Vulnerability index

Browse CVEs

2,893 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthenticationCWE-306 × clear
Unclassified MEDIUM 5.5
CVE-2025-47272

The CE Phoenix eCommerce platform, starting in version 1.0.9.7 and prior to version 1.1.0.3, allowed logged-in users to delete their accounts without…

Patch available
Fix from $1,600 2025-06-02
Unclassified CRITICAL 9.8
CVE-2025-1907

Instantel Micromate lacks authentication on a configuration port which could allow an attacker to execute commands if connected.

Mitigation only
Fix from $2,300 2025-05-30
Fortiproxy HIGH 7.2
CVE-2025-22252

A missing authentication for critical function in Fortinet FortiProxy versions 7.6.0 through 7.6.1, FortiSwitchManager version 7.2.5, and FortiOS ver…

Fix: 7.4.7+
Fix from $1,950 2025-05-28
Netalertx CRITICAL 9.8
CVE-2025-32440

NetAlertX is a network, presence scanner and alert framework. Prior to version 25.4.14, it is possible to bypass the authentication mechanism of NetA…

Fix: 25.4.14+
Fix from $2,300 2025-05-27
Unclassified CRITICAL 9.8
CVE-2025-41651

Due to missing authentication on a critical function of the devices an unauthenticated remote attacker can execute arbitrary commands, potentially en…

Mitigation only
Fix from $2,300 2025-05-27
Unclassified CRITICAL 9.3
CVE-2025-2407

Missing Authentication & Authorization in Web-API in Mobatime AMX MTAPI v6 on IIS allows adversaries to unrestricted access via the network. The vuln…

Mitigation only
Fix from $2,300 2025-05-27
Pmb CRITICAL 9.8
CVE-2025-48742

The installer in SIGB PMB before and fixed in v.8.0.1.2 allows remote code execution.

Fix: 8.0.1.2+
Fix from $2,300 2025-05-27
Gim CRITICAL 9.1
CVE-2025-40664

Missing authentication vulnerability in TCMAN GIM v11. This allows an unauthenticated attacker to access the resources /frmGestionUser.aspx/GetData, …

Mitigation only
Fix from $2,300 2025-05-26
Unclassified HIGH 7.5
CVE-2025-41655

An unauthenticated remote attacker can access a URL which causes the device to reboot.

Mitigation only
Fix from $1,950 2025-05-26
Unclassified HIGH 8.2
CVE-2025-41654

An unauthenticated remote attacker can access information about running processes via the SNMP protocol. The amount of returned data can trigger a re…

Mitigation only
Fix from $1,950 2025-05-26
Unclassified CRITICAL 10.0
CVE-2025-36535

The embedded web server lacks authentication and access controls, allowing unrestricted remote access. This could lead to configuration changes, oper…

Mitigation only
Fix from $2,300 2025-05-21
Meteobridge Vm HIGH 8.8
CVE-2025-4008 KEVEPSS 94%

The Meteobridge web interface let meteobridge administrator manage their weather station data collection and administer their meteobridge system thro…

Fix: 6.2+
Fix from $1,950 2025-05-21
Unclassified MEDIUM 6.5
CVE-2025-27803

The devices do not implement any authentication for the web interface or the MQTT server. An attacker who has network access to the device immediatel…

Mitigation only
Fix from $1,600 2025-05-21
Youtrack HIGH 7.5
CVE-2025-48391

In JetBrains YouTrack before 2025.1.76253 deletion of issues was possible due to missing permission checks in API

Fix: 2025.1.76253+
Fix from $1,950 2025-05-20
Youtrack MEDIUM 5.3
CVE-2025-47850

In JetBrains YouTrack before 2025.1.74704 restricted attachments could become visible after issue cloning

Fix: 2025.1.74704+
Fix from $1,600 2025-05-20
Unclassified MEDIUM 5.3
CVE-2025-32738

Missing authentication for critical function issue exists in I-O DATA network attached hard disk 'HDL-T Series' firmware Ver.1.21 and earlier. If exp…

Mitigation only
Fix from $1,600 2025-05-15
Unclassified MEDIUM 6.9
CVE-2025-0132

A missing authentication vulnerability in Palo Alto Networks Cortex XDR® Broker VM allows an unauthenticated user to disable certain internal service…

Mitigation only
Fix from $1,600 2025-05-14
Netalertx CRITICAL 10.0
CVE-2024-46506EPSS 62%

NetAlertX 23.01.14 through 24.x before 24.10.12 allows unauthenticated command injection via settings update because function=savesettings lacks an a…

Fix: 24.10.12+
Fix from $2,300 2025-05-13
Cp Xr De21 S Firmware MEDIUM 5.1
CVE-2025-44039

CP-XR-DE21-S -4G Router Firmware version 1.031.022 was discovered to contain insecure protections for its UART console. This vulnerability allows loc…

No fix yet
Fix from $1,600 2025-05-13
Unclassified HIGH 7.5
CVE-2024-23815

A vulnerability has been identified in Desigo CC (All versions if access from Installed Clients to Desigo CC server is allowed from networks outside …

Mitigation only
Fix from $1,950 2025-05-13
Unclassified MEDIUM 6.5
CVE-2025-4560

The ISOinsight from Netvision has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to access certain system function…

Mitigation only
Fix from $1,600 2025-05-12
Unclassified CRITICAL 9.1
CVE-2025-4557

The specific APIs of Parking Management System from ZONG YU has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to …

Mitigation only
Fix from $2,300 2025-05-12
Unclassified CRITICAL 9.8
CVE-2025-4555

The web management interface of Okcat Parking Management Platform from ZONG YU has a Missing Authentication vulnerability, allowing unauthenticated r…

Mitigation only
Fix from $2,300 2025-05-12
Unclassified MEDIUM 5.9
CVE-2025-4382

A flaw was found in systems utilizing LUKS-encrypted disks with GRUB configured for TPM-based auto-decryption. When GRUB is set to automatically decr…

Mitigation only
Fix from $1,600 2025-05-09
Unclassified HIGH 8.7
CVE-2025-3758

WF2220 exposes endpoint /cgi-bin-igd/netcore_get.cgi that returns configuration of the device to unauthorized users. Returned configuration includes …

Mitigation only
Fix from $1,950 2025-05-08
Unclassified HIGH 8.7
CVE-2025-3759

Endpoint /cgi-bin-igd/netcore_set.cgi which is used for changing device configuration is accessible without authentication. This poses a significant …

Mitigation only
Fix from $1,950 2025-05-08
Catalyst Center HIGH 7.3
CVE-2025-20210

A vulnerability in the management API of Cisco Catalyst Center, formerly Cisco DNA Center, could allow an unauthenticated, remote attacker to read an…

Fix: 2.3.7.9+
Fix from $1,950 2025-05-07
A720r Firmware MEDIUM 5.3
CVE-2025-4268

A vulnerability has been found in TOTOLINK A720R 4.1.5cu.374 and classified as critical. This vulnerability affects unknown code of the file /cgi-bin…

No fix yet
Fix from $1,600 2025-05-05
Ipados MEDIUM 5.4
CVE-2025-24271

An access issue was addressed with improved access restrictions. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, …

Fix: 2.4 / 13.7.5+
Fix from $1,600 2025-04-29
Novel Plus CRITICAL 9.8
CVE-2025-4019

A vulnerability, which was classified as critical, was found in 20120630 Novel-Plus up to 0e156c04b4b7ce0563bef6c97af4476fcda8f160. Affected is the f…

Fix: 5.1.1+
Fix from $2,300 2025-04-28