Vulnerability index

Browse CVEs

4,337 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
MEDIUM 6.5 CVE-2025-55169 WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. Prior to version 3.4.8, a path traversal vul… Wegia 3.4.8+ Fix from $1,6002025-08-12 HIGH 7.5 CVE-2025-53793 Improper authentication in Azure Stack allows an unauthorized attacker to disclose information over a network. Azure Stack Hub 1.2406.1.23 / 1.2408.1.50+ Fix from $1,9502025-08-12 HIGH 8.8 CVE-2025-53778EPSS 38% Improper authentication in Windows NTLM allows an authorized attacker to elevate privileges over a network. Windows 10 1507 10.0.10240.21100 / 10.0.14393.8330+ Fix from $1,9502025-08-12 CRITICAL 9.8 CVE-2025-8838 A vulnerability has been found in WinterChenS my-site up to 1f7525f15934d9d6a278de967f6ec9f1757738d8. This vulnerability affects the function preHand… My Site Mitigation only Fix from $2,3002025-08-11 HIGH 8.7 CVE-2025-54888 Fedify is a TypeScript library for building federated server apps powered by ActivityPub. In versions below 1.3.20, 1.4.0-dev.585 through 1.4.12, 1.5… Patch available Fix from $1,9502025-08-09 MEDIUM 5.3 CVE-2025-54786 SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. In versions 7.14.6 and 8.8.0, the broken au… Suitecrm Mitigation only Fix from $1,6002025-08-07 HIGH 8.0 CVE-2025-53786EPSS 7% On April 18th 2025, Microsoft announced Exchange Server Security Changes for Hybrid Deployments and accompanying non-security Hot Fix. Microsoft made… Exchange Server 15.02.2562.017+ Fix from $1,9502025-08-06 MEDIUM 5.3 CVE-2025-8546 A vulnerability, which was classified as problematic, was found in atjiu pybbs up to 6.0.0. This affects the function adminlogin/login of the compone… Pybbs after 6.0.0 Fix from $1,6002025-08-05 HIGH 7.5 CVE-2025-8348 A vulnerability has been found in Kehua Charging Pile Cloud Platform 1.0 and classified as critical. This vulnerability affects unknown code of the f… Charging Pile Cloud Platform No fix yet Fix from $1,9502025-07-31 MEDIUM 6.5 CVE-2025-54573 CVAT is an open source interactive video and image annotation tool for computer vision. In versions 1.1.0 through 2.41.0, email verification was not … Computer Vision Annotation Tool 2.42.0+ Fix from $1,6002025-07-30 HIGH 8.1 CVE-2025-6505 Unauthorized access and impersonation can occur in versions 4.6.2.3226 and below of Progress Software's Hybrid Data Pipeline Server on Linux. This vu… Hybrid Data Pipeline 4.6.2.3275+ Fix from $1,9502025-07-29 CRITICAL 10.0 CVE-2025-54419 A SAML library not dependent on any frameworks that runs in Node. In version 5.0.1, Node-SAML loads the assertion from the (unsigned) original respon… Patch available Fix from $2,3002025-07-28 CRITICAL 9.8 CVE-2025-45777 An issue in the OTP mechanism of Chavara Family Welfare Centre Chavara Matrimony Site v2.0 allows attackers to bypass authentication via supplying a … Chavara Matrimony Mitigation only Fix from $2,3002025-07-25 MEDIUM 5.9 CVE-2025-0249 HCL IEM is affected by an improper invalidation of access or JWT token vulnerability.  A token was not invalidated which may allow attackers to acces… Intelliops Event Management Mitigation only Fix from $1,6002025-07-25 HIGH 7.0 CVE-2024-12310 A vulnerability in Imprivata Enterprise Access Management (formerly Imprivata OneSign) allows bypassing the login screen of the shared kiosk workstat… Mitigation only Fix from $1,9502025-07-23 CRITICAL 9.8 CVE-2025-54452 Improper Authentication vulnerability in Samsung Electronics MagicINFO 9 Server allows Authentication Bypass.This issue affects MagicINFO 9 Server: l… Magicinfo 9 Server 21.1080.0+ Fix from $2,3002025-07-23 HIGH 7.8 CVE-2025-41459 Insufficient protection against brute-force and runtime manipulation in the local authentication component in Two App Studio Journey 5.5.6 on iOS all… Mitigation only Fix from $1,9502025-07-21 CRITICAL 9.8 CVE-2024-6107 Due to insufficient verification, an attacker could use a malicious client to bypass authentication checks and run RPC commands in a region. This has… Metal As A Service 3.1.4 / 3.2.11+ Fix from $2,3002025-07-21 MEDIUM 6.5 CVE-2025-53771EPSS 100% Improper authentication in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network. Sharepoint Server 16.0.18526.20508+ Fix from $1,6002025-07-20 CRITICAL 9.8 CVE-2025-7897 A vulnerability was found in harry0703 MoneyPrinterTurbo up to 1.2.6 and classified as critical. Affected by this issue is the function verify_token … Moneyprinterturbo after 1.2.6 Fix from $2,3002025-07-20 HIGH 7.5 CVE-2025-7875 A vulnerability classified as critical has been found in Metasoft 美特软件 MetaCRM up to 6.4.2. This affects an unknown part of the file /debug.jsp. … Metacrm after 6.4.2 Fix from $1,9502025-07-20 CRITICAL 9.8 CVE-2025-7862 A vulnerability has been found in TOTOLINK T6 4.1.5cu.748_B20211015 and classified as critical. Affected by this vulnerability is the function setTel… T6 Firmware Mitigation only Fix from $2,3002025-07-20 CRITICAL 9.8 CVE-2025-37106 An authentication bypass and disclosure of information vulnerability exists in HPE AutoPass License Server (APLS) prior to 9.18. Autopass License Server 9.18+ Fix from $2,3002025-07-16 CRITICAL 9.8 CVE-2025-37107 An authentication bypass vulnerability exists in HPE AutoPass License Server (APLS) prior to 9.18. Autopass License Server 9.18+ Fix from $2,3002025-07-16 HIGH 7.1 CVE-2025-7699 An improper access control vulnerability was found in the EZ Sync Manager of ADM, which allows authenticated users to copy arbitrary files from the … Mitigation only Fix from $1,9502025-07-16 CRITICAL 9.8 CVE-2025-49831 An attacker of Secrets Manager, Self-Hosted installations that route traffic from Secrets Manager to AWS through a misconfigured network device can r… Conjur 1.22.1 / 13.5.1+ Fix from $2,3002025-07-15 CRITICAL 9.8 CVE-2025-52376EPSS 10% An authentication bypass vulnerability in the /web/um_open_telnet.cgi endpoint in Nexxt Solutions NCM-X1800 Mesh Router firmware UV1.2.7 and below, a… Mitigation only Fix from $2,3002025-07-15 CRITICAL 9.6 CVE-2025-3621 Vulnerabilities* in ActADUR local server product, developed and maintained by ProTNS, allows Remote Code Inclusion on host systems.  * vulnerabilit… Mitigation only Fix from $2,3002025-07-15 MEDIUM 6.5 CVE-2025-53889 Directus is a real-time API and App dashboard for managing SQL database content. Starting in version 9.12.0 and prior to version 11.9.0, Directus Flo… Directus 11.9.0+ Fix from $1,6002025-07-15 HIGH 7.3 CVE-2024-51767 An authentication bypass vulnerability exists in HPE AutoPass License Server (APLS) prior to 9.17. Autopass License Server 9.17+ Fix from $1,9502025-07-14