Vulnerability index

Browse CVEs

2,893 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthenticationCWE-306 × clear
HIGH 8.5 CVE-2024-6406 Missing Authentication for Critical Function, Missing Authorization vulnerability in Yordam Information Technology Mobile Library Application allows … Mitigation only Fix from $1,9502024-09-18 CRITICAL 9.1 CVE-2024-8956 KEVEPSS 61% PTZOptics PT30X-SDI/NDI-xx before firmware 6.3.40 is vulnerable to an insufficient authentication issue. The camera does not properly enforce authent… Pt30x Sdi Firmware 6.3.40+ Fix from $2,3002024-09-17 HIGH 7.5 CVE-2024-8751 A vulnerability allows a remote unauthenticated attacker to modify the prod uct’s IP address over the Sopas ET interface. This can lead to a Denial o… Mitigation only Fix from $1,9502024-09-12 CRITICAL 9.8 CVE-2024-8277 The WooCommerce Photo Reviews Premium plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1.3.13.2. Thi… Woocommerce Photo Reviews 1.3.14+ Fix from $2,3002024-09-11 MEDIUM 5.3 CVE-2024-8320 Missing authentication in Network Isolation of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote unauthenticated attacker to s… Endpoint Manager 2022+ Fix from $1,6002024-09-10 HIGH 8.6 CVE-2024-8321 Missing authentication in Network Isolation of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote unauthenticated attacker to i… Endpoint Manager 2022+ Fix from $1,9502024-09-10 HIGH 7.8 CVE-2024-8012 An authentication bypass weakness in the message broker service of Ivanti Workspace Control before version 2025.2 (10.19.0.0) allows a local authenti… Workspace Control 10.18.99.0+ Fix from $1,9502024-09-10 MEDIUM 6.5 CVE-2024-37991 A vulnerability has been identified in SIMATIC Reader RF610R CMIIT (6GT2811-6BC10-2AA0) (All versions < V4.2), SIMATIC Reader RF610R ETSI (6GT2811-6B… Simatic Rf360r Firmware 1.1 / 2.2+ Fix from $1,6002024-09-10 CRITICAL 9.8 CVE-2024-7015 Missing Authentication for Critical Function vulnerability in Profelis Informatics and Consulting PassBox allows Authentication Abuse. This issue af… Passbox 1.2+ Fix from $2,3002024-09-09 CRITICAL 9.8 CVE-2024-8584 Orca HCM from LEARNING DIGITAL has an Missing Authentication vulnerability, allowing unauthenticated remote attacker to exploit this functionality to… Orca Hcm 11.0+ Fix from $2,3002024-09-09 HIGH 8.8 CVE-2024-45075 IBM webMethods Integration 10.15 could allow an authenticated user to create scheduler tasks that would allow them to escalate their privileges to ad… Webmethods Integration Mitigation only Fix from $1,9502024-09-04 CRITICAL 9.8 CVE-2024-4428 Missing Authentication for Critical Function, Missing Authorization vulnerability in Menulux Information Technologies Managment Portal allows Collect… Managment Portal after 21.05.2024 Fix from $2,3002024-08-29 HIGH 7.5 CVE-2024-45049 Hydra is a Continuous Integration service for Nix based projects. It is possible to trigger evaluations in Hydra without any authentication. Dependin… Hydra 2024-08-27+ Fix from $1,9502024-08-27 CRITICAL 9.8 CVE-2024-7940 The product exposes a service that is intended for local only to all network interfaces without any authentication. Microscada X Sys600 10.6+ Fix from $2,3002024-08-27 HIGH 7.8 CVE-2024-7125 Authentication Bypass vulnerability in Hitachi Ops Center Common Services.This issue affects Hitachi Ops Center Common Services: from 10.9.3-00 befor… Ops Center Common Services 11.0.2-01+ Fix from $1,9502024-08-27 HIGH 8.6 CVE-2024-43798 Chisel is a fast TCP/UDP tunnel, transported over HTTP, secured via SSH. The Chisel server doesn't ever read the documented `AUTH` environment variab… Mitigation only Fix from $1,9502024-08-26 CRITICAL 9.8 CVE-2024-36445 Swissphone DiCal-RED 4009 devices allow a remote attacker to gain a root shell via TELNET without authentication. Mitigation only Fix from $2,3002024-08-22 MEDIUM 6.5 CVE-2024-35151 IBM OpenPages with Watson 8.3 and 9.0 could allow authenticated users access to sensitive information through improper authorization controls on APIs. Openpages Grc Platform Mitigation only Fix from $1,6002024-08-22 MEDIUM 5.3 CVE-2024-43272 Missing Authentication for Critical Function vulnerability in icegram Icegram allows Accessing Functionality Not Properly Constrained by ACLs.This is… Mitigation only Fix from $1,6002024-08-19 CRITICAL 9.8 CVE-2024-42462 Improper Authentication vulnerability in upKeeper Solutions product upKeeper Manager allows Authentication Bypass.This issue affects upKeeper Manager… Upkeeper Manager 5.1.10+ Fix from $2,3002024-08-16 MEDIUM 6.5 CVE-2024-6347 * Unprotected privileged mode access through UDS session in the Blind Spot Detection Sensor ECU firmware in Nissan Altima (2022) allows attackers to… Blind Spot Detection Sensor Ecu Firmware Mitigation only Fix from $1,6002024-08-15 HIGH 8.1 CVE-2024-7628 The MStore API – Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to authentication bypass in versions up to, and inc… Mstore Api 4.15.3+ Fix from $1,9502024-08-15 HIGH 7.5 CVE-2024-35124 A vulnerability in the combination of the OpenBMC's FW1050.00 through FW1050.10, FW1030.00 through FW1030.50, and FW1020.00 through FW1020.60 default… Openbmc Mitigation only Fix from $1,9502024-08-13 CRITICAL 9.8 CVE-2024-7503 The WooCommerce - Social Login plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.7.5. This is due to th… Woocommerce Social Login 2.7.4+ Fix from $2,3002024-08-12 CRITICAL 9.1 CVE-2024-3279 An improper access control vulnerability exists in the mintplex-labs/anything-llm application, specifically within the import endpoint. This vulnerab… Anythingllm 1.0.0+ Fix from $2,3002024-08-12 CRITICAL 9.1 CVE-2024-35143 IBM Planning Analytics Local 2.0 and 2.1 connects to a MongoDB server. MongoDB, a document-oriented database system, is listening on the remote port,… Planning Analytics Workspace 2.0.97 / 2.1.4+ Fix from $2,3002024-08-04 MEDIUM 5.1 CVE-2024-3219 The “socket” module provides a pure-Python fallback to the socket.socketpair() function for platforms that don’t support AF_UNIX, such as Windows.… Patch available Fix from $1,6002024-07-29 HIGH 7.5 CVE-2024-7154 A vulnerability, which was classified as problematic, was found in TOTOLINK A3700R 9.1.2u.5822_B20200513. Affected is an unknown function of the file… A3700r Firmware No fix yet Fix from $1,9502024-07-28 CRITICAL 9.8 CVE-2024-7007 Positron Broadcast Signal Processor TRA7005 v1.20 is vulnerable to an authentication bypass exploit that could allow an attacker to have unauthorized… Tra7005 Firmware Mitigation only Fix from $2,3002024-07-25 MEDIUM 6.5 CVE-2024-7079 A flaw was found in the Openshift console. The /API/helm/verify endpoint is tasked to fetch and verify the installation of a Helm chart from a URI th… Openshift Container Platform Mitigation only Fix from $1,6002024-07-24