Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

Filtering: Tag: cwe-287 Clear
ID Title
CVE-2025-53786 Authentication Bypass in microsoft (CVE-2025-53786)
authentication bypass in microsoft (CVE-2025-53786). Successful exploitation can lead to full system takeover.
CVE-2025-49706 KEV [KEV] Authentication Bypass in Microsoft sharepoint (CVE-2025-49706)
authentication bypass in Microsoft sharepoint (CVE-2025-49706). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
CVE-2021-32030 KEV [KEV] Authentication Bypass in Asus routers (CVE-2021-32030)
authentication bypass in Asus routers (CVE-2021-32030). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
CVE-2025-3935 KEV [KEV] Authentication Bypass in Connectwise screenconnect (CVE-2025-3935)
authentication bypass in Connectwise screenconnect (CVE-2025-3935). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
CVE-2025-25504 Command Injection in niceforyou (CVE-2025-25504)
command injection in niceforyou (CVE-2025-25504). Risk of unauthorized operations or information disclosure.
CVE-2024-53704 KEV [KEV] Authentication Bypass in Sonicwall sonicos (CVE-2024-53704)
authentication bypass in Sonicwall sonicos (CVE-2024-53704). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
CVE-2025-0604 Authentication Bypass in CVE-2025-0604 (CVE-2025-0604)
authentication bypass in CVE-2025-0604 (CVE-2025-0604). Risk of unauthorized operations or information disclosure.
CVE-2024-11680 KEV [KEV] Vulnerability in projectsend (CVE-2024-11680)
vulnerability in projectsend (CVE-2024-11680). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
CVE-2023-28461 KEV [KEV] Authentication Bypass in Array networks array-networks (CVE-2023-28461)
authentication bypass in Array networks array-networks (CVE-2023-28461). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
CVE-2024-49039 KEV [KEV] Authentication Bypass in Microsoft windows (CVE-2024-49039)
authentication bypass in Microsoft windows (CVE-2024-49039). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
CVE-2024-10963 Authentication Bypass in CVE-2024-10963 (CVE-2024-10963)
authentication bypass in CVE-2024-10963 (CVE-2024-10963). Confidential information can be exposed externally.
CVE-2024-8956 KEV [KEV] Authentication Bypass in Ptzoptics pt30x-sdindi-cameras (CVE-2024-8956)
authentication bypass in Ptzoptics pt30x-sdindi-cameras (CVE-2024-8956). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
CVE-2024-7593 KEV [KEV] Authentication Bypass in Ivanti virtual-traffic-manager (CVE-2024-7593)
authentication bypass in Ivanti virtual-traffic-manager (CVE-2024-7593). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
CVE-2024-38225 Microsoft Dynamics 365 Business Central Elevation of Privilege Vulnerability
Microsoft Dynamics 365 Business Central Elevation of Privilege Vulnerability
CVE-2021-33045 KEV [KEV] Authentication Bypass in Dahua ip-camera-firmware (CVE-2021-33045)
authentication bypass in Dahua ip-camera-firmware (CVE-2021-33045). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
CVE-2021-33044 KEV [KEV] Authentication Bypass in Dahua ip-camera-firmware (CVE-2021-33044)
authentication bypass in Dahua ip-camera-firmware (CVE-2021-33044). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
CVE-2024-35248 Microsoft Dynamics 365 Business Central Elevation of Privilege Vulnerability
Microsoft Dynamics 365 Business Central Elevation of Privilege Vulnerability
CVE-2024-28735 Authentication Bypass in unit4 (CVE-2024-28735)
authentication bypass in unit4 (CVE-2024-28735). Confidential information can be exposed externally.
CVE-2024-21410 KEV [KEV] Authentication Bypass in Microsoft exchange-server (CVE-2024-21410)
authentication bypass in Microsoft exchange-server (CVE-2024-21410). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
CVE-2023-35082 KEV [KEV] Authentication Bypass in Ivanti endpoint-manager-mobile-epmm-and-mobileiron-core (CVE-2023-35082)
authentication bypass in Ivanti endpoint-manager-mobile-epmm-and-mobileiron-core (CVE-2023-35082). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
CVE-2023-46805 KEV [KEV] Authentication Bypass in Ivanti connect-secure-and-policy-secure (CVE-2023-46805)
authentication bypass in Ivanti connect-secure-and-policy-secure (CVE-2023-46805). Confidential information can be exposed externally. Listed in CISA KEV — actively exploited.
CVE-2023-4669 Vulnerability in exagate (CVE-2023-4669)
vulnerability in exagate (CVE-2023-4669). Successful exploitation can lead to full system takeover.
CVE-2023-4501 Vulnerability in microfocus (CVE-2023-4501)
vulnerability in microfocus (CVE-2023-4501). Successful exploitation can lead to full system takeover.
CVE-2021-27715 Authentication Bypass in mofinetwork (CVE-2021-27715)
authentication bypass in mofinetwork (CVE-2021-27715). Successful exploitation can lead to full system takeover.
CVE-2023-35078 KEV [KEV] Authentication Bypass in Ivanti endpoint-manager-mobile-epmm (CVE-2023-35078)
authentication bypass in Ivanti endpoint-manager-mobile-epmm (CVE-2023-35078). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
CVE-2023-2959 Authentication Bypass in olivaekspertiz (CVE-2023-2959)
authentication bypass in olivaekspertiz (CVE-2023-2959). Confidential information can be exposed externally.
CVE-2023-20867 KEV [KEV] Authentication Bypass in Vmware tools (CVE-2023-20867)
authentication bypass in Vmware tools (CVE-2023-20867). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
CVE-2023-23450 Authentication Bypass in sick (CVE-2023-23450)
authentication bypass in sick (CVE-2023-23450). Confidential information can be exposed externally.
CVE-2023-27823 Authentication Bypass in optoma (CVE-2023-27823)
authentication bypass in optoma (CVE-2023-27823). Successful exploitation can lead to full system takeover.
CVE-2023-1833 Vulnerability in redline (CVE-2023-1833)
vulnerability in redline (CVE-2023-1833). Successful exploitation can lead to full system takeover.
CVE-2023-1803 Vulnerability in redline (CVE-2023-1803)
vulnerability in redline (CVE-2023-1803). Successful exploitation can lead to full system takeover.
CVE-2021-27876 KEV [KEV] Authentication Bypass in Veritas backup-exec-agent (CVE-2021-27876)
authentication bypass in Veritas backup-exec-agent (CVE-2021-27876). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
CVE-2021-27877 KEV [KEV] Authentication Bypass in Veritas backup-exec-agent (CVE-2021-27877)
authentication bypass in Veritas backup-exec-agent (CVE-2021-27877). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
CVE-2021-27878 KEV [KEV] Authentication Bypass in Veritas backup-exec-agent (CVE-2021-27878)
authentication bypass in Veritas backup-exec-agent (CVE-2021-27878). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
CVE-2021-28235 Authentication Bypass in etcd (CVE-2021-28235)
authentication bypass in etcd (CVE-2021-28235). Successful exploitation can lead to full system takeover.
CVE-2023-21817 Windows Kerberos Elevation of Privilege Vulnerability
Windows Kerberos Elevation of Privilege Vulnerability
CVE-2023-21721 Microsoft OneNote Elevation of Privilege Vulnerability
Microsoft OneNote Elevation of Privilege Vulnerability
CVE-2022-45724 Authentication Bypass in comfast (CVE-2022-45724)
authentication bypass in comfast (CVE-2022-45724). Risk of unauthorized operations or information disclosure.
CVE-2022-47003 Authentication Bypass in murasoftware (CVE-2022-47003)
authentication bypass in murasoftware (CVE-2022-47003). Successful exploitation can lead to full system takeover.
CVE-2022-37774 Authentication Bypass in maarch (CVE-2022-37774)
authentication bypass in maarch (CVE-2022-37774). Risk of unauthorized operations or information disclosure.
CVE-2022-40684 KEV [KEV] Authentication Bypass in Fortinet multiple-products (CVE-2022-40684)
authentication bypass in Fortinet multiple-products (CVE-2022-40684). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
CVE-2021-39226 KEV [KEV] Authentication Bypass in Grafana labs github.com/grafana/grafana (CVE-2021-39226)
authentication bypass in Grafana labs github.com/grafana/grafana (CVE-2021-39226). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited. Mitigation: upgrade to `8.1.6` or later.
CVE-2022-35203 Authentication Bypass in trendnet (CVE-2022-35203)
authentication bypass in trendnet (CVE-2022-35203). Successful exploitation can lead to full system takeover.
CVE-2022-36524 Authentication Bypass in dlink (CVE-2022-36524)
authentication bypass in dlink (CVE-2022-36524). Confidential information can be exposed externally.
CVE-2022-30034 Authentication Bypass in flower (CVE-2022-30034)
authentication bypass in flower (CVE-2022-30034). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.2.0` or later.
CVE-2022-22576 Authentication Bypass in haxx (CVE-2022-22576)
authentication bypass in haxx (CVE-2022-22576). Confidential information can be exposed externally.
CVE-2018-7791 Authentication Bypass in schneider-electric (CVE-2018-7791)
authentication bypass in schneider-electric (CVE-2018-7791). Successful exploitation can lead to full system takeover.
CVE-2021-36460 Authentication Bypass in veryfitpro-project (CVE-2021-36460)
authentication bypass in veryfitpro-project (CVE-2021-36460). Successful exploitation can lead to full system takeover.
CVE-2022-29534 Authentication Bypass in misp-project (CVE-2022-29534)
authentication bypass in misp-project (CVE-2022-29534). Data can be tampered with by attackers.
CVE-2018-10561 KEV [KEV] Authentication Bypass in Dasan gigabit-passive-optical-network-gpon-routers (CVE-2018-10561)
authentication bypass in Dasan gigabit-passive-optical-network-gpon-routers (CVE-2018-10561). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →