Top technology
Linux 13140
Google 12530
Microsoft 12379
Oracle 6737
Apple 6692
Adobe 6387
Ibm 6330
Cisco 5757
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.5
CVE-2024-50630EPSS 23%
Missing authentication for critical function vulnerability in the webapi component in Synology Drive Server before 3.0.4-12699, 3.2.1-23280, 3.5.0-26…
Drive Server
3.0.4-12699 / 3.2.1-23280+
HIGH 7.5
CVE-2025-30111
On IROAD v9 devices, one can Remotely Dump Video Footage and the Live Video Stream. The dashcam exposes endpoints that allow unauthorized users, who …
Mitigation only
CRITICAL 9.1
CVE-2024-23943
An unauthenticated remote attacker can gain access to the cloud API due to a lack of authentication for a critical function in the affected devices. …
Mitigation only
MEDIUM 5.3
CVE-2025-2344
A vulnerability, which was classified as critical, has been found in IROAD Dash Cam X5 and Dash Cam X6 up to 20250308. Affected by this issue is some…
Mitigation only
MEDIUM 5.9
CVE-2024-13771
The Civi - Job Board & Freelance Marketplace WordPress Theme plugin for WordPress is vulnerable to authentication bypass in all versions up to, and i…
Civi
after 2.1.4
MEDIUM 5.9
CVE-2024-13772
The Civi - Job Board & Freelance Marketplace WordPress Theme plugin for WordPress is vulnerable to authentication bypass in all versions up to, and i…
Civi
after 2.1.4
MEDIUM 5.3
CVE-2024-52285
A vulnerability has been identified in SiPass integrated AC5102 (ACC-G2) (All versions < V6.4.8), SiPass integrated ACC-AP (All versions < V6.4.8). A…
Mitigation only
MEDIUM 5.3
CVE-2025-23194
SAP NetWeaver Enterprise Portal OBN does not perform proper authentication check for a particular configuration setting. As result, a non-authenticat…
Mitigation only
HIGH 8.3
CVE-2025-27256
Missing Authentication for Critical Function vulnerability in GE Vernova Enervista UR Setup application allows Authentication Bypass due to a missing…
Mitigation only
CRITICAL 9.8
CVE-2025-1315
The InWave Jobs plugin for WordPress is vulnerable to privilege escalation via password reset in all versions up to, and including, 3.5.1. This is du…
Injob
after 3.5.1
HIGH 8.8
CVE-2024-9658
The School Management System for Wordpress plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and…
School Management System
after 93.0.0
HIGH 7.2
CVE-2024-31525
Peppermint Ticket Management 0.4.6 is vulnerable to Incorrect Access Control. A regular registered user is able to elevate his privileges to admin an…
Mitigation only
CRITICAL 9.8
CVE-2025-27647
Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.913 Application 20.0.2253 allows Addition of Partial Admin Users Without Auth…
Vasion Print
20.0.2253 / 22.0.913+
CRITICAL 9.8
CVE-2025-27642
Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.933 Application 20.0.2368 allows Unauthenticated Driver Package Editing V-202…
Vasion Print
20.0.2368 / 22.0.933+
CRITICAL 9.8
CVE-2025-24924
Certain functionality within GMOD Apollo does not require authentication when passed with an administrative username
Mitigation only
CRITICAL 9.1
CVE-2025-0159
IBM FlashSystem (IBM Storage Virtualize (8.5.0.0 through 8.5.0.13, 8.5.1.0, 8.5.2.0 through 8.5.2.3, 8.5.3.0 through 8.5.3.1, 8.5.4.0, 8.6.0.0 throug…
Storage Virtualize
8.5.0.14 / 8.6.0.6+
HIGH 8.1
CVE-2025-1717
The Login Me Now plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.7.2. This is due to insecure authent…
Login Me Now
after 1.7.2
CRITICAL 9.8
CVE-2025-21355
Missing Authentication for Critical Function in Microsoft Bing allows an unauthorized attacker to execute code over a network
Bing
Patch available
MEDIUM 5.0
CVE-2024-57055
Server-Side Access Control Bypass vulnerability in WombatDialer before 25.02 could allow unauthorized users to potentially call certain services with…
Mitigation only
HIGH 7.5
CVE-2025-25224
The LuxCal Web Calendar prior to 5.3.3M (MySQL version) and prior to 5.3.3L (SQLite version) contains a missing authentication vulnerability in dload…
Luxcal Web Calendar
5.3.3l / 5.3.3m+
MEDIUM 6.5
CVE-2024-57725EPSS 6%
An issue in the Arcadyan Livebox Fibra PRV3399B_B_LT allows a remote or local attacker to modify the GPON link value without authentication, causing …
Mitigation only
CRITICAL 9.8
CVE-2025-24865EPSS 7%
The administrative web interface of
mySCADA myPRO Manager
can be accessed without authentication
which could allow an unauthorized attacker to ret…
Mypro
1.4+
CRITICAL 9.8
CVE-2025-1283
The Dingtian DT-R0 Series is vulnerable to an exploit that allows
attackers to bypass login requirements by directly navigating to the
main page.
Dt R002 Firmware
Mitigation only
CRITICAL 9.8
CVE-2025-0896
Orthanc server prior to version 1.5.8 does not enable basic authentication by default when remote access is enabled. This could result in unauthorize…
Orthanc
1.5.8+
CRITICAL 9.1
CVE-2025-0108 KEVEPSS 98%
An authentication bypass in the Palo Alto Networks PAN-OS software enables an unauthenticated attacker with network access to the management web inte…
Pan Os
10.1.14 / 10.2.7+
HIGH 7.5
CVE-2025-26364
A CWE-306 "Missing Authentication for Critical Function" in maxprofile/setup/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows…
Maxtime
after 2.11.0
HIGH 7.5
CVE-2025-26365
A CWE-306 "Missing Authentication for Critical Function" in maxprofile/setup/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows…
Maxtime
after 2.11.0
HIGH 7.5
CVE-2025-26366
A CWE-306 "Missing Authentication for Critical Function" in maxprofile/setup/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows…
Maxtime
after 2.11.0
CRITICAL 9.8
CVE-2025-26359
A CWE-306 "Missing Authentication for Critical Function" in maxprofile/accounts/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 all…
Maxtime
after 2.11.0
MEDIUM 5.3
CVE-2025-26360
A CWE-306 "Missing Authentication for Critical Function" in maxprofile/persistance/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 …
Maxtime
after 2.11.0