Vulnerability index

Browse CVEs

4,337 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
Hoverfly HIGH 7.5
CVE-2025-54376

Hoverfly is an open source API simulation tool. In versions 1.11.3 and prior, Hoverfly’s admin WebSocket endpoint /api/v2/ws/logs is not protected by…

Fix: 1.12.0+
Fix from $1,950 2025-09-10
Unclassified MEDIUM 5.7
CVE-2025-56578

An issue in RTSPtoWeb v.2.4.3 allows a remote attacker to obtain sensitive information and executearbitrary code via the lack of authentication mecha…

Mitigation only
Fix from $1,600 2025-09-10
Axxon One HIGH 7.1
CVE-2025-10224

Improper Authentication (CWE-287) in the LDAP authentication engine in AxxonSoft Axxon One (C-Werk) 2.0.2 and earlier on Windows allows a remote auth…

Fix: after 2.0.2
Fix from $1,950 2025-09-10
Bl Cpe300m Firmware HIGH 8.8
CVE-2025-57278

The LB-Link BL-CPE300M AX300 4G LTE Router firmware version BL-R8800_B10_ALK_SL_V01.01.02P42U14_06 does not implement proper session handling. After …

No fix yet
Fix from $1,950 2025-09-09
Windows 10 1507 CRITICAL 9.8
CVE-2025-55234EPSS 20%

SMB Server might be susceptible to relay attacks depending on the configuration. An attacker who successfully exploited these vulnerabilities could p…

Fix: 10.0.10240.21128 / 10.0.14393.8422+
Fix from $2,300 2025-09-09
Windows 10 1507 HIGH 8.8
CVE-2025-54918EPSS 19%

Improper authentication in Windows NTLM allows an authorized attacker to elevate privileges over a network.

Fix: 10.0.10240.21128 / 10.0.14393.8422+
Fix from $1,950 2025-09-09
Unclassified CRITICAL 9.8
CVE-2025-9994

The Amp’ed RF BT-AP 111 Bluetooth access point's HTTP admin interface does not have an authentication feature, allowing unauthorized access to anyone…

Mitigation only
Fix from $2,300 2025-09-09
Fogproject CRITICAL 9.1
CVE-2025-58443EPSS 19%

FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Versions 1.5.10.1673 and below contain an authentication bypass v…

Fix: after 1.5.10.1673
Fix from $2,300 2025-09-06
Entra Id CRITICAL 10.0
CVE-2025-55241

Azure Entra ID Elevation of Privilege Vulnerability

No fix yet
Fix from $2,300 2025-09-04
Android HIGH 8.8
CVE-2025-26438

In smp_process_secure_connection_oob_data of smp_act.cc, there is a possible way to bypass SMP authentication due to Incorrect implementation of a pr…

Patch available
Fix from $1,950 2025-09-04
Rg Es228gs P Firmware CRITICAL 9.4
CVE-2025-56752

A vulnerability in the Ruijie RG-ES series switch firmware ESW_1.0(1)B1P39 enables remote attackers to fully bypass authentication mechanisms, provid…

Mitigation only
Fix from $2,300 2025-09-03
Exynos CRITICAL 9.8
CVE-2023-21467

Error in 3GPP specification implementation in Exynos baseband prior to SMR Apr-2023 Release 1 allows incorrect handling of unencrypted message.

Mitigation only
Fix from $2,300 2025-09-03
Android HIGH 7.3
CVE-2024-40653

In multiple functions of ConnectionServiceWrapper.java, there is a possible way to retain a permission forever in the background due to a logic error…

Mitigation only
Fix from $1,950 2025-09-02
Batterykid HIGH 7.8
CVE-2025-9815

A weakness has been identified in alaneuler batteryKid up to 2.1 on macOS. The affected element is an unknown function of the file PrivilegeHelper/Pr…

Fix: after 2.1
Fix from $1,950 2025-09-02
Qvr CRITICAL 9.8
CVE-2025-52856

An improper authentication vulnerability has been reported to affect VioStor. If a remote attacker, they can then exploit the vulnerability to compro…

Fix: 5.1.6+
Fix from $2,300 2025-08-29
Ac8 Firmware MEDIUM 5.3
CVE-2025-52054

An issue was discovered in Tenda AC8 v4.0 AC1200 Dual-band Gigabit Wireless Router AC8v4.0 Firmware 16.03.33.05. The root password of the device is c…

Fix: after 16.03.33.05
Fix from $1,600 2025-08-28
Unclassified CRITICAL 9.8
CVE-2025-7955

The RingCentral Communications plugin for WordPress is vulnerable to Authentication Bypass due to improper validation within the ringcentral_admin_lo…

Mitigation only
Fix from $2,300 2025-08-28
T10 Firmware CRITICAL 9.8
CVE-2025-9533EPSS 9%

A vulnerability has been found in TOTOLINK T10 4.1.8cu.5241_B20210927. Affected is an unknown function of the file /formLoginAuth.htm. The manipulati…

Mitigation only
Fix from $2,300 2025-08-27
Unclassified CRITICAL 9.8
CVE-2024-52786

An authentication bypass vulnerability in anji-plus AJ-Report up to v1.4.2 allows unauthenticated attackers to execute arbitrary code via a crafted U…

Mitigation only
Fix from $2,300 2025-08-22
Unclassified CRITICAL 9.8
CVE-2024-50645

MallChat v1.0-SNAPSHOT has an authentication bypass vulnerability. An attacker can exploit this vulnerability to access API without any token.

Mitigation only
Fix from $2,300 2025-08-22
Unclassified CRITICAL 9.8
CVE-2024-50644

zhisheng17 blog 3.0.1-SNAPSHOT has an authentication bypass vulnerability. An attacker can exploit this vulnerability to access API without any token.

Mitigation only
Fix from $2,300 2025-08-22
Unclassified HIGH 8.1
CVE-2024-50641

An authentication bypass vulnerability in PandoraNext-TokensTool v0.6.8 and before. An attacker can exploit this vulnerability to access API without …

Mitigation only
Fix from $1,950 2025-08-21
Unclassified CRITICAL 9.8
CVE-2025-52395

An issue in Roadcute API v.1 allows a remote attacker to execute arbitrary code via the application exposing a password reset API endpoint that fails…

Mitigation only
Fix from $2,300 2025-08-21
Jeewms CRITICAL 9.8
CVE-2025-50901

JeeWMS 771e4f5d0c01ffdeae1671be4cf102b73a3fe644 (2025-05-19) contains incorrect authentication bypass vulnerability, which can lead to arbitrary file…

Mitigation only
Fix from $2,300 2025-08-20
Unclassified CRITICAL 9.8
CVE-2024-50640

jeewx-boot 1.3 has an authentication bypass vulnerability in the preHandle function

Mitigation only
Fix from $2,300 2025-08-20
Unclassified HIGH 8.8
CVE-2024-57491

Authentication Bypass vulnerability in jobx up to v1.0.1-RELEASE allows an attacker can exploit this vulnerability to access sensitive API without an…

Mitigation only
Fix from $1,950 2025-08-20
Meshtastic Firmware CRITICAL 9.8
CVE-2025-55293

Meshtastic is an open source mesh networking solution. Prior to v2.6.3, an attacker can send NodeInfo with a empty publicKey first, then overwrite it…

Fix: 2.6.3+
Fix from $2,300 2025-08-18
Hostel Management System HIGH 7.8
CVE-2025-8964

A vulnerability was identified in code-projects Hostel Management System 1.0. This affects an unknown part of the file hostel_manage.exe of the compo…

No fix yet
Fix from $1,950 2025-08-14
Ex1200t Firmware CRITICAL 9.8
CVE-2025-51451

In TOTOLINK EX1200T firmware 4.1.2cu.5215, an attacker can bypass login by sending a specific request through formLoginAuth.htm.

Mitigation only
Fix from $2,300 2025-08-13
Wegia HIGH 7.5
CVE-2025-55171

WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. Prior to version 3.4.8, the application does…

Fix: 3.4.8+
Fix from $1,950 2025-08-12