All vulnerabilities
30 / 30
Sort
9.8
CVE-2024-4358CVE KEV
In Progress Telerik Report Server, version 2024 Q1 (10.0.24.305) or earlier, on IIS, an unauthe…
2024-01-01KEV
EPSS97.5%
pct 99
9.8
CVE-2022-24112CVE KEV
An attacker can abuse the batch-requests plugin to send requests to bypass the IP restriction o…
2022-01-01KEV
EPSS96.2%
pct 99
9.8
CVE-2022-23131DEB KEV
In the case of instances where the SAML SSO authentication is enabled (non-default), session da…
2022-01-01KEV
EPSS95.7%
pct 99
9.8
CVE-2021-29441CVE
Nacos is a platform designed for dynamic service discovery and configuration and service manage…
2021-01-01Pre-auth
EPSS74.8%
pct 99
9.8
CVE-2020-7388CVE
Sage X3 Unauthenticated Remote Command Execution (RCE) as SYSTEM in AdxDSrv.exe component. By e…
2020-01-01Pre-auth
EPSS70.3%
pct 99
10.0
CVE-2024-54085CVE KEV
AMI’s SPx contains
a vulnerability in the BMC where an Attacker may bypass authentication remot…
2024-01-01KEV
EPSS61.2%
pct 99
9.8
CVE-2021-34646CVE
Versions up to, and including, 5.4.3, of the Booster for WooCommerce WordPress plugin are vulne…
2021-01-01Pre-auth
EPSS50.9%
pct 98
8.2
CVE-2025-49002ANC
DataEase is an open source business intelligence and data visualization tool. Versions prior to…
2025-01-01Pre-auth
EPSS40.3%
pct 98
9.8
CVE-2018-7842CVE
A CWE-290: Authentication Bypass by Spoofing vulnerability exists in all versions of the Modico…
2018-01-01Pre-auth
EPSS35.0%
pct 98
9.8
CVE-2019-19844AST
Django before 1.11.27, 2.x before 2.2.9, and 3.x before 3.0.1 allows account takeover. A suitab…
2019-01-01Pre-auth
EPSS34.8%
pct 98
8.1
CVE-2024-41107ANC
The CloudStack SAML authentication (disabled by default) does not enforce signature check. In C…
2024-01-01Pre-auth
EPSS17.8%
pct 96
6.5
CVE-2023-50224CVE KEV
TP-Link TL-WR841N dropbearpwd Improper Authentication Information Disclosure Vulnerability. Thi…
2023-01-01KEV
EPSS17.4%
pct 96
9.8
CVE-2018-5353CVE
The custom GINA/CP module in Zoho ManageEngine ADSelfService Plus before 5.5 build 5517 allows …
2018-01-01Pre-auth
EPSS8.1%
pct 94
5.8
CVE-2013-2172DEB
jcp/xml/dsig/internal/dom/DOMCanonicalizationMethod.java in Apache Santuario XML Security for J…
2013-01-01
EPSS5.9%
pct 92
9.1
CVE-2022-39227CVE
python-jwt is a module for generating and verifying JSON Web Tokens. Versions prior to 3.3.4 ar…
2022-01-01Pre-auth
EPSS3.6%
pct 87
9.8
CVE-2023-3128DEB
Grafana is validating Azure AD accounts based on the email claim.
On Azure AD, the profile em…
2023-01-01Pre-auth
EPSS3.4%
pct 87
4.8
CVE-2025-59501CVE
Authentication bypass by spoofing in Microsoft Configuration Manager allows an authorized attac…
2025-01-01
EPSS2.7%
pct 84
8.8
CVE-2018-5354CVE
The custom GINA/CP module in ANIXIS Password Reset Client before version 3.22 allows remote att…
2018-01-01
EPSS2.6%
pct 83
5.4
CVE-2020-10135AST
Legacy pairing and secure-connections pairing authentication in Bluetooth BR/EDR Core Specifica…
2020-01-01
EPSS2.4%
pct 81
9.9
CVE-2024-6678ANC
An issue was discovered in GitLab CE/EE affecting all versions starting from 8.14 prior to 17.1…
2024-01-01
EPSS2.0%
pct 78
7.8
CVE-2017-8422DEB
KDE kdelibs before 4.14.32 and KAuth before 5.34 allow local users to gain root privileges by s…
2017-01-01
EPSS1.8%
pct 75
6.5
CVE-2024-35539CVE
Typecho v1.3.0 was discovered to contain a race condition vulnerability in the post commenting …
2024-01-01Pre-auth
EPSS1.4%
pct 69
7.5
CVE-2022-47522CVE
The IEEE 802.11 specifications through 802.11ax allow physically proximate attackers to interce…
2022-01-01
EPSS0.9%
pct 54
6.9
CVE-2025-34065
An authentication bypass vulnerability exists in AVTECH IP camera, DVR, and NVR devices’ stream…
2025-01-01Pre-auth
EPSS0.5%
pct 40
6.5
CVE-2025-30144ANC
fast-jwt provides fast JSON Web Token (JWT) implementation. Prior to 5.0.6, the fast-jwt librar…
2025-01-01Pre-auth
EPSS0.5%
pct 39
5.3
CVE-2025-22223DEB
Spring Security 6.4.0 - 6.4.3 may not correctly locate method security annotations on parameter…
2025-01-01Pre-auth
EPSS0.5%
pct 36
7.2
CVE-2026-0834CVE
Logic vulnerability in TP-Link Archer C20 v5, 6.0, Archer AX53 v1.0 and TL-WR841N v13 (TDDP mod…
2026-01-01
EPSS0.4%
pct 31
5.4
CVE-2025-46018CVE
CSC Pay Mobile App 2.19.4 (fixed in version 2.20.0) contains a vulnerability allowing users to …
2025-01-01Pre-auth
EPSS0.3%
pct 19
5.5
CVE-2025-24091CVE
An app could impersonate system notifications. Sensitive notifications now require restricted e…
2025-01-01
EPSS0.3%
pct 16
5.1
CVE-2025-56800CVE
Reolink desktop application 8.18.12 contains a vulnerability in its local authentication mechan…
2025-01-01
EPSS0.2%
pct 15
Select a vulnerability on the left to open the preview.