Vulnerability index

Browse CVEs

4,337 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
Ipados MEDIUM 5.5
CVE-2026-20655

An authorization issue was addressed with improved state management. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3. A…

Fix: 18.7.5 / 26.3+
Fix from $1,600 2026-02-11
Outline MEDIUM 5.3
CVE-2025-68663

Outline is a service that allows for collaborative documentation. Prior to 1.1.0, a vulnerability was found in Outline's WebSocket authentication mec…

Fix: 1.1.0+
Fix from $1,600 2026-02-11
Unclassified HIGH 8.1
CVE-2025-65128

A missing authentication mechanism in the web management API components of Shenzhen Zhibotong Electronics ZBT WE2001 23.09.27 allows unauthenticated …

Mitigation only
Fix from $1,950 2026-02-11
Unclassified MEDIUM 6.5
CVE-2025-65127

A lack of session validation in the web API component of Shenzhen Zhibotong Electronics ZBT WE2001 23.09.27 allows remote unauthenticated attackers t…

Mitigation only
Fix from $1,600 2026-02-11
Unclassified CRITICAL 9.8
CVE-2026-2248

METIS WIC devices (versions <= oscore 2.1.234-r18) expose a web-based shell at the /console endpoint that does not require authentication. Accessing …

Mitigation only
Fix from $2,300 2026-02-11
Unclassified CRITICAL 9.8
CVE-2026-2249

METIS DFS devices (versions <= oscore 2.1.234-r18) expose a web-based shell at the /console endpoint that does not require authentication. Accessing …

Mitigation only
Fix from $2,300 2026-02-11
Windows 10 1607 HIGH 7.0
CVE-2026-21508

Improper authentication in Windows Storage allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.8868 / 10.0.17763.8389+
Fix from $1,950 2026-02-10
Druid CRITICAL 9.8
CVE-2026-23906

Affected Products and Versions * Apache Druid * Affected Versions: 0.17.0 through 35.x (all versions prior to 36.0.0) * Prerequisites: * d…

Fix: 36.0.0+
Fix from $2,300 2026-02-10
Fuxa CRITICAL 9.8
CVE-2026-25893

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Prior to 1.2.10, an authentication bypass vulnerability in FUXA allows an u…

Fix: 1.2.10+
Fix from $2,300 2026-02-09
Unclassified HIGH 7.3
CVE-2025-10463

Improper Authentication vulnerability in Birtech Information Technologies Industry and Trade Ltd. Co. Senseway allows Authentication Abuse. This iss…

Mitigation only
Fix from $1,950 2026-02-09
Contact Management System CRITICAL 9.8
CVE-2026-2174

A security flaw has been discovered in code-projects Contact Management System 1.0. This affects an unknown part of the component CRUD Endpoint. The …

Mitigation only
Fix from $2,300 2026-02-08
E Commerce CRITICAL 9.8
CVE-2026-2165

A weakness has been identified in detronetdip E-commerce 1.0.0. Impacted is an unknown function of the file /Admin/assets/backend/seller/add_seller.p…

Mitigation only
Fix from $2,300 2026-02-08
Antrea CRITICAL 9.1
CVE-2026-25804

Antrea is a Kubernetes networking solution intended to be Kubernetes native. Prior to versions 2.3.2 and 2.4.3, Antrea's network policy priority assi…

Fix: 2.3.2 / 2.4.3+
Fix from $2,300 2026-02-06
Smart Pixelator Firmware HIGH 8.8
CVE-2026-2065

A security flaw has been discovered in Flycatcher Toys smART Pixelator 2.0. Affected by this issue is some unknown functionality of the component Blu…

No fix yet
Fix from $1,950 2026-02-06
Gogs HIGH 8.8
CVE-2025-64175

Gogs is an open source self-hosted Git service. In version 0.13.3 and prior, Gogs’ 2FA recovery code validation does not scope codes by user, enablin…

Fix: 0.13.4+
Fix from $1,950 2026-02-06
Dokans HIGH 7.5
CVE-2025-70841

Dokans Multi-Tenancy Based eCommerce Platform SaaS 3.9.2 allows unauthenticated remote attackers to obtain sensitive application configuration data v…

No fix yet
Fix from $1,950 2026-02-03
Unclassified CRITICAL 9.6
CVE-2026-1568

Rapid7 InsightVM versions before 8.34.0 contain a signature verification issue on the Assertion Consumer Service (ACS) cloud endpoint that could allo…

Mitigation only
Fix from $2,300 2026-02-03
A8004t Firmware CRITICAL 9.8
CVE-2026-1740

A vulnerability was found in EFM ipTIME A8004T 14.18.2. This impacts the function httpcon_check_session_url of the file /cgi/timepro.cgi of the compo…

Mitigation only
Fix from $2,300 2026-02-02
Unclassified MEDIUM 6.2
CVE-2025-62349

Salt contains an authentication protocol version downgrade weakness that can allow a malicious minion to bypass newer authentication/security feature…

Mitigation only
Fix from $1,600 2026-01-30
Unclassified MEDIUM 5.8
CVE-2025-6723

Chef InSpec versions up to 5.23 and before 7.0.107 creates named pipes with overly permissive default Windows access controls. A local attacker may i…

Mitigation only
Fix from $1,600 2026-01-30
Openmanage Network Integration MEDIUM 6.5
CVE-2026-22764

Dell OpenManage Network Integration, versions prior to 3.9, contains an Improper Authentication vulnerability. A low privileged attacker with remote …

Fix: 3.9+
Fix from $1,600 2026-01-29
Secret Server MEDIUM 6.5
CVE-2025-12810

Improper Authentication vulnerability in Delinea Inc. Secret Server On-Prem (RPC Password Rotation modules).This issue affects Secret Server On-Prem:…

Mitigation only
Fix from $1,600 2026-01-27
Everest MEDIUM 5.3
CVE-2026-24003

EVerest is an EV charging software stack. In versions up to and including 2025.12.1, it is possible to bypass the sequence state verification includi…

Fix: after 2025.12.1
Fix from $1,600 2026-01-26
777vr1 Firmware MEDIUM 6.4
CVE-2026-1410

A vulnerability was detected in Beetel 777VR1 up to 01.00.09/01.00.09_55. Impacted is an unknown function of the component UART Interface. The manipu…

Fix: after 01.00.09_55
Fix from $1,600 2026-01-26
Unclassified CRITICAL 9.8
CVE-2022-25369EPSS 41%

An issue was discovered in Dynamicweb before 9.12.8. An attacker can add a new administrator user without authentication. This flaw exists due to a l…

Mitigation only
Fix from $2,300 2026-01-23
Erica Smart Fan Firmware HIGH 7.4
CVE-2025-69822

An issue in Atomberg Atomberg Erica Smart Fan Firmware Version: V1.0.36 allows an attacker to obtain sensitive information and escalate privileges vi…

No fix yet
Fix from $1,950 2026-01-22
Horilla HIGH 8.1
CVE-2026-24038

Horilla is a free and open source Human Resource Management System (HRMS). In version 1.4.0, the OTP handling logic has a flawed equality check that …

No fix yet
Fix from $1,950 2026-01-22
Crmeb CRITICAL 9.8
CVE-2026-1202

A security flaw has been discovered in CRMEB up to 5.6.3. The affected element is the function appleLogin of the file crmeb/app/api/controller/v1/Log…

Fix: after 5.6.3
Fix from $2,300 2026-01-20
Crmeb HIGH 8.1
CVE-2026-1203

A weakness has been identified in CRMEB up to 5.6.3. The impacted element is the function remoteRegister of the file crmeb/app/services/user/LoginSer…

Fix: after 5.6.3
Fix from $1,950 2026-01-20
Unclassified HIGH 8.7
CVE-2026-0629

Authentication bypass in the password recovery feature of the local web interface across multiple VIGI camera models allows an attacker on the LAN to…

Mitigation only
Fix from $1,950 2026-01-16