Vulnerability index

Browse CVEs

2,893 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthenticationCWE-306 × clear
Unclassified HIGH 8.7
CVE-2025-34113

An authenticated command injection vulnerability exists in Tiki Wiki CMS versions ≤14.1, ≤12.4 LTS, ≤9.10 LTS, and ≤6.14 via the `viewmode` GET param…

No fix yet
Fix from $1,950 2025-07-15
Unclassified HIGH 8.7
CVE-2025-34115

An authenticated command injection vulnerability exists in OP5 Monitor through version 7.1.9 via the 'cmd_str' parameter in the command_test.php endp…

No fix yet
Fix from $1,950 2025-07-15
Unclassified CRITICAL 9.3
CVE-2025-34110

A directory traversal vulnerability exists in ColoradoFTP Server ≤ 1.3 Build 8 for Windows, allowing unauthenticated attackers to read or write arbit…

Patch available
Fix from $2,300 2025-07-15
Tikiwiki Cms\/groupware CRITICAL 9.8
CVE-2025-34111

An unauthenticated arbitrary file upload vulnerability exists in Tiki Wiki CMS Groupware version 15.1 and earlier via the ELFinder component's defaul…

Fix: after 15.1
Fix from $2,300 2025-07-15
Unclassified CRITICAL 9.3
CVE-2025-34068

An unauthenticated remote command execution vulnerability exists in Samsung WLAN AP WEA453e firmware prior to version 5.2.4.T1 via improper input val…

Mitigation only
Fix from $2,300 2025-07-15
Unclassified CRITICAL 9.3
CVE-2025-34103

An unauthenticated command injection vulnerability exists in WePresent WiPG-1000 firmware versions prior to 2.2.3.0, due to improper input handling i…

No fix yet
Fix from $2,300 2025-07-15
Unclassified CRITICAL 9.4
CVE-2025-34104

An authenticated remote code execution vulnerability exists in Piwik (now Matomo) versions prior to 3.0.3 via the plugin upload mechanism. In vulnera…

Mitigation only
Fix from $2,300 2025-07-15
N300rb Firmware HIGH 8.8
CVE-2025-52089EPSS 8%

A hidden remote support feature protected by a static secret in TOTOLINK N300RB firmware version 8.54 allows an authenticated attacker to execute arb…

No fix yet
Fix from $1,950 2025-07-11
Unclassified CRITICAL 9.3
CVE-2025-34102EPSS 7%

A remote code execution vulnerability exists in CryptoLog (PHP version, discontinued since 2009) due to a chained exploitation of SQL injection and c…

No fix yet
Fix from $2,300 2025-07-10
Unclassified CRITICAL 9.3
CVE-2025-34100

An unrestricted file upload vulnerability exists in BuilderEngine 3.5.0 via the integration of the elFinder 2.0 file manager and its use of the jQuer…

No fix yet
Fix from $2,300 2025-07-10
Unclassified CRITICAL 9.3
CVE-2025-34101

An unauthenticated command injection vulnerability exists in Serviio Media Server versions 1.4 through 1.8 on Windows, in the /rest/action API endpoi…

No fix yet
Fix from $2,300 2025-07-10
Worry Free Business Security Services CRITICAL 9.8
CVE-2025-53378

A missing authentication vulnerability in Trend Micro Worry-Free Business Security Services (WFBSS) agent could have allowed an unauthenticated attac…

Fix: 6.7.3954 / 14.3.1299+
Fix from $2,300 2025-07-10
Unclassified CRITICAL 9.9
CVE-2025-3498

An unauthenticated user with management network access can get and modify the Radiflow iSAP Smart Collector (CentOS 7 - VSAP 1.20) configuration. T…

Mitigation only
Fix from $2,300 2025-07-09
Unclassified CRITICAL 10.0
CVE-2025-34077EPSS 10%

An authentication bypass vulnerability exists in the WordPress Pie Register plugin ≤ 3.7.1.4 that allows unauthenticated attackers to impersonate arb…

Mitigation only
Fix from $2,300 2025-07-09
Config Pages Viewer MEDIUM 5.3
CVE-2025-7031

Missing Authentication for Critical Function vulnerability in Drupal Config Pages Viewer allows Exploiting Incorrectly Configured Access Control Secu…

Fix: 1.0.4+
Fix from $1,600 2025-07-08
Windows 10 1607 HIGH 7.5
CVE-2025-48814

Missing authentication for critical function in Windows Remote Desktop Licensing Service allows an unauthorized attacker to bypass a security feature…

Fix: 10.0.14393.8246 / 10.0.17763.7558+
Fix from $1,950 2025-07-08
Sinec Nms CRITICAL 9.8
CVE-2025-40736

A vulnerability has been identified in SINEC NMS (All versions < V4.0). The affected application exposes an endpoint that allows an unauthorized modi…

Fix: 4.0+
Fix from $2,300 2025-07-08
Charx Sec 3000 Firmware HIGH 8.8
CVE-2025-25268

An unauthenticated adjacent attacker can modify configuration by sending specific requests to an API-endpoint resulting in read and write access due …

Fix: 1.7.3+
Fix from $1,950 2025-07-08
Sim HIGH 7.5
CVE-2025-7114

A vulnerability was found in SimStudioAI sim up to 37786d371e17d35e0764e1b5cd519d873d90d97b. It has been declared as critical. Affected by this vulne…

Fix: after 0.2.1
Fix from $1,950 2025-07-07
Unclassified HIGH 7.3
CVE-2025-7115

A vulnerability was found in rowboatlabs rowboat up to 8096eaf63b5a0732edd8f812bee05b78e214ee97. It has been rated as critical. Affected by this issu…

Mitigation only
Fix from $1,950 2025-07-07
Unclassified CRITICAL 9.3
CVE-2025-34089

An unauthenticated remote code execution vulnerability exists in Remote for Mac, a macOS remote control utility developed by Aexol Studio, in version…

No fix yet
Fix from $2,300 2025-07-03
Nsclient\+\+ HIGH 7.8
CVE-2025-34079

An authenticated remote code execution vulnerability exists in NSClient++ version 0.5.2.35 when the web interface and ExternalScripts module are enab…

No fix yet
Fix from $1,950 2025-07-02
Ns3000 Firmware CRITICAL 9.8
CVE-2025-45814

Missing authentication checks in the query.fcgi endpoint of NS3000 v8.1.1.125110 , v7.2.8.124852 , and v7.x and NS2000 v7.02.08 allows attackers to e…

Mitigation only
Fix from $2,300 2025-07-02
Unclassified HIGH 8.7
CVE-2025-34057EPSS 8%

An information disclosure vulnerability exists in Ruijie NBR series routers (known to affect NBR2000G, NBR1300G, and NBR1000 models) via the /WEB_VMS…

Mitigation only
Fix from $1,950 2025-07-02
Kerio Control CRITICAL 9.8
CVE-2025-34069

An authentication bypass vulnerability exists in GFI Kerio Control 9.4.5 due to insecure default proxy configuration and weak access control in the G…

Mitigation only
Fix from $2,300 2025-07-02
Kerio Control CRITICAL 9.8
CVE-2025-34070

A missing authentication vulnerability in the GFIAgent component of GFI Kerio Control 9.4.5 allows unauthenticated remote attackers to perform privil…

Mitigation only
Fix from $2,300 2025-07-02
Kerio Control CRITICAL 9.8
CVE-2025-34071

A remote code execution vulnerability in GFI Kerio Control 9.4.5 allows attackers with administrative access to upload and execute arbitrary code thr…

Mitigation only
Fix from $2,300 2025-07-02
Unclassified CRITICAL 10.0
CVE-2025-34073

An unauthenticated command injection vulnerability exists in stamparm/maltrail (Maltrail) versions <=0.54. A remote attacker can execute arbitrary op…

Mitigation only
Fix from $2,300 2025-07-02
Ai Inference Server MEDIUM 5.3
CVE-2025-6920

A flaw was found in the authentication enforcement mechanism of a model inference API in ai-inference-server. All /v1/* endpoints are expected to enf…

Mitigation only
Fix from $1,600 2025-07-01
Unclassified CRITICAL 10.0
CVE-2025-41656EPSS 12%

An unauthenticated remote attacker can run arbitrary commands on the affected devices with high privileges because the authentication for the Node_RE…

Mitigation only
Fix from $2,300 2025-07-01