Vulnerability index

Browse CVEs

2,893 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthenticationCWE-306 × clear
Unclassified HIGH 8.8
CVE-2025-30037

The system exposes several endpoints, typically including "/int/" in their path, that should be restricted to internal services, but are instead publ…

Mitigation only
Fix from $1,950 2025-08-27
Ris 9160 Firmware MEDIUM 6.8
CVE-2025-25736

Kapsch TrafficCom RIS-9260 RSU LEO v3.2.0.829.23, v3.8.0.1119.42, and v4.6.0.1211.28 were discovered to contain Android Debug Bridge (ADB) pre-instal…

No fix yet
Fix from $1,600 2025-08-26
Kp303 Firmware HIGH 8.8
CVE-2025-8627

The TP-Link KP303 Smartplug can be issued unauthenticated protocol commands that may cause unintended power-off condition and potential information l…

Fix: 1.1.0+
Fix from $1,950 2025-08-25
Unclassified CRITICAL 9.8
CVE-2025-53118EPSS 29%

An authentication bypass vulnerability exists which allows an unauthenticated attacker to control administrator backup functions, leading to compromi…

Mitigation only
Fix from $2,300 2025-08-25
Unclassified CRITICAL 9.8
CVE-2022-43110

Voltronic Power ViewPower through 1.04-21353 and PowerShield Netguard before 1.04-23292 allows a remote attacker to configure the system via an unspe…

Mitigation only
Fix from $2,300 2025-08-22
Dcs 825l Firmware HIGH 7.3
CVE-2025-55581

D-Link DCS-825L firmware version 1.08.01 and possibly prior versions contain an insecure implementation in the mydlink-watch-dog.sh script. The scrip…

Fix: after 1.08.01
Fix from $1,950 2025-08-22
Webitr CRITICAL 9.8
CVE-2025-9254

WebITR developed by Uniong has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to log into the system as arbitrary …

Fix: 2_1_0_33+
Fix from $2,300 2025-08-22
Unclassified CRITICAL 9.1
CVE-2024-45438

An issue was discovered in TitanHQ SpamTitan Email Security Gateway 8.00.x before 8.00.101 and 8.01.x before 8.01.14. The file quarantine.php within …

Mitigation only
Fix from $2,300 2025-08-21
Unclassified CRITICAL 9.8
CVE-2025-27214

A Missing Authentication for Critical Function vulnerability in the UniFi Connect EV Station Pro may allow a malicious actor with physical or adjacen…

Mitigation only
Fix from $2,300 2025-08-21
Cyber Backup CRITICAL 9.8
CVE-2025-8610

AOMEI Cyber Backup Missing Authentication for Critical Function Remote Code Execution Vulnerability. This vulnerability allows remote attackers to ex…

Mitigation only
Fix from $2,300 2025-08-20
Cyber Backup CRITICAL 9.8
CVE-2025-8611

AOMEI Cyber Backup Missing Authentication for Critical Function Remote Code Execution Vulnerability. This vulnerability allows remote attackers to ex…

Mitigation only
Fix from $2,300 2025-08-20
Unclassified CRITICAL 9.8
CVE-2025-51543

An issue was discovered in Cicool builder 3.4.4 allowing attackers to reset the administrator's password via the /administrator/auth/reset_password e…

Mitigation only
Fix from $2,300 2025-08-19
Unclassified HIGH 8.2
CVE-2025-8450

Improper Access Control issue in the Workflow component of Fortra's FileCatalyst allows unauthenticated users to upload arbitrary files via the order…

Mitigation only
Fix from $1,950 2025-08-19
Unclassified HIGH 7.5
CVE-2025-41689

An unauthenticated remote attacker can get access without password protection to the affected device. This enables the unprotected read-only access t…

Mitigation only
Fix from $1,950 2025-08-19
Authenticator Login CRITICAL 9.8
CVE-2025-8995

Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Authenticator Login allows Authentication Bypass.This issue affects …

Fix: 2.1.4+
Fix from $2,300 2025-08-15
Unclassified CRITICAL 9.1
CVE-2025-43983

KuWFi CPF908-CP5 WEB5.0_LCD_20210125 devices have multiple unauthenticated access control vulnerabilities within goform/goform_set_cmd_process and go…

Mitigation only
Fix from $2,300 2025-08-14
Unclassified HIGH 8.8
CVE-2025-7774

A security issue exists within the 5032 16pt Digital Configurable module’s web server. Intercepted session credentials can be used within a 3-minute …

Mitigation only
Fix from $1,950 2025-08-14
Flowise CRITICAL 9.8
CVE-2025-8943EPSS 72%

The Custom MCPs feature is designed to execute OS commands, for instance, using tools like `npx` to spin up local MCP Servers. However, Flowise's inh…

Fix: 3.0.1+
Fix from $2,300 2025-08-14
Unclassified CRITICAL 10.0
CVE-2011-10013

Traq versions 2.0 through 2.3 contain a remote code execution vulnerability in the admincp/common.php script. The flawed authorization logic fails to…

Mitigation only
Fix from $2,300 2025-08-13
Unclassified HIGH 7.5
CVE-2025-8754

Missing Authentication for Critical Function vulnerability in ABB ABB AbilityTM zenon.This issue affects ABB AbilityTM zenon: from 7.50 through 14.

Mitigation only
Fix from $1,950 2025-08-13
Windows 10 1507 HIGH 7.8
CVE-2025-53789

Missing authentication for critical function in Windows StateRepository API allows an authorized attacker to elevate privileges locally.

Fix: 10.0.10240.21073 / 10.0.14393.8246+
Fix from $1,950 2025-08-12
Hydra HIGH 7.5
CVE-2025-54864

Hydra is a continuous integration service for Nix based projects. Prior to commit f7bda02, /api/push-github and /api/push-gitea are called by the cor…

Fix: 2025-08-12+
Fix from $1,950 2025-08-12
Unclassified HIGH 7.8
CVE-2025-41686

A low-privileged local attacker can exploit improper permissions on nssm.exe to escalate their privileges and gain administrative access.

Mitigation only
Fix from $1,950 2025-08-12
Confluence MEDIUM 5.3
CVE-2025-54478

Mattermost Confluence Plugin version <1.5.0 fails to enforce authentication of the user to the Mattermost instance which allows unauthenticated attac…

Fix: 1.5.0+
Fix from $1,600 2025-08-11
Unclassified HIGH 8.1
CVE-2025-7679

The ASPECT system allows users to bypass authentication. This issue affects all versions of ASPECT

No fix yet
Fix from $1,950 2025-08-11
Confluence HIGH 7.2
CVE-2025-44004

Mattermost Confluence Plugin version <1.5.0 fails to check the authorization of the user to the Mattermost instance which allows attackers to create …

Fix: 1.5.0+
Fix from $1,950 2025-08-11
Unclassified CRITICAL 9.8
CVE-2025-5095

Burk Technology ARC Solo's password change mechanism can be utilized without proper authentication procedures, allowing an attacker to take over the…

Mitigation only
Fix from $2,300 2025-08-08
Unclassified CRITICAL 9.8
CVE-2025-8284

By default, the Packet Power Monitoring and Control Web Interface do not enforce authentication mechanisms. This vulnerability could allow unauthor…

Mitigation only
Fix from $2,300 2025-08-08
Unclassified CRITICAL 9.3
CVE-2014-125113

An unrestricted file upload vulnerability exists in Dell (acquired by Quest) KACE K1000 System Management Appliance version 5.0 - 5.3, 5.4 prior to 5…

No fix yet
Fix from $2,300 2025-08-05
Freefloat Ftp Server CRITICAL 9.8
CVE-2012-10030

FreeFloat FTP Server contains multiple critical design flaws that allow unauthenticated remote attackers to upload arbitrary files to sensitive syste…

Mitigation only
Fix from $2,300 2025-08-05