Vulnerability index

Browse CVEs

4,337 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
Unclassified HIGH 8.1
CVE-2025-22236

Minion event bus authorization bypass. An attacker with access to a minion key can craft a message which may be able to execute a job on other minion…

Mitigation only
Fix from $1,950 2025-06-13
Postgresql Jdbc Driver MEDIUM 5.9
CVE-2025-49146

pgjdbc is an open source postgresql JDBC Driver. From 42.7.4 and until 42.7.7, when the PostgreSQL JDBC driver is configured with channel binding set…

Fix: 42.7.7+
Fix from $1,600 2025-06-11
School Fees Payment System HIGH 7.3
CVE-2025-5985

A vulnerability was found in code-projects School Fees Payment System 1.0 and classified as critical. Affected by this issue is some unknown function…

No fix yet
Fix from $1,950 2025-06-10
Laundry System CRITICAL 9.8
CVE-2025-5906

A vulnerability classified as critical has been found in code-projects Laundry System 1.0. This affects an unknown part of the file /data/. The manip…

Mitigation only
Fix from $2,300 2025-06-10
Keeperchat MEDIUM 6.8
CVE-2025-29627

An issue in KeeperChat IOS Application v.5.8.8 allows a physically proximate attacker to escalate privileges via the Biometric Authentication Module

No fix yet
Fix from $1,600 2025-06-09
Unclassified MEDIUM 5.3
CVE-2025-5876

A vulnerability classified as problematic was found in Lucky LM-520-SC, LM-520-FSC and LM-520-FSC-SAM up to 20250321. Affected by this vulnerability …

Mitigation only
Fix from $1,600 2025-06-09
Unclassified MEDIUM 5.3
CVE-2025-5871

A vulnerability was found in Papendorf SOL Connect Center 3.3.0.0 and classified as problematic. Affected by this issue is some unknown functionality…

Mitigation only
Fix from $1,600 2025-06-09
Unclassified MEDIUM 5.3
CVE-2025-5872

A vulnerability was found in eGauge EG3000 Energy Monitor 3.6.3. It has been classified as problematic. This affects an unknown part of the component…

Mitigation only
Fix from $1,600 2025-06-09
Unclassified HIGH 7.3
CVE-2025-5870

A vulnerability has been found in TRENDnet TV-IP121W 1.1.1 Build 36 and classified as critical. Affected by this vulnerability is an unknown function…

Mitigation only
Fix from $1,950 2025-06-09
Qurouter HIGH 7.8
CVE-2024-13088

An improper authentication vulnerability has been reported to affect QHora. If an attacker gains local network access, they can then exploit the vuln…

Mitigation only
Fix from $1,950 2025-06-06
Harmonyos HIGH 7.1
CVE-2025-48909

Bypass vulnerability in the device management channel Impact: Successful exploitation of this vulnerability may affect service confidentiality.

No fix yet
Fix from $1,950 2025-06-06
Unclassified MEDIUM 5.4
CVE-2025-49012

Himmelblau is an interoperability suite for Microsoft Azure Entra ID and Intune. Himmelblau versions 0.9.0 through 0.9.14 and 1.00-alpha are vulnerab…

Patch available
Fix from $1,600 2025-06-05
Unclassified CRITICAL 10.0
CVE-2025-5597

Improper Authentication vulnerability in WF Steuerungstechnik GmbH airleader MASTER allows Authentication Bypass.This issue affects airleader MASTER:…

No fix yet
Fix from $2,300 2025-06-04
Dataease CRITICAL 9.8
CVE-2025-49001EPSS 22%

DataEase is an open source business intelligence and data visualization tool. Prior to version 2.10.10, secret verification does not take effect succ…

Fix: after 2.10.10
Fix from $2,300 2025-06-03
Shiyi Blog CRITICAL 9.8
CVE-2025-5512

A vulnerability, which was classified as critical, was found in quequnlong shiyi-blog up to 1.2.1. Affected is an unknown function of the file /api/s…

Fix: after 1.2.1
Fix from $2,300 2025-06-03
Pekko Management MEDIUM 6.5
CVE-2025-46548

If you enable Basic Authentication in Pekko Management using the Java DSL, the authenticator may not be properly applied. Users that rely on authen…

Fix: 1.6.1+
Fix from $1,600 2025-06-03
Wnr614 Firmware CRITICAL 9.8
CVE-2025-5495

A vulnerability was found in Netgear WNR614 1.1.0.28_1.0.1WW. It has been classified as critical. This affects an unknown part of the component URL H…

No fix yet
Fix from $2,300 2025-06-03
Storeonce System CRITICAL 9.8
CVE-2025-37093

An authentication bypass vulnerability exists in HPE StoreOnce Software.

Fix: 4.3.11+
Fix from $2,300 2025-06-02
Unclassified MEDIUM 5.3
CVE-2025-5437

A vulnerability classified as critical has been found in Multilaser Sirius RE016 MLT1.0. Affected is an unknown function of the file /cgi-bin/cstecgi…

Mitigation only
Fix from $1,600 2025-06-02
Directory Manager MEDIUM 6.5
CVE-2025-48746

Netwrix Directory Manager (formerly Imanami GroupID) v.11.0.0.0 and before, as well as after v.11.1.25134.03 lacks Authentication for a Critical Func…

Fix: after 11.0.0.0
Fix from $1,600 2025-05-28
Unclassified HIGH 7.3
CVE-2025-5247

A vulnerability, which was classified as critical, has been found in Gowabby HFish 0.1. This issue affects the function LoadUrl of the file \view\url…

Mitigation only
Fix from $1,950 2025-05-27
Wcms HIGH 8.1
CVE-2025-5149

A vulnerability was found in WCMS up to 8.3.11. It has been declared as critical. Affected by this vulnerability is the function getMemberByUid of th…

Fix: after 8.3.11
Fix from $1,950 2025-05-25
Identity Server MEDIUM 5.8
CVE-2024-7487

An improper authentication vulnerability exists in WSO2 Identity Server 7.0.0 due to an implementation flaw that allows app-native authentication to …

Mitigation only
Fix from $1,600 2025-05-22
Innovation CRITICAL 9.8
CVE-2024-41195

An issue in Ocuco Innovation - INNOVASERVICEINTF.EXE v2.10.24.17 allows attackers to bypass authentication and escalate privileges to Administrator v…

No fix yet
Fix from $2,300 2025-05-22
Innovation CRITICAL 9.8
CVE-2024-41196

An issue in Ocuco Innovation - REPORTSERVER.EXE v2.10.24.13 allows attackers to bypass authentication and escalate privileges to Administrator via a …

No fix yet
Fix from $2,300 2025-05-22
Innovation CRITICAL 9.8
CVE-2024-41197

An issue in Ocuco Innovation - INVCLIENT.EXE v2.10.24.5 allows attackers to bypass authentication and escalate privileges to Administrator via a craf…

No fix yet
Fix from $2,300 2025-05-22
Innovation CRITICAL 9.8
CVE-2024-41198

An issue in Ocuco Innovation - REPORTS.EXE v2.10.24.13 allows attackers to bypass authentication and escalate privileges to Administrator via a craft…

No fix yet
Fix from $2,300 2025-05-22
Innovation HIGH 7.2
CVE-2024-41199

An issue in Ocuco Innovation - JOBMANAGER.EXE v2.10.24.16 allows attackers to bypass authentication and escalate privileges to Administrator via a cr…

No fix yet
Fix from $1,950 2025-05-22
Netmri MEDIUM 6.5
CVE-2025-32815EPSS 40%

An issue was discovered in Infoblox NETMRI before 7.6.1. Authentication Bypass via a Hardcoded credential can occur.

Fix: 7.6.1+
Fix from $1,600 2025-05-22
Di 8100 Firmware CRITICAL 9.8
CVE-2025-44083

An issue in D-Link DI-8100 16.07.26A1 allows a remote attacker to bypass administrator login authentication

Mitigation only
Fix from $2,300 2025-05-21