Vulnerability index

Browse CVEs

2,893 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthenticationCWE-306 × clear
Unclassified HIGH 8.8
CVE-2025-20702EPSS 8%

In the Airoha Bluetooth audio SDK, there is a possible unauthorized access to the RACE protocol. This could lead to remote escalation of privilege wi…

Mitigation only
Fix from $1,950 2025-08-04
Unclassified HIGH 8.8
CVE-2025-20700EPSS 8%

In the Airoha Bluetooth audio SDK, there is a possible permission bypass that allows access critical data of RACE protocol through Bluetooth LE GATT …

Mitigation only
Fix from $1,950 2025-08-04
Unclassified HIGH 8.5
CVE-2013-10046

A local privilege escalation vulnerability exists in Agnitum Outpost Internet Security 8.1 that allows an unprivileged user to execute arbitrary code…

No fix yet
Fix from $1,950 2025-08-01
Unclassified CRITICAL 9.3
CVE-2025-8286

The affected products expose an unauthenticated Telnet-based command line interface that could allow an attacker to modify hardware configurations, m…

Mitigation only
Fix from $2,300 2025-07-31
Unclassified CRITICAL 9.2
CVE-2014-125126

An unrestricted file upload vulnerability exists in Simple E-Document versions 3.0 to 3.1 that allows an unauthenticated attacker to bypass authentic…

No fix yet
Fix from $2,300 2025-07-31
Unclassified CRITICAL 10.0
CVE-2014-125124

An unauthenticated remote command execution vulnerability exists in Pandora FMS versions up to and including 5.0RC1 via the Anyterm web interface, wh…

Mitigation only
Fix from $2,300 2025-07-31
Language Server CRITICAL 9.8
CVE-2025-8279

Insufficient input validation within GitLab Language Server 7.6.0 and later before 7.30.0 allows arbitrary GraphQL query execution

Fix: 7.30.0+
Fix from $2,300 2025-07-28
Unclassified MEDIUM 5.3
CVE-2025-30126

An issue was discovered on Marbella KR8s Dashcam FF 2.0.8 devices. Via port 7777 without any need to pair or press a physical button, a remote attack…

Mitigation only
Fix from $1,600 2025-07-28
Fx2 Firmware CRITICAL 9.4
CVE-2025-30135

An issue was discovered on IROAD Dashcam FX2 devices. Dumping Files Over HTTP and RTSP Without Authentication can occur. It lacks authentication cont…

Mitigation only
Fix from $2,300 2025-07-25
Unclassified CRITICAL 9.3
CVE-2014-125116

A remote code execution vulnerability exists in HybridAuth versions 2.0.9 through 2.2.2 due to insecure use of the install.php installation script. T…

No fix yet
Fix from $2,300 2025-07-25
Unclassified CRITICAL 9.4
CVE-2014-125118

A command injection vulnerability exists in the eScan Web Management Console version 5.5-2. The application fails to properly sanitize the 'pass' par…

No fix yet
Fix from $2,300 2025-07-25
Unclassified HIGH 8.6
CVE-2016-15046

A client-side remote code execution vulnerability exists in Hanwha Techwin Smart Security Manager (SSM) versions 1.32 and 1.4, due to improper restri…

Mitigation only
Fix from $1,950 2025-07-25
Getsimplecms HIGH 8.8
CVE-2013-10032

An authenticated remote code execution vulnerability exists in GetSimpleCMS version 3.2.1. The application’s upload.php endpoint allows authenticated…

No fix yet
Fix from $1,950 2025-07-25
Unclassified CRITICAL 9.8
CVE-2025-6260

The embedded web server on the thermostat listed version ranges contain a vulnerability that allows unauthenticated attackers, either on the local ar…

Mitigation only
Fix from $2,300 2025-07-24
Unclassified CRITICAL 9.3
CVE-2022-4978

Remote Control Server, maintained by Steppschuh, 3.1.1.12 allows unauthenticated remote code execution when authentication is disabled, which is the …

Mitigation only
Fix from $2,300 2025-07-23
Unclassified CRITICAL 9.3
CVE-2015-10141EPSS 5%

An unauthenticated OS command injection vulnerability exists within Xdebug versions 2.5.5 and earlier, a PHP debugging extension developed by Derick …

No fix yet
Fix from $2,300 2025-07-23
Unclassified HIGH 8.5
CVE-2016-15045

A local privilege escalation vulnerability exists in lastore-daemon, the system package manager daemon used in Deepin Linux (developed by Wuhan Deepi…

No fix yet
Fix from $1,950 2025-07-23
Unclassified HIGH 7.5
CVE-2025-48733

DuraComm SPM-500 DP-10iN-100-MU lacks access controls for a function that should require user authentication. This could allow an attacker to repea…

Mitigation only
Fix from $1,950 2025-07-22
Moneyprinterturbo CRITICAL 9.8
CVE-2025-7897

A vulnerability was found in harry0703 MoneyPrinterTurbo up to 1.2.6 and classified as critical. Affected by this issue is the function verify_token …

Fix: after 1.2.6
Fix from $2,300 2025-07-20
T6 Firmware CRITICAL 9.8
CVE-2025-7862

A vulnerability has been found in TOTOLINK T6 4.1.5cu.748_B20211015 and classified as critical. Affected by this vulnerability is the function setTel…

Mitigation only
Fix from $2,300 2025-07-20
Mattermost Server MEDIUM 6.5
CVE-2025-6226

Mattermost versions 10.5.x <= 10.5.6, 10.8.x <= 10.8.1, 10.7.x <= 10.7.3, 9.11.x <= 9.11.16 fail to verify authorization when retrieving cached posts…

Fix: 9.11.17 / 10.5.7+
Fix from $1,600 2025-07-18
Unclassified HIGH 8.7
CVE-2025-34130

An unauthenticated arbitrary file read exists in LILIN Digital Video Recorder (DVR) devices prior to firmware version 2.0b60_20200207 via the /z/zbin…

Mitigation only
Fix from $1,950 2025-07-16
Unclassified CRITICAL 9.3
CVE-2025-34121

An unauthenticated arbitrary file upload vulnerability exists in Idera Up.Time Monitoring Station versions up to and including 7.2. The `wizards/post…

No fix yet
Fix from $2,300 2025-07-16
Unclassified CRITICAL 9.3
CVE-2025-34117EPSS 20%

A remote code execution vulnerability exists in multiple Netcore and Netis routers models with firmware released prior to August 2014 due to the pres…

No fix yet
Fix from $2,300 2025-07-16
Unclassified HIGH 8.8
CVE-2025-34119

A remote file disclosure vulnerability exists in EasyCafe Server 2.2.14, exploitable by unauthenticated remote attackers via TCP port 831. The server…

No fix yet
Fix from $1,950 2025-07-16
Unclassified HIGH 8.7
CVE-2025-34120

An unauthenticated file download vulnerability exists in LimeSurvey versions from 2.0+ up to and including 2.06+ Build 151014. The application fails …

Mitigation only
Fix from $1,950 2025-07-16
Wegia HIGH 7.5
CVE-2025-53938

WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. An Authentication Bypass vulnerability was i…

Fix: 3.4.5+
Fix from $1,950 2025-07-16
Weblogic Server HIGH 7.5
CVE-2025-30762

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4…

Patch available
Fix from $1,950 2025-07-15
Unclassified HIGH 8.7
CVE-2025-34116

A remote command execution vulnerability exists in IPFire before version 2.19 Core Update 101 via the 'proxy.cgi' CGI interface. An authenticated att…

No fix yet
Fix from $1,950 2025-07-15
Unclassified CRITICAL 10.0
CVE-2025-34112

An authenticated multi-stage remote code execution vulnerability exists in Riverbed SteelCentral NetProfiler and NetExpress 10.8.7 virtual appliances…

Mitigation only
Fix from $2,300 2025-07-15