Vulnerability index

Browse CVEs

2,893 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthenticationCWE-306 × clear
HIGH 7.5 CVE-2024-13185 The MinigameCenter module has insufficient restrictions on loading URLs, which may lead to some information leakage. No fix yet Fix from $1,9502025-01-08 HIGH 7.5 CVE-2024-13186 The MinigameCenter module has insufficient restrictions on loading URLs, which may lead to some information leakage. Mitigation only Fix from $1,9502025-01-08 HIGH 7.5 CVE-2024-13173 The health module has insufficient restrictions on loading URLs, which may lead to some information leakage. Mitigation only Fix from $1,9502025-01-08 HIGH 7.5 CVE-2025-21623 ClipBucket V5 provides open source video hosting with PHP. Prior to 5.5.1 - 238, ClipBucket V5 allows unauthenticated attackers to change the templat… Clipbucket 5.5.1-238+ Fix from $1,9502025-01-07 HIGH 7.5 CVE-2024-12106EPSS 10% In WhatsUp Gold versions released before 2024.0.2, an unauthenticated attacker can configure LDAP settings. Whatsup Gold 24.0.2+ Fix from $1,9502024-12-31 CRITICAL 10.0 CVE-2024-56799 Simofa is a tool to help automate static website building and deployment. Prior to version 0.2.7, due to a design mistake in the RouteLoader class, s… Patch available Fix from $2,3002024-12-30 MEDIUM 6.8 CVE-2024-7726 There exists an unauthenticated accessible JTAG port on the Kioxia PM6, PM7 and CM6 devices - On the Kioxia CM6, PM6 and PM7 disk drives it was disco… Cm6 Firmware No fix yet Fix from $1,6002024-12-20 CRITICAL 9.8 CVE-2024-54983 An issue in Quectel BC95-CNV V100R001C00SPC051 allows attackers to bypass authentication via a crafted NAS message. Mitigation only Fix from $2,3002024-12-19 CRITICAL 9.8 CVE-2024-54984 An issue in Quectel BG96 BG96MAR02A08M1G allows attackers to bypass authentication via a crafted NAS message. NOTE: this is disputed by the supplier. Mitigation only Fix from $2,3002024-12-19 CRITICAL 9.3 CVE-2024-12371 A device takeover vulnerability exists in the Rockwell Automation Power Monitor 1000. This vulnerability allows configuration of a new Policyholder u… Mitigation only Fix from $2,3002024-12-18 HIGH 7.9 CVE-2021-26280 Locally installed application can bypass the permission check and perform system operations that require permission. No fix yet Fix from $1,9502024-12-17 MEDIUM 6.3 CVE-2021-26278 The wifi module exposes the interface and has improper permission control, leaking sensitive information about the device. No fix yet Fix from $1,6002024-12-17 MEDIUM 6.4 CVE-2020-12484 When using special mode to connect to enterprise wifi, certain options are not properly configured and attackers can pretend to be enterprise wifi th… Mitigation only Fix from $1,6002024-12-17 CRITICAL 9.4 CVE-2024-10205 Authentication Bypass vulnerability in Hitachi Ops Center Analyzer on Linux, 64 bit (Hitachi Ops Center Analyzer detail view component), Hitachi Infr… Mitigation only Fix from $2,3002024-12-17 CRITICAL 9.8 CVE-2024-11639 An authentication bypass in the admin web console of Ivanti CSA before 5.0.3 allows a remote unauthenticated attacker to gain administrative access Cloud Services Appliance 5.0.3+ Fix from $2,3002024-12-10 HIGH 7.3 CVE-2024-10774 Unauthenticated CROWN APIs allow access to critical functions. This leads to the accessibility of large parts of the web application without authenti… Mitigation only Fix from $1,9502024-12-06 HIGH 8.2 CVE-2024-10776 Lua apps can be deployed, removed, started, reloaded or stopped without authorization via AppManager. This allows an attacker to remove legitimate ap… Mitigation only Fix from $1,9502024-12-06 MEDIUM 5.3 CVE-2024-54155 In JetBrains YouTrack before 2024.3.51866 improper access control allowed listing of project names during app import without authentication Youtrack 2024.3.51866+ Fix from $1,6002024-12-04 MEDIUM 6.5 CVE-2024-54153 In JetBrains YouTrack before 2024.3.51866 unauthenticated database backup download was possible via vulnerable query parameter Youtrack 2024.3.51866+ Fix from $1,6002024-12-04 HIGH 8.8 CVE-2024-42456 A vulnerability in Veeam Backup & Replication platform allows a low-privileged user with a specific role to exploit a method that updates critical co… Veeam Backup \& Replication 12.3.0.310+ Fix from $1,9502024-12-04 HIGH 8.8 CVE-2024-40717 A vulnerability in Veeam Backup & Replication allows a low-privileged user with certain roles to perform remote code execution (RCE) by updating exis… Veeam Backup \& Replication 12.3.0.310+ Fix from $1,9502024-12-04 HIGH 8.1 CVE-2024-42455EPSS 15% A vulnerability in Veeam Backup & Replication allows a low-privileged user to connect to remoting services and exploit insecure deserialization by se… Veeam Backup \& Replication 12.3.0.310+ Fix from $1,9502024-12-04 MEDIUM 5.3 CVE-2024-37303 Synapse is an open-source Matrix homeserver. Synapse before version 1.106 allows, by design, unauthenticated remote participants to trigger a downloa… Synapse 1.106.0+ Fix from $1,6002024-12-03 HIGH 8.8 CVE-2024-50381 A vulnerability exists in Snap One OVRC cloud where an attacker can impersonate a Hub device and send requests to claim and unclaim devices. The atta… Mitigation only Fix from $1,9502024-12-02 HIGH 7.5 CVE-2024-53623 Incorrect access control in the component l_0_0.xml of TP-Link ARCHER-C7 v5 allows attackers to access sensitive information. Mitigation only Fix from $1,9502024-11-29 HIGH 8.6 CVE-2024-11980 Certain modes of routers from Billion Electric have a Missing Authentication vulnerability, allowing unauthenticated remote attackers to directly acc… Mitigation only Fix from $1,9502024-11-29 CRITICAL 9.8 CVE-2024-49052 Missing authentication for critical function in Microsoft Azure PolicyWatch allows an unauthorized attacker to elevate privileges over a network. Azure Functions Mitigation only Fix from $2,3002024-11-26 CRITICAL 9.8 CVE-2024-50375 A CWE-306 "Missing Authentication for Critical Function" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G (<= … Eki 6333ac 2g Firmware 1.2.2 / 1.6.5+ Fix from $2,3002024-11-26 CRITICAL 9.8 CVE-2024-11680 KEVEPSS 92% ProjectSend versions prior to r1720 are affected by an improper authentication vulnerability. Remote, unauthenticated attackers can exploit this flaw… Projectsend Patch available Fix from $2,3002024-11-26 MEDIUM 5.3 CVE-2024-33616 Admin authentication can be bypassed with some specific invalid credentials, which allows logging in with an administrative privilege. Sharp Corporat… Mitigation only Fix from $1,6002024-11-26