Vulnerability index

Browse CVEs

2,866 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthenticationCWE-306 × clear
Minidvblinux CRITICAL 9.8
CVE-2023-53771

MiniDVBLinux 5.4 contains an authentication bypass vulnerability that allows remote attackers to change the root password without authentication. Att…

Fix: after 5.4
Fix from $2,300 2025-12-09
Minidvblinux MEDIUM 5.3
CVE-2023-53773

MiniDVBLinux 5.4 contains an unauthenticated vulnerability in the tv_action.sh script that allows remote attackers to generate live stream snapshots …

Fix: after 5.4
Fix from $1,600 2025-12-09
Minidvblinux CRITICAL 9.8
CVE-2023-53774

MiniDVBLinux 5.4 contains a remote code execution vulnerability in the SVDRP protocol that allows remote attackers to send commands to manipulate TV …

Fix: after 5.4
Fix from $2,300 2025-12-09
Izero Box Full Firmware MEDIUM 5.3
CVE-2021-47727

Selea Targa IP OCR-ANPR Camera contains an unauthenticated vulnerability that allows remote attackers to access live video streams without authentica…

No fix yet
Fix from $1,600 2025-12-09
Izero Box Full Firmware CRITICAL 9.8
CVE-2021-47731

Selea Targa IP OCR-ANPR Camera contains a hard-coded developer password vulnerability that allows unauthorized configuration access through an undocu…

Mitigation only
Fix from $2,300 2025-12-09
Unclassified HIGH 8.7
CVE-2021-47710

COMMAX Smart Home System is a smart IoT home solution that allows an unauthenticated attacker to disclose RTSP credentials in plain-text by exploitin…

No fix yet
Fix from $1,950 2025-12-09
Unclassified HIGH 8.7
CVE-2021-47709

COMMAX Smart Home System allows an unauthenticated attacker to change configuration and cause denial-of-service through the setconf endpoint. Attacke…

No fix yet
Fix from $1,950 2025-12-09
Windows 10 1809 HIGH 7.8
CVE-2025-59516

Missing authentication for critical function in Windows Storage VSP Driver allows an authorized attacker to elevate privileges locally.

Fix: 10.0.17763.8146 / 10.0.19044.6691+
Fix from $1,950 2025-12-09
Unclassified CRITICAL 9.3
CVE-2025-34414

Entrust Instant Financial Issuance (IFI) On Premise software (formerly referred to as CardWizard) versions 5.x, prior to 6.10.5, and prior to 6.11.1 …

Mitigation only
Fix from $2,300 2025-12-09
C6230 Firmware MEDIUM 5.7
CVE-2025-12941

Denial of Service Vulnerability in NETGEAR C6220 and C6230 (DOCSIS® 3.0 Two-in-one Cable Modem + WiFi Router) allows authenticated local WiFi users r…

Mitigation only
Fix from $1,600 2025-12-09
Unclassified MEDIUM 6.6
CVE-2025-42875

The SAP Internet Communication Framework does not conduct any authentication checks for features that need user identification allowing an attacker t…

Mitigation only
Fix from $1,600 2025-12-09
Android MEDIUM 5.5
CVE-2025-48608

In isValidMediaUri of SettingsProvider.java, there is a possible cross user media read due to a missing permission check. This could lead to local in…

Mitigation only
Fix from $1,600 2025-12-08
Android HIGH 7.8
CVE-2025-48572 KEV

In multiple locations, there is a possible way to launch activities from the background due to a permissions bypass. This could lead to local escalat…

Mitigation only
Fix from $1,950 2025-12-08
Infinera Mtc 9 Firmware CRITICAL 9.8
CVE-2025-27019

Remote shell service (RSH) in Infinera MTC-9 version R22.1.1.0275 allows an attacker to utilize password-less user accounts and obtain system acces…

Fix: 23.0+
Fix from $2,300 2025-12-08
Infinera Mtc 9 Firmware CRITICAL 9.8
CVE-2025-27020

Improper configuration of the SSH service in Infinera MTC-9 allows an unauthenticated attacker to execute arbitrary commands and access data on file …

Fix: 23.0+
Fix from $2,300 2025-12-08
Unclassified HIGH 8.8
CVE-2025-66555

AirKeyboard iOS App 1.0.5 contains a missing authentication vulnerability that allows unauthenticated attackers to type arbitrary keystrokes directly…

No fix yet
Fix from $1,950 2025-12-04
Unclassified HIGH 8.6
CVE-2025-27935

The OTP Integration Kit for PingFederate fails to enforce HTTP method validation and state validation properly. The server advances the authenticatio…

Mitigation only
Fix from $1,950 2025-12-04
Jxl 9 Inch Car Android Double Din Player Firmware HIGH 7.6
CVE-2025-63896

An issue in the Bluetooth Human Interface Device (HID) of JXL 9 Inch Car Android Double Din Player Android v12.0 allows attackers to inject arbitrary…

No fix yet
Fix from $1,950 2025-12-04
Beedrive HIGH 7.8
CVE-2025-54158

Missing authentication for critical function vulnerability in BeeDrive in Synology BeeDrive for desktop before 1.4.2-13960 allows local users to exec…

Fix: 1.4.2-13960+
Fix from $1,950 2025-12-04
Unclassified CRITICAL 9.3
CVE-2025-13510

The Iskra iHUB and iHUB Lite smart metering gateway exposes its web management interface without requiring authentication, allowing unauthenticated u…

Mitigation only
Fix from $2,300 2025-12-02
Nshield 5c Firmware CRITICAL 9.8
CVE-2025-59695

Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7, allow a user with OS root access to alter firmware on the Chassis …

Fix: 13.6.12 / 13.9.0+
Fix from $2,300 2025-12-02
Diris M 70 Firmware HIGH 7.5
CVE-2025-54850

A denial of service vulnerability exists in the Modbus TCP and Modbus RTU over TCP functionality of Socomec DIRIS Digiware M-70 1.6.9. A specially cr…

Mitigation only
Fix from $1,950 2025-12-01
Diris M 70 Firmware HIGH 7.5
CVE-2025-54851

A denial of service vulnerability exists in the Modbus TCP and Modbus RTU over TCP functionality of Socomec DIRIS Digiware M-70 1.6.9. A specially cr…

Mitigation only
Fix from $1,950 2025-12-01
Diris M 70 Firmware HIGH 7.5
CVE-2025-55221

A denial of service vulnerability exists in the Modbus TCP and Modbus RTU over TCP USB Function functionality of Socomec DIRIS Digiware M-70 1.6.9. A…

Mitigation only
Fix from $1,950 2025-12-01
Diris M 70 Firmware HIGH 7.5
CVE-2025-55222

A denial of service vulnerability exists in the Modbus TCP and Modbus RTU over TCP USB Function functionality of Socomec DIRIS Digiware M-70 1.6.9. A…

Mitigation only
Fix from $1,950 2025-12-01
Diris Digiware M 70 Firmware HIGH 7.5
CVE-2025-54848

A denial of service vulnerability exists in the Modbus TCP and Modbus RTU over TCP functionality of Socomec DIRIS Digiware M-70 1.6.9. A specially cr…

Mitigation only
Fix from $1,950 2025-12-01
Diris Digiware M 70 Firmware HIGH 7.5
CVE-2025-54849

A denial of service vulnerability exists in the Modbus TCP and Modbus RTU over TCP functionality of Socomec DIRIS Digiware M-70 1.6.9. A specially cr…

Mitigation only
Fix from $1,950 2025-12-01
Diris M 70 Firmware HIGH 7.5
CVE-2025-23417

A denial of service vulnerability exists in the Modbus RTU over TCP functionality of Socomec DIRIS Digiware M-70 1.6.9. A specially crafted network p…

Mitigation only
Fix from $1,950 2025-12-01
Diris M 70 Firmware MEDIUM 6.5
CVE-2025-20085

A denial of service vulnerability exists in the Modbus RTU over TCP functionality of Socomec DIRIS Digiware M-70 1.6.9. A specially crafted network p…

Mitigation only
Fix from $1,600 2025-12-01
Diris M 70 Firmware MEDIUM 6.5
CVE-2024-49572

A denial of service vulnerability exists in the Modbus TCP functionality of Socomec DIRIS Digiware M-70 1.6.9. A specially crafted network packet can…

Mitigation only
Fix from $1,600 2025-12-01