Vulnerability index

Browse CVEs

2,893 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthenticationCWE-306 × clear
Unclassified CRITICAL 9.8
CVE-2024-47138

The administrative interface listens by default on all interfaces on a TCP port and does not require authentication when being accessed.

Mitigation only
Fix from $2,300 2024-11-22
Unified Secops Platform HIGH 8.1
CVE-2024-5718

Logsign Unified SecOps Platform Missing Authentication Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arb…

Fix: 6.4.8+
Fix from $1,950 2024-11-22
Unified Secops Platform HIGH 8.1
CVE-2024-5721EPSS 6%

Logsign Unified SecOps Platform Missing Authentication Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arb…

Fix: 6.4.8+
Fix from $1,950 2024-11-22
Notes Station 3 CRITICAL 9.8
CVE-2024-38643

A missing authentication for critical function vulnerability has been reported to affect Notes Station 3. If exploited, the vulnerability could allow…

Fix: 3.9.7+
Fix from $2,300 2024-11-22
Gocast CRITICAL 9.8
CVE-2024-21855

A lack of authentication vulnerability exists in the HTTP API functionality of GoCast 1.1.3. A specially crafted HTTP request can lead to arbitrary c…

Mitigation only
Fix from $2,300 2024-11-21
Unclassified HIGH 8.8
CVE-2024-52437

Missing Authentication for Critical Function vulnerability in Saul Morales Pacheco Banner System banner-system allows Privilege Escalation.This issue…

Mitigation only
Fix from $1,950 2024-11-20
Unclassified HIGH 8.8
CVE-2024-52438

Missing Authentication for Critical Function vulnerability in deco.agency de:branding debranding allows Privilege Escalation.This issue affects de:br…

Mitigation only
Fix from $1,950 2024-11-20
Unclassified MEDIUM 5.3
CVE-2024-47865

Missing authentication for critical function vulnerability exists in Rakuten Turbo 5G firmware version V1.3.18 and earlier. If this vulnerability is …

Mitigation only
Fix from $1,600 2024-11-20
Pan Os CRITICAL 9.8
CVE-2024-0012 KEVEPSS 100%

An authentication bypass in Palo Alto Networks PAN-OS software enables an unauthenticated attacker with network access to the management web interfac…

Mitigation only
Fix from $2,300 2024-11-18
Unclassified HIGH 8.1
CVE-2024-41967

A low privileged remote attacker may modify the boot mode configuration setup of the device, leading to modification of the firmware upgrade process …

Mitigation only
Fix from $1,950 2024-11-18
Unclassified MEDIUM 5.4
CVE-2024-41968

A low privileged remote attacker may modify the docker settings setup of the device, leading to a limited DoS.

No fix yet
Fix from $1,600 2024-11-18
Unclassified HIGH 8.8
CVE-2024-41969

A low privileged remote attacker may modify the configuration of the CODESYS V3 service through a missing authentication vulnerability which could le…

Mitigation only
Fix from $1,950 2024-11-18
Really Simple Security CRITICAL 9.8
CVE-2024-10924EPSS 82%

The Really Simple Security (Free, Pro, and Pro Multisite) plugins for WordPress are vulnerable to authentication bypass in versions 9.0.0 to 9.1.1.1.…

Fix: 9.1.2+
Fix from $2,300 2024-11-15
Unclassified CRITICAL 10.0
CVE-2024-48966

The software tools used by service personnel to test & calibrate the ventilator do not support user authentication. An attacker with access to the Se…

Mitigation only
Fix from $2,300 2024-11-14
Unclassified MEDIUM 5.3
CVE-2024-39707

Insyde IHISI function 0x49 can restore factory defaults for certain UEFI variables without further authentication by default, which could lead to a p…

Mitigation only
Fix from $1,600 2024-11-14
Thinfinity Workspace HIGH 7.3
CVE-2024-40408

Cybele Software Thinfinity Workspace before v7.0.2.113 was discovered to contain an access control issue in the Create Profile section. This vulnerab…

Fix: 7.0.2.113+
Fix from $1,950 2024-11-13
Thinfinity Workspace CRITICAL 9.8
CVE-2024-40404

Cybele Software Thinfinity Workspace before v7.0.2.113 was discovered to contain an access control issue in the API endpoint where Web Sockets connec…

Fix: 7.0.2.113+
Fix from $2,300 2024-11-13
Thinfinity Workspace HIGH 8.1
CVE-2024-40405

Incorrect access control in Cybele Software Thinfinity Workspace before v7.0.3.109 allows attackers to gain access to a secondary broker via a crafte…

Fix: 7.0.3.109+
Fix from $1,950 2024-11-13
Forticlient HIGH 7.8
CVE-2024-47574

A authentication bypass using an alternate path or channel in Fortinet FortiClientWindows version 7.4.0, versions 7.2.4 through 7.2.0, versions 7.0.1…

Fix: 7.0.13 / 7.2.5+
Fix from $1,950 2024-11-13
Fabric Operating System HIGH 7.1
CVE-2024-7516

A vulnerability in Brocade Fabric OS versions before 9.2.2 could allow man-in-the-middle attackers to conduct remote Service Session Hijacking that m…

Fix: 9.2.2+
Fix from $1,950 2024-11-12
Fortios CRITICAL 9.8
CVE-2024-26011

A missing authentication for critical function in Fortinet FortiManager version 7.4.0 through 7.4.2, 7.2.0 through 7.2.4, 7.0.0 through 7.0.11, 6.4.0…

Fix: 1.3.0 / 6.0.15+
Fix from $2,300 2024-11-12
Unclassified CRITICAL 9.3
CVE-2024-8074

Missing Authentication for Critical Function, Missing Authorization vulnerability in Nomysoft Informatics Nomysem allows Collect Data as Provided by …

Mitigation only
Fix from $2,300 2024-11-12
Ce21 Suite CRITICAL 9.8
CVE-2024-10284

The CE21 Suite plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.2.0. This is due to hardcoded encrypti…

Fix: 2.2.1+
Fix from $2,300 2024-11-09
Unclassified HIGH 7.5
CVE-2024-50589

An unauthenticated attacker with access to the local network of the medical office can query an unprotected Fast Healthcare Interoperability Resour…

Mitigation only
Fix from $1,950 2024-11-08
Siem HIGH 7.5
CVE-2024-48950

An issue was discovered in Logpoint before 7.5.0. An endpoint used by Distributed Logpoint Setup was exposed, allowing unauthenticated attackers to b…

Fix: 7.5.0+
Fix from $1,950 2024-11-07
Soar MEDIUM 6.4
CVE-2024-48952

An issue was discovered in Logpoint before 7.5.0. SOAR uses a static JWT secret key to generate tokens that allow access to SOAR API endpoints withou…

Fix: 7.5.0+
Fix from $1,600 2024-11-07
Siem HIGH 7.5
CVE-2024-48953

An issue was discovered in Logpoint before 7.5.0. Endpoints for creating, editing, or deleting third-party authentication modules lacked proper autho…

Fix: 7.5.0+
Fix from $1,950 2024-11-07
Octoprint MEDIUM 6.5
CVE-2024-51493

OctoPrint provides a web interface for controlling consumer 3D printers. OctoPrint versions up until and including 1.10.2 contain a vulnerability tha…

Fix: 1.10.3+
Fix from $1,600 2024-11-05
Unclassified MEDIUM 6.5
CVE-2024-51362

The LSC Smart Connect Indoor IP Camera V7.6.32 is vulnerable to an information disclosure issue where live camera footage can be accessed through the…

Mitigation only
Fix from $1,600 2024-11-05
Unclassified MEDIUM 5.3
CVE-2024-9430

The Get Quote For Woocommerce – Request A Quote For Woocommerce plugin for WordPress is vulnerable to unauthorized access of Quote data due to a miss…

Mitigation only
Fix from $1,600 2024-10-31