3.5.1
Fix from $2,300 2025-03-07
School Management System HIGH 8.8
CVE-2024-9658

The School Management System for Wordpress plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and…

Fix: after 93.0.0
Fix from $1,950 2025-03-07
Unclassified HIGH 7.2
CVE-2024-31525

Peppermint Ticket Management 0.4.6 is vulnerable to Incorrect Access Control. A regular registered user is able to elevate his privileges to admin an…

Mitigation only
Fix from $1,950 2025-03-05
Vasion Print CRITICAL 9.8
CVE-2025-27647

Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.913 Application 20.0.2253 allows Addition of Partial Admin Users Without Auth…

Fix: 20.0.2253 / 22.0.913+
Fix from $2,300 2025-03-05
Vasion Print CRITICAL 9.8
CVE-2025-27642

Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.933 Application 20.0.2368 allows Unauthenticated Driver Package Editing V-202…

Fix: 20.0.2368 / 22.0.933+
Fix from $2,300 2025-03-05
Unclassified CRITICAL 9.8
CVE-2025-24924

Certain functionality within GMOD Apollo does not require authentication when passed with an administrative username

Mitigation only
Fix from $2,300 2025-03-05
Storage Virtualize CRITICAL 9.1
CVE-2025-0159

IBM FlashSystem (IBM Storage Virtualize (8.5.0.0 through 8.5.0.13, 8.5.1.0, 8.5.2.0 through 8.5.2.3, 8.5.3.0 through 8.5.3.1, 8.5.4.0, 8.6.0.0 throug…

Fix: 8.5.0.14 / 8.6.0.6+
Fix from $2,300 2025-02-28
Login Me Now HIGH 8.1
CVE-2025-1717

The Login Me Now plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.7.2. This is due to insecure authent…

Fix: after 1.7.2
Fix from $1,950 2025-02-27
Bing CRITICAL 9.8
CVE-2025-21355

Missing Authentication for Critical Function in Microsoft Bing allows an unauthorized attacker to execute code over a network

Patch available
Fix from $2,300 2025-02-19
Unclassified MEDIUM 5.0
CVE-2024-57055

Server-Side Access Control Bypass vulnerability in WombatDialer before 25.02 could allow unauthorized users to potentially call certain services with…

Mitigation only
Fix from $1,600 2025-02-18
Luxcal Web Calendar HIGH 7.5
CVE-2025-25224

The LuxCal Web Calendar prior to 5.3.3M (MySQL version) and prior to 5.3.3L (SQLite version) contains a missing authentication vulnerability in dload…

Fix: 5.3.3l / 5.3.3m+
Fix from $1,950 2025-02-18
Unclassified MEDIUM 6.5
CVE-2024-57725EPSS 6%

An issue in the Arcadyan Livebox Fibra PRV3399B_B_LT allows a remote or local attacker to modify the GPON link value without authentication, causing …

Mitigation only
Fix from $1,600 2025-02-14
Mypro CRITICAL 9.8
CVE-2025-24865EPSS 7%

The administrative web interface of mySCADA myPRO Manager can be accessed without authentication which could allow an unauthorized attacker to ret…

Fix: 1.4+
Fix from $2,300 2025-02-13
Dt R002 Firmware CRITICAL 9.8
CVE-2025-1283

The Dingtian DT-R0 Series is vulnerable to an exploit that allows attackers to bypass login requirements by directly navigating to the main page.

Mitigation only
Fix from $2,300 2025-02-13
Orthanc CRITICAL 9.8
CVE-2025-0896

Orthanc server prior to version 1.5.8 does not enable basic authentication by default when remote access is enabled. This could result in unauthorize…

Fix: 1.5.8+
Fix from $2,300 2025-02-13
Pan Os CRITICAL 9.1
CVE-2025-0108 KEVEPSS 98%

An authentication bypass in the Palo Alto Networks PAN-OS software enables an unauthenticated attacker with network access to the management web inte…

Fix: 10.1.14 / 10.2.7+
Fix from $2,300 2025-02-12
Maxtime HIGH 7.5
CVE-2025-26364

A CWE-306 "Missing Authentication for Critical Function" in maxprofile/setup/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows…

Fix: after 2.11.0
Fix from $1,950 2025-02-12
Maxtime HIGH 7.5
CVE-2025-26365

A CWE-306 "Missing Authentication for Critical Function" in maxprofile/setup/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows…

Fix: after 2.11.0
Fix from $1,950 2025-02-12
Maxtime HIGH 7.5
CVE-2025-26366

A CWE-306 "Missing Authentication for Critical Function" in maxprofile/setup/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows…

Fix: after 2.11.0
Fix from $1,950 2025-02-12
Maxtime CRITICAL 9.8
CVE-2025-26359

A CWE-306 "Missing Authentication for Critical Function" in maxprofile/accounts/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 all…

Fix: after 2.11.0
Fix from $2,300 2025-02-12
Maxtime MEDIUM 5.3
CVE-2025-26360

A CWE-306 "Missing Authentication for Critical Function" in maxprofile/persistance/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 …

Fix: after 2.11.0
Fix from $1,600 2025-02-12