Vulnerability index

Browse CVEs

4,337 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
Student Study Center Desk Management System CRITICAL 9.8
CVE-2023-44752

An issue in Student Study Center Desk Management System v1.0 allows attackers to bypass authentication via a crafted GET request to /php-sscdms/admin…

No fix yet
Fix from $2,300 2025-04-22
Performance Cluster Manager HIGH 8.1
CVE-2025-27086

A vulnerability in the HPE Performance Cluster Manager (HPCM) GUI could allow an attacker to bypass authentication.

Fix: 1.13+
Fix from $1,950 2025-04-21
Zulip Server HIGH 8.2
CVE-2025-31478

Zulip is an open-source team collaboration tool. Zulip supports a configuration where account creation is limited solely by being able to authenticat…

Fix: 10.2+
Fix from $1,950 2025-04-16
Unclassified CRITICAL 9.6
CVE-2025-30215

NATS-Server is a High-Performance server for NATS.io, the cloud and edge native messaging system. In versions starting from 2.2.0 but prior to 2.10.2…

Mitigation only
Fix from $2,300 2025-04-16
Rdbms Listener MEDIUM 6.5
CVE-2025-30733

Vulnerability in the RDBMS Listener component of Oracle Database Server. Supported versions that are affected are 19.3-19.26, 21.3-21.17 and 23.4-2…

Fix: after 23.7
Fix from $1,600 2025-04-15
Steve MEDIUM 5.9
CVE-2024-44843

An issue in the web socket handshake process of SteVe v3.7.1 allows attackers to bypass authentication and execute arbitrary coammands via supplying …

No fix yet
Fix from $1,600 2025-04-15
Joturl MEDIUM 6.5
CVE-2025-24949

In JotUrl 2.0, is possible to bypass security requirements during the password change process.

No fix yet
Fix from $1,600 2025-04-15
Whatsup Gold MEDIUM 5.3
CVE-2025-2572

In WhatsUp Gold versions released before 2024.0.3, a database manipulation vulnerability allows an unauthenticated attacker to modify the content…

Fix: 24.0.3+
Fix from $1,600 2025-04-14
Unclassified MEDIUM 5.3
CVE-2025-22232

Spring Cloud Config Server may not use Vault token sent by clients using a X-CONFIG-TOKEN header when making requests to Vault. Your application may …

Mitigation only
Fix from $1,600 2025-04-10
Unclassified CRITICAL 9.3
CVE-2025-22375

An authentication bypass vulnerability was found in Videx's CyberAudit-Web. Through the exploitation of a logic flaw, an attacker could create a vali…

Mitigation only
Fix from $2,300 2025-04-10
Coldfusion HIGH 8.2
CVE-2025-30287

ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Authentication vulnerability that could result in arbitrary code…

Mitigation only
Fix from $1,950 2025-04-08
Coldfusion CRITICAL 9.1
CVE-2025-30282

ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Authentication vulnerability that could result in arbitrary code…

Mitigation only
Fix from $2,300 2025-04-08
Joomla\! HIGH 7.5
CVE-2025-25227

Insufficient state checks lead to a vector that allows to bypass 2FA checks.

Fix: 4.4.13 / 5.2.6+
Fix from $1,950 2025-04-08
Tinywebserver CRITICAL 9.8
CVE-2025-3268

A vulnerability has been found in qinguoyi TinyWebServer up to 1.0 and classified as critical. This vulnerability affects unknown code of the file ht…

Fix: after 1.0
Fix from $2,300 2025-04-04
Material Admin MEDIUM 6.6
CVE-2025-3061

Vulnerability in Drupal Material Admin.This issue affects Material Admin: *.*.

No fix yet
Fix from $1,600 2025-03-31
Admin Lte Theme MEDIUM 6.6
CVE-2025-3062

Vulnerability in Drupal Drupal Admin LTE theme.This issue affects Drupal Admin LTE theme: *.*.

No fix yet
Fix from $1,600 2025-03-31
Ipados CRITICAL 9.8
CVE-2025-30430

This issue was addressed through improved state management. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, visionOS 2.4, watchO…

Fix: 2.4 / 15.4+
Fix from $2,300 2025-03-31
Ipados MEDIUM 6.4
CVE-2025-30432

A logic issue was addressed with improved state management. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sonoma 14.7.5, macO…

Fix: 2.4 / 13.7.5+
Fix from $1,600 2025-03-31
Unclassified CRITICAL 9.0
CVE-2025-31122

scratch-coding-hut.github.io is the website for Coding Hut. In 1.0-beta3 and earlier, the login link can be used to login to any account by changing …

Mitigation only
Fix from $2,300 2025-03-31
Unclassified CRITICAL 9.8
CVE-2024-13804

Unauthenticated RCE in HPE Insight Cluster Management Utility

No fix yet
Fix from $2,300 2025-03-30
Satech Bcu Firmware CRITICAL 9.8
CVE-2025-2859

An attacker with network access, could capture traffic and obtain user cookies, allowing the attacker to steal the active user session and make chang…

Mitigation only
Fix from $2,300 2025-03-28
Wegia CRITICAL 9.8
CVE-2025-30361

WeGIA is a Web manager for charitable institutions. A security vulnerability was identified in versions prior to 3.2.6, where it is possible to chang…

Fix: 3.2.6+
Fix from $2,300 2025-03-27
Frappe HIGH 7.5
CVE-2025-30214

Frappe is a full-stack web application framework. Prior to versions 14.89.0 and 15.51.0, making crafted requests could lead to information disclosure…

Fix: 14.89.0 / 15.51.0+
Fix from $1,950 2025-03-25
Unclassified MEDIUM 6.9
CVE-2025-30168

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 7.5.2 and 8.0.2, the 3rd party authe…

Patch available
Fix from $1,600 2025-03-21
Ioffice20 HIGH 7.7
CVE-2024-57490

Guangzhou Hongfan Technology Co., LTD. iOffice20 has any user login vulnerability. An attacker can log in to any system account including the system …

Mitigation only
Fix from $1,950 2025-03-21
Unclassified HIGH 7.4
CVE-2025-22228

BCryptPasswordEncoder.matches(CharSequence,String) will incorrectly return true for passwords larger than 72 characters as long as the first 72 chara…

Mitigation only
Fix from $1,950 2025-03-20
Secure Connect Gateway MEDIUM 5.5
CVE-2025-26475

Dell Secure Connect Gateway (SCG) 5.0 Appliance - SRS, version(s) 5.26, Enables Live-Restore setting which enhances security by keeping containers ru…

Patch available
Fix from $1,600 2025-03-19
Dr 820 Firmware CRITICAL 9.1
CVE-2025-30114

An issue was discovered on the Forvia Hella HELLA Driving Recorder DR 820. Bypassing of Device Pairing can occur. The pairing mechanism relies solely…

Mitigation only
Fix from $2,300 2025-03-18
Dr 820 Firmware HIGH 7.5
CVE-2025-30116

An issue was discovered on the Forvia Hella HELLA Driving Recorder DR 820. Remotely Dumping of Video Footage and the Live Video Stream can occur. It …

Mitigation only
Fix from $1,950 2025-03-18
Unclassified HIGH 7.3
CVE-2025-2388

A vulnerability was found in Keytop 路内停车收费系统 2.7.1. It has been declared as critical. Affected by this vulnerability is an unknown functional…

Mitigation only
Fix from $1,950 2025-03-17