Vulnerability index

Browse CVEs

2,893 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthenticationCWE-306 × clear
Unclassified HIGH 8.7
CVE-2020-36873

Astak CM-818T3 2.4GHz wireless security surveillance cameras contain an unauthenticated configuration disclosure vulnerability in the /web/cgi-bin/hi…

Mitigation only
Fix from $1,950 2025-11-26
Unclassified HIGH 8.7
CVE-2020-36874

ACE SECURITY WIP-90113 HD cameras contain an unauthenticated configuration disclosure vulnerability in the /web/cgi-bin/hi3510/backup.cgi endpoint. T…

Mitigation only
Fix from $1,950 2025-11-26
Unclassified HIGH 8.7
CVE-2019-25227

Tellion HN-2204AP routers contain an unauthenticated configuration disclosure vulnerability in the /cgi-bin/system_config_file management endpoint. T…

Mitigation only
Fix from $1,950 2025-11-26
Unclassified HIGH 8.7
CVE-2019-25226

Dongyoung Media DM-AP240T/W wireless access points contain an unauthenticated configuration disclosure vulnerability in the /cgi-bin/sys_system_confi…

Mitigation only
Fix from $1,950 2025-11-26
Unclassified HIGH 8.8
CVE-2025-13483

SiRcom SMART Alert (SiSA) allows unauthorized access to backend APIs. This allows an unauthenticated attacker to bypass the login screen using browse…

Mitigation only
Fix from $1,950 2025-11-25
Unclassified HIGH 8.2
CVE-2025-12003

A path traversal vulnerability has been identified in WebDAV, which may allow unauthenticated remote attackers to impact the integrity of the device.…

Mitigation only
Fix from $1,950 2025-11-25
Unclassified HIGH 8.7
CVE-2024-14007

Shenzhen TVT Digital Technology Co., Ltd. NVMS-9000 firmware (used by many white-labeled DVR/NVR/IPC products) versions prior to 1.3.4 contain an aut…

Mitigation only
Fix from $1,950 2025-11-24
Vision Tools Workspace CRITICAL 9.8
CVE-2025-63958

MILLENSYS Vision Tools Workspace 6.5.0.2585 exposes a sensitive configuration endpoint (/MILLENSYS/settings) that is accessible without authenticatio…

Mitigation only
Fix from $2,300 2025-11-24
Fluent Bit MEDIUM 6.5
CVE-2025-12969

Fluent Bit in_forward input plugin does not properly enforce the security.users authentication mechanism under certain configuration conditions. This…

Mitigation only
Fix from $1,600 2025-11-24
Unclassified MEDIUM 5.3
CVE-2025-11771

The Cryptocurrency (Token), Launchpad (Presale), ICO & IDO, Airdrop by TokenICO plugin for WordPress is vulnerable to unauthenticated and unauthorize…

Mitigation only
Fix from $1,600 2025-11-21
Unclassified MEDIUM 6.8
CVE-2025-64770

The affected products allow unauthenticated access to Open Network Video Interface Forum (ONVIF) services, which may allow an attacker unauthorized a…

Mitigation only
Fix from $1,600 2025-11-20
Unclassified MEDIUM 6.8
CVE-2025-62674

The affected product allows unauthenticated access to Real Time Streaming Protocol (RTSP) services, which may allow an attacker unauthorized access t…

Mitigation only
Fix from $1,600 2025-11-20
Ds2924 Firmware CRITICAL 9.8
CVE-2025-63206

An authentication bypass issue was discovered in Dasan Switch DS2924 web based interface, firmware versions 1.01.18 and 1.02.00, allowing attackers t…

Mitigation only
Fix from $2,300 2025-11-19
Fax Server HIGH 7.5
CVE-2025-34331

AudioCodes Fax Server and Auto-Attendant IVR appliances versions up to and including 2.6.23 contain an unauthenticated file read vulnerability via th…

Fix: after 2.6.23
Fix from $1,950 2025-11-19
Unclassified MEDIUM 5.3
CVE-2025-12349

The Icegram Express - Email Subscribers, Newsletters and Marketing Automation Plugin for WordPress is vulnerable to Authorization in versions up to, …

Mitigation only
Fix from $1,600 2025-11-19
Api Control Plane CRITICAL 9.8
CVE-2025-9312

A missing authentication enforcement vulnerability exists in the mutual TLS (mTLS) implementation used by System REST APIs and SOAP services in multi…

Mitigation only
Fix from $2,300 2025-11-18
Unclassified CRITICAL 10.0
CVE-2025-58083

General Industrial Controls Lynx+ Gateway  is missing critical authentication in the embedded web server which could allow an attacker to remotely r…

Mitigation only
Fix from $2,300 2025-11-15
Unclassified HIGH 7.5
CVE-2025-59780

General Industrial Controls Lynx+ Gateway is missing critical authentication in the embedded web server which could allow an attacker to send GET re…

Mitigation only
Fix from $1,950 2025-11-15
Unclassified MEDIUM 6.5
CVE-2025-64307

The Brightpick Internal Logic Control web interface is accessible without requiring user authentication. An unauthorized user could exploit this inte…

Mitigation only
Fix from $1,600 2025-11-15
Sft Dab 600\/c Firmware MEDIUM 5.3
CVE-2023-7328

Screen SFT DAB 600/C firmware versions up to and including 1.9.3 contain an improper access control on the user management API allows unauthenticated…

Fix: after 1.9.3
Fix from $1,600 2025-11-14
Unclassified HIGH 8.7
CVE-2021-4468

PLANEX CS-QP50F-ING2 smart cameras expose a configuration backup interface over HTTP that does not require authentication. A remote, unauthenticated …

Mitigation only
Fix from $1,950 2025-11-14
Unclassified HIGH 8.7
CVE-2021-4469

Denver SHO-110 IP cameras expose a secondary HTTP service on TCP port 8001 that provides access to a '/snapshot' endpoint without authentication. Whi…

No fix yet
Fix from $1,950 2025-11-14
Mattermost Server HIGH 7.5
CVE-2025-55070

Mattermost versions <11 fail to enforce multi-factor authentication on WebSocket connections which allows unauthenticated users to access sensitive i…

Fix: 11.0.0+
Fix from $1,950 2025-11-14
Mattermost Server MEDIUM 5.3
CVE-2025-55073

Mattermost versions 10.11.x <= 10.11.3, 10.5.x <= 10.5.11, 10.12.x <= 10.12.0 fail to validate the relationship between the post being updated and th…

Fix: 10.5.12 / 10.11.4+
Fix from $1,600 2025-11-14
Dsl Ac51 Firmware CRITICAL 9.8
CVE-2025-59367

An authentication bypass vulnerability has been identified in certain DSL series routers, may allow remote attackers to gain unauthorized access into…

Fix: 1.1.2.3_1010+
Fix from $2,300 2025-11-13
Unclassified HIGH 8.7
CVE-2023-7329

Tinycontrol LAN Controller v3 (LK3) firmware versions up to 1.58a (hardware v3.8) contain a missing authentication vulnerability in the stm.cgi endpo…

No fix yet
Fix from $1,950 2025-11-12
Unclassified HIGH 7.6
CVE-2025-40816

A vulnerability has been identified in LOGO! 12/24RCE (6ED1052-1MD08-0BA2) (All versions), LOGO! 12/24RCEo (6ED1052-2MD08-0BA2) (All versions), LOGO!…

Mitigation only
Fix from $1,950 2025-11-11
Unclassified MEDIUM 6.5
CVE-2025-40817

A vulnerability has been identified in LOGO! 12/24RCE (6ED1052-1MD08-0BA2) (All versions), LOGO! 12/24RCEo (6ED1052-2MD08-0BA2) (All versions), LOGO!…

Mitigation only
Fix from $1,600 2025-11-11
Unclassified MEDIUM 5.3
CVE-2025-11986

The Crypto plugin for WordPress is vulnerable to Information exposure in all versions up to, and including, 2.22. This is due to the plugin registeri…

Mitigation only
Fix from $1,600 2025-11-11
Unclassified MEDIUM 5.8
CVE-2025-42885

Due to missing authentication, SAP HANA 2.0 (hdbrss) allows an unauthenticated attacker to call a remote-enabled function that will enable them to vi…

Mitigation only
Fix from $1,600 2025-11-11