Vulnerabilities (CVE)

Filtered by CWE-306
Total 2876 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-13186 2026-06-17 N/A 7.5 HIGH
The MinigameCenter module has insufficient restrictions on loading URLs, which may lead to some information leakage.
CVE-2024-13185 2026-06-17 N/A 7.5 HIGH
The MinigameCenter module has insufficient restrictions on loading URLs, which may lead to some information leakage.
CVE-2024-13173 2026-06-17 N/A 7.5 HIGH
The health module has insufficient restrictions on loading URLs, which may lead to some information leakage.
CVE-2024-12957 2026-06-17 N/A N/A
A file handling command vulnerability in certain versions of Armoury Crate may result in arbitrary file deletion. Refer to the '01/23/2025 Security Update for Armoury Crate App' section on the ASUS Security Advisory for more information.
CVE-2024-12869 1 Infiniflow 1 Ragflow 2026-06-17 N/A 4.3 MEDIUM
In infiniflow/ragflow version v0.12.0, there is an improper authentication vulnerability that allows a user to view another user's invite list. This can lead to a privacy breach where users' personal or private information, such as email addresses or usernames in the invite list, could be exposed without their consent. This data leakage can facilitate further attacks, such as phishing or spam, and result in loss of trust and potential regulatory issues.
CVE-2024-12857 1 Scriptsbundle 1 Adforest 2026-06-17 N/A 9.8 CRITICAL
The AdForest theme for WordPress is vulnerable to authentication bypass in all versions up to, and including, 5.1.8. This is due to the plugin not properly verifying a user's identity prior to logging them in as that user. This makes it possible for unauthenticated attackers to authenticate as any user as long as they have configured OTP login by phone number.
CVE-2024-12847 1 Netgear 2 Dgn1000, Dgn1000 Firmware 2026-06-17 N/A 9.8 CRITICAL
NETGEAR DGN1000 before 1.1.00.48 is vulnerable to an authentication bypass vulnerability. A remote and unauthenticated attacker can execute arbitrary operating system commands as root by sending crafted HTTP requests to the setup.cgi endpoint. This vulnerability has been observed to be exploited in the wild since at least 2017 and specifically by the Shadowserver Foundation on 2025-02-06 UTC.
CVE-2024-12757 2026-06-17 N/A 8.6 HIGH
Nedap Librix Ecoreader is missing authentication for critical functions that could allow an unauthenticated attacker to potentially execute malicious code.
CVE-2024-12511 2026-06-17 N/A 7.6 HIGH
With address book access, SMB/FTP settings could be modified, redirecting scans and possibly capturing credentials. This requires enabled scan functions and printer access.
CVE-2024-12371 2026-06-17 N/A N/A
A device takeover vulnerability exists in the Rockwell Automation Power Monitor 1000. This vulnerability allows configuration of a new Policyholder user without any authentication via API. Policyholder user is the most privileged user that can perform edit operations, creating admin users and performing factory reset.
CVE-2024-12106 1 Progress 1 Whatsup Gold 2026-06-17 N/A 9.4 CRITICAL
In WhatsUp Gold versions released before 2024.0.2, an unauthenticated attacker can configureĀ LDAP settings.
CVE-2024-11980 2026-06-17 N/A 8.6 HIGH
Certain modes of routers from Billion Electric have a Missing Authentication vulnerability, allowing unauthenticated remote attackers to directly access the specific functionality to obtain partial device information, modify the WiFi SSID, and restart the device.
CVE-2024-11639 1 Ivanti 1 Cloud Services Appliance 2026-06-17 N/A 10.0 CRITICAL
An authentication bypass in the admin web console of Ivanti CSA before 5.0.3 allows a remote unauthenticated attacker to gain administrative access
CVE-2024-10924 1 Really-simple-plugins 1 Really Simple Security 2026-06-17 N/A 9.8 CRITICAL
The Really Simple Security (Free, Pro, and Pro Multisite) plugins for WordPress are vulnerable to authentication bypass in versions 9.0.0 to 9.1.1.1. This is due to improper user check error handling in the two-factor REST API actions with the 'check_login_and_get_user' function. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, when the "Two-Factor Authentication" setting is enabled (disabled by default).
CVE-2024-10776 2026-06-17 N/A 8.2 HIGH
Lua apps can be deployed, removed, started, reloaded or stopped without authorization via AppManager. This allows an attacker to remove legitimate apps creating a DoS attack, read and write files or load apps that use all features of the product available to a customer.
CVE-2024-10774 2026-06-17 N/A 7.3 HIGH
Unauthenticated CROWN APIs allow access to critical functions. This leads to the accessibility of large parts of the web application without authentication.
CVE-2024-10649 2026-06-17 N/A 6.1 MEDIUM
wandb/openui latest commit c945bb859979659add5f490a874140ad17c56a5d contains a vulnerability where unauthenticated endpoints allow file uploads and downloads from an AWS S3 bucket. This can lead to multiple security issues including denial of service, stored XSS, and information disclosure. The affected endpoints are '/v1/share/{id:str}' for uploading and '/v1/share/{id:str}' for downloading JSON files. The lack of authentication allows any user to upload and overwrite files, potentially causing the S3 bucket to run out of space, injecting malicious scripts, and accessing sensitive information.
CVE-2024-10386 1 Rockwellautomation 1 Thinmanager 2026-06-17 N/A 9.8 CRITICAL
CVE-2024-10386 IMPACT An authentication vulnerability exists in the affected product. The vulnerability could allow a threat actor with network access to send crafted messages to the device, potentially resulting in database manipulation.
CVE-2024-10284 1 Ce21 1 Ce21 Suite 2026-06-17 N/A 9.8 CRITICAL
The CE21 Suite plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.2.0. This is due to hardcoded encryption key in the 'ce21_authentication_phrase' function. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the email.
CVE-2024-10205 2026-06-17 N/A 9.4 CRITICAL
Authentication Bypass vulnerability in Hitachi Ops Center Analyzer on Linux, 64 bit (Hitachi Ops Center Analyzer detail view component), Hitachi Infrastructure Analytics Advisor on Linux, 64 bit (Hitachi Data Center Analytics component ).This issue affects Hitachi Ops Center Analyzer: from 10.0.0-00 before 11.0.3-00; Hitachi Infrastructure Analytics Advisor: from 2.1.0-00 through 4.4.0-00.