Vulnerability index

Browse CVEs

2,893 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthenticationCWE-306 × clear
Maxtime CRITICAL 9.1
CVE-2025-26361

A CWE-306 "Missing Authentication for Critical Function" in maxprofile/setup/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows…

Fix: after 2.11.0
Fix from $2,300 2025-02-12
Maxtime HIGH 7.5
CVE-2025-26362

A CWE-306 "Missing Authentication for Critical Function" in maxprofile/setup/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows…

Fix: after 2.11.0
Fix from $1,950 2025-02-12
Maxtime HIGH 7.5
CVE-2025-26363

A CWE-306 "Missing Authentication for Critical Function" in maxprofile/setup/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows…

Fix: after 2.11.0
Fix from $1,950 2025-02-12
Maxtime CRITICAL 9.8
CVE-2025-26344

A CWE-306 "Missing Authentication for Critical Function" in maxprofile/guest-mode/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 a…

Fix: after 2.11.0
Fix from $2,300 2025-02-12
Maxtime CRITICAL 9.8
CVE-2025-26345

A CWE-306 "Missing Authentication for Critical Function" in maxprofile/menu/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows …

Fix: after 2.11.0
Fix from $2,300 2025-02-12
Maxtime CRITICAL 9.8
CVE-2025-26347

A CWE-306 "Missing Authentication for Critical Function" in maxprofile/menu/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows …

Fix: after 2.11.0
Fix from $2,300 2025-02-12
Maxtime CRITICAL 9.8
CVE-2025-26339

A CWE-306 "Missing Authentication for Critical Function" in maxtime/handleRoute.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an …

Fix: after 2.11.0
Fix from $2,300 2025-02-12
Maxtime CRITICAL 9.8
CVE-2025-26341

A CWE-306 "Missing Authentication for Critical Function" in maxprofile/accounts/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 all…

Fix: after 2.11.0
Fix from $2,300 2025-02-12
Maxtime CRITICAL 9.8
CVE-2025-26342

A CWE-306 "Missing Authentication for Critical Function" in maxprofile/accounts/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 all…

Fix: after 2.11.0
Fix from $2,300 2025-02-12
Hpc Pack 2016 CRITICAL 9.0
CVE-2025-21198

Microsoft High Performance Compute (HPC) Pack Remote Code Execution Vulnerability

Fix: 6.3.8328.0 / 2016.3+
Fix from $2,300 2025-02-11
Unclassified MEDIUM 6.1
CVE-2024-10649

wandb/openui latest commit c945bb859979659add5f490a874140ad17c56a5d contains a vulnerability where unauthenticated endpoints allow file uploads and d…

Mitigation only
Fix from $1,600 2025-02-10
Devops Deploy MEDIUM 6.5
CVE-2024-54176

IBM DevOps Deploy 8.0 through 8.0.1.4, 8.1 through 8.1.0.0 and IBM UrbanCode Deploy (UCD) 7.0 through 7.0.5.25, 7.1 through 7.1.2.21, 7.2 through 7.2…

Fix: 7.0.5.26 / 7.1.2.22+
Fix from $1,600 2025-02-08
Unclassified CRITICAL 9.8
CVE-2024-36555

Built-in SMS-configuration command in Forever KidsWatch Call Me KW50 R36_YDR_A3PW_GM7S_V1.0_2019_07_15_16.19.24_cob_h and Forever KidsWatch Call Me 2…

Mitigation only
Fix from $2,300 2025-02-06
F3x36 Firmware CRITICAL 9.8
CVE-2024-9644

The Four-Faith F3x36 router using firmware v2.0.0 is vulnerable to an authentication bypass vulnerability in the administrative web server. Authenti…

Mitigation only
Fix from $2,300 2025-02-04
Unclassified HIGH 7.6
CVE-2024-12511

With address book access, SMB/FTP settings could be modified, redirecting scans and possibly capturing credentials. This requires enabled scan functi…

Mitigation only
Fix from $1,950 2025-02-03
Unclassified HIGH 8.4
CVE-2024-12957

A file handling command vulnerability in certain versions of Armoury Crate may result in arbitrary file deletion. Refer to the '01/23/2025 Security U…

Mitigation only
Fix from $1,950 2025-01-23
Adforest CRITICAL 9.8
CVE-2024-12857

The AdForest theme for WordPress is vulnerable to authentication bypass in all versions up to, and including, 5.1.8. This is due to the plugin not pr…

Fix: 5.1.9+
Fix from $2,300 2025-01-22
Mysql Server MEDIUM 5.5
CVE-2025-21559

Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.40 and prior, 8.4.3 and …

Fix: after 9.1.0
Fix from $1,600 2025-01-21
Weblogic Server CRITICAL 9.8
CVE-2025-21535

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4…

Mitigation only
Fix from $2,300 2025-01-21
Jd Edwards Enterpriseone Tools CRITICAL 9.8
CVE-2025-21524

Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Monitoring and Diagnostics SEC). Supported versions tha…

Fix: 9.2.9.0+
Fix from $2,300 2025-01-21
Jd Edwards Enterpriseone Tools HIGH 8.8
CVE-2025-21515

Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime SEC). Supported versions that are affected …

Fix: 9.2.9.0+
Fix from $1,950 2025-01-21
Hub HIGH 8.8
CVE-2025-24456

In JetBrains Hub before 2024.3.55417 privilege escalation was possible via LDAP authentication mapping

Fix: 2024.3.55417+
Fix from $1,950 2025-01-21
Unclassified HIGH 8.6
CVE-2024-12757

Nedap Librix Ecoreader is missing authentication for critical functions that could allow an unauthenticated attacker to potentially execute malici…

Mitigation only
Fix from $1,950 2025-01-17
Unclassified CRITICAL 9.8
CVE-2025-0456

The airPASS from NetVision Information has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to access the specific a…

Mitigation only
Fix from $2,300 2025-01-16
Unclassified HIGH 7.5
CVE-2025-0355

Missing Authentication for Critical Function vulnerability in NEC Corporation Aterm WG2600HS Ver.1.7.2 and earlier, WF1200CRS Ver.1.6.0 and earlier, …

Mitigation only
Fix from $1,950 2025-01-15
Wl Wn533a8 Firmware MEDIUM 5.3
CVE-2024-39773

An information disclosure vulnerability exists in the testsave.sh functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP reques…

No fix yet
Fix from $1,600 2025-01-14
Wl Wn533a8 Firmware CRITICAL 9.8
CVE-2024-39608

A firmware update vulnerability exists in the login.cgi functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead…

No fix yet
Fix from $2,300 2025-01-14
Wl Wn533a8 Firmware HIGH 8.1
CVE-2024-39273

A firmware update vulnerability exists in the fw_check.sh functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can le…

No fix yet
Fix from $1,950 2025-01-14
Fortimanager HIGH 7.5
CVE-2024-35277

A missing authentication for critical function in Fortinet FortiPortal version 6.0.0 through 6.0.15, FortiManager version 7.4.0 through 7.4.2, 7.2.0 …

Fix: 6.4.15 / 7.0.13+
Fix from $1,950 2025-01-14
Dgn1000 Firmware CRITICAL 9.8
CVE-2024-12847EPSS 30%

NETGEAR DGN1000 before 1.1.00.48 is vulnerable to an authentication bypass vulnerability. A remote and unauthenticated attacker can execute arbitrary…

Fix: 1.1.00.48+
Fix from $2,300 2025-01-10