Vulnerability index

Browse CVEs

2,893 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthenticationCWE-306 × clear
Unclassified CRITICAL 9.4
CVE-2024-9137

The affected product lacks an authentication check when sending commands to the server via the Moxa service. This vulnerability allows an attacker to…

Mitigation only
Fix from $2,300 2024-10-14
Unclassified HIGH 7.5
CVE-2024-48768

An issue in almaodo GmbH appinventor.ai_google.almando_control 2.3.1 allows a remote attacker to obtain sensitive information via the firmware update…

Mitigation only
Fix from $1,950 2024-10-11
Unclassified HIGH 7.5
CVE-2024-48771

An issue in almando GmbH Almando Play APP (com.almando.play) 1.8.2 allows a remote attacker to obtain sensitive information via the firmware update p…

Mitigation only
Fix from $1,950 2024-10-11
Unclassified HIGH 7.5
CVE-2024-48773

An issue in WoFit v.7.2.3 allows a remote attacker to obtain sensitive information via the firmware update process

Mitigation only
Fix from $1,950 2024-10-11
Unclassified HIGH 7.5
CVE-2024-48774

An issue in Fermax Asia Pacific Pte Ltd com.fermax.vida 2.4.6 allows a remote attacker to obtain sensitve information via the firmware update process.

Mitigation only
Fix from $1,950 2024-10-11
Unclassified HIGH 7.5
CVE-2024-48775

An issue in Plug n Play Camera com.ezset.delaney 1.2.0 allows a remote attacker to obtain sensitive information via the firmware update process.

Mitigation only
Fix from $1,950 2024-10-11
Unclassified HIGH 7.5
CVE-2024-48776

An issue in Shelly com.home.shelly 1.0.4 allows a remote attacker to obtain sensitive information via the firmware update process

Mitigation only
Fix from $1,950 2024-10-11
Unclassified HIGH 7.5
CVE-2024-48777

LEDVANCE com.ledvance.smartplus.eu 2.1.10 allows a remote attacker to obtain sensitive information via the firmware update process.

Mitigation only
Fix from $1,950 2024-10-11
Unclassified MEDIUM 5.9
CVE-2024-8530

CWE-306: Missing Authentication for Critical Function vulnerability exists that could cause exposure of private data when an already generated “logca…

Mitigation only
Fix from $1,600 2024-10-11
GitLab HIGH 8.8
CVE-2024-9164

An issue was discovered in GitLab EE affecting all versions starting from 12.5 prior to 17.2.9, starting from 17.3, prior to 17.3.5, and starting fro…

Fix: 17.2.9 / 17.3.5+
Fix from $1,950 2024-10-11
Wp Users Masquerade HIGH 8.8
CVE-2024-9522

The WP Users Masquerade plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.0.0. This is due to incorrect…

Fix: after 2.0.0
Fix from $1,950 2024-10-10
Visual Studio Code CRITICAL 9.8
CVE-2024-43488

Missing authentication for critical function in Visual Studio Code extension for Arduino allows an unauthenticated attacker to perform remote code ex…

Patch available
Fix from $2,300 2024-10-08
Latepoint CRITICAL 9.8
CVE-2024-8943

The LatePoint plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 5.0.12. This is due to insufficient veri…

Fix: 5.0.13+
Fix from $2,300 2024-10-08
Unclassified HIGH 8.3
CVE-2024-47555

Missing Authentication - User & System Configuration

No fix yet
Fix from $1,950 2024-10-07
Unclassified CRITICAL 9.3
CVE-2024-41988

TEM Opera Plus FM Family Transmitter allows access to an unprotected endpoint that allows MPFS File System binary image upload without authentication…

Mitigation only
Fix from $2,300 2024-10-03
Unclassified MEDIUM 6.5
CVE-2024-35294

An unauthenticated remote attacker may use the devices traffic capture without authentication to grab plaintext administrative credentials.

Mitigation only
Fix from $1,600 2024-10-02
Unclassified CRITICAL 9.1
CVE-2024-35293

An unauthenticated remote attacker may use a missing authentication for critical function vulnerability to reboot or erase the affected devices resul…

Mitigation only
Fix from $2,300 2024-10-02
Affiliate Pro CRITICAL 9.8
CVE-2024-9289

The WordPress & WooCommerce Affiliate Program plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 8.4.1…

Fix: 8.5.0+
Fix from $2,300 2024-10-01
Unclassified CRITICAL 10.0
CVE-2024-42017

An issue was discovered in Atos Eviden iCare 2.7.1 through 2.7.11. The application exposes a web interface locally. In the worst-case scenario, if th…

Mitigation only
Fix from $2,300 2024-09-30
Online Medicine Ordering System CRITICAL 9.8
CVE-2024-46293

Sourcecodester Online Medicine Ordering System 1.0 is vulnerable to Incorrect Access Control. There is a lack of authorization checks for admin opera…

Mitigation only
Fix from $2,300 2024-09-30
Gs 4210 24p2s Firmware CRITICAL 9.8
CVE-2024-8456

Certain switch models from PLANET Technology lack proper access control in firmware upload and download functionality, allowing unauthenticated remot…

Fix: 2.305b240719 / 3.305b240802+
Fix from $2,300 2024-09-30
Unclassified MEDIUM 6.3
CVE-2024-39364

Advantech ADAM-5630 has built-in commands that can be executed without authenticating the user. These commands allow for restarting the operating s…

Mitigation only
Fix from $1,600 2024-09-27
Unclassified CRITICAL 9.8
CVE-2024-6981

OMNTEC Proteus Tank Monitoring OEL8000III Series could allow an attacker to perform administrative actions without proper authentication.

Mitigation only
Fix from $2,300 2024-09-27
Unclassified CRITICAL 9.8
CVE-2024-8310

OPW Fuel Management Systems SiteSentinel could allow an attacker to bypass authentication to the server and obtain full admin privileges.

Mitigation only
Fix from $2,300 2024-09-27
Gotenna Pro MEDIUM 6.5
CVE-2024-47130

The goTenna Pro App allows unauthenticated attackers to remotely update the local public keys used for P2P and group messages. It is advised to upd…

Fix: 2.0.3+
Fix from $1,600 2024-09-26
Jupiter X Core CRITICAL 9.8
CVE-2024-7781

The Jupiter X Core plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 4.7.5. This is due to improper a…

Fix: 4.7.8+
Fix from $2,300 2024-09-26
Active Backup For Business Agent MEDIUM 5.5
CVE-2023-52949

Missing authentication for critical function vulnerability in proxy settings functionality in Synology Active Backup for Business Agent before 2.7.0-…

Fix: 2.7.0-3221+
Fix from $1,600 2024-09-26
Authentication Gateway CRITICAL 9.1
CVE-2024-6592

An incorrect authorization vulnerability in the protocol communication between the WatchGuard Authentication Gateway (aka Single Sign-On Agent) on Wi…

Fix: after 12.10.2
Fix from $2,300 2024-09-25
Unclassified MEDIUM 6.6
CVE-2024-45229

The Versa Director offers REST APIs for orchestration and management. By design, certain APIs, such as the login screen, banner display, and device r…

Mitigation only
Fix from $1,600 2024-09-20
Mautic HIGH 7.5
CVE-2022-25770

Mautic allows you to update the application via an upgrade script. The upgrade logic isn't shielded off correctly, which may lead to vulnerable situ…

Fix: 4.4.13 / 5.1.1+
Fix from $1,950 2024-09-18