Vulnerability index

Browse CVEs

2,893 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthenticationCWE-306 × clear
Cyberpanel CRITICAL 9.8
CVE-2024-51567 KEVEPSS 87%

upgrademysqlstatus in databases/views.py in CyberPanel (aka Cyber Panel) before 5b08cd6 allows remote attackers to bypass authentication and execute …

Fix: 2.3.8+
Fix from $2,300 2024-10-29
Token Login HIGH 8.8
CVE-2024-50488

Authentication Bypass Using an Alternate Path or Channel vulnerability in yespbs Token Login token-login allows Authentication Bypass.This issue affe…

Fix: after 1.0.3
Fix from $1,950 2024-10-28
Stacks Mobile App Builder CRITICAL 9.8
CVE-2024-50477EPSS 8%

Authentication Bypass Using an Alternate Path or Channel vulnerability in Stacks Stacks Mobile App Builder stacks-mobile-app-builder allows Authentic…

Fix: after 5.2.3
Fix from $2,300 2024-10-28
Flutter Api CRITICAL 9.8
CVE-2024-50486

Authentication Bypass Using an Alternate Path or Channel vulnerability in Acnoo Acnoo Flutter API acnoo-flutter-api allows Authentication Bypass.This…

Fix: after 1.0.5
Fix from $2,300 2024-10-28
Maanstore Api CRITICAL 9.8
CVE-2024-50487

Authentication Bypass Using an Alternate Path or Channel vulnerability in Acnoo MaanStore API maanstore-api allows Authentication Bypass.This issue a…

Fix: after 1.0.1
Fix from $2,300 2024-10-28
Realty Workstation CRITICAL 9.8
CVE-2024-50489

Authentication Bypass Using an Alternate Path or Channel vulnerability in realtyworkstation Realty Workstation realty-workstation allows Authenticati…

Fix: after 1.0.45
Fix from $2,300 2024-10-28
Thinmanager CRITICAL 9.8
CVE-2024-10386EPSS 19%

CVE-2024-10386 IMPACT An authentication vulnerability exists in the affected product. The vulnerability could allow a threat actor with network ac…

Fix: 11.2.10 / 12.0.8+
Fix from $2,300 2024-10-25
E Studio1058 Firmware CRITICAL 9.8
CVE-2024-47406

Sharp and Toshiba Tec MFPs improperly process HTTP authentication requests, resulting in an authentication bypass vulnerability.

Mitigation only
Fix from $2,300 2024-10-25
Unclassified MEDIUM 6.5
CVE-2024-48442

Incorrect access control in Shenzhen Tuoshi Network Communications Co.,Ltd 5G CPE Router NR500-EA RG500UEAABxCOMSLICv3.2.2543.12.18 allows attackers …

Mitigation only
Fix from $1,600 2024-10-24
Intermesh 7177 Hybrid 2.0 Subscriber CRITICAL 9.8
CVE-2024-47902

A vulnerability has been identified in InterMesh 7177 Hybrid 2.0 Subscriber (All versions < V8.2.12), InterMesh 7707 Fire Subscriber (All versions < …

Fix: 7.2.12 / 8.2.12+
Fix from $2,300 2024-10-23
Fortimanager CRITICAL 9.8
CVE-2024-47575 KEVEPSS 95%

A missing authentication for critical function in FortiManager 7.6.0, FortiManager 7.4.0 through 7.4.4, FortiManager 7.2.0 through 7.2.7, FortiManage…

Fix: 6.2.13 / 6.4.15+
Fix from $2,300 2024-10-23
Unclassified CRITICAL 9.0
CVE-2024-26519

An issue in Casa Systems NTC-221 version 2.0.99.0 and before allows a remote attacker to execute arbitrary code via a crafted payload to the /www/cgi…

Mitigation only
Fix from $2,300 2024-10-22
Safeq HIGH 7.8
CVE-2022-23862

A Local Privilege Escalation issue was discovered in Y Soft SAFEQ 6 Build 53. The SafeQ JMX service running on port 9696 is vulnerable to JMX MLet at…

No fix yet
Fix from $1,950 2024-10-22
Rover Idx HIGH 8.8
CVE-2024-10002

The Rover IDX plugin for WordPress is vulnerable to Authentication Bypass in versions up to, and including, 3.0.0.2905. This is due to insufficient v…

Fix: 3.0.0.2906+
Fix from $1,950 2024-10-22
Vilo 5 Firmware CRITICAL 9.6
CVE-2024-40087

Vilo 5 Mesh WiFi System <= 5.16.1.33 is vulnerable to Insecure Permissions. Lack of authentication in the custom TCP service on port 5432 allows remo…

Fix: after 5.16.1.33
Fix from $2,300 2024-10-21
Vilo 5 Firmware MEDIUM 5.3
CVE-2024-40091

Vilo 5 Mesh WiFi System <= 5.16.1.33 lacks authentication in the Boa webserver, which allows remote, unauthenticated attackers to retrieve logs with …

Fix: after 5.16.1.33
Fix from $1,600 2024-10-21
Micollab HIGH 8.2
CVE-2024-47912

A vulnerability in the AWV (Audio, Web, and Video) Conferencing component of Mitel MiCollab through 9.8 SP1 FP2 (9.8.1.201) could allow an unauthenti…

Fix: after 9.8.1.201
Fix from $1,950 2024-10-21
Memberhero CRITICAL 9.8
CVE-2024-49604

Authentication Bypass Using an Alternate Path or Channel vulnerability in N-Media Simple User Registration wp-registration allows Authentication Bypa…

Fix: after 5.5
Fix from $2,300 2024-10-20
Wp Rest Api Fns CRITICAL 9.8
CVE-2024-49328

Authentication Bypass Using an Alternate Path or Channel vulnerability in vivek2tamrakar WP REST API FNS rest-api-fns allows Authentication Bypass.Th…

Fix: after 1.0.0
Fix from $2,300 2024-10-20
Unclassified HIGH 8.7
CVE-2024-49399

The affected product is vulnerable to an attacker being able to use commands without providing a password which may allow an attacker to leak informa…

No fix yet
Fix from $1,950 2024-10-17
Unclassified CRITICAL 9.1
CVE-2024-48920

PutongOJ is online judging software. Prior to version 2.1.0-beta.1, unprivileged users can escalate privileges by constructing requests. This can lea…

Patch available
Fix from $2,300 2024-10-17
Otp Verification With Firebase HIGH 8.1
CVE-2024-9861

The Miniorange OTP Verification with Firebase plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.6.0. Th…

Fix: 3.6.1+
Fix from $1,950 2024-10-17
Big Ip Access Policy Manager HIGH 7.2
CVE-2024-45844EPSS 11%

BIG-IP monitor functionality may allow an attacker to bypass access control restrictions, regardless of the port lockdown settings.  Note: Software v…

Fix: 15.1.10.5 / 16.1.5+
Fix from $1,950 2024-10-16
Unclassified HIGH 8.8
CVE-2023-22650

A vulnerability has been identified in which Rancher does not automatically clean up a user which has been deleted from the configured authentication…

Mitigation only
Fix from $1,950 2024-10-16
MySQL HIGH 7.5
CVE-2024-21272

Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/Python). Supported versions that are affected are 9.0.0 and prio…

Mitigation only
Fix from $1,950 2024-10-15
F9a29a Firmware HIGH 7.5
CVE-2024-5749

Certain HP DesignJet products may be vulnerable to credential reflection which allow viewing SMTP server credentials.

Fix: 001.2419b+
Fix from $1,950 2024-10-15
Mbnet.mini Firmware CRITICAL 9.8
CVE-2024-45274

An unauthenticated remote attacker can execute OS commands via UDP on the device due to missing authentication.

Fix: 2.3.1+
Fix from $2,300 2024-10-15
Mbnet.mini Firmware HIGH 7.5
CVE-2024-45276

An unauthenticated remote attacker can get read access to files in the "/tmp" directory due to missing authentication.

Fix: 2.3.1+
Fix from $1,950 2024-10-15
Enterprise Cloud Database CRITICAL 9.8
CVE-2024-9984

Enterprise Cloud Database from Ragic does not authenticate access to specific functionality, allowing unauthenticated remote attackers to use this fu…

Fix: 2024-08-08+
Fix from $2,300 2024-10-15
Unclassified HIGH 7.5
CVE-2024-48791

An issue in Plug n Play Camera com.starvedia.mCamView.zwave 5.5.1 allows a remote attacker to obtain sensitive information via the firmware update pr…

Mitigation only
Fix from $1,950 2024-10-14