Vulnerability index

Browse CVEs

4,337 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
Unclassified CRITICAL 9.8
CVE-2025-7574

A vulnerability, which was classified as critical, was found in LB-LINK BL-AC1900, BL-AC2100_AZ3, BL-AC3600, BL-AX1800, BL-AX5400P and BL-WR9000 up t…

Mitigation only
Fix from $2,300 2025-07-14
HTTP Server HIGH 7.4
CVE-2025-49812

In some mod_ssl configurations on Apache HTTP Server versions through to 2.4.63, an HTTP desynchronisation attack allows a man-in-the-middle attacker…

Fix: 2.4.64+
Fix from $1,950 2025-07-10
Sharepoint Enterprise Server MEDIUM 6.5
CVE-2025-49706 KEVEPSS 100%

Improper authentication in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.

Fix: 16.0.18526.20424+
Fix from $1,600 2025-07-08
Unclassified MEDIUM 6.9
CVE-2025-53545

Press, a Frappe custom app that runs Frappe Cloud, manages infrastructure, subscription, marketplace, and software-as-a-service (SaaS). Users can cir…

Patch available
Fix from $1,600 2025-07-08
Ar8035 Firmware CRITICAL 9.1
CVE-2025-21450

Cryptographic issue occurs due to use of insecure connection method while downloading.

No fix yet
Fix from $2,300 2025-07-08
Chrome Os MEDIUM 6.1
CVE-2025-6044

An Improper Access Control vulnerability in the Stylus Tools component of Google ChromeOS version 16238.64.0 on the garaged stylus devices allows a p…

Mitigation only
Fix from $1,600 2025-07-07
Sim HIGH 7.5
CVE-2025-7114

A vulnerability was found in SimStudioAI sim up to 37786d371e17d35e0764e1b5cd519d873d90d97b. It has been declared as critical. Affected by this vulne…

Fix: after 0.2.1
Fix from $1,950 2025-07-07
Unclassified HIGH 7.3
CVE-2025-7115

A vulnerability was found in rowboatlabs rowboat up to 8096eaf63b5a0732edd8f812bee05b78e214ee97. It has been rated as critical. Affected by this issu…

Mitigation only
Fix from $1,950 2025-07-07
Harmonyos HIGH 7.6
CVE-2025-53169

Vulnerability of bypassing the process to start SA and use related functions on distributed cameras Impact: Successful exploitation of this vulnerabi…

Mitigation only
Fix from $1,950 2025-07-07
Internet Security MEDIUM 6.1
CVE-2025-7095

A vulnerability classified as critical has been found in Comodo Internet Security Premium 12.3.4.8162. This affects an unknown part of the component …

No fix yet
Fix from $1,600 2025-07-06
Unclassified HIGH 8.8
CVE-2025-6926

Improper Authentication vulnerability in Wikimedia Foundation Mediawiki - CentralAuth Extension allows : Bypass Authentication.This issue affects Med…

Mitigation only
Fix from $1,950 2025-07-03
Unclassified MEDIUM 5.7
CVE-2025-52294

Insufficient validation of the screen lock mechanism in Trust Wallet v8.45 allows physically proximate attackers to bypass the lock screen and view t…

Mitigation only
Fix from $1,600 2025-07-01
T6 Firmware HIGH 8.8
CVE-2025-6916

A vulnerability, which was classified as critical, was found in TOTOLINK T6 4.1.5cu.748_B20211015. This affects the function Form_Login of the file /…

No fix yet
Fix from $1,950 2025-06-30
Unclassified MEDIUM 6.8
CVE-2025-24292

A misconfigured query in UniFi Network (v9.1.120 and earlier) could allow users to authenticate to Enterprise WiFi or VPN Server (l2tp and OpenVPN) u…

Mitigation only
Fix from $1,600 2025-06-29
Authentik CRITICAL 9.6
CVE-2025-52553

authentik is an open-source identity provider. After authorizing access to a RAC endpoint, authentik creates a token which is used for a single conne…

Fix: 2025.4.3 / 2025.6.3+
Fix from $2,300 2025-06-27
T7611 Firmware HIGH 8.1
CVE-2025-6763

A vulnerability was found in Comet System T0510, T3510, T3511, T4511, T6640, T7511, T7611, P8510, P8552 and H3531 1.60. Affected by this issue is som…

No fix yet
Fix from $1,950 2025-06-27
Unclassified MEDIUM 5.2
CVE-2025-53013

Himmelblau is an interoperability suite for Microsoft Azure Entra ID and Intune. A vulnerability present in versions 0.9.10 through 0.9.16 allows a u…

Patch available
Fix from $1,600 2025-06-26
Cloud Init HIGH 8.8
CVE-2024-6174

When a non-x86 platform is detected, cloud-init grants root access to a hardcoded url with a local IP address. To prevent this, cloud-init default co…

Fix: 25.1.3+
Fix from $1,950 2025-06-26
Unclassified CRITICAL 10.0
CVE-2025-52572

Hikka, a Telegram userbot, has vulnerability affects all users on all versions of Hikka. Two scenarios are possible. 1. Web interface does not have a…

Mitigation only
Fix from $2,300 2025-06-24
Unclassified CRITICAL 9.6
CVE-2025-52571

Hikka is a Telegram userbot. A vulnerability affects all users of versions below 1.6.2, including most of the forks. It allows an unauthenticated att…

Patch available
Fix from $2,300 2025-06-24
Control Id Idsecure CRITICAL 9.8
CVE-2025-49851

ControlID iDSecure On-premises versions 4.7.48.0 and prior are vulnerable to an improper authentication vulnerability which could allow an attacker t…

Fix: 4.7.50.0+
Fix from $2,300 2025-06-24
Kace Systems Management Appliance CRITICAL 10.0
CVE-2025-32975 KEV

Quest KACE Systems Management Appliance (SMA) 13.0.x before 13.0.385, 13.1.x before 13.1.81, 13.2.x before 13.2.183, 14.0.x before 14.0.341 (Patch 5)…

Fix: 13.0.385 / 13.1.81+
Fix from $2,300 2025-06-24
Novel Plus MEDIUM 5.9
CVE-2025-6533

A vulnerability, which was classified as critical, has been found in xxyopen/201206030 novel-plus up to 5.1.3. Affected by this issue is the function…

Fix: after 5.1.3
Fix from $1,600 2025-06-24
Unclassified CRITICAL 9.6
CVE-2024-45347

An unauthorized access vulnerability exists in the Xiaomi Mi Connect Service APP. The vulnerability is caused by the validation logic is flawed and c…

Mitigation only
Fix from $2,300 2025-06-23
Coros Pace 3 Firmware CRITICAL 9.8
CVE-2025-32877

An issue was discovered on COROS PACE 3 devices through 3.0808.0. It identifies itself as a device without input or output capabilities, which result…

Fix: after 3.0808.0
Fix from $2,300 2025-06-20
Coros Pace 3 Firmware HIGH 8.8
CVE-2025-32879

An issue was discovered on COROS PACE 3 devices through 3.0808.0. It starts advertising if no device is connected via Bluetooth. This allows an attac…

Fix: after 3.0808.0
Fix from $1,950 2025-06-20
Unclassified MEDIUM 5.7
CVE-2025-32875

An issue was discovered in the COROS application through 3.8.12 for Android. Bluetooth pairing and bonding is neither initiated nor enforced by the a…

Mitigation only
Fix from $1,600 2025-06-20
Cryptpad CRITICAL 9.1
CVE-2025-49591

CryptPad is a collaboration suite. Prior to version 2025.3.0, enforcement of Two-Factor Authentication (2FA) in CryptPad can be trivially bypassed, d…

Fix: 2025.3.0+
Fix from $2,300 2025-06-18
Unclassified CRITICAL 9.8
CVE-2025-6172

Permission vulnerability in the mobile application (com.afmobi.boomplayer) may lead to the risk of unauthorized operation.

Mitigation only
Fix from $2,300 2025-06-16
Unclassified MEDIUM 6.4
CVE-2024-38825

The salt.auth.pki module does not properly authenticate callers. The "password" field contains a public certificate which is validated against a CA c…

Mitigation only
Fix from $1,600 2025-06-13