Vulnerability index

Browse CVEs

4,337 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
HIGH 8.1 CVE-2025-22236 Minion event bus authorization bypass. An attacker with access to a minion key can craft a message which may be able to execute a job on other minion… Mitigation only Fix from $1,9502025-06-13 MEDIUM 5.9 CVE-2025-49146 pgjdbc is an open source postgresql JDBC Driver. From 42.7.4 and until 42.7.7, when the PostgreSQL JDBC driver is configured with channel binding set… Postgresql Jdbc Driver 42.7.7+ Fix from $1,6002025-06-11 HIGH 7.3 CVE-2025-5985 A vulnerability was found in code-projects School Fees Payment System 1.0 and classified as critical. Affected by this issue is some unknown function… School Fees Payment System No fix yet Fix from $1,9502025-06-10 CRITICAL 9.8 CVE-2025-5906 A vulnerability classified as critical has been found in code-projects Laundry System 1.0. This affects an unknown part of the file /data/. The manip… Laundry System Mitigation only Fix from $2,3002025-06-10 MEDIUM 6.8 CVE-2025-29627 An issue in KeeperChat IOS Application v.5.8.8 allows a physically proximate attacker to escalate privileges via the Biometric Authentication Module Keeperchat No fix yet Fix from $1,6002025-06-09 MEDIUM 5.3 CVE-2025-5876 A vulnerability classified as problematic was found in Lucky LM-520-SC, LM-520-FSC and LM-520-FSC-SAM up to 20250321. Affected by this vulnerability … Mitigation only Fix from $1,6002025-06-09 MEDIUM 5.3 CVE-2025-5871 A vulnerability was found in Papendorf SOL Connect Center 3.3.0.0 and classified as problematic. Affected by this issue is some unknown functionality… Mitigation only Fix from $1,6002025-06-09 MEDIUM 5.3 CVE-2025-5872 A vulnerability was found in eGauge EG3000 Energy Monitor 3.6.3. It has been classified as problematic. This affects an unknown part of the component… Mitigation only Fix from $1,6002025-06-09 HIGH 7.3 CVE-2025-5870 A vulnerability has been found in TRENDnet TV-IP121W 1.1.1 Build 36 and classified as critical. Affected by this vulnerability is an unknown function… Mitigation only Fix from $1,9502025-06-09 HIGH 7.8 CVE-2024-13088 An improper authentication vulnerability has been reported to affect QHora. If an attacker gains local network access, they can then exploit the vuln… Qurouter Mitigation only Fix from $1,9502025-06-06 HIGH 7.1 CVE-2025-48909 Bypass vulnerability in the device management channel Impact: Successful exploitation of this vulnerability may affect service confidentiality. Harmonyos No fix yet Fix from $1,9502025-06-06 MEDIUM 5.4 CVE-2025-49012 Himmelblau is an interoperability suite for Microsoft Azure Entra ID and Intune. Himmelblau versions 0.9.0 through 0.9.14 and 1.00-alpha are vulnerab… Patch available Fix from $1,6002025-06-05 CRITICAL 10.0 CVE-2025-5597 Improper Authentication vulnerability in WF Steuerungstechnik GmbH airleader MASTER allows Authentication Bypass.This issue affects airleader MASTER:… No fix yet Fix from $2,3002025-06-04 CRITICAL 9.8 CVE-2025-49001EPSS 22% DataEase is an open source business intelligence and data visualization tool. Prior to version 2.10.10, secret verification does not take effect succ… Dataease after 2.10.10 Fix from $2,3002025-06-03 CRITICAL 9.8 CVE-2025-5512 A vulnerability, which was classified as critical, was found in quequnlong shiyi-blog up to 1.2.1. Affected is an unknown function of the file /api/s… Shiyi Blog after 1.2.1 Fix from $2,3002025-06-03 MEDIUM 6.5 CVE-2025-46548 If you enable Basic Authentication in Pekko Management using the Java DSL, the authenticator may not be properly applied. Users that rely on authen… Pekko Management 1.6.1+ Fix from $1,6002025-06-03 CRITICAL 9.8 CVE-2025-5495 A vulnerability was found in Netgear WNR614 1.1.0.28_1.0.1WW. It has been classified as critical. This affects an unknown part of the component URL H… Wnr614 Firmware No fix yet Fix from $2,3002025-06-03 CRITICAL 9.8 CVE-2025-37093 An authentication bypass vulnerability exists in HPE StoreOnce Software. Storeonce System 4.3.11+ Fix from $2,3002025-06-02 MEDIUM 5.3 CVE-2025-5437 A vulnerability classified as critical has been found in Multilaser Sirius RE016 MLT1.0. Affected is an unknown function of the file /cgi-bin/cstecgi… Mitigation only Fix from $1,6002025-06-02 MEDIUM 6.5 CVE-2025-48746 Netwrix Directory Manager (formerly Imanami GroupID) v.11.0.0.0 and before, as well as after v.11.1.25134.03 lacks Authentication for a Critical Func… Directory Manager after 11.0.0.0 Fix from $1,6002025-05-28 HIGH 7.3 CVE-2025-5247 A vulnerability, which was classified as critical, has been found in Gowabby HFish 0.1. This issue affects the function LoadUrl of the file \view\url… Mitigation only Fix from $1,9502025-05-27 HIGH 8.1 CVE-2025-5149 A vulnerability was found in WCMS up to 8.3.11. It has been declared as critical. Affected by this vulnerability is the function getMemberByUid of th… Wcms after 8.3.11 Fix from $1,9502025-05-25 MEDIUM 5.8 CVE-2024-7487 An improper authentication vulnerability exists in WSO2 Identity Server 7.0.0 due to an implementation flaw that allows app-native authentication to … Identity Server Mitigation only Fix from $1,6002025-05-22 CRITICAL 9.8 CVE-2024-41195 An issue in Ocuco Innovation - INNOVASERVICEINTF.EXE v2.10.24.17 allows attackers to bypass authentication and escalate privileges to Administrator v… Innovation No fix yet Fix from $2,3002025-05-22 CRITICAL 9.8 CVE-2024-41196 An issue in Ocuco Innovation - REPORTSERVER.EXE v2.10.24.13 allows attackers to bypass authentication and escalate privileges to Administrator via a … Innovation No fix yet Fix from $2,3002025-05-22 CRITICAL 9.8 CVE-2024-41197 An issue in Ocuco Innovation - INVCLIENT.EXE v2.10.24.5 allows attackers to bypass authentication and escalate privileges to Administrator via a craf… Innovation No fix yet Fix from $2,3002025-05-22 CRITICAL 9.8 CVE-2024-41198 An issue in Ocuco Innovation - REPORTS.EXE v2.10.24.13 allows attackers to bypass authentication and escalate privileges to Administrator via a craft… Innovation No fix yet Fix from $2,3002025-05-22 HIGH 7.2 CVE-2024-41199 An issue in Ocuco Innovation - JOBMANAGER.EXE v2.10.24.16 allows attackers to bypass authentication and escalate privileges to Administrator via a cr… Innovation No fix yet Fix from $1,9502025-05-22 MEDIUM 6.5 CVE-2025-32815EPSS 40% An issue was discovered in Infoblox NETMRI before 7.6.1. Authentication Bypass via a Hardcoded credential can occur. Netmri 7.6.1+ Fix from $1,6002025-05-22 CRITICAL 9.8 CVE-2025-44083 An issue in D-Link DI-8100 16.07.26A1 allows a remote attacker to bypass administrator login authentication Di 8100 Firmware Mitigation only Fix from $2,3002025-05-21