Vulnerability index

Browse CVEs

4,337 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
Unclassified CRITICAL 10.0
CVE-2025-9265

A broken authorization vulnerability in Kiloview NDI N30 allows a remote unauthenticated attacker to deactivate user verification, giving them access…

Mitigation only
Fix from $2,300 2025-10-13
School Management System CRITICAL 9.8
CVE-2025-11661

A vulnerability was found in ProjectsAndPrograms School Management System up to 6b6fae5426044f89c08d0dd101c7fa71f9042a59. This affects an unknown par…

Mitigation only
Fix from $2,300 2025-10-13
Furbo Mini Firmware MEDIUM 5.9
CVE-2025-11633

A vulnerability was identified in Tomofun Furbo 360 and Furbo Mini. Affected by this issue is the function upload_file_to_s3 of the file collect_logs…

Fix: after 074
Fix from $1,600 2025-10-12
Configurator HIGH 7.5
CVE-2025-61884 KEVEPSS 98%

Vulnerability in the Oracle Configurator product of Oracle E-Business Suite (component: Runtime UI). Supported versions that are affected are 12.2.3…

Fix: after 12.2.14
Fix from $1,950 2025-10-12
Simple Car Rental System CRITICAL 9.9
CVE-2025-60306

code-projects Simple Car Rental System 1.0 has a permission bypass issue where low privilege users can forge high privilege sessions and perform sens…

Mitigation only
Fix from $2,300 2025-10-10
Churchcrm CRITICAL 9.8
CVE-2025-11529

A security flaw has been discovered in ChurchCRM up to 5.18.0. This impacts the function AuthMiddleware of the file src/ChurchCRM/Slim/Middleware/Aut…

Fix: 5.19.0+
Fix from $2,300 2025-10-09
Fabric Engine \(voss\) HIGH 8.6
CVE-2025-11192

A vulnerability in Extreme Networks’ Fabric Engine (VOSS) before 9.3 was discovered. When SD-WAN AutoSense is enabled on a port, it may automatically…

Fix: 9.3+
Fix from $1,950 2025-10-07
Mcphub CRITICAL 9.8
CVE-2025-11287

A vulnerability was identified in samanhappy MCPHub up to 0.9.10. This vulnerability affects the function handleSseConnectionfunction of the file src…

Fix: after 0.9.10
Fix from $2,300 2025-10-05
Concurrent Processing CRITICAL 9.8
CVE-2025-61882 KEVEPSS 100%

Vulnerability in the Oracle Concurrent Processing product of Oracle E-Business Suite (component: BI Publisher Integration). Supported versions that …

Fix: after 12.2.14
Fix from $2,300 2025-10-05
Unclassified HIGH 7.7
CVE-2025-61679

Anyquery is an SQL query engine built on top of SQLite. Versions 0.4.3 and below allow attackers who have already gained access to localhost, even wi…

Patch available
Fix from $1,950 2025-10-03
Authenticator MEDIUM 6.8
CVE-2025-54154

An improper authentication vulnerability has been reported to affect QNAP Authenticator. If an attacker gains physical access, they can then exploit …

Fix: 1.3.1.1227+
Fix from $1,600 2025-10-03
Wegia HIGH 7.5
CVE-2025-61665

WeGIA is an open source web manager with a focus on charitable institutions. Versions 3.4.12 and below contain a Broken Access Control vulnerability,…

Fix: 3.5.0+
Fix from $1,950 2025-10-02
Unclassified CRITICAL 9.3
CVE-2025-41064

Incorrect authentication vulnerability in OpenSIAC, which could allow an attacker to impersonate a person using Cl@ve as an authentication method.

Mitigation only
Fix from $2,300 2025-10-02
Unclassified HIGH 8.4
CVE-2025-11130

A weakness has been identified in iHongRen pptp-vpn 1.0/1.0.1 on macOS. This issue affects the function shouldAcceptNewConnection of the file HelpToo…

Mitigation only
Fix from $1,950 2025-09-29
Unclassified CRITICAL 9.4
CVE-2025-59934EPSS 8%

Formbricks is an open source qualtrics alternative. Prior to version 4.0.1, Formbricks is missing JWT signature verification. This vulnerability stem…

Patch available
Fix from $2,300 2025-09-26
Unclassified HIGH 8.1
CVE-2025-20160

A vulnerability in the implementation of the TACACS+ protocol in Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote …

Mitigation only
Fix from $1,950 2025-09-24
Unclassified HIGH 8.4
CVE-2025-10906

A flaw has been found in Magnetism Studios Endurance up to 3.3.0 on macOS. This affects the function loadModuleNamed:WithReply of the file /Applicati…

Mitigation only
Fix from $1,950 2025-09-24
Identity Server MEDIUM 6.8
CVE-2025-0663

A cross-tenant authentication vulnerability exists in multiple WSO2 products due to improper cryptographic design in Adaptive Authentication. A singl…

Mitigation only
Fix from $1,600 2025-09-23
Unclassified CRITICAL 9.3
CVE-2025-9965

Improper authentication vulnerability in Novakon P series allows unauthenticated attackers to upload and download any application from/to the device.…

Mitigation only
Fix from $2,300 2025-09-23
Creabox Manager HIGH 8.8
CVE-2025-57434

Creacast Creabox Manager contains a critical authentication flaw that allows an attacker to bypass login validation. The system grants access when th…

No fix yet
Fix from $1,950 2025-09-22
Unclassified MEDIUM 6.3
CVE-2025-10772

A vulnerability was identified in huggingface LeRobot up to 0.3.3. Affected by this vulnerability is an unknown functionality of the file lerobot/com…

Mitigation only
Fix from $1,600 2025-09-22
Ppress HIGH 8.0
CVE-2025-54761

An issue was discovered in PPress 0.0.9 allowing attackers to gain escilated privlidges via crafted session cookie.

No fix yet
Fix from $1,950 2025-09-19
Unclassified HIGH 7.8
CVE-2025-10672

A vulnerability was found in whuan132 AIBattery up to 1.0.9. The affected element is an unknown function of the file AIBatteryHelper/XPC/BatteryXPCSe…

Mitigation only
Fix from $1,950 2025-09-18
Eve X1 Server Firmware CRITICAL 9.8
CVE-2025-34186

Ilevia EVE X1/X5 Server version ≤ 4.7.18.0.eden contains a vulnerability in its authentication mechanism. Unsanitized input is passed to a system() c…

Fix: after 4.7.18.0
Fix from $2,300 2025-09-16
macOS HIGH 7.5
CVE-2025-31271

This issue was addressed through improved state management. This issue is fixed in macOS Tahoe 26. Incoming FaceTime calls can appear or be accepted …

Fix: 26.0+
Fix from $1,950 2025-09-15
Universal Traffic Recorder Firmware CRITICAL 9.1
CVE-2025-45583

Incorrect access control in the FTP protocol of Audi UTR 2.0 Universal Traffic Recorder 2.0 allows attackers to authenticate into the service using a…

No fix yet
Fix from $2,300 2025-09-12
Unclassified CRITICAL 9.3
CVE-2025-10365EPSS 6%

The Evertz SDVN 3080ipx-10G is a High Bandwidth Ethernet Switching Fabric for Video Application. This device exposes a web management interface on po…

Mitigation only
Fix from $2,300 2025-09-12
Unclassified MEDIUM 5.3
CVE-2025-10288

A vulnerability was found in roncoo roncoo-pay up to 9428382af21cd5568319eae7429b7e1d0332ff40. The impacted element is an unknown function of the fil…

Mitigation only
Fix from $1,600 2025-09-12
Flask Appbuilder MEDIUM 6.5
CVE-2025-58065

Flask-AppBuilder is an application development framework. Prior to version 4.8.1, when Flask-AppBuilder is configured to use OAuth, LDAP, or other no…

Fix: 4.8.1+
Fix from $1,600 2025-09-11
Cups HIGH 8.0
CVE-2025-58060

OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.12 and earlier, when the `AuthTy…

Fix: 2.4.13+
Fix from $1,950 2025-09-11