Vulnerability index

Browse CVEs

2,893 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthenticationCWE-306 × clear
Unclassified HIGH 7.5
CVE-2024-13185

The MinigameCenter module has insufficient restrictions on loading URLs, which may lead to some information leakage.

No fix yet
Fix from $1,950 2025-01-08
Unclassified HIGH 7.5
CVE-2024-13186

The MinigameCenter module has insufficient restrictions on loading URLs, which may lead to some information leakage.

Mitigation only
Fix from $1,950 2025-01-08
Unclassified HIGH 7.5
CVE-2024-13173

The health module has insufficient restrictions on loading URLs, which may lead to some information leakage.

Mitigation only
Fix from $1,950 2025-01-08
Clipbucket HIGH 7.5
CVE-2025-21623

ClipBucket V5 provides open source video hosting with PHP. Prior to 5.5.1 - 238, ClipBucket V5 allows unauthenticated attackers to change the templat…

Fix: 5.5.1-238+
Fix from $1,950 2025-01-07
Whatsup Gold HIGH 7.5
CVE-2024-12106EPSS 10%

In WhatsUp Gold versions released before 2024.0.2, an unauthenticated attacker can configure LDAP settings.

Fix: 24.0.2+
Fix from $1,950 2024-12-31
Unclassified CRITICAL 10.0
CVE-2024-56799

Simofa is a tool to help automate static website building and deployment. Prior to version 0.2.7, due to a design mistake in the RouteLoader class, s…

Patch available
Fix from $2,300 2024-12-30
Cm6 Firmware MEDIUM 6.8
CVE-2024-7726

There exists an unauthenticated accessible JTAG port on the Kioxia PM6, PM7 and CM6 devices - On the Kioxia CM6, PM6 and PM7 disk drives it was disco…

No fix yet
Fix from $1,600 2024-12-20
Unclassified CRITICAL 9.8
CVE-2024-54983

An issue in Quectel BC95-CNV V100R001C00SPC051 allows attackers to bypass authentication via a crafted NAS message.

Mitigation only
Fix from $2,300 2024-12-19
Unclassified CRITICAL 9.8
CVE-2024-54984

An issue in Quectel BG96 BG96MAR02A08M1G allows attackers to bypass authentication via a crafted NAS message. NOTE: this is disputed by the supplier.

Mitigation only
Fix from $2,300 2024-12-19
Unclassified CRITICAL 9.3
CVE-2024-12371

A device takeover vulnerability exists in the Rockwell Automation Power Monitor 1000. This vulnerability allows configuration of a new Policyholder u…

Mitigation only
Fix from $2,300 2024-12-18
Unclassified HIGH 7.9
CVE-2021-26280

Locally installed application can bypass the permission check and perform system operations that require permission.

No fix yet
Fix from $1,950 2024-12-17
Unclassified MEDIUM 6.3
CVE-2021-26278

The wifi module exposes the interface and has improper permission control, leaking sensitive information about the device.

No fix yet
Fix from $1,600 2024-12-17
Unclassified MEDIUM 6.4
CVE-2020-12484

When using special mode to connect to enterprise wifi, certain options are not properly configured and attackers can pretend to be enterprise wifi th…

Mitigation only
Fix from $1,600 2024-12-17
Unclassified CRITICAL 9.4
CVE-2024-10205

Authentication Bypass vulnerability in Hitachi Ops Center Analyzer on Linux, 64 bit (Hitachi Ops Center Analyzer detail view component), Hitachi Infr…

Mitigation only
Fix from $2,300 2024-12-17
Cloud Services Appliance CRITICAL 9.8
CVE-2024-11639

An authentication bypass in the admin web console of Ivanti CSA before 5.0.3 allows a remote unauthenticated attacker to gain administrative access

Fix: 5.0.3+
Fix from $2,300 2024-12-10
Unclassified HIGH 7.3
CVE-2024-10774

Unauthenticated CROWN APIs allow access to critical functions. This leads to the accessibility of large parts of the web application without authenti…

Mitigation only
Fix from $1,950 2024-12-06
Unclassified HIGH 8.2
CVE-2024-10776

Lua apps can be deployed, removed, started, reloaded or stopped without authorization via AppManager. This allows an attacker to remove legitimate ap…

Mitigation only
Fix from $1,950 2024-12-06
Youtrack MEDIUM 5.3
CVE-2024-54155

In JetBrains YouTrack before 2024.3.51866 improper access control allowed listing of project names during app import without authentication

Fix: 2024.3.51866+
Fix from $1,600 2024-12-04
Youtrack MEDIUM 6.5
CVE-2024-54153

In JetBrains YouTrack before 2024.3.51866 unauthenticated database backup download was possible via vulnerable query parameter

Fix: 2024.3.51866+
Fix from $1,600 2024-12-04
Veeam Backup \& Replication HIGH 8.8
CVE-2024-42456

A vulnerability in Veeam Backup & Replication platform allows a low-privileged user with a specific role to exploit a method that updates critical co…

Fix: 12.3.0.310+
Fix from $1,950 2024-12-04
Veeam Backup \& Replication HIGH 8.8
CVE-2024-40717

A vulnerability in Veeam Backup & Replication allows a low-privileged user with certain roles to perform remote code execution (RCE) by updating exis…

Fix: 12.3.0.310+
Fix from $1,950 2024-12-04
Veeam Backup \& Replication HIGH 8.1
CVE-2024-42455EPSS 15%

A vulnerability in Veeam Backup & Replication allows a low-privileged user to connect to remoting services and exploit insecure deserialization by se…

Fix: 12.3.0.310+
Fix from $1,950 2024-12-04
Synapse MEDIUM 5.3
CVE-2024-37303

Synapse is an open-source Matrix homeserver. Synapse before version 1.106 allows, by design, unauthenticated remote participants to trigger a downloa…

Fix: 1.106.0+
Fix from $1,600 2024-12-03
Unclassified HIGH 8.8
CVE-2024-50381

A vulnerability exists in Snap One OVRC cloud where an attacker can impersonate a Hub device and send requests to claim and unclaim devices. The atta…

Mitigation only
Fix from $1,950 2024-12-02
Unclassified HIGH 7.5
CVE-2024-53623

Incorrect access control in the component l_0_0.xml of TP-Link ARCHER-C7 v5 allows attackers to access sensitive information.

Mitigation only
Fix from $1,950 2024-11-29
Unclassified HIGH 8.6
CVE-2024-11980

Certain modes of routers from Billion Electric have a Missing Authentication vulnerability, allowing unauthenticated remote attackers to directly acc…

Mitigation only
Fix from $1,950 2024-11-29
Azure Functions CRITICAL 9.8
CVE-2024-49052

Missing authentication for critical function in Microsoft Azure PolicyWatch allows an unauthorized attacker to elevate privileges over a network.

Mitigation only
Fix from $2,300 2024-11-26
Eki 6333ac 2g Firmware CRITICAL 9.8
CVE-2024-50375

A CWE-306 "Missing Authentication for Critical Function" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G (<= …

Fix: 1.2.2 / 1.6.5+
Fix from $2,300 2024-11-26
Projectsend CRITICAL 9.8
CVE-2024-11680 KEVEPSS 92%

ProjectSend versions prior to r1720 are affected by an improper authentication vulnerability. Remote, unauthenticated attackers can exploit this flaw…

Patch available
Fix from $2,300 2024-11-26
Unclassified MEDIUM 5.3
CVE-2024-33616

Admin authentication can be bypassed with some specific invalid credentials, which allows logging in with an administrative privilege. Sharp Corporat…

Mitigation only
Fix from $1,600 2024-11-26