Vulnerability index

Browse CVEs

2,893 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthenticationCWE-306 × clear
Unclassified MEDIUM 6.5
CVE-2024-39601

A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V5.40), SICORE Base system (All versions < V1.4.0). Af…

Mitigation only
Fix from $1,600 2024-07-22
Dsl 225 Firmware CRITICAL 9.8
CVE-2024-38437

D-Link - CWE-288:Authentication Bypass Using an Alternate Path or Channel

No fix yet
Fix from $2,300 2024-07-21
Woocommerce Social Login HIGH 7.3
CVE-2024-6635

The WooCommerce - Social Login plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.7.3. This is due to in…

Fix: 2.7.4+
Fix from $1,950 2024-07-20
Unclassified MEDIUM 6.1
CVE-2024-6895

Insufficient authentication in user account management in Yugabyte Platform allows local network attackers with a compromised user session to change …

Patch available
Fix from $1,600 2024-07-19
Weblogic Server HIGH 7.5
CVE-2024-21183

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4…

Mitigation only
Fix from $1,950 2024-07-16
Trade Management HIGH 8.1
CVE-2024-21146

Vulnerability in the Oracle Trade Management product of Oracle E-Business Suite (component: GL Accounts). Supported versions that are affected are 1…

Fix: after 12.2.13
Fix from $1,950 2024-07-16
Unclassified MEDIUM 5.3
CVE-2024-36457

The vulnerability allows an attacker to bypass the authentication requirements for a specific PAM endpoint.

No fix yet
Fix from $1,600 2024-07-15
Expedition CRITICAL 9.8
CVE-2024-5910 KEVEPSS 92%

Missing authentication for a critical function in Palo Alto Networks Expedition can lead to an Expedition admin account takeover for attackers with n…

Fix: 1.2.92+
Fix from $2,300 2024-07-10
Oit700 F113 B12 Cb Firmware CRITICAL 9.8
CVE-2024-6422

An unauthenticated remote attacker can manipulate the device via Telnet, stop processes, read, delete and change data.

Fix: after 2.11.0
Fix from $2,300 2024-07-10
14finger HIGH 7.5
CVE-2024-37767

Insecure permissions in the component /api/admin/user of 14Finger v1.1 allows attackers to access all user information via a crafted GET request.

No fix yet
Fix from $1,950 2024-07-05
Unclassified MEDIUM 5.9
CVE-2024-1573

Missing Authentication for Critical Function vulnerability in the mobile monitoring feature of Mitsubishi Electric GENESIS64 versions 10.97.2 and pri…

Mitigation only
Fix from $1,600 2024-07-04
Unclassified CRITICAL 10.0
CVE-2023-41918

A vulnerability allows unauthorized access to functionality inadequately constrained by ACLs. Attackers may exploit this to unauthenticated execute c…

Mitigation only
Fix from $2,300 2024-07-02
Openbmc HIGH 7.5
CVE-2024-31916

IBM OpenBMC FW1050.00 through FW1050.10 BMCWeb HTTPS server component could disclose sensitive URI content to an unauthorized actor that bypasses aut…

Mitigation only
Fix from $1,950 2024-06-27
Unclassified CRITICAL 9.8
CVE-2024-0949

Missing Authentication, Files or Directories Accessible to External Parties, Use of Hard-coded Credentials vulnerability in Talya Informatics Elektra…

Mitigation only
Fix from $2,300 2024-06-27
Unclassified MEDIUM 6.5
CVE-2024-33622

Missing authentication for critical function vulnerability exists in ID Link Manager and FUJITSU Software TIME CREATOR. If this vulnerability is expl…

Mitigation only
Fix from $1,600 2024-06-18
Factorytalk View HIGH 7.5
CVE-2024-37368

A user authentication vulnerability exists in the Rockwell Automation FactoryTalk® View SE. The vulnerability allows a user from a remote system with…

Fix: 14.0+
Fix from $1,950 2024-06-14
Unclassified HIGH 8.4
CVE-2024-27169

Toshiba printers provides API without authentication for internal access. A local attacker can bypass authentication in applications, providing admin…

Mitigation only
Fix from $1,950 2024-06-14
Dse855 Firmware MEDIUM 6.5
CVE-2024-5951

Deep Sea Electronics DSE855 Factory Reset Missing Authentication Denial-of-Service Vulnerability. This vulnerability allows network-adjacent attacker…

Mitigation only
Fix from $1,600 2024-06-13
Dse855 Firmware MEDIUM 6.5
CVE-2024-5952

Deep Sea Electronics DSE855 Restart Missing Authentication Denial-of-Service Vulnerability. This vulnerability allows network-adjacent attackers to b…

Mitigation only
Fix from $1,600 2024-06-13
Dse855 Firmware MEDIUM 6.5
CVE-2024-5947

Deep Sea Electronics DSE855 Configuration Backup Missing Authentication Information Disclosure Vulnerability. This vulnerability allows network-adjac…

Mitigation only
Fix from $1,600 2024-06-13
Foxman Un CRITICAL 10.0
CVE-2024-2013

An authentication bypass vulnerability exists in the FOXMAN-UN/UNEM server / API Gateway component that if exploited allows attackers without any ac…

Mitigation only
Fix from $2,300 2024-06-11
Unclassified CRITICAL 9.1
CVE-2024-32752

The iSTAR door controllers running firmware prior to version 6.6.B, does not support authenticated communications with ICU, which may allow an attack…

Mitigation only
Fix from $2,300 2024-06-06
Ds8900f Firmware MEDIUM 6.3
CVE-2024-22326

IBM System Storage DS8900F 89.22.19.0, 89.30.68.0, 89.32.40.0, 89.33.48.0, 89.40.83.0, and 89.40.93.0 could allow a remote user to create an LDAP con…

Mitigation only
Fix from $1,600 2024-06-06
Argo Cd HIGH 7.5
CVE-2024-37152

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. The vulnerability allows unauthorized access to the sensitive settings expo…

Fix: 2.9.17 / 2.10.12+
Fix from $1,950 2024-06-06
Powerbank HIGH 7.5
CVE-2024-1662

Missing Authentication for Critical Function, Missing Authorization vulnerability in PORTY Smart Tech Technology Joint Stock Company PowerBank Applic…

Fix: 2.02+
Fix from $1,950 2024-06-05
Unclassified CRITICAL 9.3
CVE-2024-4332

An authentication bypass vulnerability has been identified in the REST and SOAP API components of Tripwire Enterprise (TE) 9.1.0 when TE is configure…

Mitigation only
Fix from $2,300 2024-06-03
Unclassified CRITICAL 9.4
CVE-2024-0336

Missing Authentication for Critical Function vulnerability in EMTA Grup PDKS allows Exploiting Incorrectly Configured Access Control Security Levels.…

Mitigation only
Fix from $2,300 2024-06-03
Devicehub CRITICAL 9.8
CVE-2024-36388

MileSight DeviceHub - CWE-305 Missing Authentication for Critical Function

No fix yet
Fix from $2,300 2024-06-02
Teamcity CRITICAL 9.8
CVE-2024-36470

In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 authentication bypass was possible in specific edge cases

Fix: 2022.04.7 / 2022.10.6+
Fix from $2,300 2024-05-29
W1a78a Firmware MEDIUM 6.8
CVE-2024-5143

A user with device administrative privileges can change existing SMTP server settings on the device, without having to re-enter SMTP server credentia…

Fix: 002_2413A+
Fix from $1,600 2024-05-23