Vulnerability index

Browse CVEs

2,866 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthenticationCWE-306 × clear
Smart Visu Server Firmware HIGH 7.5
CVE-2026-26235

JUNG Smart Visu Server 1.1.1050 contains a denial of service vulnerability that allows unauthenticated attackers to remotely shutdown or reboot the s…

Fix: after 1.1.1050
Fix from $1,950 2026-02-12
Unclassified CRITICAL 9.8
CVE-2026-1729

The AdForest theme for WordPress is vulnerable to authentication bypass in all versions up to, and including, 6.0.12. This is due to the plugin not p…

Mitigation only
Fix from $2,300 2026-02-12
Unclassified CRITICAL 9.8
CVE-2026-24789

An unprotected API endpoint allows an attacker to remotely change the device password without providing authentication.

Mitigation only
Fix from $2,300 2026-02-11
Unclassified CRITICAL 9.8
CVE-2026-25084

Authentication for ZLAN5143D can be bypassed by directly accessing internal URLs.

Mitigation only
Fix from $2,300 2026-02-11
Unclassified CRITICAL 9.8
CVE-2026-2248

METIS WIC devices (versions <= oscore 2.1.234-r18) expose a web-based shell at the /console endpoint that does not require authentication. Accessing …

Mitigation only
Fix from $2,300 2026-02-11
Unclassified CRITICAL 9.8
CVE-2026-2249

METIS DFS devices (versions <= oscore 2.1.234-r18) expose a web-based shell at the /console endpoint that does not require authentication. Accessing …

Mitigation only
Fix from $2,300 2026-02-11
Unclassified CRITICAL 9.8
CVE-2025-8025

Missing Authentication for Critical Function, Improper Access Control vulnerability in Dinosoft Business Solutions Dinosoft ERP allows Accessing Func…

Mitigation only
Fix from $2,300 2026-02-11
Endpoint Manager HIGH 7.5
CVE-2026-1603 KEVEPSS 81%

An authentication bypass in Ivanti Endpoint Manager before version 2024 SU5 allows a remote unauthenticated attacker to leak specific stored credenti…

Fix: 2024+
Fix from $1,950 2026-02-10
Fuxa CRITICAL 9.8
CVE-2026-25938

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. From 1.2.8 through 1.2.10, an authentication bypass vulnerability in FUXA a…

Fix: 1.2.11+
Fix from $2,300 2026-02-09
Fuxa CRITICAL 9.8
CVE-2026-25895

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. A path traversal vulnerability in FUXA allows an unauthenticated, remote at…

Fix: 1.2.10+
Fix from $2,300 2026-02-09
Polarlearn HIGH 7.5
CVE-2026-25885

PolarLearn is a free and open-source learning program. In 0-PRERELEASE-16 and earlier, the group chat WebSocket at wss://polarlearn.nl/api/v1/ws can …

Patch available
Fix from $1,950 2026-02-09
Froshadminer MEDIUM 5.3
CVE-2026-25878

FroshAdminer is the Adminer plugin for Shopware Platform. Prior to 2.2.1, the Adminer route (/admin/adminer) was accessible without Shopware admin au…

Fix: 2.2.1+
Fix from $1,600 2026-02-09
Sliver HIGH 7.5
CVE-2026-25791

Sliver is a command and control framework that uses a custom Wireguard netstack. Prior to 1.7.0, the DNS C2 listener accepts unauthenticated TOTP boo…

Fix: 1.7.0+
Fix from $1,950 2026-02-09
Hub CRITICAL 9.8
CVE-2026-25848

In JetBrains Hub before 2025.3.119807 authentication bypass allowing administrative actions was possible

Fix: 2025.3.119807+
Fix from $2,300 2026-02-09
Unclassified CRITICAL 9.1
CVE-2026-2234

C&Cm@il developed by HGiga has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to read and modify any user's mail …

Mitigation only
Fix from $2,300 2026-02-09
E Commerce CRITICAL 9.8
CVE-2026-2165

A weakness has been identified in detronetdip E-commerce 1.0.0. Impacted is an unknown function of the file /Admin/assets/backend/seller/add_seller.p…

Mitigation only
Fix from $2,300 2026-02-08
Unclassified HIGH 7.5
CVE-2020-37146

ACE Security WiP-90113 HD Camera contains a configuration disclosure vulnerability that allows unauthenticated attackers to retrieve sensitive config…

No fix yet
Fix from $1,950 2026-02-07
Unclassified HIGH 7.5
CVE-2020-37157

DBPower C300 HD Camera contains a configuration disclosure vulnerability that allows unauthenticated attackers to retrieve sensitive credentials thro…

No fix yet
Fix from $1,950 2026-02-07
Openclaw HIGH 8.4
CVE-2026-25593

OpenClaw is a personal AI assistant. Prior to 2026.1.20, an unauthenticated local client could use the Gateway WebSocket API to write config via conf…

Fix: 2026.1.20+
Fix from $1,950 2026-02-06
Smart Pixelator Firmware HIGH 8.8
CVE-2026-2065

A security flaw has been discovered in Flycatcher Toys smART Pixelator 2.0. Affected by this issue is some unknown functionality of the component Blu…

No fix yet
Fix from $1,950 2026-02-06
Fuxa HIGH 7.5
CVE-2026-25751

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. An information disclosure vulnerability in FUXA allows an unauthenticated, …

Fix: 1.2.10+
Fix from $1,950 2026-02-06
Bambuddy CRITICAL 9.8
CVE-2026-25505

Bambuddy is a self-hosted print archive and management system for Bambu Lab 3D printers. Prior to version 0.1.7, a hardcoded secret key used for sign…

Fix: 0.1.7+
Fix from $2,300 2026-02-04
Unclassified CRITICAL 10.0
CVE-2026-1633

The Synectix LAN 232 TRIO 3-Port serial to ethernet adapter exposes its web management interface without requiring authentication, allowing unauthent…

Mitigation only
Fix from $2,300 2026-02-04
Unclassified CRITICAL 9.1
CVE-2026-1632

MOMA Seismic Station Version v2.4.2520 and prior exposes its web management interface without requiring authentication, which could allow an unauthen…

Mitigation only
Fix from $2,300 2026-02-03
Unclassified CRITICAL 9.3
CVE-2026-1341

Avation Light Engine Pro exposes its configuration and control interface without any authentication or access control.

Mitigation only
Fix from $2,300 2026-02-03
Unclassified CRITICAL 9.1
CVE-2026-25137EPSS 10%

The NixOs Odoo package is an open source ERP and CRM system. From 21.11 to before 25.11 and 26.05, every NixOS based Odoo setup publicly exposes the …

Patch available
Fix from $2,300 2026-02-02
Unclassified MEDIUM 6.5
CVE-2022-50980

A unauthenticated adjacent attacker could potentially disrupt operations by switching between multiple configuration presets via CAN.

Mitigation only
Fix from $1,600 2026-02-02
Unclassified CRITICAL 9.8
CVE-2022-50981

An unauthenticated remote attacker can gain full access on the affected devices as they are shipped without a password by default and setting one is …

Mitigation only
Fix from $2,300 2026-02-02
Unclassified HIGH 7.5
CVE-2022-50977

An unauthenticated remote attacker could potentially disrupt operations by switching between multiple configuration presets via HTTP.

Mitigation only
Fix from $1,950 2026-02-02
Unclassified HIGH 7.5
CVE-2022-50978

An unauthenticated remote attacker could potentially disrupt operations by switching between multiple configuration presets via Modbus (TCP).

Mitigation only
Fix from $1,950 2026-02-02