Vulnerability index

Browse CVEs

4,337 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
Wegia MEDIUM 6.5
CVE-2025-55169

WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. Prior to version 3.4.8, a path traversal vul…

Fix: 3.4.8+
Fix from $1,600 2025-08-12
Azure Stack Hub HIGH 7.5
CVE-2025-53793

Improper authentication in Azure Stack allows an unauthorized attacker to disclose information over a network.

Fix: 1.2406.1.23 / 1.2408.1.50+
Fix from $1,950 2025-08-12
Windows 10 1507 HIGH 8.8
CVE-2025-53778EPSS 38%

Improper authentication in Windows NTLM allows an authorized attacker to elevate privileges over a network.

Fix: 10.0.10240.21100 / 10.0.14393.8330+
Fix from $1,950 2025-08-12
My Site CRITICAL 9.8
CVE-2025-8838

A vulnerability has been found in WinterChenS my-site up to 1f7525f15934d9d6a278de967f6ec9f1757738d8. This vulnerability affects the function preHand…

Mitigation only
Fix from $2,300 2025-08-11
Unclassified HIGH 8.7
CVE-2025-54888

Fedify is a TypeScript library for building federated server apps powered by ActivityPub. In versions below 1.3.20, 1.4.0-dev.585 through 1.4.12, 1.5…

Patch available
Fix from $1,950 2025-08-09
Suitecrm MEDIUM 5.3
CVE-2025-54786

SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. In versions 7.14.6 and 8.8.0, the broken au…

Mitigation only
Fix from $1,600 2025-08-07
Exchange Server HIGH 8.0
CVE-2025-53786EPSS 7%

On April 18th 2025, Microsoft announced Exchange Server Security Changes for Hybrid Deployments and accompanying non-security Hot Fix. Microsoft made…

Fix: 15.02.2562.017+
Fix from $1,950 2025-08-06
Pybbs MEDIUM 5.3
CVE-2025-8546

A vulnerability, which was classified as problematic, was found in atjiu pybbs up to 6.0.0. This affects the function adminlogin/login of the compone…

Fix: after 6.0.0
Fix from $1,600 2025-08-05
Charging Pile Cloud Platform HIGH 7.5
CVE-2025-8348

A vulnerability has been found in Kehua Charging Pile Cloud Platform 1.0 and classified as critical. This vulnerability affects unknown code of the f…

No fix yet
Fix from $1,950 2025-07-31
Computer Vision Annotation Tool MEDIUM 6.5
CVE-2025-54573

CVAT is an open source interactive video and image annotation tool for computer vision. In versions 1.1.0 through 2.41.0, email verification was not …

Fix: 2.42.0+
Fix from $1,600 2025-07-30
Hybrid Data Pipeline HIGH 8.1
CVE-2025-6505

Unauthorized access and impersonation can occur in versions 4.6.2.3226 and below of Progress Software's Hybrid Data Pipeline Server on Linux. This vu…

Fix: 4.6.2.3275+
Fix from $1,950 2025-07-29
Unclassified CRITICAL 10.0
CVE-2025-54419

A SAML library not dependent on any frameworks that runs in Node. In version 5.0.1, Node-SAML loads the assertion from the (unsigned) original respon…

Patch available
Fix from $2,300 2025-07-28
Chavara Matrimony CRITICAL 9.8
CVE-2025-45777

An issue in the OTP mechanism of Chavara Family Welfare Centre Chavara Matrimony Site v2.0 allows attackers to bypass authentication via supplying a …

Mitigation only
Fix from $2,300 2025-07-25
Intelliops Event Management MEDIUM 5.9
CVE-2025-0249

HCL IEM is affected by an improper invalidation of access or JWT token vulnerability.  A token was not invalidated which may allow attackers to acces…

Mitigation only
Fix from $1,600 2025-07-25
Unclassified HIGH 7.0
CVE-2024-12310

A vulnerability in Imprivata Enterprise Access Management (formerly Imprivata OneSign) allows bypassing the login screen of the shared kiosk workstat…

Mitigation only
Fix from $1,950 2025-07-23
Magicinfo 9 Server CRITICAL 9.8
CVE-2025-54452

Improper Authentication vulnerability in Samsung Electronics MagicINFO 9 Server allows Authentication Bypass.This issue affects MagicINFO 9 Server: l…

Fix: 21.1080.0+
Fix from $2,300 2025-07-23
Unclassified HIGH 7.8
CVE-2025-41459

Insufficient protection against brute-force and runtime manipulation in the local authentication component in Two App Studio Journey 5.5.6 on iOS all…

Mitigation only
Fix from $1,950 2025-07-21
Metal As A Service CRITICAL 9.8
CVE-2024-6107

Due to insufficient verification, an attacker could use a malicious client to bypass authentication checks and run RPC commands in a region. This has…

Fix: 3.1.4 / 3.2.11+
Fix from $2,300 2025-07-21
Sharepoint Server MEDIUM 6.5
CVE-2025-53771EPSS 100%

Improper authentication in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.

Fix: 16.0.18526.20508+
Fix from $1,600 2025-07-20
Moneyprinterturbo CRITICAL 9.8
CVE-2025-7897

A vulnerability was found in harry0703 MoneyPrinterTurbo up to 1.2.6 and classified as critical. Affected by this issue is the function verify_token …

Fix: after 1.2.6
Fix from $2,300 2025-07-20
Metacrm HIGH 7.5
CVE-2025-7875

A vulnerability classified as critical has been found in Metasoft 美特软件 MetaCRM up to 6.4.2. This affects an unknown part of the file /debug.jsp. …

Fix: after 6.4.2
Fix from $1,950 2025-07-20
T6 Firmware CRITICAL 9.8
CVE-2025-7862

A vulnerability has been found in TOTOLINK T6 4.1.5cu.748_B20211015 and classified as critical. Affected by this vulnerability is the function setTel…

Mitigation only
Fix from $2,300 2025-07-20
Autopass License Server CRITICAL 9.8
CVE-2025-37106

An authentication bypass and disclosure of information vulnerability exists in HPE AutoPass License Server (APLS) prior to 9.18.

Fix: 9.18+
Fix from $2,300 2025-07-16
Autopass License Server CRITICAL 9.8
CVE-2025-37107

An authentication bypass vulnerability exists in HPE AutoPass License Server (APLS) prior to 9.18.

Fix: 9.18+
Fix from $2,300 2025-07-16
Unclassified HIGH 7.1
CVE-2025-7699

An improper access control vulnerability was found in the EZ Sync Manager of ADM, which allows authenticated users to copy arbitrary files from the …

Mitigation only
Fix from $1,950 2025-07-16
Conjur CRITICAL 9.8
CVE-2025-49831

An attacker of Secrets Manager, Self-Hosted installations that route traffic from Secrets Manager to AWS through a misconfigured network device can r…

Fix: 1.22.1 / 13.5.1+
Fix from $2,300 2025-07-15
Unclassified CRITICAL 9.8
CVE-2025-52376EPSS 10%

An authentication bypass vulnerability in the /web/um_open_telnet.cgi endpoint in Nexxt Solutions NCM-X1800 Mesh Router firmware UV1.2.7 and below, a…

Mitigation only
Fix from $2,300 2025-07-15
Unclassified CRITICAL 9.6
CVE-2025-3621

Vulnerabilities* in ActADUR local server product, developed and maintained by ProTNS, allows Remote Code Inclusion on host systems.  * vulnerabilit…

Mitigation only
Fix from $2,300 2025-07-15
Directus MEDIUM 6.5
CVE-2025-53889

Directus is a real-time API and App dashboard for managing SQL database content. Starting in version 9.12.0 and prior to version 11.9.0, Directus Flo…

Fix: 11.9.0+
Fix from $1,600 2025-07-15
Autopass License Server HIGH 7.3
CVE-2024-51767

An authentication bypass vulnerability exists in HPE AutoPass License Server (APLS) prior to 9.17.

Fix: 9.17+
Fix from $1,950 2025-07-14