Vulnerability index

Browse CVEs

4,337 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
MEDIUM 5.5 CVE-2026-20655 An authorization issue was addressed with improved state management. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3. A… Ipados 18.7.5 / 26.3+ Fix from $1,6002026-02-11 MEDIUM 5.3 CVE-2025-68663 Outline is a service that allows for collaborative documentation. Prior to 1.1.0, a vulnerability was found in Outline's WebSocket authentication mec… Outline 1.1.0+ Fix from $1,6002026-02-11 HIGH 8.1 CVE-2025-65128 A missing authentication mechanism in the web management API components of Shenzhen Zhibotong Electronics ZBT WE2001 23.09.27 allows unauthenticated … Mitigation only Fix from $1,9502026-02-11 MEDIUM 6.5 CVE-2025-65127 A lack of session validation in the web API component of Shenzhen Zhibotong Electronics ZBT WE2001 23.09.27 allows remote unauthenticated attackers t… Mitigation only Fix from $1,6002026-02-11 CRITICAL 9.8 CVE-2026-2248 METIS WIC devices (versions <= oscore 2.1.234-r18) expose a web-based shell at the /console endpoint that does not require authentication. Accessing … Mitigation only Fix from $2,3002026-02-11 CRITICAL 9.8 CVE-2026-2249 METIS DFS devices (versions <= oscore 2.1.234-r18) expose a web-based shell at the /console endpoint that does not require authentication. Accessing … Mitigation only Fix from $2,3002026-02-11 HIGH 7.0 CVE-2026-21508 Improper authentication in Windows Storage allows an authorized attacker to elevate privileges locally. Windows 10 1607 10.0.14393.8868 / 10.0.17763.8389+ Fix from $1,9502026-02-10 CRITICAL 9.8 CVE-2026-23906 Affected Products and Versions * Apache Druid * Affected Versions: 0.17.0 through 35.x (all versions prior to 36.0.0) * Prerequisites: * d… Druid 36.0.0+ Fix from $2,3002026-02-10 CRITICAL 9.8 CVE-2026-25893 FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Prior to 1.2.10, an authentication bypass vulnerability in FUXA allows an u… Fuxa 1.2.10+ Fix from $2,3002026-02-09 HIGH 7.3 CVE-2025-10463 Improper Authentication vulnerability in Birtech Information Technologies Industry and Trade Ltd. Co. Senseway allows Authentication Abuse. This iss… Mitigation only Fix from $1,9502026-02-09 CRITICAL 9.8 CVE-2026-2174 A security flaw has been discovered in code-projects Contact Management System 1.0. This affects an unknown part of the component CRUD Endpoint. The … Contact Management System Mitigation only Fix from $2,3002026-02-08 CRITICAL 9.8 CVE-2026-2165 A weakness has been identified in detronetdip E-commerce 1.0.0. Impacted is an unknown function of the file /Admin/assets/backend/seller/add_seller.p… E Commerce Mitigation only Fix from $2,3002026-02-08 CRITICAL 9.1 CVE-2026-25804 Antrea is a Kubernetes networking solution intended to be Kubernetes native. Prior to versions 2.3.2 and 2.4.3, Antrea's network policy priority assi… Antrea 2.3.2 / 2.4.3+ Fix from $2,3002026-02-06 HIGH 8.8 CVE-2026-2065 A security flaw has been discovered in Flycatcher Toys smART Pixelator 2.0. Affected by this issue is some unknown functionality of the component Blu… Smart Pixelator Firmware No fix yet Fix from $1,9502026-02-06 HIGH 8.8 CVE-2025-64175 Gogs is an open source self-hosted Git service. In version 0.13.3 and prior, Gogs’ 2FA recovery code validation does not scope codes by user, enablin… Gogs 0.13.4+ Fix from $1,9502026-02-06 HIGH 7.5 CVE-2025-70841 Dokans Multi-Tenancy Based eCommerce Platform SaaS 3.9.2 allows unauthenticated remote attackers to obtain sensitive application configuration data v… Dokans No fix yet Fix from $1,9502026-02-03 CRITICAL 9.6 CVE-2026-1568 Rapid7 InsightVM versions before 8.34.0 contain a signature verification issue on the Assertion Consumer Service (ACS) cloud endpoint that could allo… Mitigation only Fix from $2,3002026-02-03 CRITICAL 9.8 CVE-2026-1740 A vulnerability was found in EFM ipTIME A8004T 14.18.2. This impacts the function httpcon_check_session_url of the file /cgi/timepro.cgi of the compo… A8004t Firmware Mitigation only Fix from $2,3002026-02-02 MEDIUM 6.2 CVE-2025-62349 Salt contains an authentication protocol version downgrade weakness that can allow a malicious minion to bypass newer authentication/security feature… Mitigation only Fix from $1,6002026-01-30 MEDIUM 5.8 CVE-2025-6723 Chef InSpec versions up to 5.23 and before 7.0.107 creates named pipes with overly permissive default Windows access controls. A local attacker may i… Mitigation only Fix from $1,6002026-01-30 MEDIUM 6.5 CVE-2026-22764 Dell OpenManage Network Integration, versions prior to 3.9, contains an Improper Authentication vulnerability. A low privileged attacker with remote … Openmanage Network Integration 3.9+ Fix from $1,6002026-01-29 MEDIUM 6.5 CVE-2025-12810 Improper Authentication vulnerability in Delinea Inc. Secret Server On-Prem (RPC Password Rotation modules).This issue affects Secret Server On-Prem:… Secret Server Mitigation only Fix from $1,6002026-01-27 MEDIUM 5.3 CVE-2026-24003 EVerest is an EV charging software stack. In versions up to and including 2025.12.1, it is possible to bypass the sequence state verification includi… Everest after 2025.12.1 Fix from $1,6002026-01-26 MEDIUM 6.4 CVE-2026-1410 A vulnerability was detected in Beetel 777VR1 up to 01.00.09/01.00.09_55. Impacted is an unknown function of the component UART Interface. The manipu… 777vr1 Firmware after 01.00.09_55 Fix from $1,6002026-01-26 CRITICAL 9.8 CVE-2022-25369EPSS 41% An issue was discovered in Dynamicweb before 9.12.8. An attacker can add a new administrator user without authentication. This flaw exists due to a l… Mitigation only Fix from $2,3002026-01-23 HIGH 7.4 CVE-2025-69822 An issue in Atomberg Atomberg Erica Smart Fan Firmware Version: V1.0.36 allows an attacker to obtain sensitive information and escalate privileges vi… Erica Smart Fan Firmware No fix yet Fix from $1,9502026-01-22 HIGH 8.1 CVE-2026-24038 Horilla is a free and open source Human Resource Management System (HRMS). In version 1.4.0, the OTP handling logic has a flawed equality check that … Horilla No fix yet Fix from $1,9502026-01-22 CRITICAL 9.8 CVE-2026-1202 A security flaw has been discovered in CRMEB up to 5.6.3. The affected element is the function appleLogin of the file crmeb/app/api/controller/v1/Log… Crmeb after 5.6.3 Fix from $2,3002026-01-20 HIGH 8.1 CVE-2026-1203 A weakness has been identified in CRMEB up to 5.6.3. The impacted element is the function remoteRegister of the file crmeb/app/services/user/LoginSer… Crmeb after 5.6.3 Fix from $1,9502026-01-20 HIGH 8.7 CVE-2026-0629 Authentication bypass in the password recovery feature of the local web interface across multiple VIGI camera models allows an attacker on the LAN to… Mitigation only Fix from $1,9502026-01-16