Vulnerability index

Browse CVEs

4,337 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
MEDIUM 6.5 CVE-2025-65925 An issue was discovered in Zeroheight (SaaS) prior to 2025-06-13. A legacy user creation API pathway allowed accounts to be created without completin… Zeroheight 2025-06-13+ Fix from $1,6002025-12-30 CRITICAL 9.8 CVE-2025-56333 An issue in Fossorial fosrl/pangolin v.1.6.2 and before allows a remote attacker to escalate privileges via the 2FA component Pangolin 1.7.0+ Fix from $2,3002025-12-29 CRITICAL 9.8 CVE-2025-15069 Improper Authentication vulnerability in Gmission Web Fax allows Privilege Escalation.This issue affects Web Fax: from 3.0 before 3.0.1 Web Fax 4.0+ Fix from $2,3002025-12-29 MEDIUM 6.3 CVE-2025-15135 A weakness has been identified in joey-zhou xiaozhi-esp32-server-java up to 3.0.0. This impacts the function tryAuthenticateWithCookies of the file A… Mitigation only Fix from $1,6002025-12-28 CRITICAL 9.8 CVE-2025-15099 A vulnerability was identified in simstudioai sim up to 0.5.27. This vulnerability affects unknown code of the file apps/sim/lib/auth/internal.ts of … Sim after 0.5.27 Fix from $2,3002025-12-26 HIGH 7.3 CVE-2025-15097 A vulnerability was found in Alteryx Server. Affected by this issue is some unknown functionality of the file /gallery/api/status/. Performing manipu… Mitigation only Fix from $1,9502025-12-26 MEDIUM 5.3 CVE-2023-52210 Vulnerability in Tyche softwares Product Delivery Date for WooCommerce – Lite.This issue affects Product Delivery Date for WooCommerce – Lite: from n… No fix yet Fix from $1,6002025-12-23 MEDIUM 6.8 CVE-2025-66174 There is an improper authentication vulnerability in some Hikvision DVR products. Due to the improper implementation of authentication for the serial… Ds 7104hghi F1 Firmware after 4.30.122_201107 Fix from $1,6002025-12-19 HIGH 8.1 CVE-2025-14908 A security flaw has been discovered in JeecgBoot up to 3.9.0. The affected element is an unknown function of the file jeecg-boot/jeecg-module-system/… Jeecg Boot after 3.9.0 Fix from $1,9502025-12-19 MEDIUM 6.9 CVE-2025-13427 An authentication bypass vulnerability in Google Cloud Dialogflow CX Messenger allowed unauthenticated users to interact with restricted chat agents,… Mitigation only Fix from $1,6002025-12-18 HIGH 7.5 CVE-2025-14738 Improper authentication vulnerability in TP-Link WA850RE (httpd modules) allows unauthenticated attackers to download the configuration file.This iss… Tl Wa850re Firmware after 160922 Fix from $1,9502025-12-18 CRITICAL 9.8 CVE-2025-67791 An issue was discovered in DriveLock 24.1 through 24.1.*, 24.2 through 24.2.*, and 25.1 through 25.1.*. An incomplete configuration (agent authentica… Drivelock after 25.1.6 Fix from $2,3002025-12-17 CRITICAL 10.0 CVE-2025-44005 An attacker can bypass authorization checks and force a Step CA ACME or SCEP provisioner to create certificates without completing certain protocol a… Mitigation only Fix from $2,3002025-12-17 HIGH 7.2 CVE-2025-14097 A vulnerability in the application software of multiple Radiometer products may allow remote code execution and unauthorized device management when s… Mitigation only Fix from $1,9502025-12-17 HIGH 8.1 CVE-2025-14002 The WPCOM Member plugin for WordPress is vulnerable to authentication bypass via brute force in all versions up to, and including, 1.7.16. This is du… Mitigation only Fix from $1,9502025-12-16 MEDIUM 6.5 CVE-2025-14746 A vulnerability has been found in Ningyuanda TC155 57.0.2.0. The affected element is an unknown function of the component RTSP Live Video Stream Endp… Tc155 Firmware No fix yet Fix from $1,6002025-12-16 MEDIUM 5.4 CVE-2025-65431 An issue was discovered in allauth-django before 65.13.0. Both Okta and NetIQ were using preferred_username as the identifier for third-party provide… Allauth 65.13.0+ Fix from $1,6002025-12-15 HIGH 8.2 CVE-2025-65781 An issue was discovered in Wekan The Open Source kanban board system up to version 18.15, fixed in 18.16. Attachment upload API treats the Authorizat… Wekan 8.16+ Fix from $1,9502025-12-15 HIGH 7.4 CVE-2025-37731 Improper Authentication in Elasticsearch PKI realm can lead to user impersonation via specially crafted client certificates. A malicious actor would … Elasticsearch 8.19.8 / 9.1.8+ Fix from $1,9502025-12-15 MEDIUM 5.3 CVE-2025-14703 A vulnerability has been found in Shiguangwu sgwbox N3 2.0.25. The affected element is an unknown function of the file /fsnotify of the component POS… N3 Firmware after 2.0.25 Fix from $1,6002025-12-15 HIGH 7.5 CVE-2025-14567 A weakness has been identified in haxxorsid Stock-Management-System up to fbbbf213e9c93b87183a3891f77e3cc7095f22b0. This affects an unknown function … Stock Management System after 2018-01-27 Fix from $1,9502025-12-12 HIGH 8.1 CVE-2025-67507 Filament is a collection of full-stack components for accelerated Laravel development. Versions 4.0.0 through 4.3.0 contain a flaw in the handling of… Filament 4.3.1+ Fix from $1,9502025-12-10 CRITICAL 9.8 CVE-2025-66039 FreePBX Endpoint Manager is a module for managing telephony endpoints in FreePBX systems. Versions are vulnerable to authentication bypass when the a… Freepbx 16.0.44 / 17.0.23+ Fix from $2,3002025-12-09 CRITICAL 9.8 CVE-2025-12374 The Email Verification, Email OTP, Block Spam Email, Passwordless login, Hide Login, Magic Login – User Verification plugin for WordPress is vulnerab… Mitigation only Fix from $2,3002025-12-05 CRITICAL 9.8 CVE-2025-64055 An issue was discovered in Fanvil x210 V2 2.12.20 allowing unauthenticated attackers on the local network to access administrative functions of the d… X210 Firmware Mitigation only Fix from $2,3002025-12-03 CRITICAL 9.8 CVE-2025-66022 FACTION is a PenTesting Report Generation and Collaboration Framework. Prior to version 1.7.1, an extension execution path in Faction’s extension fra… Faction 1.7.1+ Fix from $2,3002025-11-26 HIGH 8.8 CVE-2025-9803 lunary-ai/lunary version 1.9.34 is vulnerable to an account takeover due to improper authentication in the Google OAuth integration. The application … Lunary Patch available Fix from $1,9502025-11-25 CRITICAL 9.8 CVE-2025-63210 The Newtec Celox UHD (models: CELOXA504, CELOXA820) running firmware version celox-21.6.13 is vulnerable to an authentication bypass. An attacker can… Celoxa504 Firmware Mitigation only Fix from $2,3002025-11-19 CRITICAL 9.8 CVE-2025-63207EPSS 7% The R.V.R Elettronica TEX product (firmware TEXL-000400, Web GUI TLAN-000400) is vulnerable to broken access control due to improper authentication c… Tex30lcd\/s Firmware Mitigation only Fix from $2,3002025-11-19 CRITICAL 10.0 CVE-2025-63224 The Itel DAB Encoder (IDEnc build 25aec8d) is vulnerable to Authentication Bypass due to improper JWT validation across devices. Attackers can reuse … Idenc Firmware Mitigation only Fix from $2,3002025-11-19