Vulnerability index

Browse CVEs

2,893 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthenticationCWE-306 × clear
MEDIUM 6.5 CVE-2024-39601 A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V5.40), SICORE Base system (All versions < V1.4.0). Af… Mitigation only Fix from $1,6002024-07-22 CRITICAL 9.8 CVE-2024-38437 D-Link - CWE-288:Authentication Bypass Using an Alternate Path or Channel Dsl 225 Firmware No fix yet Fix from $2,3002024-07-21 HIGH 7.3 CVE-2024-6635 The WooCommerce - Social Login plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.7.3. This is due to in… Woocommerce Social Login 2.7.4+ Fix from $1,9502024-07-20 MEDIUM 6.1 CVE-2024-6895 Insufficient authentication in user account management in Yugabyte Platform allows local network attackers with a compromised user session to change … Patch available Fix from $1,6002024-07-19 HIGH 7.5 CVE-2024-21183 Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4… Weblogic Server Mitigation only Fix from $1,9502024-07-16 HIGH 8.1 CVE-2024-21146 Vulnerability in the Oracle Trade Management product of Oracle E-Business Suite (component: GL Accounts). Supported versions that are affected are 1… Trade Management after 12.2.13 Fix from $1,9502024-07-16 MEDIUM 5.3 CVE-2024-36457 The vulnerability allows an attacker to bypass the authentication requirements for a specific PAM endpoint. No fix yet Fix from $1,6002024-07-15 CRITICAL 9.8 CVE-2024-5910 KEVEPSS 92% Missing authentication for a critical function in Palo Alto Networks Expedition can lead to an Expedition admin account takeover for attackers with n… Expedition 1.2.92+ Fix from $2,3002024-07-10 CRITICAL 9.8 CVE-2024-6422 An unauthenticated remote attacker can manipulate the device via Telnet, stop processes, read, delete and change data. Oit700 F113 B12 Cb Firmware after 2.11.0 Fix from $2,3002024-07-10 HIGH 7.5 CVE-2024-37767 Insecure permissions in the component /api/admin/user of 14Finger v1.1 allows attackers to access all user information via a crafted GET request. 14finger No fix yet Fix from $1,9502024-07-05 MEDIUM 5.9 CVE-2024-1573 Missing Authentication for Critical Function vulnerability in the mobile monitoring feature of Mitsubishi Electric GENESIS64 versions 10.97.2 and pri… Mitigation only Fix from $1,6002024-07-04 CRITICAL 10.0 CVE-2023-41918 A vulnerability allows unauthorized access to functionality inadequately constrained by ACLs. Attackers may exploit this to unauthenticated execute c… Mitigation only Fix from $2,3002024-07-02 HIGH 7.5 CVE-2024-31916 IBM OpenBMC FW1050.00 through FW1050.10 BMCWeb HTTPS server component could disclose sensitive URI content to an unauthorized actor that bypasses aut… Openbmc Mitigation only Fix from $1,9502024-06-27 CRITICAL 9.8 CVE-2024-0949 Missing Authentication, Files or Directories Accessible to External Parties, Use of Hard-coded Credentials vulnerability in Talya Informatics Elektra… Mitigation only Fix from $2,3002024-06-27 MEDIUM 6.5 CVE-2024-33622 Missing authentication for critical function vulnerability exists in ID Link Manager and FUJITSU Software TIME CREATOR. If this vulnerability is expl… Mitigation only Fix from $1,6002024-06-18 HIGH 7.5 CVE-2024-37368 A user authentication vulnerability exists in the Rockwell Automation FactoryTalk® View SE. The vulnerability allows a user from a remote system with… Factorytalk View 14.0+ Fix from $1,9502024-06-14 HIGH 8.4 CVE-2024-27169 Toshiba printers provides API without authentication for internal access. A local attacker can bypass authentication in applications, providing admin… Mitigation only Fix from $1,9502024-06-14 MEDIUM 6.5 CVE-2024-5951 Deep Sea Electronics DSE855 Factory Reset Missing Authentication Denial-of-Service Vulnerability. This vulnerability allows network-adjacent attacker… Dse855 Firmware Mitigation only Fix from $1,6002024-06-13 MEDIUM 6.5 CVE-2024-5952 Deep Sea Electronics DSE855 Restart Missing Authentication Denial-of-Service Vulnerability. This vulnerability allows network-adjacent attackers to b… Dse855 Firmware Mitigation only Fix from $1,6002024-06-13 MEDIUM 6.5 CVE-2024-5947 Deep Sea Electronics DSE855 Configuration Backup Missing Authentication Information Disclosure Vulnerability. This vulnerability allows network-adjac… Dse855 Firmware Mitigation only Fix from $1,6002024-06-13 CRITICAL 10.0 CVE-2024-2013 An authentication bypass vulnerability exists in the FOXMAN-UN/UNEM server / API Gateway component that if exploited allows attackers without any ac… Foxman Un Mitigation only Fix from $2,3002024-06-11 CRITICAL 9.1 CVE-2024-32752 The iSTAR door controllers running firmware prior to version 6.6.B, does not support authenticated communications with ICU, which may allow an attack… Mitigation only Fix from $2,3002024-06-06 MEDIUM 6.3 CVE-2024-22326 IBM System Storage DS8900F 89.22.19.0, 89.30.68.0, 89.32.40.0, 89.33.48.0, 89.40.83.0, and 89.40.93.0 could allow a remote user to create an LDAP con… Ds8900f Firmware Mitigation only Fix from $1,6002024-06-06 HIGH 7.5 CVE-2024-37152 Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. The vulnerability allows unauthorized access to the sensitive settings expo… Argo Cd 2.9.17 / 2.10.12+ Fix from $1,9502024-06-06 HIGH 7.5 CVE-2024-1662 Missing Authentication for Critical Function, Missing Authorization vulnerability in PORTY Smart Tech Technology Joint Stock Company PowerBank Applic… Powerbank 2.02+ Fix from $1,9502024-06-05 CRITICAL 9.3 CVE-2024-4332 An authentication bypass vulnerability has been identified in the REST and SOAP API components of Tripwire Enterprise (TE) 9.1.0 when TE is configure… Mitigation only Fix from $2,3002024-06-03 CRITICAL 9.4 CVE-2024-0336 Missing Authentication for Critical Function vulnerability in EMTA Grup PDKS allows Exploiting Incorrectly Configured Access Control Security Levels.… Mitigation only Fix from $2,3002024-06-03 CRITICAL 9.8 CVE-2024-36388 MileSight DeviceHub - CWE-305 Missing Authentication for Critical Function Devicehub No fix yet Fix from $2,3002024-06-02 CRITICAL 9.8 CVE-2024-36470 In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 authentication bypass was possible in specific edge cases Teamcity 2022.04.7 / 2022.10.6+ Fix from $2,3002024-05-29 MEDIUM 6.8 CVE-2024-5143 A user with device administrative privileges can change existing SMTP server settings on the device, without having to re-enter SMTP server credentia… W1a78a Firmware 002_2413A+ Fix from $1,6002024-05-23