Vulnerability index

Browse CVEs

4,337 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
CRITICAL 9.4 CVE-2025-67822 A vulnerability in the Provisioning Manager component of Mitel MiVoice MX-ONE 7.3 (7.3.0.0.50) through 7.8 SP1 (7.8.1.0.14) could allow an unauthenti… Mivoice Mx One 7.8+ Fix from $2,3002026-01-15 MEDIUM 6.8 CVE-2025-65397 An insecure authentication mechanism in the safe_exec.sh startup script of Blurams Flare Camera version 24.1114.151.929 and earlier allows an attacke… Dome Flare Firmware after 24.1114.151.929 Fix from $1,6002026-01-14 CRITICAL 9.8 CVE-2025-37184 A vulnerability exists in an Orchestrator service that could allow an unauthenticated remote attacker to bypass multi-factor authentication requireme… Edgeconnect Sd Wan Orchestrator 9.3.6 / 9.4.3+ Fix from $2,3002026-01-14 CRITICAL 9.8 CVE-2026-22236 The vulnerability exists in BLUVOYIX due to improper authentication in the BLUVOYIX backend APIs. An unauthenticated remote attacker could exploit th… Bluvoyix Mitigation only Fix from $2,3002026-01-14 MEDIUM 5.1 CVE-2025-67859 A Improper Authentication vulnerability in TLP allows local users to arbitrarily control the power profile in use as well as the daemon’s log setting… Mitigation only Fix from $1,6002026-01-14 HIGH 7.5 CVE-2025-68931 Jervis is a library for Job DSL plugin scripts and shared Jenkins pipeline libraries. Prior to 2.2, AES/CBC/PKCS5Padding lacks authentication, making… Jervis 2.2+ Fix from $1,9502026-01-13 HIGH 8.0 CVE-2026-0408 A path traversal vulnerability in NETGEAR WiFi range extenders allows an attacker with LAN authentication to access the router's IP and review the … Ex2800 Firmware 1.0.1.82+ Fix from $1,9502026-01-13 HIGH 7.8 CVE-2026-0405 An authentication bypass vulnerability in NETGEAR Orbi devices allows users connected to the local network to access the router web interface as an… Cbr750 Firmware 4.6.14.8 / 4.6.15.14+ Fix from $1,9502026-01-13 HIGH 8.0 CVE-2026-0407 An insufficient authentication vulnerability in NETGEAR WiFi range extenders allows a network adjacent attacker with WiFi authentication or a physi… Ex5000 Firmware 1.0.1.82+ Fix from $1,9502026-01-13 HIGH 8.6 CVE-2025-66698 An issue in Semantic machines v5.4.8 allows attackers to bypass authentication via sending a crafted HTTP request to various API endpoints. Veda No fix yet Fix from $1,9502026-01-13 HIGH 7.5 CVE-2025-69273 Improper Authentication vulnerability in Broadcom DX NetOps Spectrum on Windows, Linux allows Authentication Bypass.This issue affects DX NetOps Spec… Dx Netops Spectrum 24.3.11+ Fix from $1,9502026-01-12 MEDIUM 6.3 CVE-2026-0842 A flaw has been found in Flycatcher Toys smART Sketcher up to 2.0. This affects an unknown part of the component Bluetooth Low Energy Interface. This… Mitigation only Fix from $1,6002026-01-11 HIGH 8.1 CVE-2026-22594 Ghost is a Node.js content management system. In versions 5.105.0 through 5.130.5 and 6.0.0 through 6.10.3, a vulnerability in Ghost's 2FA mechanism … Ghost 5.130.6 / 6.11.0+ Fix from $1,9502026-01-10 CRITICAL 9.4 CVE-2025-68717 KAYSUS KS-WR3600 routers with firmware 1.0.5.9.1 allow authentication bypass during session validation. If any user is logged in, endpoints such as /… Ks Wr3600 Firmware No fix yet Fix from $2,3002026-01-08 CRITICAL 9.8 CVE-2026-21891 ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In versions up to and including 1.5.0, the application… Zimaos after 1.5.0 Fix from $2,3002026-01-08 CRITICAL 9.1 CVE-2026-21881 Kanboard is project management software focused on Kanban methodology. Versions 1.2.48 and below is vulnerable to a critical authentication bypass wh… Kanboard 1.2.49+ Fix from $2,3002026-01-08 CRITICAL 9.3 CVE-2025-15346 A vulnerability in the handling of verify_mode = CERT_REQUIRED in the wolfssl Python package (wolfssl-py) causes client certificate requirements to n… Patch available Fix from $2,3002026-01-08 CRITICAL 9.8 CVE-2026-21854 The Tarkov Data Manager is a tool to manage the Tarkov item data. Prior to 02 January 2025, an authentication bypass vulnerability in the login endpo… Tarkov Data Manager 2025-01-02+ Fix from $2,3002026-01-07 CRITICAL 9.8 CVE-2025-14942 wolfSSH’s key exchange state machine can be manipulated to leak the client’s password in the clear, trick the client to send a bogus signature, or tr… Wolfssh 1.4.22+ Fix from $2,3002026-01-06 CRITICAL 9.8 CVE-2025-60534 Blue Access Cobalt v02.000.195 suffers from an authentication bypass vulnerability, which allows an attacker to selectively proxy requests in order t… Cobalt X1 Mitigation only Fix from $2,3002026-01-06 MEDIUM 6.5 CVE-2025-69197 Pterodactyl is a free, open-source game server management panel. Versions 1.11.11 and below allow TOTP to be used multiple times during its validity … Panel 1.12.0+ Fix from $1,6002026-01-06 HIGH 8.8 CVE-2025-64423 Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. In Coolify versions up to and including v4.0.0-be… Coolify 4.0.0+ Fix from $1,9502026-01-05 HIGH 8.8 CVE-2026-21633 A malicious actor with access to the adjacent network could obtain unauthorized access to a UniFi Protect Camera by exploiting a discovery protocol v… Unifi Protect 6.2.72+ Fix from $1,9502026-01-05 HIGH 7.3 CVE-2026-0589 A vulnerability was found in code-projects Online Product Reservation System 1.0. Impacted is an unknown function of the component Administration Bac… Online Product Reservation System No fix yet Fix from $1,9502026-01-05 CRITICAL 9.8 CVE-2025-15458 A vulnerability was determined in bg5sbk MiniCMS up to 1.8. This affects an unknown function of the file /mc-admin/post-edit.php of the component Art… Minicms after 1.8 Fix from $2,3002026-01-05 CRITICAL 9.8 CVE-2025-15457 A vulnerability was found in bg5sbk MiniCMS up to 1.8. The impacted element is an unknown function of the file /minicms/mc-admin/post.php of the comp… Minicms after 1.8 Fix from $2,3002026-01-05 HIGH 7.5 CVE-2025-15456 A vulnerability has been found in bg5sbk MiniCMS up to 1.8. The affected element is an unknown function of the file /mc-admin/page-edit.php of the co… Minicms after 1.8 Fix from $1,9502026-01-05 MEDIUM 6.5 CVE-2025-15455 A flaw has been found in bg5sbk MiniCMS up to 1.8. Impacted is the function delete_page of the file /minicms/mc-admin/page.php of the component File … Minicms after 1.8 Fix from $1,6002026-01-05 HIGH 7.5 CVE-2025-67158 An authentication bypass in the /cgi-bin/jvsweb.cgi endpoint of Revotech I6032W-FHW v1.0.0014 - 20210517 allows attackers to access sensitive informa… I6032w Fhw Firmware No fix yet Fix from $1,9502026-01-02 CRITICAL 9.8 CVE-2025-68926EPSS 30% RustFS is a distributed object storage system built in Rust. In versions prior to 1.0.0-alpha.78, RustFS implements gRPC authentication using a hardc… Rustfs Mitigation only Fix from $2,3002025-12-30