Vulnerability index

Browse CVEs

4,337 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
Mivoice Mx One CRITICAL 9.4
CVE-2025-67822

A vulnerability in the Provisioning Manager component of Mitel MiVoice MX-ONE 7.3 (7.3.0.0.50) through 7.8 SP1 (7.8.1.0.14) could allow an unauthenti…

Fix: 7.8+
Fix from $2,300 2026-01-15
Dome Flare Firmware MEDIUM 6.8
CVE-2025-65397

An insecure authentication mechanism in the safe_exec.sh startup script of Blurams Flare Camera version 24.1114.151.929 and earlier allows an attacke…

Fix: after 24.1114.151.929
Fix from $1,600 2026-01-14
Edgeconnect Sd Wan Orchestrator CRITICAL 9.8
CVE-2025-37184

A vulnerability exists in an Orchestrator service that could allow an unauthenticated remote attacker to bypass multi-factor authentication requireme…

Fix: 9.3.6 / 9.4.3+
Fix from $2,300 2026-01-14
Bluvoyix CRITICAL 9.8
CVE-2026-22236

The vulnerability exists in BLUVOYIX due to improper authentication in the BLUVOYIX backend APIs. An unauthenticated remote attacker could exploit th…

Mitigation only
Fix from $2,300 2026-01-14
Unclassified MEDIUM 5.1
CVE-2025-67859

A Improper Authentication vulnerability in TLP allows local users to arbitrarily control the power profile in use as well as the daemon’s log setting…

Mitigation only
Fix from $1,600 2026-01-14
Jervis HIGH 7.5
CVE-2025-68931

Jervis is a library for Job DSL plugin scripts and shared Jenkins pipeline libraries. Prior to 2.2, AES/CBC/PKCS5Padding lacks authentication, making…

Fix: 2.2+
Fix from $1,950 2026-01-13
Ex2800 Firmware HIGH 8.0
CVE-2026-0408

A path traversal vulnerability in NETGEAR WiFi range extenders allows an attacker with LAN authentication to access the router's IP and review the …

Fix: 1.0.1.82+
Fix from $1,950 2026-01-13
Cbr750 Firmware HIGH 7.8
CVE-2026-0405

An authentication bypass vulnerability in NETGEAR Orbi devices allows users connected to the local network to access the router web interface as an…

Fix: 4.6.14.8 / 4.6.15.14+
Fix from $1,950 2026-01-13
Ex5000 Firmware HIGH 8.0
CVE-2026-0407

An insufficient authentication vulnerability in NETGEAR WiFi range extenders allows a network adjacent attacker with WiFi authentication or a physi…

Fix: 1.0.1.82+
Fix from $1,950 2026-01-13
Veda HIGH 8.6
CVE-2025-66698

An issue in Semantic machines v5.4.8 allows attackers to bypass authentication via sending a crafted HTTP request to various API endpoints.

No fix yet
Fix from $1,950 2026-01-13
Dx Netops Spectrum HIGH 7.5
CVE-2025-69273

Improper Authentication vulnerability in Broadcom DX NetOps Spectrum on Windows, Linux allows Authentication Bypass.This issue affects DX NetOps Spec…

Fix: 24.3.11+
Fix from $1,950 2026-01-12
Unclassified MEDIUM 6.3
CVE-2026-0842

A flaw has been found in Flycatcher Toys smART Sketcher up to 2.0. This affects an unknown part of the component Bluetooth Low Energy Interface. This…

Mitigation only
Fix from $1,600 2026-01-11
Ghost HIGH 8.1
CVE-2026-22594

Ghost is a Node.js content management system. In versions 5.105.0 through 5.130.5 and 6.0.0 through 6.10.3, a vulnerability in Ghost's 2FA mechanism …

Fix: 5.130.6 / 6.11.0+
Fix from $1,950 2026-01-10
Ks Wr3600 Firmware CRITICAL 9.4
CVE-2025-68717

KAYSUS KS-WR3600 routers with firmware 1.0.5.9.1 allow authentication bypass during session validation. If any user is logged in, endpoints such as /…

No fix yet
Fix from $2,300 2026-01-08
Zimaos CRITICAL 9.8
CVE-2026-21891

ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In versions up to and including 1.5.0, the application…

Fix: after 1.5.0
Fix from $2,300 2026-01-08
Kanboard CRITICAL 9.1
CVE-2026-21881

Kanboard is project management software focused on Kanban methodology. Versions 1.2.48 and below is vulnerable to a critical authentication bypass wh…

Fix: 1.2.49+
Fix from $2,300 2026-01-08
Unclassified CRITICAL 9.3
CVE-2025-15346

A vulnerability in the handling of verify_mode = CERT_REQUIRED in the wolfssl Python package (wolfssl-py) causes client certificate requirements to n…

Patch available
Fix from $2,300 2026-01-08
Tarkov Data Manager CRITICAL 9.8
CVE-2026-21854

The Tarkov Data Manager is a tool to manage the Tarkov item data. Prior to 02 January 2025, an authentication bypass vulnerability in the login endpo…

Fix: 2025-01-02+
Fix from $2,300 2026-01-07
Wolfssh CRITICAL 9.8
CVE-2025-14942

wolfSSH’s key exchange state machine can be manipulated to leak the client’s password in the clear, trick the client to send a bogus signature, or tr…

Fix: 1.4.22+
Fix from $2,300 2026-01-06
Cobalt X1 CRITICAL 9.8
CVE-2025-60534

Blue Access Cobalt v02.000.195 suffers from an authentication bypass vulnerability, which allows an attacker to selectively proxy requests in order t…

Mitigation only
Fix from $2,300 2026-01-06
Panel MEDIUM 6.5
CVE-2025-69197

Pterodactyl is a free, open-source game server management panel. Versions 1.11.11 and below allow TOTP to be used multiple times during its validity …

Fix: 1.12.0+
Fix from $1,600 2026-01-06
Coolify HIGH 8.8
CVE-2025-64423

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. In Coolify versions up to and including v4.0.0-be…

Fix: 4.0.0+
Fix from $1,950 2026-01-05
Unifi Protect HIGH 8.8
CVE-2026-21633

A malicious actor with access to the adjacent network could obtain unauthorized access to a UniFi Protect Camera by exploiting a discovery protocol v…

Fix: 6.2.72+
Fix from $1,950 2026-01-05
Online Product Reservation System HIGH 7.3
CVE-2026-0589

A vulnerability was found in code-projects Online Product Reservation System 1.0. Impacted is an unknown function of the component Administration Bac…

No fix yet
Fix from $1,950 2026-01-05
Minicms CRITICAL 9.8
CVE-2025-15458

A vulnerability was determined in bg5sbk MiniCMS up to 1.8. This affects an unknown function of the file /mc-admin/post-edit.php of the component Art…

Fix: after 1.8
Fix from $2,300 2026-01-05
Minicms CRITICAL 9.8
CVE-2025-15457

A vulnerability was found in bg5sbk MiniCMS up to 1.8. The impacted element is an unknown function of the file /minicms/mc-admin/post.php of the comp…

Fix: after 1.8
Fix from $2,300 2026-01-05
Minicms HIGH 7.5
CVE-2025-15456

A vulnerability has been found in bg5sbk MiniCMS up to 1.8. The affected element is an unknown function of the file /mc-admin/page-edit.php of the co…

Fix: after 1.8
Fix from $1,950 2026-01-05
Minicms MEDIUM 6.5
CVE-2025-15455

A flaw has been found in bg5sbk MiniCMS up to 1.8. Impacted is the function delete_page of the file /minicms/mc-admin/page.php of the component File …

Fix: after 1.8
Fix from $1,600 2026-01-05
I6032w Fhw Firmware HIGH 7.5
CVE-2025-67158

An authentication bypass in the /cgi-bin/jvsweb.cgi endpoint of Revotech I6032W-FHW v1.0.0014 - 20210517 allows attackers to access sensitive informa…

No fix yet
Fix from $1,950 2026-01-02
Rustfs CRITICAL 9.8
CVE-2025-68926EPSS 30%

RustFS is a distributed object storage system built in Rust. In versions prior to 1.0.0-alpha.78, RustFS implements gRPC authentication using a hardc…

Mitigation only
Fix from $2,300 2025-12-30