Vulnerability index

Browse CVEs

2,893 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthenticationCWE-306 × clear
Financial Services Analytical Applications Infrastructure MEDIUM 5.4
CVE-2025-53034

Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: P…

Mitigation only
Fix from $1,600 2025-10-21
Financial Services Analytical Applications Infrastructure CRITICAL 9.8
CVE-2025-53037

Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: P…

Mitigation only
Fix from $2,300 2025-10-21
Unclassified HIGH 7.5
CVE-2025-11949

EasyFlow .NET and EasyFlow AiNet, developed by Digiwin, has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to obta…

Mitigation only
Fix from $1,950 2025-10-21
Unclassified CRITICAL 10.0
CVE-2025-9574

Missing Authentication for Critical Function vulnerability in ABB ALS-mini-s4 IP, ABB ALS-mini-s8 IP.This issue affects .  All firmware versions wit…

Mitigation only
Fix from $2,300 2025-10-20
Unclassified MEDIUM 6.8
CVE-2025-60856

Reolink Video Doorbell WiFi DB_566128M5MP_W allows root shell access through an unsecured UART/serial console. An attacker with physical access can c…

Mitigation only
Fix from $1,600 2025-10-20
X200 Firmware CRITICAL 9.8
CVE-2025-11942

A flaw has been found in 70mai X200 up to 20251010. Affected is an unknown function of the component Pairing. Executing manipulation can lead to miss…

Fix: after 2025-10-10
Fix from $2,300 2025-10-19
Unclassified MEDIUM 5.3
CVE-2025-11852

A vulnerability was found in Apeman ID71 218.53.203.117. The impacted element is an unknown function of the file /onvif/device_service of the compone…

Mitigation only
Fix from $1,600 2025-10-16
Foiaxpress CRITICAL 9.8
CVE-2025-62586

OPEXUS FOIAXpress allows a remote, unauthenticated attacker to reset the administrator password. Fixed in FOIAXpress version 11.13.2.0.

Fix: 11.13.2.0+
Fix from $2,300 2025-10-16
Api Control Plane CRITICAL 9.8
CVE-2025-9152

An improper privilege management vulnerability exists in WSO2 API Manager due to missing authentication and authorization checks in the keymanager-op…

Mitigation only
Fix from $2,300 2025-10-16
Unclassified MEDIUM 5.3
CVE-2025-11728

The Oceanpayment CreditCard Gateway plugin for WordPress is vulnerable to unauthenticated and unauthorized modification of data due to missing authen…

Mitigation only
Fix from $1,600 2025-10-15
Unclassified HIGH 8.4
CVE-2025-23356

NVIDIA Isaac Lab contains a vulnerability in SB3 configuration parsing. A successful exploit of this vulnerability might lead to code execution, deni…

Mitigation only
Fix from $1,950 2025-10-14
1783 Natr Firmware CRITICAL 9.8
CVE-2025-7328

Multiple Broken Authentication security issues exist in the affected product. The security issues are due to missing authentication checks on critica…

Fix: 1.007+
Fix from $2,300 2025-10-14
Telecontrol Server Basic CRITICAL 9.8
CVE-2025-40765

A vulnerability has been identified in TeleControl Server Basic V3.1 (All versions >= V3.1.2.2 < V3.1.2.3). The affected application contains an info…

Mitigation only
Fix from $2,300 2025-10-14
Unclassified CRITICAL 9.8
CVE-2025-40771

A vulnerability has been identified in SIMATIC CP 1542SP-1 (6GK7542-6UX00-0XE0) (All versions < V2.4.24), SIMATIC CP 1542SP-1 IRC (6GK7542-6VX00-0XE0…

Mitigation only
Fix from $2,300 2025-10-14
Unclassified HIGH 7.5
CVE-2025-41703

An unauthenticated remote attacker can cause a Denial of Service by turning off the output of the UPS via Modbus command.

Mitigation only
Fix from $1,950 2025-10-14
Unclassified MEDIUM 5.3
CVE-2025-11671

Uniweb/SoliPACS WebServer developed by EBM Technologies has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to acce…

Mitigation only
Fix from $1,600 2025-10-13
Unclassified MEDIUM 5.3
CVE-2025-11672

Uniweb/SoliPACS WebServer developed by EBM Technologies has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to acce…

Mitigation only
Fix from $1,600 2025-10-13
School Management System CRITICAL 9.8
CVE-2025-11661

A vulnerability was found in ProjectsAndPrograms School Management System up to 6b6fae5426044f89c08d0dd101c7fa71f9042a59. This affects an unknown par…

Mitigation only
Fix from $2,300 2025-10-13
Unclassified CRITICAL 9.3
CVE-2025-61928EPSS 18%

Better Auth is an authentication and authorization library for TypeScript. In versions prior to 1.3.26, unauthenticated attackers can create or modif…

Patch available
Fix from $2,300 2025-10-09
Entra Id CRITICAL 9.8
CVE-2025-59246EPSS 7%

Azure Entra ID Elevation of Privilege Vulnerability

No fix yet
Fix from $2,300 2025-10-09
Project Center CRITICAL 9.8
CVE-2025-35050

Newforma Info Exchange (NIX) accepts serialized .NET data via the '/remoteweb/remote.rem' endpoint, allowing a remote, unauthenticated attacker to ex…

Mitigation only
Fix from $2,300 2025-10-09
Project Center CRITICAL 9.8
CVE-2025-35051

Newforma Project Center Server (NPCS) accepts serialized .NET data via the '/ProjectCenter.rem' endpoint on 9003/tcp, allowing a remote, unauthentica…

Mitigation only
Fix from $2,300 2025-10-09
Security Director Policy Enforcer HIGH 7.4
CVE-2025-11198

A Missing Authentication for Critical Function vulnerability in Juniper Networks Security Director Policy Enforcer allows an unauthenticated, network…

Fix: 23.1+
Fix from $1,950 2025-10-09
Churchcrm CRITICAL 9.8
CVE-2025-11529

A security flaw has been discovered in ChurchCRM up to 5.18.0. This impacts the function AuthMiddleware of the file src/ChurchCRM/Slim/Middleware/Aut…

Fix: 5.19.0+
Fix from $2,300 2025-10-09
Unclassified MEDIUM 5.3
CVE-2025-11171

The Chartify – WordPress Chart Plugin for WordPress is vulnerable to Missing Authentication for Critical Function in all versions up to, and includin…

Mitigation only
Fix from $1,600 2025-10-08
Unclassified HIGH 7.2
CVE-2023-6215

A potential security vulnerability has been identified in HP Sure Start’s protection of the Intel Flash Descriptor in certain HP PC products, which m…

Mitigation only
Fix from $1,950 2025-10-07
Flagforge CRITICAL 9.1
CVE-2025-61777

Flag Forge is a Capture The Flag (CTF) platform. Starting in version 2.0.0 and prior to version 2.3.2, the `/api/admin/badge-templates` (GET) and `/a…

Fix: 2.3.2+
Fix from $2,300 2025-10-06
Unclassified CRITICAL 9.3
CVE-2025-61778

Akka.NET is a .NET port of the Akka project from the Scala / Java community. In all versions of Akka.Remote from v1.2.0 to v1.5.51, TLS could be enab…

Patch available
Fix from $2,300 2025-10-06
Unclassified MEDIUM 6.5
CVE-2025-10746

The Integrate Dynamics 365 CRM plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 1.0.9. This is due to …

Mitigation only
Fix from $1,600 2025-10-04
Unclassified HIGH 8.6
CVE-2025-61673

Karapace is an open-source implementation of Kafka REST and Schema Registry. Versions 5.0.0 and 5.0.1 contain an authentication bypass vulnerability …

Patch available
Fix from $1,950 2025-10-03