Vulnerability index

Browse CVEs

4,337 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
Idgateway Firmware CRITICAL 10.0
CVE-2025-63216

The Itel DAB Gateway (IDGat build c041640a) is vulnerable to Authentication Bypass due to improper JWT validation across devices. Attackers can reuse…

Mitigation only
Fix from $2,300 2025-11-18
Memos HIGH 7.5
CVE-2024-21635

Memos is a privacy-first, lightweight note-taking service that uses Access Tokens to authenticate application access. When a user changes their passw…

Fix: after 0.18.1
Fix from $1,950 2025-11-14
Zitadel CRITICAL 9.8
CVE-2025-64717

ZITADEL is an open source identity management platform. Starting in version 2.50.0 and prior to versions 2.71.19, 3.4.4, and 4.6.6, a vulnerability i…

Fix: 2.71.19 / 3.4.4+
Fix from $2,300 2025-11-13
Unclassified HIGH 8.2
CVE-2025-12998

Improper Authentication vulnerability in TYPO3 Extension "Modules" codingms/modules.This issue affects Extension "Modules": before 4.3.11, from 5.0.0…

Mitigation only
Fix from $1,950 2025-11-12
Unclassified CRITICAL 9.3
CVE-2025-64513

Milvus is an open-source vector database built for generative AI applications. An unauthenticated attacker can exploit a vulnerability in versions pr…

Patch available
Fix from $2,300 2025-11-10
Kubevirt MEDIUM 6.3
CVE-2025-64434

KubeVirt is a virtual machine management add-on for Kubernetes. Prior to 1.5.3 and 1.6.1, due to the peer verification logic in virt-handler (via ver…

Fix: 1.5.3+
Fix from $1,600 2025-11-07
Unclassified CRITICAL 9.3
CVE-2025-3222

Improper Authentication vulnerability in GE Vernova Smallworld on Windows, Linux allows Authentication Abuse.This issue affects Smallworld: 5.3.3 and…

Mitigation only
Fix from $2,300 2025-11-07
Yocto MEDIUM 6.7
CVE-2025-20730

In preloader, there is a possible escalation of privilege due to an insecure default value. This could lead to local escalation of privilege if a mal…

Mitigation only
Fix from $1,600 2025-11-04
Zitadel CRITICAL 9.8
CVE-2025-64103

Starting from 2.53.6, 2.54.3, and 2.55.0, Zitadel only required multi factor authentication in case the login policy has either enabled requireMFA or…

Fix: 2.71.18 / 3.4.3+
Fix from $2,300 2025-10-29
Fusion HIGH 7.6
CVE-2025-60424

A lack of rate limiting in the OTP verification component of Nagios Fusion v2024R1.2 and v2024R2 allows attackers to bypass authentication via a brut…

Mitigation only
Fix from $1,950 2025-10-27
Emlog CRITICAL 9.1
CVE-2025-62717

Emlog is an open source website building system. In version 2.5.23, Emlog Pro is vulnerable to a session verification code error due to a clearing lo…

Patch available
Fix from $2,300 2025-10-24
Storage Manager CRITICAL 9.8
CVE-2025-43995

Dell Storage Center - Dell Storage Manager, version(s) 20.1.21, contain(s) an Improper Authentication vulnerability. An unauthenticated attacker with…

Fix: 2020+
Fix from $2,300 2025-10-24
Unclassified HIGH 8.8
CVE-2025-6979

Captive Portal can allow authentication bypass

No fix yet
Fix from $1,950 2025-10-23
Unclassified HIGH 8.1
CVE-2025-62169

OctoPrint-SpoolManager is a plugin for managing spools and all their usage metadata. In versions 1.8.0a2 and older of the testing branch and versions…

Patch available
Fix from $1,950 2025-10-23
Moodle MEDIUM 5.4
CVE-2025-62398

A serious authentication flaw allowed attackers with valid credentials to bypass multi-factor authentication under certain conditions, potentially co…

Fix: 4.4.11 / 4.5.7+
Fix from $1,600 2025-10-23
Unclassified CRITICAL 9.8
CVE-2025-56447

TM2 Monitoring v3.04 contains an authentication bypass and plaintext credential disclosure.

Mitigation only
Fix from $2,300 2025-10-22
Vision 60 Firmware CRITICAL 9.8
CVE-2025-41108

The communication protocol implemented in Ghost Robotics Vision 60 v0.27.2 could allow an attacker to send commands to the robot from an external att…

Mitigation only
Fix from $2,300 2025-10-22
Vision 60 Firmware HIGH 8.8
CVE-2025-41110

Encrypted WiFi and SSH credentials were found in the Ghost Robotics Vision 60 v0.27.2 APK. This vulnerability allows an attacker to connect to the ro…

Mitigation only
Fix from $1,950 2025-10-22
Unclassified CRITICAL 9.8
CVE-2025-60772

Improper authentication in the web-based management interface of NETLINK HG322G V1.0.00-231017, allows a remote unauthenticated attacker to escalate …

Mitigation only
Fix from $2,300 2025-10-21
Wolfssh CRITICAL 9.8
CVE-2025-11625

Improper host authentication vulnerability in wolfSSH version 1.4.20 and earlier clients that allows authentication bypass and leaking of clients cre…

Fix: after 1.4.20
Fix from $2,300 2025-10-21
X200 Firmware CRITICAL 9.8
CVE-2025-11942

A flaw has been found in 70mai X200 up to 20251010. Affected is an unknown function of the component Pairing. Executing manipulation can lead to miss…

Fix: after 2025-10-10
Fix from $2,300 2025-10-19
Unclassified MEDIUM 5.3
CVE-2025-11852

A vulnerability was found in Apeman ID71 218.53.203.117. The impacted element is an unknown function of the file /onvif/device_service of the compone…

Mitigation only
Fix from $1,600 2025-10-16
Prestashop Checkout CRITICAL 9.1
CVE-2025-61922

PrestaShop Checkout is the PrestaShop official payment module in partnership with PayPal. Starting in version 1.3.0 and prior to versions 4.4.1 and 5…

Fix: 7.4.4.1 / 7.5.0.5+
Fix from $2,300 2025-10-16
macOS HIGH 7.8
CVE-2025-43281

The issue was addressed with improved authentication. This issue is fixed in macOS Sequoia 15.6. A local attacker may be able to elevate their privil…

Fix: 15.6+
Fix from $1,950 2025-10-15
Unclassified HIGH 8.8
CVE-2025-10293

The Keyy Two Factor Authentication (like Clef) plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to,…

Mitigation only
Fix from $1,950 2025-10-15
Unclassified CRITICAL 9.5
CVE-2025-62376

pwn.college DOJO is an education platform for learning cybersecurity. Prior to commit 467db0b9ea0d9a929dc89b41f6eb59f7cfc68bef, the /workspace endpoi…

Patch available
Fix from $2,300 2025-10-14
Windows 10 21h2 HIGH 7.0
CVE-2025-55340

Improper authentication in Windows Remote Desktop Protocol allows an authorized attacker to bypass a security feature locally.

Fix: 10.0.19044.6456 / 10.0.19045.6456+
Fix from $1,950 2025-10-14
Fortianalyzer MEDIUM 6.5
CVE-2025-53845

An improper authentication vulnerability [CWE-287] in Fortinet FortiAnalyzer version 7.6.0 through 7.6.3 and before 7.4.6 allows an unauthenticated a…

Fix: 7.4.7 / 7.6.4+
Fix from $1,600 2025-10-14
Factorytalk View CRITICAL 9.8
CVE-2025-9063

An authentication bypass security issue exists within FactoryTalk View Machine Edition Web Browser ActiveX control. Exploitation of this vulnerabili…

Fix: after 15.0
Fix from $2,300 2025-10-14
Factorytalk View CRITICAL 9.1
CVE-2025-9064

A path traversal security issue exists within FactoryTalk View Machine Edition, allowing unauthenticated attackers on the same network as the device …

Fix: after 15.0
Fix from $2,300 2025-10-14