Vulnerability index

Browse CVEs

2,893 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthenticationCWE-306 × clear
Unclassified HIGH 8.5
CVE-2024-6406

Missing Authentication for Critical Function, Missing Authorization vulnerability in Yordam Information Technology Mobile Library Application allows …

Mitigation only
Fix from $1,950 2024-09-18
Pt30x Sdi Firmware CRITICAL 9.1
CVE-2024-8956 KEVEPSS 61%

PTZOptics PT30X-SDI/NDI-xx before firmware 6.3.40 is vulnerable to an insufficient authentication issue. The camera does not properly enforce authent…

Fix: 6.3.40+
Fix from $2,300 2024-09-17
Unclassified HIGH 7.5
CVE-2024-8751

A vulnerability allows a remote unauthenticated attacker to modify the prod uct’s IP address over the Sopas ET interface. This can lead to a Denial o…

Mitigation only
Fix from $1,950 2024-09-12
Woocommerce Photo Reviews CRITICAL 9.8
CVE-2024-8277

The WooCommerce Photo Reviews Premium plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1.3.13.2. Thi…

Fix: 1.3.14+
Fix from $2,300 2024-09-11
Endpoint Manager MEDIUM 5.3
CVE-2024-8320

Missing authentication in Network Isolation of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote unauthenticated attacker to s…

Fix: 2022+
Fix from $1,600 2024-09-10
Endpoint Manager HIGH 8.6
CVE-2024-8321

Missing authentication in Network Isolation of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote unauthenticated attacker to i…

Fix: 2022+
Fix from $1,950 2024-09-10
Workspace Control HIGH 7.8
CVE-2024-8012

An authentication bypass weakness in the message broker service of Ivanti Workspace Control before version 2025.2 (10.19.0.0) allows a local authenti…

Fix: 10.18.99.0+
Fix from $1,950 2024-09-10
Simatic Rf360r Firmware MEDIUM 6.5
CVE-2024-37991

A vulnerability has been identified in SIMATIC Reader RF610R CMIIT (6GT2811-6BC10-2AA0) (All versions < V4.2), SIMATIC Reader RF610R ETSI (6GT2811-6B…

Fix: 1.1 / 2.2+
Fix from $1,600 2024-09-10
Passbox CRITICAL 9.8
CVE-2024-7015

Missing Authentication for Critical Function vulnerability in Profelis Informatics and Consulting PassBox allows Authentication Abuse. This issue af…

Fix: 1.2+
Fix from $2,300 2024-09-09
Orca Hcm CRITICAL 9.8
CVE-2024-8584

Orca HCM from LEARNING DIGITAL has an Missing Authentication vulnerability, allowing unauthenticated remote attacker to exploit this functionality to…

Fix: 11.0+
Fix from $2,300 2024-09-09
Webmethods Integration HIGH 8.8
CVE-2024-45075

IBM webMethods Integration 10.15 could allow an authenticated user to create scheduler tasks that would allow them to escalate their privileges to ad…

Mitigation only
Fix from $1,950 2024-09-04
Managment Portal CRITICAL 9.8
CVE-2024-4428

Missing Authentication for Critical Function, Missing Authorization vulnerability in Menulux Information Technologies Managment Portal allows Collect…

Fix: after 21.05.2024
Fix from $2,300 2024-08-29
Hydra HIGH 7.5
CVE-2024-45049

Hydra is a Continuous Integration service for Nix based projects. It is possible to trigger evaluations in Hydra without any authentication. Dependin…

Fix: 2024-08-27+
Fix from $1,950 2024-08-27
Microscada X Sys600 CRITICAL 9.8
CVE-2024-7940

The product exposes a service that is intended for local only to all network interfaces without any authentication.

Fix: 10.6+
Fix from $2,300 2024-08-27
Ops Center Common Services HIGH 7.8
CVE-2024-7125

Authentication Bypass vulnerability in Hitachi Ops Center Common Services.This issue affects Hitachi Ops Center Common Services: from 10.9.3-00 befor…

Fix: 11.0.2-01+
Fix from $1,950 2024-08-27
Unclassified HIGH 8.6
CVE-2024-43798

Chisel is a fast TCP/UDP tunnel, transported over HTTP, secured via SSH. The Chisel server doesn't ever read the documented `AUTH` environment variab…

Mitigation only
Fix from $1,950 2024-08-26
Unclassified CRITICAL 9.8
CVE-2024-36445

Swissphone DiCal-RED 4009 devices allow a remote attacker to gain a root shell via TELNET without authentication.

Mitigation only
Fix from $2,300 2024-08-22
Openpages Grc Platform MEDIUM 6.5
CVE-2024-35151

IBM OpenPages with Watson 8.3 and 9.0 could allow authenticated users access to sensitive information through improper authorization controls on APIs.

Mitigation only
Fix from $1,600 2024-08-22
Unclassified MEDIUM 5.3
CVE-2024-43272

Missing Authentication for Critical Function vulnerability in icegram Icegram allows Accessing Functionality Not Properly Constrained by ACLs.This is…

Mitigation only
Fix from $1,600 2024-08-19
Upkeeper Manager CRITICAL 9.8
CVE-2024-42462

Improper Authentication vulnerability in upKeeper Solutions product upKeeper Manager allows Authentication Bypass.This issue affects upKeeper Manager…

Fix: 5.1.10+
Fix from $2,300 2024-08-16
Blind Spot Detection Sensor Ecu Firmware MEDIUM 6.5
CVE-2024-6347

* Unprotected privileged mode access through UDS session in the Blind Spot Detection Sensor ECU firmware in Nissan Altima (2022) allows attackers to…

Mitigation only
Fix from $1,600 2024-08-15
Mstore Api HIGH 8.1
CVE-2024-7628

The MStore API – Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to authentication bypass in versions up to, and inc…

Fix: 4.15.3+
Fix from $1,950 2024-08-15
Openbmc HIGH 7.5
CVE-2024-35124

A vulnerability in the combination of the OpenBMC's FW1050.00 through FW1050.10, FW1030.00 through FW1030.50, and FW1020.00 through FW1020.60 default…

Mitigation only
Fix from $1,950 2024-08-13
Woocommerce Social Login CRITICAL 9.8
CVE-2024-7503

The WooCommerce - Social Login plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.7.5. This is due to th…

Fix: 2.7.4+
Fix from $2,300 2024-08-12
Anythingllm CRITICAL 9.1
CVE-2024-3279

An improper access control vulnerability exists in the mintplex-labs/anything-llm application, specifically within the import endpoint. This vulnerab…

Fix: 1.0.0+
Fix from $2,300 2024-08-12
Planning Analytics Workspace CRITICAL 9.1
CVE-2024-35143

IBM Planning Analytics Local 2.0 and 2.1 connects to a MongoDB server. MongoDB, a document-oriented database system, is listening on the remote port,…

Fix: 2.0.97 / 2.1.4+
Fix from $2,300 2024-08-04
Unclassified MEDIUM 5.1
CVE-2024-3219

The “socket” module provides a pure-Python fallback to the socket.socketpair() function for platforms that don’t support AF_UNIX, such as Windows.…

Patch available
Fix from $1,600 2024-07-29
A3700r Firmware HIGH 7.5
CVE-2024-7154

A vulnerability, which was classified as problematic, was found in TOTOLINK A3700R 9.1.2u.5822_B20200513. Affected is an unknown function of the file…

No fix yet
Fix from $1,950 2024-07-28
Tra7005 Firmware CRITICAL 9.8
CVE-2024-7007

Positron Broadcast Signal Processor TRA7005 v1.20 is vulnerable to an authentication bypass exploit that could allow an attacker to have unauthorized…

Mitigation only
Fix from $2,300 2024-07-25
Openshift Container Platform MEDIUM 6.5
CVE-2024-7079

A flaw was found in the Openshift console. The /API/helm/verify endpoint is tasked to fetch and verify the installation of a Helm chart from a URI th…

Mitigation only
Fix from $1,600 2024-07-24