Vulnerability index

Browse CVEs

2,866 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthenticationCWE-306 × clear
Unclassified HIGH 7.5
CVE-2018-25137

FLIR Brickstream 3D+ 2.1.742.1842 contains an unauthenticated vulnerability in the ExportConfig REST API that allows attackers to download sensitive …

No fix yet
Fix from $1,950 2025-12-24
Flir Ax8 Firmware HIGH 7.5
CVE-2018-25139

FLIR AX8 Thermal Camera 1.32.16 contains an unauthenticated vulnerability that allows remote attackers to access live video streams without credentia…

No fix yet
Fix from $1,950 2025-12-24
Unclassified HIGH 7.1
CVE-2025-66445

Authorization bypass vulnerability in Hitachi Infrastructure Analytics Advisor (Data Center Analytics component) and Hitachi Ops Center Analyzer (Hit…

Mitigation only
Fix from $1,950 2025-12-24
Xm530v200 X6 Weq 8m Firmware CRITICAL 9.8
CVE-2025-65856

Authentication bypass vulnerability in Xiongmai XM530 IP cameras on Firmware V5.00.R02.000807D8.10010.346624.S.ONVIF 21.06 allows unauthenticated rem…

Mitigation only
Fix from $2,300 2025-12-22
Dsl 124 Firmware HIGH 7.5
CVE-2023-53974

D-Link DSL-124 ME_1.00 contains a configuration file disclosure vulnerability that allows unauthenticated attackers to retrieve router settings throu…

No fix yet
Fix from $1,950 2025-12-22
Sft Dab 600\/c Firmware HIGH 7.5
CVE-2023-53967

Screen SFT DAB 600/C firmware 1.9.3 contains an authentication bypass vulnerability that allows attackers to change the admin password without requir…

No fix yet
Fix from $1,950 2025-12-22
Sft Dab 600\/c Firmware CRITICAL 9.8
CVE-2023-53968

Screen SFT DAB 600/C Firmware 1.9.3 contains a session management vulnerability that allows attackers to bypass authentication controls by exploiting…

Mitigation only
Fix from $2,300 2025-12-22
Sft Dab 600\/c Firmware HIGH 7.5
CVE-2023-53969

Screen SFT DAB 600/C firmware 1.9.3 contains a session management vulnerability that allows attackers to bypass authentication controls by exploiting…

No fix yet
Fix from $1,950 2025-12-22
Sft Dab 600\/c Firmware HIGH 7.5
CVE-2023-53970

Screen SFT DAB 600/C Firmware 1.9.3 contains a weak session management vulnerability that allows attackers to bypass authentication controls by reusi…

No fix yet
Fix from $1,950 2025-12-22
Impact Firmware CRITICAL 9.8
CVE-2023-53964

SOUND4 IMPACT/FIRST/PULSE/Eco v2.x contains an unauthenticated vulnerability in the /usr/cgi-bin/restorefactory.cgi endpoint that allows remote attac…

Mitigation only
Fix from $2,300 2025-12-22
Mp 01 Firmware CRITICAL 9.8
CVE-2025-12049

Missing Authentication for Critical Function vulnerability in Sharp Display Solutions Media Player MP-01 All Verisons allows a attacker may access to…

Mitigation only
Fix from $2,300 2025-12-22
Tapo C200 Firmware HIGH 8.1
CVE-2025-14300

The HTTPS service on Tapo C200 v3, v5, C425 v1.2 and C100 v5  exposes a connectAP interface without proper authentication. An unauthenticated attacke…

Mitigation only
Fix from $1,950 2025-12-20
E9450 Sg Firmware HIGH 8.8
CVE-2025-52692EPSS 6%

Successful exploitation of the vulnerability could allow an attacker with local network access to send a specially crafted URL to access certain admi…

No fix yet
Fix from $1,950 2025-12-19
Ollama CRITICAL 9.8
CVE-2025-63389

A critical authentication bypass vulnerability exists in Ollama platform's API endpoints in versions prior to and including v0.12.3. The platform exp…

Fix: after 0.12.3
Fix from $2,300 2025-12-18
Anythingllm MEDIUM 5.3
CVE-2025-63390

An authentication bypass vulnerability exists in AnythingLLM v1.8.5 in via the /api/workspaces endpoint. The endpoint fails to implement proper authe…

Mitigation only
Fix from $1,600 2025-12-18
Unclassified HIGH 7.1
CVE-2025-65010

WODESYS WD-R608U router (also known as WDR122B V2.0 and WDR28) is vulnerable to Broken Access Control in initial configuration wizard.cgi endpoint. M…

Mitigation only
Fix from $1,950 2025-12-18
Unclassified HIGH 8.7
CVE-2025-65007

In WODESYS WD-R608U router (also known as WDR122B V2.0 and WDR28) due to lack of authentication in the configuration change module in the adm.cgi end…

Mitigation only
Fix from $1,950 2025-12-18
Ipados CRITICAL 9.8
CVE-2025-43428

A configuration issue was addressed with additional restrictions. This issue is fixed in iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2, visionOS 26.2. P…

Fix: 26.2+
Fix from $2,300 2025-12-17
Avideo CRITICAL 9.1
CVE-2025-34434

AVideo versions prior to 20.1 with the ImageGallery plugin enabled is vulnerable to unauthenticated file upload and deletion. Plugin endpoints respon…

Fix: 20.0+
Fix from $2,300 2025-12-17
Dap 1325 Firmware HIGH 7.5
CVE-2023-53896

D-Link DAP-1325 firmware version 1.01 contains a broken access control vulnerability that allows unauthenticated attackers to download device configu…

No fix yet
Fix from $1,950 2025-12-16
Hybrid Manager HIGH 7.0
CVE-2025-14038

EDB Hybrid Manager contains a flaw that allows an unauthenticated attacker to directly access certain gRPC endpoints. This could allow an attacker to…

Fix: 1.3.3 / 2025.12.0+
Fix from $1,950 2025-12-15
Stock Management System HIGH 7.5
CVE-2025-14567

A weakness has been identified in haxxorsid Stock-Management-System up to fbbbf213e9c93b87183a3891f77e3cc7095f22b0. This affects an unknown function …

Fix: after 2018-01-27
Fix from $1,950 2025-12-12
Unclassified MEDIUM 5.3
CVE-2025-12348

The Icegram Express - Email Subscribers, Newsletters and Marketing Automation Plugin for WordPress is vulnerable to Missing Authorization in versions…

Mitigation only
Fix from $1,600 2025-12-12
Unclassified HIGH 8.7
CVE-2024-58300

Siklu MultiHaul TG series devices before version 2.0.0 contain an unauthenticated vulnerability that allows remote attackers to retrieve randomly gen…

No fix yet
Fix from $1,950 2025-12-11
Meatmeet Pro Wifi \& Bluetooth Meat Thermometer Firmware HIGH 8.8
CVE-2025-65824

An unauthenticated attacker within proximity of the Meatmeet device can perform an unauthorized Over The Air (OTA) firmware upgrade using Bluetooth L…

No fix yet
Fix from $1,950 2025-12-10
Meatmeet Pro Wifi \& Bluetooth Meat Thermometer Firmware MEDIUM 6.5
CVE-2025-65828

An unauthenticated attacker within proximity of the Meatmeet device can issue several commands over Bluetooth Low Energy (BLE) to these devices which…

No fix yet
Fix from $1,600 2025-12-10
I Media Server Digital Signage CRITICAL 9.8
CVE-2020-36892

Eibiz i-Media Server Digital Signage 3.8.0 contains an unauthenticated privilege escalation vulnerability in the updateUser object that allows attack…

Mitigation only
Fix from $2,300 2025-12-10
I Media Server Digital Signage HIGH 7.5
CVE-2020-36894

Eibiz i-Media Server Digital Signage 3.8.0 contains an authentication bypass vulnerability that allows unauthenticated attackers to create admin user…

No fix yet
Fix from $1,950 2025-12-10
Unclassified CRITICAL 9.4
CVE-2025-13607

A malicious actor can access camera configuration information, including account credentials, without authenticating when accessing a vulnerable URL.

Mitigation only
Fix from $2,300 2025-12-10
Unclassified HIGH 8.8
CVE-2024-2104

Due to improper BLE security configurations on the device's GATT server, an adjacent unauthenticated attacker can read and write device control comma…

Mitigation only
Fix from $1,950 2025-12-10