Vulnerability index

Browse CVEs

2,893 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthenticationCWE-306 × clear
T6 Firmware HIGH 8.8
CVE-2025-6916

A vulnerability, which was classified as critical, was found in TOTOLINK T6 4.1.5cu.748_B20211015. This affects the function Form_Login of the file /…

No fix yet
Fix from $1,950 2025-06-30
Unclassified HIGH 7.5
CVE-2024-8419

The endpoint hosts a script that allows an unauthorized remote attacker to put the system in a fail-safe state over the network due to missing authen…

Mitigation only
Fix from $1,950 2025-06-30
Unclassified CRITICAL 9.8
CVE-2025-5310

Dover Fueling Solutions ProGauge MagLink LX Consoles expose an undocumented and unauthenticated target communication framework (TCF) interface on a s…

Mitigation only
Fix from $2,300 2025-06-27
T7611 Firmware HIGH 8.1
CVE-2025-6763

A vulnerability was found in Comet System T0510, T3510, T3511, T4511, T6640, T7511, T7611, P8510, P8552 and H3531 1.60. Affected by this issue is som…

No fix yet
Fix from $1,950 2025-06-27
Unclassified CRITICAL 9.8
CVE-2025-3699

Missing Authentication for Critical Function vulnerability in Mitsubishi Electric Corporation G-50 all versions, G-50-W all versions, G-50A all versi…

Mitigation only
Fix from $2,300 2025-06-26
GitLab MEDIUM 5.3
CVE-2025-1754

An issue has been discovered in GitLab CE/EE affecting all versions from 17.2 before 17.11.5, 18.0 before 18.0.3, and 18.1 before 18.1.1 that could h…

Fix: 17.11.5 / 18.0.3+
Fix from $1,600 2025-06-26
Maxicharger Ac Elite Business C50 Firmware HIGH 7.5
CVE-2025-6678

Autel MaxiCharger AC Wallbox Commercial PIN Missing Authentication Information Disclosure Vulnerability. This vulnerability allows remote attackers t…

Fix: 1.39.51 / 1.56.51+
Fix from $1,950 2025-06-25
Unclassified HIGH 7.5
CVE-2025-32978

Quest KACE Systems Management Appliance (SMA) 13.0.x before 13.0.385, 13.1.x before 13.1.81, 13.2.x before 13.2.183, 14.0.x before 14.0.341 (Patch 5)…

Mitigation only
Fix from $1,950 2025-06-24
Unclassified HIGH 8.2
CVE-2025-3090

An unauthenticated remote attacker can obtain limited sensitive information and/or DoS the device due to missing authentication for critical function.

Mitigation only
Fix from $1,950 2025-06-24
Wise 4060lan Firmware CRITICAL 9.6
CVE-2025-48469

Successful exploitation of the vulnerability could allow an unauthenticated attacker to upload firmware through a public update page, potentially lea…

No fix yet
Fix from $2,300 2025-06-24
Unclassified CRITICAL 10.0
CVE-2025-34039

A code injection vulnerability exists in Yonyou UFIDA NC v6.5 and prior due to the exposure of the BeanShell testing servlet (bsh.servlet.BshServlet)…

Mitigation only
Fix from $2,300 2025-06-24
Spectrum Protect Server CRITICAL 9.8
CVE-2025-3319

IBM Spectrum Protect Server 8.1 through 8.1.26 could allow attacker to bypass authentication due to improper session authentication which can result …

Fix: after 8.1.26
Fix from $2,300 2025-06-20
Coros Pace 3 Firmware HIGH 8.8
CVE-2025-32879

An issue was discovered on COROS PACE 3 devices through 3.0808.0. It starts advertising if no device is connected via Bluetooth. This allows an attac…

Fix: after 3.0808.0
Fix from $1,950 2025-06-20
Coros Pace 3 Firmware MEDIUM 6.8
CVE-2025-32876

An issue was discovered on COROS PACE 3 devices through 3.0808.0. The BLE implementation of the COROS smartwatch does not support LE Secure Connectio…

Fix: after 3.0808.0
Fix from $1,600 2025-06-20
Seatunnel MEDIUM 6.5
CVE-2025-32896

# Summary Unauthorized users can perform Arbitrary File Read and Deserialization attack by submit job using restful api-v1. # Details Unauthorized …

Fix: 2.3.11+
Fix from $1,600 2025-06-19
Unclassified CRITICAL 9.4
CVE-2025-49596EPSS 45%

The MCP inspector is a developer tool for testing and debugging MCP servers. Versions of MCP Inspector below 0.14.1 are vulnerable to remote code exe…

Patch available
Fix from $2,300 2025-06-13
Unclassified MEDIUM 6.1
CVE-2024-35295

A vulnerability has been identified in Perfect Harmony GH180 (All versions >= V8.0 < V8.3.3 with NXGPro+ controller manufactured between April 2020 t…

Mitigation only
Fix from $1,600 2025-06-11
Unclassified HIGH 7.8
CVE-2024-9062

The Archify application contains a local privilege escalation vulnerability due to insufficient client validation in its privileged helper tool, com.…

Mitigation only
Fix from $1,950 2025-06-11
Laundry System CRITICAL 9.8
CVE-2025-5906

A vulnerability classified as critical has been found in code-projects Laundry System 1.0. This affects an unknown part of the file /data/. The manip…

Mitigation only
Fix from $2,300 2025-06-10
011209 Sip Emergency Intercom HIGH 7.5
CVE-2025-26468

CyberData  011209 Intercom exposes features that could allow an unauthenticated to gain access and cause a denial-of-service condition or system …

Fix: 22.0.1+
Fix from $1,950 2025-06-09
Unclassified CRITICAL 9.8
CVE-2025-49652

Missing Authentication in the registration feature of Lablup's BackendAI allows arbitrary users to create user accounts that can access private data …

Mitigation only
Fix from $2,300 2025-06-09
Unclassified MEDIUM 5.3
CVE-2025-5876

A vulnerability classified as problematic was found in Lucky LM-520-SC, LM-520-FSC and LM-520-FSC-SAM up to 20250321. Affected by this vulnerability …

Mitigation only
Fix from $1,600 2025-06-09
Unclassified MEDIUM 5.3
CVE-2025-5871

A vulnerability was found in Papendorf SOL Connect Center 3.3.0.0 and classified as problematic. Affected by this issue is some unknown functionality…

Mitigation only
Fix from $1,600 2025-06-09
Unclassified MEDIUM 5.3
CVE-2025-5872

A vulnerability was found in eGauge EG3000 Energy Monitor 3.6.3. It has been classified as problematic. This affects an unknown part of the component…

Mitigation only
Fix from $1,600 2025-06-09
Qhs710 Firmware CRITICAL 9.8
CVE-2025-3461

The Quantenna Wi-Fi chips ship with an unauthenticated telnet interface by default. This is an instance of CWE-306, "Missing Authentication for Criti…

Mitigation only
Fix from $2,300 2025-06-08
Unclassified CRITICAL 9.0
CVE-2024-55585

In the moPS App through 1.8.618, all users can access administrative API endpoints without additional authentication, resulting in unrestricted read …

Mitigation only
Fix from $2,300 2025-06-07
Hr Portal HIGH 7.5
CVE-2025-5192

A missing authentication for critical function vulnerability in the client application of Soar Cloud HRD Human Resource Management System through ver…

Fix: after 7.3.2025.0408
Fix from $1,950 2025-06-06
Unclassified MEDIUM 5.1
CVE-2025-5719

The wallet has an authentication bypass vulnerability that allows access to specific pages.

No fix yet
Fix from $1,600 2025-06-06
Signal MEDIUM 6.4
CVE-2025-5715

A vulnerability was found in Signal App 7.41.4 on Android. It has been declared as problematic. This vulnerability affects unknown code of the compon…

No fix yet
Fix from $1,600 2025-06-06
Unclassified HIGH 8.9
CVE-2025-1701

CVE-2025-1701 is a high-severity vulnerability in the MIM Admin service. An attacker could exploit this vulnerability by sending a specially crafted …

Mitigation only
Fix from $1,950 2025-06-04