Vulnerability index

Browse CVEs

2,893 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthenticationCWE-306 × clear
CRITICAL 9.4 CVE-2024-9137 The affected product lacks an authentication check when sending commands to the server via the Moxa service. This vulnerability allows an attacker to… Mitigation only Fix from $2,3002024-10-14 HIGH 7.5 CVE-2024-48768 An issue in almaodo GmbH appinventor.ai_google.almando_control 2.3.1 allows a remote attacker to obtain sensitive information via the firmware update… Mitigation only Fix from $1,9502024-10-11 HIGH 7.5 CVE-2024-48771 An issue in almando GmbH Almando Play APP (com.almando.play) 1.8.2 allows a remote attacker to obtain sensitive information via the firmware update p… Mitigation only Fix from $1,9502024-10-11 HIGH 7.5 CVE-2024-48773 An issue in WoFit v.7.2.3 allows a remote attacker to obtain sensitive information via the firmware update process Mitigation only Fix from $1,9502024-10-11 HIGH 7.5 CVE-2024-48774 An issue in Fermax Asia Pacific Pte Ltd com.fermax.vida 2.4.6 allows a remote attacker to obtain sensitve information via the firmware update process. Mitigation only Fix from $1,9502024-10-11 HIGH 7.5 CVE-2024-48775 An issue in Plug n Play Camera com.ezset.delaney 1.2.0 allows a remote attacker to obtain sensitive information via the firmware update process. Mitigation only Fix from $1,9502024-10-11 HIGH 7.5 CVE-2024-48776 An issue in Shelly com.home.shelly 1.0.4 allows a remote attacker to obtain sensitive information via the firmware update process Mitigation only Fix from $1,9502024-10-11 HIGH 7.5 CVE-2024-48777 LEDVANCE com.ledvance.smartplus.eu 2.1.10 allows a remote attacker to obtain sensitive information via the firmware update process. Mitigation only Fix from $1,9502024-10-11 MEDIUM 5.9 CVE-2024-8530 CWE-306: Missing Authentication for Critical Function vulnerability exists that could cause exposure of private data when an already generated “logca… Mitigation only Fix from $1,6002024-10-11 HIGH 8.8 CVE-2024-9164 An issue was discovered in GitLab EE affecting all versions starting from 12.5 prior to 17.2.9, starting from 17.3, prior to 17.3.5, and starting fro… GitLab 17.2.9 / 17.3.5+ Fix from $1,9502024-10-11 HIGH 8.8 CVE-2024-9522 The WP Users Masquerade plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.0.0. This is due to incorrect… Wp Users Masquerade after 2.0.0 Fix from $1,9502024-10-10 CRITICAL 9.8 CVE-2024-43488 Missing authentication for critical function in Visual Studio Code extension for Arduino allows an unauthenticated attacker to perform remote code ex… Visual Studio Code Patch available Fix from $2,3002024-10-08 CRITICAL 9.8 CVE-2024-8943 The LatePoint plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 5.0.12. This is due to insufficient veri… Latepoint 5.0.13+ Fix from $2,3002024-10-08 HIGH 8.3 CVE-2024-47555 Missing Authentication - User & System Configuration No fix yet Fix from $1,9502024-10-07 CRITICAL 9.3 CVE-2024-41988 TEM Opera Plus FM Family Transmitter allows access to an unprotected endpoint that allows MPFS File System binary image upload without authentication… Mitigation only Fix from $2,3002024-10-03 MEDIUM 6.5 CVE-2024-35294 An unauthenticated remote attacker may use the devices traffic capture without authentication to grab plaintext administrative credentials. Mitigation only Fix from $1,6002024-10-02 CRITICAL 9.1 CVE-2024-35293 An unauthenticated remote attacker may use a missing authentication for critical function vulnerability to reboot or erase the affected devices resul… Mitigation only Fix from $2,3002024-10-02 CRITICAL 9.8 CVE-2024-9289 The WordPress & WooCommerce Affiliate Program plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 8.4.1… Affiliate Pro 8.5.0+ Fix from $2,3002024-10-01 CRITICAL 10.0 CVE-2024-42017 An issue was discovered in Atos Eviden iCare 2.7.1 through 2.7.11. The application exposes a web interface locally. In the worst-case scenario, if th… Mitigation only Fix from $2,3002024-09-30 CRITICAL 9.8 CVE-2024-46293 Sourcecodester Online Medicine Ordering System 1.0 is vulnerable to Incorrect Access Control. There is a lack of authorization checks for admin opera… Online Medicine Ordering System Mitigation only Fix from $2,3002024-09-30 CRITICAL 9.8 CVE-2024-8456 Certain switch models from PLANET Technology lack proper access control in firmware upload and download functionality, allowing unauthenticated remot… Gs 4210 24p2s Firmware 2.305b240719 / 3.305b240802+ Fix from $2,3002024-09-30 MEDIUM 6.3 CVE-2024-39364 Advantech ADAM-5630 has built-in commands that can be executed without authenticating the user. These commands allow for restarting the operating s… Mitigation only Fix from $1,6002024-09-27 CRITICAL 9.8 CVE-2024-6981 OMNTEC Proteus Tank Monitoring OEL8000III Series could allow an attacker to perform administrative actions without proper authentication. Mitigation only Fix from $2,3002024-09-27 CRITICAL 9.8 CVE-2024-8310 OPW Fuel Management Systems SiteSentinel could allow an attacker to bypass authentication to the server and obtain full admin privileges. Mitigation only Fix from $2,3002024-09-27 MEDIUM 6.5 CVE-2024-47130 The goTenna Pro App allows unauthenticated attackers to remotely update the local public keys used for P2P and group messages. It is advised to upd… Gotenna Pro 2.0.3+ Fix from $1,6002024-09-26 CRITICAL 9.8 CVE-2024-7781 The Jupiter X Core plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 4.7.5. This is due to improper a… Jupiter X Core 4.7.8+ Fix from $2,3002024-09-26 MEDIUM 5.5 CVE-2023-52949 Missing authentication for critical function vulnerability in proxy settings functionality in Synology Active Backup for Business Agent before 2.7.0-… Active Backup For Business Agent 2.7.0-3221+ Fix from $1,6002024-09-26 CRITICAL 9.1 CVE-2024-6592 An incorrect authorization vulnerability in the protocol communication between the WatchGuard Authentication Gateway (aka Single Sign-On Agent) on Wi… Authentication Gateway after 12.10.2 Fix from $2,3002024-09-25 MEDIUM 6.6 CVE-2024-45229 The Versa Director offers REST APIs for orchestration and management. By design, certain APIs, such as the login screen, banner display, and device r… Mitigation only Fix from $1,6002024-09-20 HIGH 7.5 CVE-2022-25770 Mautic allows you to update the application via an upgrade script. The upgrade logic isn't shielded off correctly, which may lead to vulnerable situ… Mautic 4.4.13 / 5.1.1+ Fix from $1,9502024-09-18