Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.4
CVE-2024-9137
The affected product lacks an authentication check when sending commands to the server via the Moxa service. This vulnerability allows an attacker to…
Mitigation only
HIGH 7.5
CVE-2024-48768
An issue in almaodo GmbH appinventor.ai_google.almando_control 2.3.1 allows a remote attacker to obtain sensitive information via the firmware update…
Mitigation only
HIGH 7.5
CVE-2024-48771
An issue in almando GmbH Almando Play APP (com.almando.play) 1.8.2 allows a remote attacker to obtain sensitive information via the firmware update p…
Mitigation only
HIGH 7.5
CVE-2024-48773
An issue in WoFit v.7.2.3 allows a remote attacker to obtain sensitive information via the firmware update process
Mitigation only
HIGH 7.5
CVE-2024-48774
An issue in Fermax Asia Pacific Pte Ltd com.fermax.vida 2.4.6 allows a remote attacker to obtain sensitve information via the firmware update process.
Mitigation only
HIGH 7.5
CVE-2024-48775
An issue in Plug n Play Camera com.ezset.delaney 1.2.0 allows a remote attacker to obtain sensitive information via the firmware update process.
Mitigation only
HIGH 7.5
CVE-2024-48776
An issue in Shelly com.home.shelly 1.0.4 allows a remote attacker to obtain sensitive information via the firmware update process
Mitigation only
HIGH 7.5
CVE-2024-48777
LEDVANCE com.ledvance.smartplus.eu 2.1.10 allows a remote attacker to obtain sensitive information via the firmware update process.
Mitigation only
MEDIUM 5.9
CVE-2024-8530
CWE-306: Missing Authentication for Critical Function vulnerability exists that could
cause exposure of private data when an already generated “logca…
Mitigation only
HIGH 8.8
CVE-2024-9164
An issue was discovered in GitLab EE affecting all versions starting from 12.5 prior to 17.2.9, starting from 17.3, prior to 17.3.5, and starting fro…
GitLab
17.2.9 / 17.3.5+
HIGH 8.8
CVE-2024-9522
The WP Users Masquerade plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.0.0. This is due to incorrect…
Wp Users Masquerade
after 2.0.0
CRITICAL 9.8
CVE-2024-43488
Missing authentication for critical function in Visual Studio Code extension for Arduino allows an unauthenticated attacker to perform remote code ex…
Visual Studio Code
Patch available
CRITICAL 9.8
CVE-2024-8943
The LatePoint plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 5.0.12. This is due to insufficient veri…
Latepoint
5.0.13+
HIGH 8.3
CVE-2024-47555
Missing Authentication - User & System Configuration
No fix yet
CRITICAL 9.3
CVE-2024-41988
TEM Opera Plus FM Family Transmitter allows access to an unprotected endpoint that allows MPFS File System binary image upload without authentication…
Mitigation only
MEDIUM 6.5
CVE-2024-35294
An unauthenticated remote attacker may use the devices traffic capture without authentication to grab plaintext administrative credentials.
Mitigation only
CRITICAL 9.1
CVE-2024-35293
An unauthenticated remote attacker may use a missing authentication for critical function vulnerability to reboot or erase the affected devices resul…
Mitigation only
CRITICAL 9.8
CVE-2024-9289
The WordPress & WooCommerce Affiliate Program plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 8.4.1…
Affiliate Pro
8.5.0+
CRITICAL 10.0
CVE-2024-42017
An issue was discovered in Atos Eviden iCare 2.7.1 through 2.7.11. The application exposes a web interface locally. In the worst-case scenario, if th…
Mitigation only
CRITICAL 9.8
CVE-2024-46293
Sourcecodester Online Medicine Ordering System 1.0 is vulnerable to Incorrect Access Control. There is a lack of authorization checks for admin opera…
Online Medicine Ordering System
Mitigation only
CRITICAL 9.8
CVE-2024-8456
Certain switch models from PLANET Technology lack proper access control in firmware upload and download functionality, allowing unauthenticated remot…
Gs 4210 24p2s Firmware
2.305b240719 / 3.305b240802+
MEDIUM 6.3
CVE-2024-39364
Advantech ADAM-5630
has built-in commands that can be executed without authenticating the
user. These commands allow for restarting the operating s…
Mitigation only
CRITICAL 9.8
CVE-2024-6981
OMNTEC Proteus Tank Monitoring OEL8000III Series
could allow an attacker to perform administrative actions without proper authentication.
Mitigation only
CRITICAL 9.8
CVE-2024-8310
OPW Fuel Management Systems SiteSentinel
could allow an attacker to bypass authentication to the server and obtain full admin privileges.
Mitigation only
MEDIUM 6.5
CVE-2024-47130
The goTenna Pro App allows unauthenticated attackers to remotely update
the local public keys used for P2P and group messages. It is advised to
upd…
Gotenna Pro
2.0.3+
CRITICAL 9.8
CVE-2024-7781
The Jupiter X Core plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 4.7.5. This is due to improper a…
Jupiter X Core
4.7.8+
MEDIUM 5.5
CVE-2023-52949
Missing authentication for critical function vulnerability in proxy settings functionality in Synology Active Backup for Business Agent before 2.7.0-…
Active Backup For Business Agent
2.7.0-3221+
CRITICAL 9.1
CVE-2024-6592
An incorrect authorization vulnerability in the protocol communication between the WatchGuard Authentication Gateway (aka Single Sign-On Agent) on Wi…
Authentication Gateway
after 12.10.2
MEDIUM 6.6
CVE-2024-45229
The Versa Director offers REST APIs for orchestration and management. By design, certain APIs, such as the login screen, banner display, and device r…
Mitigation only
HIGH 7.5
CVE-2022-25770
Mautic allows you to update the application via an upgrade script.
The upgrade logic isn't shielded off correctly, which may lead to vulnerable situ…
Mautic
4.4.13 / 5.1.1+