Vulnerability index

Browse CVEs

4,337 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
CRITICAL 10.0 CVE-2025-9265 A broken authorization vulnerability in Kiloview NDI N30 allows a remote unauthenticated attacker to deactivate user verification, giving them access… Mitigation only Fix from $2,3002025-10-13 CRITICAL 9.8 CVE-2025-11661 A vulnerability was found in ProjectsAndPrograms School Management System up to 6b6fae5426044f89c08d0dd101c7fa71f9042a59. This affects an unknown par… School Management System Mitigation only Fix from $2,3002025-10-13 MEDIUM 5.9 CVE-2025-11633 A vulnerability was identified in Tomofun Furbo 360 and Furbo Mini. Affected by this issue is the function upload_file_to_s3 of the file collect_logs… Furbo Mini Firmware after 074 Fix from $1,6002025-10-12 HIGH 7.5 CVE-2025-61884 KEVEPSS 98% Vulnerability in the Oracle Configurator product of Oracle E-Business Suite (component: Runtime UI). Supported versions that are affected are 12.2.3… Configurator after 12.2.14 Fix from $1,9502025-10-12 CRITICAL 9.9 CVE-2025-60306 code-projects Simple Car Rental System 1.0 has a permission bypass issue where low privilege users can forge high privilege sessions and perform sens… Simple Car Rental System Mitigation only Fix from $2,3002025-10-10 CRITICAL 9.8 CVE-2025-11529 A security flaw has been discovered in ChurchCRM up to 5.18.0. This impacts the function AuthMiddleware of the file src/ChurchCRM/Slim/Middleware/Aut… Churchcrm 5.19.0+ Fix from $2,3002025-10-09 HIGH 8.6 CVE-2025-11192 A vulnerability in Extreme Networks’ Fabric Engine (VOSS) before 9.3 was discovered. When SD-WAN AutoSense is enabled on a port, it may automatically… Fabric Engine \(voss\) 9.3+ Fix from $1,9502025-10-07 CRITICAL 9.8 CVE-2025-11287 A vulnerability was identified in samanhappy MCPHub up to 0.9.10. This vulnerability affects the function handleSseConnectionfunction of the file src… Mcphub after 0.9.10 Fix from $2,3002025-10-05 CRITICAL 9.8 CVE-2025-61882 KEVEPSS 100% Vulnerability in the Oracle Concurrent Processing product of Oracle E-Business Suite (component: BI Publisher Integration). Supported versions that … Concurrent Processing after 12.2.14 Fix from $2,3002025-10-05 HIGH 7.7 CVE-2025-61679 Anyquery is an SQL query engine built on top of SQLite. Versions 0.4.3 and below allow attackers who have already gained access to localhost, even wi… Patch available Fix from $1,9502025-10-03 MEDIUM 6.8 CVE-2025-54154 An improper authentication vulnerability has been reported to affect QNAP Authenticator. If an attacker gains physical access, they can then exploit … Authenticator 1.3.1.1227+ Fix from $1,6002025-10-03 HIGH 7.5 CVE-2025-61665 WeGIA is an open source web manager with a focus on charitable institutions. Versions 3.4.12 and below contain a Broken Access Control vulnerability,… Wegia 3.5.0+ Fix from $1,9502025-10-02 CRITICAL 9.3 CVE-2025-41064 Incorrect authentication vulnerability in OpenSIAC, which could allow an attacker to impersonate a person using Cl@ve as an authentication method. Mitigation only Fix from $2,3002025-10-02 HIGH 8.4 CVE-2025-11130 A weakness has been identified in iHongRen pptp-vpn 1.0/1.0.1 on macOS. This issue affects the function shouldAcceptNewConnection of the file HelpToo… Mitigation only Fix from $1,9502025-09-29 CRITICAL 9.4 CVE-2025-59934EPSS 8% Formbricks is an open source qualtrics alternative. Prior to version 4.0.1, Formbricks is missing JWT signature verification. This vulnerability stem… Patch available Fix from $2,3002025-09-26 HIGH 8.1 CVE-2025-20160 A vulnerability in the implementation of the TACACS+ protocol in Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote … Mitigation only Fix from $1,9502025-09-24 HIGH 8.4 CVE-2025-10906 A flaw has been found in Magnetism Studios Endurance up to 3.3.0 on macOS. This affects the function loadModuleNamed:WithReply of the file /Applicati… Mitigation only Fix from $1,9502025-09-24 MEDIUM 6.8 CVE-2025-0663 A cross-tenant authentication vulnerability exists in multiple WSO2 products due to improper cryptographic design in Adaptive Authentication. A singl… Identity Server Mitigation only Fix from $1,6002025-09-23 CRITICAL 9.3 CVE-2025-9965 Improper authentication vulnerability in Novakon P series allows unauthenticated attackers to upload and download any application from/to the device.… Mitigation only Fix from $2,3002025-09-23 HIGH 8.8 CVE-2025-57434 Creacast Creabox Manager contains a critical authentication flaw that allows an attacker to bypass login validation. The system grants access when th… Creabox Manager No fix yet Fix from $1,9502025-09-22 MEDIUM 6.3 CVE-2025-10772 A vulnerability was identified in huggingface LeRobot up to 0.3.3. Affected by this vulnerability is an unknown functionality of the file lerobot/com… Mitigation only Fix from $1,6002025-09-22 HIGH 8.0 CVE-2025-54761 An issue was discovered in PPress 0.0.9 allowing attackers to gain escilated privlidges via crafted session cookie. Ppress No fix yet Fix from $1,9502025-09-19 HIGH 7.8 CVE-2025-10672 A vulnerability was found in whuan132 AIBattery up to 1.0.9. The affected element is an unknown function of the file AIBatteryHelper/XPC/BatteryXPCSe… Mitigation only Fix from $1,9502025-09-18 CRITICAL 9.8 CVE-2025-34186 Ilevia EVE X1/X5 Server version ≤ 4.7.18.0.eden contains a vulnerability in its authentication mechanism. Unsanitized input is passed to a system() c… Eve X1 Server Firmware after 4.7.18.0 Fix from $2,3002025-09-16 HIGH 7.5 CVE-2025-31271 This issue was addressed through improved state management. This issue is fixed in macOS Tahoe 26. Incoming FaceTime calls can appear or be accepted … macOS 26.0+ Fix from $1,9502025-09-15 CRITICAL 9.1 CVE-2025-45583 Incorrect access control in the FTP protocol of Audi UTR 2.0 Universal Traffic Recorder 2.0 allows attackers to authenticate into the service using a… Universal Traffic Recorder Firmware No fix yet Fix from $2,3002025-09-12 CRITICAL 9.3 CVE-2025-10365EPSS 6% The Evertz SDVN 3080ipx-10G is a High Bandwidth Ethernet Switching Fabric for Video Application. This device exposes a web management interface on po… Mitigation only Fix from $2,3002025-09-12 MEDIUM 5.3 CVE-2025-10288 A vulnerability was found in roncoo roncoo-pay up to 9428382af21cd5568319eae7429b7e1d0332ff40. The impacted element is an unknown function of the fil… Mitigation only Fix from $1,6002025-09-12 MEDIUM 6.5 CVE-2025-58065 Flask-AppBuilder is an application development framework. Prior to version 4.8.1, when Flask-AppBuilder is configured to use OAuth, LDAP, or other no… Flask Appbuilder 4.8.1+ Fix from $1,6002025-09-11 HIGH 8.0 CVE-2025-58060 OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.12 and earlier, when the `AuthTy… Cups 2.4.13+ Fix from $1,9502025-09-11