Vulnerability index

Browse CVEs

2,893 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthenticationCWE-306 × clear
HIGH 7.5 CVE-2024-50630EPSS 23% Missing authentication for critical function vulnerability in the webapi component in Synology Drive Server before 3.0.4-12699, 3.2.1-23280, 3.5.0-26… Drive Server 3.0.4-12699 / 3.2.1-23280+ Fix from $1,9502025-03-19 HIGH 7.5 CVE-2025-30111 On IROAD v9 devices, one can Remotely Dump Video Footage and the Live Video Stream. The dashcam exposes endpoints that allow unauthorized users, who … Mitigation only Fix from $1,9502025-03-18 CRITICAL 9.1 CVE-2024-23943 An unauthenticated remote attacker can gain access to the cloud API due to a lack of authentication for a critical function in the affected devices. … Mitigation only Fix from $2,3002025-03-18 MEDIUM 5.3 CVE-2025-2344 A vulnerability, which was classified as critical, has been found in IROAD Dash Cam X5 and Dash Cam X6 up to 20250308. Affected by this issue is some… Mitigation only Fix from $1,6002025-03-16 MEDIUM 5.9 CVE-2024-13771 The Civi - Job Board & Freelance Marketplace WordPress Theme plugin for WordPress is vulnerable to authentication bypass in all versions up to, and i… Civi after 2.1.4 Fix from $1,6002025-03-14 MEDIUM 5.9 CVE-2024-13772 The Civi - Job Board & Freelance Marketplace WordPress Theme plugin for WordPress is vulnerable to authentication bypass in all versions up to, and i… Civi after 2.1.4 Fix from $1,6002025-03-14 MEDIUM 5.3 CVE-2024-52285 A vulnerability has been identified in SiPass integrated AC5102 (ACC-G2) (All versions < V6.4.8), SiPass integrated ACC-AP (All versions < V6.4.8). A… Mitigation only Fix from $1,6002025-03-11 MEDIUM 5.3 CVE-2025-23194 SAP NetWeaver Enterprise Portal OBN does not perform proper authentication check for a particular configuration setting. As result, a non-authenticat… Mitigation only Fix from $1,6002025-03-11 HIGH 8.3 CVE-2025-27256 Missing Authentication for Critical Function vulnerability in GE Vernova Enervista UR Setup application allows Authentication Bypass due to a missing… Mitigation only Fix from $1,9502025-03-10 CRITICAL 9.8 CVE-2025-1315 The InWave Jobs plugin for WordPress is vulnerable to privilege escalation via password reset in all versions up to, and including, 3.5.1. This is du… Injob after 3.5.1 Fix from $2,3002025-03-07 HIGH 8.8 CVE-2024-9658 The School Management System for Wordpress plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and… School Management System after 93.0.0 Fix from $1,9502025-03-07 HIGH 7.2 CVE-2024-31525 Peppermint Ticket Management 0.4.6 is vulnerable to Incorrect Access Control. A regular registered user is able to elevate his privileges to admin an… Mitigation only Fix from $1,9502025-03-05 CRITICAL 9.8 CVE-2025-27647 Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.913 Application 20.0.2253 allows Addition of Partial Admin Users Without Auth… Vasion Print 20.0.2253 / 22.0.913+ Fix from $2,3002025-03-05 CRITICAL 9.8 CVE-2025-27642 Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.933 Application 20.0.2368 allows Unauthenticated Driver Package Editing V-202… Vasion Print 20.0.2368 / 22.0.933+ Fix from $2,3002025-03-05 CRITICAL 9.8 CVE-2025-24924 Certain functionality within GMOD Apollo does not require authentication when passed with an administrative username Mitigation only Fix from $2,3002025-03-05 CRITICAL 9.1 CVE-2025-0159 IBM FlashSystem (IBM Storage Virtualize (8.5.0.0 through 8.5.0.13, 8.5.1.0, 8.5.2.0 through 8.5.2.3, 8.5.3.0 through 8.5.3.1, 8.5.4.0, 8.6.0.0 throug… Storage Virtualize 8.5.0.14 / 8.6.0.6+ Fix from $2,3002025-02-28 HIGH 8.1 CVE-2025-1717 The Login Me Now plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.7.2. This is due to insecure authent… Login Me Now after 1.7.2 Fix from $1,9502025-02-27 CRITICAL 9.8 CVE-2025-21355 Missing Authentication for Critical Function in Microsoft Bing allows an unauthorized attacker to execute code over a network Bing Patch available Fix from $2,3002025-02-19 MEDIUM 5.0 CVE-2024-57055 Server-Side Access Control Bypass vulnerability in WombatDialer before 25.02 could allow unauthorized users to potentially call certain services with… Mitigation only Fix from $1,6002025-02-18 HIGH 7.5 CVE-2025-25224 The LuxCal Web Calendar prior to 5.3.3M (MySQL version) and prior to 5.3.3L (SQLite version) contains a missing authentication vulnerability in dload… Luxcal Web Calendar 5.3.3l / 5.3.3m+ Fix from $1,9502025-02-18 MEDIUM 6.5 CVE-2024-57725EPSS 6% An issue in the Arcadyan Livebox Fibra PRV3399B_B_LT allows a remote or local attacker to modify the GPON link value without authentication, causing … Mitigation only Fix from $1,6002025-02-14 CRITICAL 9.8 CVE-2025-24865EPSS 7% The administrative web interface of mySCADA myPRO Manager can be accessed without authentication which could allow an unauthorized attacker to ret… Mypro 1.4+ Fix from $2,3002025-02-13 CRITICAL 9.8 CVE-2025-1283 The Dingtian DT-R0 Series is vulnerable to an exploit that allows attackers to bypass login requirements by directly navigating to the main page. Dt R002 Firmware Mitigation only Fix from $2,3002025-02-13 CRITICAL 9.8 CVE-2025-0896 Orthanc server prior to version 1.5.8 does not enable basic authentication by default when remote access is enabled. This could result in unauthorize… Orthanc 1.5.8+ Fix from $2,3002025-02-13 CRITICAL 9.1 CVE-2025-0108 KEVEPSS 98% An authentication bypass in the Palo Alto Networks PAN-OS software enables an unauthenticated attacker with network access to the management web inte… Pan Os 10.1.14 / 10.2.7+ Fix from $2,3002025-02-12 HIGH 7.5 CVE-2025-26364 A CWE-306 "Missing Authentication for Critical Function" in maxprofile/setup/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows… Maxtime after 2.11.0 Fix from $1,9502025-02-12 HIGH 7.5 CVE-2025-26365 A CWE-306 "Missing Authentication for Critical Function" in maxprofile/setup/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows… Maxtime after 2.11.0 Fix from $1,9502025-02-12 HIGH 7.5 CVE-2025-26366 A CWE-306 "Missing Authentication for Critical Function" in maxprofile/setup/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows… Maxtime after 2.11.0 Fix from $1,9502025-02-12 CRITICAL 9.8 CVE-2025-26359 A CWE-306 "Missing Authentication for Critical Function" in maxprofile/accounts/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 all… Maxtime after 2.11.0 Fix from $2,3002025-02-12 MEDIUM 5.3 CVE-2025-26360 A CWE-306 "Missing Authentication for Critical Function" in maxprofile/persistance/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 … Maxtime after 2.11.0 Fix from $1,6002025-02-12