Vulnerability index

Browse CVEs

2,893 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthenticationCWE-306 × clear
CRITICAL 9.8 CVE-2024-51567 KEVEPSS 87% upgrademysqlstatus in databases/views.py in CyberPanel (aka Cyber Panel) before 5b08cd6 allows remote attackers to bypass authentication and execute … Cyberpanel 2.3.8+ Fix from $2,3002024-10-29 HIGH 8.8 CVE-2024-50488 Authentication Bypass Using an Alternate Path or Channel vulnerability in yespbs Token Login token-login allows Authentication Bypass.This issue affe… Token Login after 1.0.3 Fix from $1,9502024-10-28 CRITICAL 9.8 CVE-2024-50477EPSS 8% Authentication Bypass Using an Alternate Path or Channel vulnerability in Stacks Stacks Mobile App Builder stacks-mobile-app-builder allows Authentic… Stacks Mobile App Builder after 5.2.3 Fix from $2,3002024-10-28 CRITICAL 9.8 CVE-2024-50486 Authentication Bypass Using an Alternate Path or Channel vulnerability in Acnoo Acnoo Flutter API acnoo-flutter-api allows Authentication Bypass.This… Flutter Api after 1.0.5 Fix from $2,3002024-10-28 CRITICAL 9.8 CVE-2024-50487 Authentication Bypass Using an Alternate Path or Channel vulnerability in Acnoo MaanStore API maanstore-api allows Authentication Bypass.This issue a… Maanstore Api after 1.0.1 Fix from $2,3002024-10-28 CRITICAL 9.8 CVE-2024-50489 Authentication Bypass Using an Alternate Path or Channel vulnerability in realtyworkstation Realty Workstation realty-workstation allows Authenticati… Realty Workstation after 1.0.45 Fix from $2,3002024-10-28 CRITICAL 9.8 CVE-2024-10386EPSS 19% CVE-2024-10386 IMPACT An authentication vulnerability exists in the affected product. The vulnerability could allow a threat actor with network ac… Thinmanager 11.2.10 / 12.0.8+ Fix from $2,3002024-10-25 CRITICAL 9.8 CVE-2024-47406 Sharp and Toshiba Tec MFPs improperly process HTTP authentication requests, resulting in an authentication bypass vulnerability. E Studio1058 Firmware Mitigation only Fix from $2,3002024-10-25 MEDIUM 6.5 CVE-2024-48442 Incorrect access control in Shenzhen Tuoshi Network Communications Co.,Ltd 5G CPE Router NR500-EA RG500UEAABxCOMSLICv3.2.2543.12.18 allows attackers … Mitigation only Fix from $1,6002024-10-24 CRITICAL 9.8 CVE-2024-47902 A vulnerability has been identified in InterMesh 7177 Hybrid 2.0 Subscriber (All versions < V8.2.12), InterMesh 7707 Fire Subscriber (All versions < … Intermesh 7177 Hybrid 2.0 Subscriber 7.2.12 / 8.2.12+ Fix from $2,3002024-10-23 CRITICAL 9.8 CVE-2024-47575 KEVEPSS 95% A missing authentication for critical function in FortiManager 7.6.0, FortiManager 7.4.0 through 7.4.4, FortiManager 7.2.0 through 7.2.7, FortiManage… Fortimanager 6.2.13 / 6.4.15+ Fix from $2,3002024-10-23 CRITICAL 9.0 CVE-2024-26519 An issue in Casa Systems NTC-221 version 2.0.99.0 and before allows a remote attacker to execute arbitrary code via a crafted payload to the /www/cgi… Mitigation only Fix from $2,3002024-10-22 HIGH 7.8 CVE-2022-23862 A Local Privilege Escalation issue was discovered in Y Soft SAFEQ 6 Build 53. The SafeQ JMX service running on port 9696 is vulnerable to JMX MLet at… Safeq No fix yet Fix from $1,9502024-10-22 HIGH 8.8 CVE-2024-10002 The Rover IDX plugin for WordPress is vulnerable to Authentication Bypass in versions up to, and including, 3.0.0.2905. This is due to insufficient v… Rover Idx 3.0.0.2906+ Fix from $1,9502024-10-22 CRITICAL 9.6 CVE-2024-40087 Vilo 5 Mesh WiFi System <= 5.16.1.33 is vulnerable to Insecure Permissions. Lack of authentication in the custom TCP service on port 5432 allows remo… Vilo 5 Firmware after 5.16.1.33 Fix from $2,3002024-10-21 MEDIUM 5.3 CVE-2024-40091 Vilo 5 Mesh WiFi System <= 5.16.1.33 lacks authentication in the Boa webserver, which allows remote, unauthenticated attackers to retrieve logs with … Vilo 5 Firmware after 5.16.1.33 Fix from $1,6002024-10-21 HIGH 8.2 CVE-2024-47912 A vulnerability in the AWV (Audio, Web, and Video) Conferencing component of Mitel MiCollab through 9.8 SP1 FP2 (9.8.1.201) could allow an unauthenti… Micollab after 9.8.1.201 Fix from $1,9502024-10-21 CRITICAL 9.8 CVE-2024-49604 Authentication Bypass Using an Alternate Path or Channel vulnerability in N-Media Simple User Registration wp-registration allows Authentication Bypa… Memberhero after 5.5 Fix from $2,3002024-10-20 CRITICAL 9.8 CVE-2024-49328 Authentication Bypass Using an Alternate Path or Channel vulnerability in vivek2tamrakar WP REST API FNS rest-api-fns allows Authentication Bypass.Th… Wp Rest Api Fns after 1.0.0 Fix from $2,3002024-10-20 HIGH 8.7 CVE-2024-49399 The affected product is vulnerable to an attacker being able to use commands without providing a password which may allow an attacker to leak informa… No fix yet Fix from $1,9502024-10-17 CRITICAL 9.1 CVE-2024-48920 PutongOJ is online judging software. Prior to version 2.1.0-beta.1, unprivileged users can escalate privileges by constructing requests. This can lea… Patch available Fix from $2,3002024-10-17 HIGH 8.1 CVE-2024-9861 The Miniorange OTP Verification with Firebase plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.6.0. Th… Otp Verification With Firebase 3.6.1+ Fix from $1,9502024-10-17 HIGH 7.2 CVE-2024-45844EPSS 11% BIG-IP monitor functionality may allow an attacker to bypass access control restrictions, regardless of the port lockdown settings.  Note: Software v… Big Ip Access Policy Manager 15.1.10.5 / 16.1.5+ Fix from $1,9502024-10-16 HIGH 8.8 CVE-2023-22650 A vulnerability has been identified in which Rancher does not automatically clean up a user which has been deleted from the configured authentication… Mitigation only Fix from $1,9502024-10-16 HIGH 7.5 CVE-2024-21272 Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/Python). Supported versions that are affected are 9.0.0 and prio… MySQL Mitigation only Fix from $1,9502024-10-15 HIGH 7.5 CVE-2024-5749 Certain HP DesignJet products may be vulnerable to credential reflection which allow viewing SMTP server credentials. F9a29a Firmware 001.2419b+ Fix from $1,9502024-10-15 CRITICAL 9.8 CVE-2024-45274 An unauthenticated remote attacker can execute OS commands via UDP on the device due to missing authentication. Mbnet.mini Firmware 2.3.1+ Fix from $2,3002024-10-15 HIGH 7.5 CVE-2024-45276 An unauthenticated remote attacker can get read access to files in the "/tmp" directory due to missing authentication. Mbnet.mini Firmware 2.3.1+ Fix from $1,9502024-10-15 CRITICAL 9.8 CVE-2024-9984 Enterprise Cloud Database from Ragic does not authenticate access to specific functionality, allowing unauthenticated remote attackers to use this fu… Enterprise Cloud Database 2024-08-08+ Fix from $2,3002024-10-15 HIGH 7.5 CVE-2024-48791 An issue in Plug n Play Camera com.starvedia.mCamView.zwave 5.5.1 allows a remote attacker to obtain sensitive information via the firmware update pr… Mitigation only Fix from $1,9502024-10-14