Vulnerability index

Browse CVEs

2,893 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthenticationCWE-306 × clear
Wiz Connected HIGH 7.5
CVE-2025-56562

An incorrect API discovered in Signify Wiz Connected 1.9.1 allows attackers to remotely launch a DoS on Wiz devices only requiring the MAC address.

Mitigation only
Fix from $1,950 2025-09-16
Chaos Mesh HIGH 7.5
CVE-2025-59358

The Chaos Controller Manager in Chaos Mesh exposes a GraphQL debugging server without authentication to the entire Kubernetes cluster, which provides…

Fix: 2.7.3+
Fix from $1,950 2025-09-15
Unclassified CRITICAL 9.8
CVE-2025-10452

Statistical Database System developed by Gotac has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to read, modify,…

Mitigation only
Fix from $2,300 2025-09-15
Unclassified HIGH 7.1
CVE-2025-10204

A vulnerability has been discovered in AC Smart II where passwords can be changed without authorization. This page contains a hidden form for resetti…

Mitigation only
Fix from $1,950 2025-09-14
Flowise CRITICAL 9.8
CVE-2025-58434EPSS 50%

Flowise is a drag & drop user interface to build a customized large language model flow. In version 3.0.5 and earlier, the `forgot-password` endpoint…

Fix: 3.0.6+
Fix from $2,300 2025-09-12
Unclassified MEDIUM 5.3
CVE-2025-10267

NUP Portal developed by NewType Infortech has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to directly upload fi…

Mitigation only
Fix from $1,600 2025-09-12
Unclassified MEDIUM 5.4
CVE-2025-9214

A missing authentication vulnerability was reported in some Lenovo printers that could allow a user to view limited device information or modify netw…

Mitigation only
Fix from $1,600 2025-09-11
Mcp Server HIGH 7.5
CVE-2025-56405

An issue was discovered in litmusautomation litmus-mcp-server thru 0.0.1 allowing unauthorized attackers to control the target's MCP service through …

No fix yet
Fix from $1,950 2025-09-10
Unclassified MEDIUM 6.3
CVE-2025-36757

It is possible to bypass the administrator login screen on SolaX Cloud. An attacker could use parameter tampering to bypass the login screen and gain…

Mitigation only
Fix from $1,600 2025-09-10
Unclassified MEDIUM 5.8
CVE-2025-36756

A problem with missing authorization on SolaX Cloud platform allows taking over any SolaX solarpanel inverter of which the serial number is known.

Mitigation only
Fix from $1,600 2025-09-10
Calix Gigacenter Ont HIGH 7.7
CVE-2025-7635

Unauthenticated Telnet access vulnerability in Calix GigaCenter ONT allows root access.This issue affects GigaCenter ONT: 844E, 844G, 844GE, 854GE.

No fix yet
Fix from $1,950 2025-09-09
Unclassified CRITICAL 9.8
CVE-2025-9994

The Amp’ed RF BT-AP 111 Bluetooth access point's HTTP admin interface does not have an authentication feature, allowing unauthorized access to anyone…

Mitigation only
Fix from $2,300 2025-09-09
Unclassified HIGH 7.0
CVE-2025-9160

A code execution security issue exists in the affected product. An attacker with physical access could abuse the maintenance menu of the controller w…

Mitigation only
Fix from $1,950 2025-09-09
Factorytalk Activation Manager HIGH 7.5
CVE-2025-7970

A security issue exists within FactoryTalk Activation Manager. An error in the implementation of cryptography within the software could allow attack…

Fix: after 5.01.01
Fix from $1,950 2025-09-09
Netweaver Application Server Java MEDIUM 5.3
CVE-2025-42926

SAP NetWeaver Application Server Java does not perform an authentication check when an attacker attempts to access internal files within the web appl…

Patch available
Fix from $1,600 2025-09-09
Fogproject CRITICAL 9.1
CVE-2025-58443EPSS 19%

FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Versions 1.5.10.1673 and below contain an authentication bypass v…

Fix: after 1.5.10.1673
Fix from $2,300 2025-09-06
Unclassified MEDIUM 6.5
CVE-2025-7045

The Cloud SAML SSO plugin for WordPress is vulnerable to Identity Provider Deletion due to a missing capability check on the delete_config action of …

Mitigation only
Fix from $1,600 2025-09-06
Unclassified CRITICAL 9.3
CVE-2025-52551

E2 Facility Management Systems use a proprietary protocol that allows for unauthenticated file operations on any file in the file system.

Mitigation only
Fix from $2,300 2025-09-02
Batterykid HIGH 7.8
CVE-2025-9815

A weakness has been identified in alaneuler batteryKid up to 2.1 on macOS. The affected element is an unknown function of the file PrivilegeHelper/Pr…

Fix: after 2.1
Fix from $1,950 2025-09-02
Unclassified MEDIUM 5.9
CVE-2025-58318

Delta Electronics DIAView has an authentication bypass vulnerability.

No fix yet
Fix from $1,600 2025-09-01
Unclassified HIGH 7.3
CVE-2025-7405

Missing Authentication for Critical Function vulnerability in Mitsubishi Electric Corporation MELSEC iQ-F Series CPU module allows a remote unauthent…

Mitigation only
Fix from $1,950 2025-09-01
Unclassified HIGH 8.7
CVE-2012-10062

A vulnerability in XAMPP, developed by Apache Friends, version 1.7.3's default WebDAV configuration allows remote authenticated attackers to upload a…

No fix yet
Fix from $1,950 2025-08-30
Ehrd Ctms CRITICAL 9.8
CVE-2025-54942

A missing authentication for critical function vulnerability in SUNNET Corporate Training Management System before 10.11 allows remote attackers to a…

Fix: 10.11+
Fix from $2,300 2025-08-30
Unclassified CRITICAL 9.8
CVE-2025-8861

TSA developed by Changing has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to read, modify, and delete database …

Mitigation only
Fix from $2,300 2025-08-29
Dir 868l Firmware CRITICAL 9.8
CVE-2025-55583EPSS 6%

D-Link DIR-868L B1 router firmware version FW2.05WWB02 contains an unauthenticated OS command injection vulnerability in the fileaccess.cgi component…

Mitigation only
Fix from $2,300 2025-08-28
Secgate3600 Firmware HIGH 7.5
CVE-2023-7308EPSS 7%

SecGate3600, a network firewall product developed by NSFOCUS, contains a sensitive information disclosure vulnerability in the /cgi-bin/authUser/auth…

No fix yet
Fix from $1,950 2025-08-27
Unclassified MEDIUM 5.3
CVE-2025-30048

The "serverConfig" endpoint, which returns the module configuration including credentials, is accessible without authentication.

Mitigation only
Fix from $1,600 2025-08-27
Unclassified CRITICAL 9.0
CVE-2025-30041

The paths "/cgi-bin/CliniNET.prd/utils/userlogstat.pl", "/cgi-bin/CliniNET.prd/utils/usrlogstat.pl", and "/cgi-bin/CliniNET.prd/utils/dblogstat.pl" e…

Mitigation only
Fix from $2,300 2025-08-27
Unclassified CRITICAL 9.0
CVE-2025-30039

Unauthenticated access to the "/cgi-bin/CliniNET.prd/GetActiveSessions.pl" endpoint allows takeover of any user session logged into the system, inclu…

Mitigation only
Fix from $2,300 2025-08-27
Unclassified CRITICAL 9.0
CVE-2025-30040

The vulnerability allows unauthenticated users to download a file containing session ID data by directly accessing the "/cgi-bin/CliniNET.prd/utils/u…

Mitigation only
Fix from $2,300 2025-08-27