Vulnerability index

Browse CVEs

2,866 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthenticationCWE-306 × clear
Hana Database HIGH 8.8
CVE-2026-0492

SAP HANA database is vulnerable to privilege escalation allowing an attacker with valid credentials of any user to switch to another user potentially…

Patch available
Fix from $1,950 2026-01-13
Opencode HIGH 8.8
CVE-2026-22812EPSS 17%

OpenCode is an open source AI coding agent. Prior to 1.0.216, OpenCode automatically starts an unauthenticated HTTP server that allows any local proc…

Fix: 1.0.216+
Fix from $1,950 2026-01-12
Wem HIGH 8.2
CVE-2026-22788

WebErpMesv2 is a Resource Management and Manufacturing execution system Web for industry. Prior to 1.19, the WebErpMesV2 application exposes multiple…

Fix: 1.19+
Fix from $1,950 2026-01-12
Unclassified MEDIUM 6.3
CVE-2026-0842

A flaw has been found in Flycatcher Toys smART Sketcher up to 2.0. This affects an unknown part of the component Bluetooth Low Energy Interface. This…

Mitigation only
Fix from $1,600 2026-01-11
Unclassified CRITICAL 10.0
CVE-2025-69425

The Ruckus vRIoT IoT Controller firmware versions prior to 3.0.0.0 (GA) expose a command execution service on TCP port 2004 running with root privile…

Mitigation only
Fix from $2,300 2026-01-09
Ip7137 Firmware HIGH 7.5
CVE-2025-66049

Vivotek IP7137 camera with firmware version 0200a is vulnerable to an information disclosure issue where live camera footage can be accessed through …

Mitigation only
Fix from $1,950 2026-01-09
Ks Wr3600 Firmware HIGH 8.4
CVE-2025-68716

KAYSUS KS-WR3600 routers with firmware 1.0.5.9.1 enable the SSH service enabled by default on the LAN interface. The root account is configured with …

Mitigation only
Fix from $1,950 2026-01-08
Pwru01 Firmware CRITICAL 9.1
CVE-2025-68715

An issue was discovered in Panda Wireless PWRU0 devices with firmware 2.2.9 that exposes multiple HTTP endpoints (/goform/setWan, /goform/setLan, /go…

No fix yet
Fix from $2,300 2026-01-08
Dir 605l Firmware MEDIUM 6.8
CVE-2025-65731

An issue was discovered in D-Link Router DIR-605L (Hardware version F1; Firmware version: V6.02CN02) allowing an attacker with physical access to the…

No fix yet
Fix from $1,600 2026-01-08
Unclassified CRITICAL 9.3
CVE-2025-15346

A vulnerability in the handling of verify_mode = CERT_REQUIRED in the wolfssl Python package (wolfssl-py) causes client certificate requirements to n…

Patch available
Fix from $2,300 2026-01-08
Unclassified HIGH 7.5
CVE-2017-20213

FLIR Thermal Camera F/FC/PT/D Stream firmware version 8.0.0.64 contains an unauthenticated vulnerability that allows remote attackers to access live …

No fix yet
Fix from $1,950 2026-01-08
Unclassified CRITICAL 9.3
CVE-2026-0650

OpenFlagr versions prior to and including 1.1.18 contain an authentication bypass vulnerability in the HTTP middleware. Due to improper handling of p…

Mitigation only
Fix from $2,300 2026-01-07
Unclassified CRITICAL 9.3
CVE-2026-0625

Multiple D-Link DSL/DIR/DNS devices contain an authentication bypass and improper access control vulnerability in the dnscfg.cgi endpoint that allows…

Mitigation only
Fix from $2,300 2026-01-05
Unclassified CRITICAL 9.8
CVE-2025-14346EPSS 6%

WHILL Model C2 Electric Wheelchairs and Model F Power Chairs do not enforce authentication for Bluetooth connections. An attacker within range can pa…

Mitigation only
Fix from $2,300 2026-01-05
Awie CRITICAL 9.8
CVE-2025-15026

Missing Authentication for Critical Function vulnerability in Centreon Infra Monitoring centreon-awie (Awie import module) allows Accessing Functiona…

Fix: 24.04.3 / 24.10.3+
Fix from $2,300 2026-01-05
Petlibro HIGH 8.2
CVE-2025-3646

Petlibro Smart Pet Feeder Platform versions up to 1.7.31 contains an authorization bypass vulnerability that allows unauthorized users to add users a…

Fix: after 1.7.31
Fix from $1,950 2026-01-04
Bagisto CRITICAL 9.8
CVE-2026-21446

Bagisto is an open source laravel eCommerce platform. In versions on the 2.3 branch prior to 2.3.10, API routes remain active even after initial inst…

Fix: 2.3.10+
Fix from $2,300 2026-01-02
Langflow CRITICAL 9.1
CVE-2026-21445EPSS 34%

Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to version 1.7.0.dev45, multiple critical API endpoints in Langf…

Fix: 1.7.1+
Fix from $2,300 2026-01-02
Unclassified HIGH 7.5
CVE-2020-36904

Selea CarPlateServer 4.0.1.6 contains a remote program execution vulnerability that allows attackers to execute arbitrary Windows binaries by manipul…

No fix yet
Fix from $1,950 2025-12-31
S539 Firmware MEDIUM 5.3
CVE-2024-58336

Akuvox Smart Intercom S539 contains an unauthenticated vulnerability that allows remote attackers to access live video streams by requesting the vide…

No fix yet
Fix from $1,600 2025-12-30
Impact Firmware HIGH 7.5
CVE-2022-50790

SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x and below contain an unauthenticated vulnerability that allows remote attackers to access live radio strea…

No fix yet
Fix from $1,950 2025-12-30
Pexip Infinity HIGH 7.5
CVE-2025-66377

Pexip Infinity before 39.0 has Missing Authentication for a Critical Function in a product-internal API, allowing an attacker (who already has access…

Fix: 39.0+
Fix from $1,950 2025-12-25
Unclassified HIGH 7.5
CVE-2025-3232

A remote unauthenticated attacker may be able to bypass authentication by utilizing a specific API route to execute arbitrary OS commands.

Mitigation only
Fix from $1,950 2025-12-24
Unclassified HIGH 7.5
CVE-2019-25248

Beward N100 M2.1.6.04C014 contains an unauthenticated vulnerability that allows remote attackers to access live video streams without credentials. At…

No fix yet
Fix from $1,950 2025-12-24
Unclassified CRITICAL 9.8
CVE-2019-25236

iSeeQ Hybrid DVR WH-H4 1.03R contains an unauthenticated vulnerability in the get_jpeg script that allows unauthorized access to live video streams. …

Mitigation only
Fix from $2,300 2025-12-24
Unclassified CRITICAL 9.8
CVE-2019-25240

Rifatron 5brid DVR contains an unauthenticated vulnerability in the animate.cgi script that allows unauthorized access to live video streams. Attacke…

Mitigation only
Fix from $2,300 2025-12-24
Unclassified HIGH 7.5
CVE-2018-25140

FLIR thermal traffic cameras contain an unauthenticated device manipulation vulnerability in their WebSocket implementation that allows attackers to …

No fix yet
Fix from $1,950 2025-12-24
Unclassified HIGH 7.5
CVE-2018-25141

FLIR thermal traffic cameras contain an unauthenticated vulnerability that allows remote attackers to access live video streams without credentials. …

No fix yet
Fix from $1,950 2025-12-24
Unclassified CRITICAL 9.8
CVE-2018-25134

Synaccess netBooter NP-02x/NP-08x 6.8 contains an authentication bypass vulnerability in the webNewAcct.cgi script that allows unauthenticated attack…

Mitigation only
Fix from $2,300 2025-12-24
Unclassified HIGH 7.5
CVE-2018-25136

FLIR Brickstream 3D+ 2.1.742.1842 contains an unauthenticated vulnerability that allows remote attackers to access live video streams without credent…

No fix yet
Fix from $1,950 2025-12-24