Vulnerability index

Browse CVEs

2,893 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthenticationCWE-306 × clear
CRITICAL 9.8 CVE-2024-47138 The administrative interface listens by default on all interfaces on a TCP port and does not require authentication when being accessed. Mitigation only Fix from $2,3002024-11-22 HIGH 8.1 CVE-2024-5718 Logsign Unified SecOps Platform Missing Authentication Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arb… Unified Secops Platform 6.4.8+ Fix from $1,9502024-11-22 HIGH 8.1 CVE-2024-5721EPSS 6% Logsign Unified SecOps Platform Missing Authentication Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arb… Unified Secops Platform 6.4.8+ Fix from $1,9502024-11-22 CRITICAL 9.8 CVE-2024-38643 A missing authentication for critical function vulnerability has been reported to affect Notes Station 3. If exploited, the vulnerability could allow… Notes Station 3 3.9.7+ Fix from $2,3002024-11-22 CRITICAL 9.8 CVE-2024-21855 A lack of authentication vulnerability exists in the HTTP API functionality of GoCast 1.1.3. A specially crafted HTTP request can lead to arbitrary c… Gocast Mitigation only Fix from $2,3002024-11-21 HIGH 8.8 CVE-2024-52437 Missing Authentication for Critical Function vulnerability in Saul Morales Pacheco Banner System banner-system allows Privilege Escalation.This issue… Mitigation only Fix from $1,9502024-11-20 HIGH 8.8 CVE-2024-52438 Missing Authentication for Critical Function vulnerability in deco.agency de:branding debranding allows Privilege Escalation.This issue affects de:br… Mitigation only Fix from $1,9502024-11-20 MEDIUM 5.3 CVE-2024-47865 Missing authentication for critical function vulnerability exists in Rakuten Turbo 5G firmware version V1.3.18 and earlier. If this vulnerability is … Mitigation only Fix from $1,6002024-11-20 CRITICAL 9.8 CVE-2024-0012 KEVEPSS 100% An authentication bypass in Palo Alto Networks PAN-OS software enables an unauthenticated attacker with network access to the management web interfac… Pan Os Mitigation only Fix from $2,3002024-11-18 HIGH 8.1 CVE-2024-41967 A low privileged remote attacker may modify the boot mode configuration setup of the device, leading to modification of the firmware upgrade process … Mitigation only Fix from $1,9502024-11-18 MEDIUM 5.4 CVE-2024-41968 A low privileged remote attacker may modify the docker settings setup of the device, leading to a limited DoS. No fix yet Fix from $1,6002024-11-18 HIGH 8.8 CVE-2024-41969 A low privileged remote attacker may modify the configuration of the CODESYS V3 service through a missing authentication vulnerability which could le… Mitigation only Fix from $1,9502024-11-18 CRITICAL 9.8 CVE-2024-10924EPSS 82% The Really Simple Security (Free, Pro, and Pro Multisite) plugins for WordPress are vulnerable to authentication bypass in versions 9.0.0 to 9.1.1.1.… Really Simple Security 9.1.2+ Fix from $2,3002024-11-15 CRITICAL 10.0 CVE-2024-48966 The software tools used by service personnel to test & calibrate the ventilator do not support user authentication. An attacker with access to the Se… Mitigation only Fix from $2,3002024-11-14 MEDIUM 5.3 CVE-2024-39707 Insyde IHISI function 0x49 can restore factory defaults for certain UEFI variables without further authentication by default, which could lead to a p… Mitigation only Fix from $1,6002024-11-14 HIGH 7.3 CVE-2024-40408 Cybele Software Thinfinity Workspace before v7.0.2.113 was discovered to contain an access control issue in the Create Profile section. This vulnerab… Thinfinity Workspace 7.0.2.113+ Fix from $1,9502024-11-13 CRITICAL 9.8 CVE-2024-40404 Cybele Software Thinfinity Workspace before v7.0.2.113 was discovered to contain an access control issue in the API endpoint where Web Sockets connec… Thinfinity Workspace 7.0.2.113+ Fix from $2,3002024-11-13 HIGH 8.1 CVE-2024-40405 Incorrect access control in Cybele Software Thinfinity Workspace before v7.0.3.109 allows attackers to gain access to a secondary broker via a crafte… Thinfinity Workspace 7.0.3.109+ Fix from $1,9502024-11-13 HIGH 7.8 CVE-2024-47574 A authentication bypass using an alternate path or channel in Fortinet FortiClientWindows version 7.4.0, versions 7.2.4 through 7.2.0, versions 7.0.1… Forticlient 7.0.13 / 7.2.5+ Fix from $1,9502024-11-13 HIGH 7.1 CVE-2024-7516 A vulnerability in Brocade Fabric OS versions before 9.2.2 could allow man-in-the-middle attackers to conduct remote Service Session Hijacking that m… Fabric Operating System 9.2.2+ Fix from $1,9502024-11-12 CRITICAL 9.8 CVE-2024-26011 A missing authentication for critical function in Fortinet FortiManager version 7.4.0 through 7.4.2, 7.2.0 through 7.2.4, 7.0.0 through 7.0.11, 6.4.0… Fortios 1.3.0 / 6.0.15+ Fix from $2,3002024-11-12 CRITICAL 9.3 CVE-2024-8074 Missing Authentication for Critical Function, Missing Authorization vulnerability in Nomysoft Informatics Nomysem allows Collect Data as Provided by … Mitigation only Fix from $2,3002024-11-12 CRITICAL 9.8 CVE-2024-10284 The CE21 Suite plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.2.0. This is due to hardcoded encrypti… Ce21 Suite 2.2.1+ Fix from $2,3002024-11-09 HIGH 7.5 CVE-2024-50589 An unauthenticated attacker with access to the local network of the medical office can query an unprotected Fast Healthcare Interoperability Resour… Mitigation only Fix from $1,9502024-11-08 HIGH 7.5 CVE-2024-48950 An issue was discovered in Logpoint before 7.5.0. An endpoint used by Distributed Logpoint Setup was exposed, allowing unauthenticated attackers to b… Siem 7.5.0+ Fix from $1,9502024-11-07 MEDIUM 6.4 CVE-2024-48952 An issue was discovered in Logpoint before 7.5.0. SOAR uses a static JWT secret key to generate tokens that allow access to SOAR API endpoints withou… Soar 7.5.0+ Fix from $1,6002024-11-07 HIGH 7.5 CVE-2024-48953 An issue was discovered in Logpoint before 7.5.0. Endpoints for creating, editing, or deleting third-party authentication modules lacked proper autho… Siem 7.5.0+ Fix from $1,9502024-11-07 MEDIUM 6.5 CVE-2024-51493 OctoPrint provides a web interface for controlling consumer 3D printers. OctoPrint versions up until and including 1.10.2 contain a vulnerability tha… Octoprint 1.10.3+ Fix from $1,6002024-11-05 MEDIUM 6.5 CVE-2024-51362 The LSC Smart Connect Indoor IP Camera V7.6.32 is vulnerable to an information disclosure issue where live camera footage can be accessed through the… Mitigation only Fix from $1,6002024-11-05 MEDIUM 5.3 CVE-2024-9430 The Get Quote For Woocommerce – Request A Quote For Woocommerce plugin for WordPress is vulnerable to unauthorized access of Quote data due to a miss… Mitigation only Fix from $1,6002024-10-31