Vulnerability index

Browse CVEs

4,337 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
Zeroheight MEDIUM 6.5
CVE-2025-65925

An issue was discovered in Zeroheight (SaaS) prior to 2025-06-13. A legacy user creation API pathway allowed accounts to be created without completin…

Fix: 2025-06-13+
Fix from $1,600 2025-12-30
Pangolin CRITICAL 9.8
CVE-2025-56333

An issue in Fossorial fosrl/pangolin v.1.6.2 and before allows a remote attacker to escalate privileges via the 2FA component

Fix: 1.7.0+
Fix from $2,300 2025-12-29
Web Fax CRITICAL 9.8
CVE-2025-15069

Improper Authentication vulnerability in Gmission Web Fax allows Privilege Escalation.This issue affects Web Fax: from 3.0 before 3.0.1

Fix: 4.0+
Fix from $2,300 2025-12-29
Unclassified MEDIUM 6.3
CVE-2025-15135

A weakness has been identified in joey-zhou xiaozhi-esp32-server-java up to 3.0.0. This impacts the function tryAuthenticateWithCookies of the file A…

Mitigation only
Fix from $1,600 2025-12-28
Sim CRITICAL 9.8
CVE-2025-15099

A vulnerability was identified in simstudioai sim up to 0.5.27. This vulnerability affects unknown code of the file apps/sim/lib/auth/internal.ts of …

Fix: after 0.5.27
Fix from $2,300 2025-12-26
Unclassified HIGH 7.3
CVE-2025-15097

A vulnerability was found in Alteryx Server. Affected by this issue is some unknown functionality of the file /gallery/api/status/. Performing manipu…

Mitigation only
Fix from $1,950 2025-12-26
Unclassified MEDIUM 5.3
CVE-2023-52210

Vulnerability in Tyche softwares Product Delivery Date for WooCommerce – Lite.This issue affects Product Delivery Date for WooCommerce – Lite: from n…

No fix yet
Fix from $1,600 2025-12-23
Ds 7104hghi F1 Firmware MEDIUM 6.8
CVE-2025-66174

There is an improper authentication vulnerability in some Hikvision DVR products. Due to the improper implementation of authentication for the serial…

Fix: after 4.30.122_201107
Fix from $1,600 2025-12-19
Jeecg Boot HIGH 8.1
CVE-2025-14908

A security flaw has been discovered in JeecgBoot up to 3.9.0. The affected element is an unknown function of the file jeecg-boot/jeecg-module-system/…

Fix: after 3.9.0
Fix from $1,950 2025-12-19
Unclassified MEDIUM 6.9
CVE-2025-13427

An authentication bypass vulnerability in Google Cloud Dialogflow CX Messenger allowed unauthenticated users to interact with restricted chat agents,…

Mitigation only
Fix from $1,600 2025-12-18
Tl Wa850re Firmware HIGH 7.5
CVE-2025-14738

Improper authentication vulnerability in TP-Link WA850RE (httpd modules) allows unauthenticated attackers to download the configuration file.This iss…

Fix: after 160922
Fix from $1,950 2025-12-18
Drivelock CRITICAL 9.8
CVE-2025-67791

An issue was discovered in DriveLock 24.1 through 24.1.*, 24.2 through 24.2.*, and 25.1 through 25.1.*. An incomplete configuration (agent authentica…

Fix: after 25.1.6
Fix from $2,300 2025-12-17
Unclassified CRITICAL 10.0
CVE-2025-44005

An attacker can bypass authorization checks and force a Step CA ACME or SCEP provisioner to create certificates without completing certain protocol a…

Mitigation only
Fix from $2,300 2025-12-17
Unclassified HIGH 7.2
CVE-2025-14097

A vulnerability in the application software of multiple Radiometer products may allow remote code execution and unauthorized device management when s…

Mitigation only
Fix from $1,950 2025-12-17
Unclassified HIGH 8.1
CVE-2025-14002

The WPCOM Member plugin for WordPress is vulnerable to authentication bypass via brute force in all versions up to, and including, 1.7.16. This is du…

Mitigation only
Fix from $1,950 2025-12-16
Tc155 Firmware MEDIUM 6.5
CVE-2025-14746

A vulnerability has been found in Ningyuanda TC155 57.0.2.0. The affected element is an unknown function of the component RTSP Live Video Stream Endp…

No fix yet
Fix from $1,600 2025-12-16
Allauth MEDIUM 5.4
CVE-2025-65431

An issue was discovered in allauth-django before 65.13.0. Both Okta and NetIQ were using preferred_username as the identifier for third-party provide…

Fix: 65.13.0+
Fix from $1,600 2025-12-15
Wekan HIGH 8.2
CVE-2025-65781

An issue was discovered in Wekan The Open Source kanban board system up to version 18.15, fixed in 18.16. Attachment upload API treats the Authorizat…

Fix: 8.16+
Fix from $1,950 2025-12-15
Elasticsearch HIGH 7.4
CVE-2025-37731

Improper Authentication in Elasticsearch PKI realm can lead to user impersonation via specially crafted client certificates. A malicious actor would …

Fix: 8.19.8 / 9.1.8+
Fix from $1,950 2025-12-15
N3 Firmware MEDIUM 5.3
CVE-2025-14703

A vulnerability has been found in Shiguangwu sgwbox N3 2.0.25. The affected element is an unknown function of the file /fsnotify of the component POS…

Fix: after 2.0.25
Fix from $1,600 2025-12-15
Stock Management System HIGH 7.5
CVE-2025-14567

A weakness has been identified in haxxorsid Stock-Management-System up to fbbbf213e9c93b87183a3891f77e3cc7095f22b0. This affects an unknown function …

Fix: after 2018-01-27
Fix from $1,950 2025-12-12
Filament HIGH 8.1
CVE-2025-67507

Filament is a collection of full-stack components for accelerated Laravel development. Versions 4.0.0 through 4.3.0 contain a flaw in the handling of…

Fix: 4.3.1+
Fix from $1,950 2025-12-10
Freepbx CRITICAL 9.8
CVE-2025-66039

FreePBX Endpoint Manager is a module for managing telephony endpoints in FreePBX systems. Versions are vulnerable to authentication bypass when the a…

Fix: 16.0.44 / 17.0.23+
Fix from $2,300 2025-12-09
Unclassified CRITICAL 9.8
CVE-2025-12374

The Email Verification, Email OTP, Block Spam Email, Passwordless login, Hide Login, Magic Login – User Verification plugin for WordPress is vulnerab…

Mitigation only
Fix from $2,300 2025-12-05
X210 Firmware CRITICAL 9.8
CVE-2025-64055

An issue was discovered in Fanvil x210 V2 2.12.20 allowing unauthenticated attackers on the local network to access administrative functions of the d…

Mitigation only
Fix from $2,300 2025-12-03
Faction CRITICAL 9.8
CVE-2025-66022

FACTION is a PenTesting Report Generation and Collaboration Framework. Prior to version 1.7.1, an extension execution path in Faction’s extension fra…

Fix: 1.7.1+
Fix from $2,300 2025-11-26
Lunary HIGH 8.8
CVE-2025-9803

lunary-ai/lunary version 1.9.34 is vulnerable to an account takeover due to improper authentication in the Google OAuth integration. The application …

Patch available
Fix from $1,950 2025-11-25
Celoxa504 Firmware CRITICAL 9.8
CVE-2025-63210

The Newtec Celox UHD (models: CELOXA504, CELOXA820) running firmware version celox-21.6.13 is vulnerable to an authentication bypass. An attacker can…

Mitigation only
Fix from $2,300 2025-11-19
Tex30lcd\/s Firmware CRITICAL 9.8
CVE-2025-63207EPSS 7%

The R.V.R Elettronica TEX product (firmware TEXL-000400, Web GUI TLAN-000400) is vulnerable to broken access control due to improper authentication c…

Mitigation only
Fix from $2,300 2025-11-19
Idenc Firmware CRITICAL 10.0
CVE-2025-63224

The Itel DAB Encoder (IDEnc build 25aec8d) is vulnerable to Authentication Bypass due to improper JWT validation across devices. Attackers can reuse …

Mitigation only
Fix from $2,300 2025-11-19