Vulnerability index

Browse CVEs

2,866 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthenticationCWE-306 × clear
Unclassified MEDIUM 6.5
CVE-2022-50979

An unauthenticated adjacent attacker could potentially disrupt operations by switching between multiple configuration presets via Modbus (RS485).

No fix yet
Fix from $1,600 2026-02-02
Unclassified CRITICAL 9.3
CVE-2026-24728

A missing authentication for critical function vulnerability in the /servlet/baServer3 endpoint of Interinfo DreamMaker versions before 2025/10/22 al…

Mitigation only
Fix from $2,300 2026-01-30
Runtipi HIGH 8.8
CVE-2026-25116

Runtipi is a personal homeserver orchestrator. Starting in version 4.5.0 and prior to version 4.7.2, an unauthenticated Path Traversal vulnerability …

Fix: 4.7.2+
Fix from $1,950 2026-01-29
Unclassified CRITICAL 9.8
CVE-2026-1453

A missing authentication for critical function vulnerability in KiloView Encoder Series could allow an unauthenticated attacker to create or delete a…

Mitigation only
Fix from $2,300 2026-01-29
Unclassified HIGH 7.5
CVE-2020-36963

Intelbras Router RF 301K firmware version 1.1.2 contains an authentication bypass vulnerability that allows unauthenticated attackers to download rou…

No fix yet
Fix from $1,950 2026-01-28
Unclassified MEDIUM 6.9
CVE-2025-12386

Pix-Link LV-WR21Q does not enforce any form of authentication for endpoint /goform/getHomePageInfo. Remote unauthenticated attacker is able to use th…

Mitigation only
Fix from $1,600 2026-01-27
Unclassified CRITICAL 9.3
CVE-2025-59097

The exos 9300 application can be used to configure Access Managers (e.g. 92xx, 9230 and 9290). The configuration is done in a graphical user interfac…

Mitigation only
Fix from $2,300 2026-01-26
Unclassified CRITICAL 9.3
CVE-2025-59090

On the exos 9300 server, a SOAP API is reachable on port 8002. This API does not require any authentication prior to sending requests. Therefore, net…

Mitigation only
Fix from $2,300 2026-01-26
777vr1 Firmware MEDIUM 6.4
CVE-2026-1410

A vulnerability was detected in Beetel 777VR1 up to 01.00.09/01.00.09_55. Impacted is an unknown function of the component UART Interface. The manipu…

Fix: after 01.00.09_55
Fix from $1,600 2026-01-26
Gemscms Backend CRITICAL 9.4
CVE-2025-52024

A vulnerability exists in the Aptsys POS Platform Web Services module thru 2025-05-28, which exposes internal API testing tools to unauthenticated us…

Fix: after 2025-05-28
Fix from $2,300 2026-01-23
Smartermail CRITICAL 9.8
CVE-2026-24423 KEVEPSS 88%

SmarterTools SmarterMail versions prior to build 9511 contain an unauthenticated remote code execution vulnerability in the ConnectToHub API method. …

Fix: 100.0.9511+
Fix from $2,300 2026-01-23
Unclassified CRITICAL 9.8
CVE-2021-47891

Unified Remote 3.9.0.2463 contains a remote code execution vulnerability that allows attackers to send crafted network packets to execute arbitrary c…

Mitigation only
Fix from $2,300 2026-01-23
Unclassified CRITICAL 9.8
CVE-2026-1364

IAQS and I6 developed by JNC has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to directly operate system adminis…

Mitigation only
Fix from $2,300 2026-01-23
Unclassified HIGH 8.8
CVE-2026-0778

Enel X JuiceBox 40 Telnet Service Missing Authentication Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to…

Mitigation only
Fix from $1,950 2026-01-23
Dragonfly CRITICAL 9.8
CVE-2026-24124

Dragonfly is an open source P2P-based file distribution and image acceleration system. In versions 2.4.1-rc.0 and below, the Job API endpoints (/api/…

Fix: 2.4.1+
Fix from $2,300 2026-01-22
Evmapa CRITICAL 9.8
CVE-2025-54816

This vulnerability occurs when a WebSocket endpoint does not enforce proper authentication mechanisms, allowing unauthorized users to establish con…

Mitigation only
Fix from $2,300 2026-01-22
Meetinghub Paperless Meetings MEDIUM 5.3
CVE-2026-1332

MeetingHub developed by HAMASTAR Technology has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to access specific …

Fix: 2025-12-10+
Fix from $1,600 2026-01-22
Sqlbot MEDIUM 6.1
CVE-2025-69285

SQLBot is an intelligent data query system based on a large language model and RAG. Versions prior to 1.5.0 contain a missing authentication vulnerab…

Fix: 1.5.0+
Fix from $1,600 2026-01-21
D301 Firmware HIGH 7.5
CVE-2021-47802

Tenda D151 and D301 routers contain an unauthenticated configuration download vulnerability that allows remote attackers to retrieve router configura…

No fix yet
Fix from $1,950 2026-01-21
Arcane CRITICAL 9.8
CVE-2026-23944

Arcane is an interface for managing Docker containers, images, networks, and volumes. Prior to version 1.13.2, unauthenticated requests could be prox…

Fix: 1.13.2+
Fix from $2,300 2026-01-19
Inspector CRITICAL 9.8
CVE-2026-23744EPSS 45%

MCPJam inspector is the local-first development platform for MCP servers. Versions 1.4.2 and earlier are vulnerable to remote code execution (RCE) vu…

Fix: 1.4.3+
Fix from $2,300 2026-01-16
Unclassified MEDIUM 5.3
CVE-2026-0942

The Rede Itaú for WooCommerce — Payment PIX, Credit Card and Debit plugin for WordPress is vulnerable to unauthorized modification of data due to a m…

Mitigation only
Fix from $1,600 2026-01-16
Statistics Database System HIGH 7.5
CVE-2026-1023

Statistics Database System developed by Gotac has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to directly explo…

Fix: 1.0.4+
Fix from $1,950 2026-01-16
Police Statistics Database System CRITICAL 9.8
CVE-2026-1019

Police Statistics Database System developed by Gotac has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to read, m…

Fix: after 1.0.3
Fix from $2,300 2026-01-16
Diaview CRITICAL 9.8
CVE-2025-62582

Delta Electronics DIAView has multiple vulnerabilities.

Fix: 4.4.0+
Fix from $2,300 2026-01-16
Unclassified CRITICAL 9.3
CVE-2026-23746

Entrust Instant Financial Issuance (IFI) On Premise software (formerly referred to as CardWizard) versions 5.x, prior to 6.10.5, and prior to 6.11.1 …

Mitigation only
Fix from $2,300 2026-01-15
Bluvoyix CRITICAL 9.8
CVE-2026-22238

The vulnerability exists in BLUVOYIX due to improper authentication in the BLUVOYIX admin APIs. An unauthenticated remote attacker could exploit this…

Mitigation only
Fix from $2,300 2026-01-14
Extplorer CRITICAL 9.8
CVE-2023-54335EPSS 5%

eXtplorer 2.1.14 contains an authentication bypass vulnerability that allows attackers to login without a password by manipulating the login request.…

Fix: after 2.1.14
Fix from $2,300 2026-01-13
Sql Server 2022 HIGH 7.2
CVE-2026-20803

Missing authentication for critical function in SQL Server allows an authorized attacker to elevate privileges over a network.

Fix: 16.0.1165.1 / 16.0.4230.2+
Fix from $1,950 2026-01-13
Unclassified CRITICAL 9.0
CVE-2025-12548

A flaw was found in Eclipse Che che-machine-exec. This vulnerability allows unauthenticated remote arbitrary command execution and secret exfiltratio…

Mitigation only
Fix from $2,300 2026-01-13