Vulnerability index

Browse CVEs

2,893 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthenticationCWE-306 × clear
Novel Plus HIGH 7.5
CVE-2025-4018

A vulnerability, which was classified as critical, has been found in 20120630 Novel-Plus up to 0e156c04b4b7ce0563bef6c97af4476fcda8f160. This issue a…

Fix: 5.1.1+
Fix from $1,950 2025-04-28
Novel Plus HIGH 7.5
CVE-2025-4015

A vulnerability was found in 20120630 Novel-Plus up to 0e156c04b4b7ce0563bef6c97af4476fcda8f160. It has been rated as critical. Affected by this issu…

Fix: 5.1.1+
Fix from $1,950 2025-04-28
Unclassified CRITICAL 9.8
CVE-2025-46275

WGS-80HPT-V2 and WGS-4215-8T2S are missing authentication that could allow an attacker to create an administrator account without knowing any exist…

Mitigation only
Fix from $2,300 2025-04-24
Commvault CRITICAL 10.0
CVE-2025-34028 KEVEPSS 98%

The Commvault Command Center Innovation Release allows an unauthenticated actor to upload ZIP files that represent install packages that, when expand…

Fix: 11.38.20+
Fix from $2,300 2025-04-22
Unclassified MEDIUM 6.5
CVE-2025-32377

Rasa Pro is a framework for building scalable, dynamic conversational AI assistants that integrate large language models (LLMs). A vulnerability has …

Mitigation only
Fix from $1,600 2025-04-18
Dryice Myxalytics HIGH 7.5
CVE-2024-42178

HCL MyXalytics is affected by a failure to restrict URL access vulnerability. Unauthenticated users might gain unauthorized access to potentially con…

Mitigation only
Fix from $1,950 2025-04-17
Confd Basic CRITICAL 10.0
CVE-2025-32433 KEVEPSS 99%

Erlang/OTP is a set of libraries for the Erlang programming language. Prior to versions OTP-27.3.3, OTP-26.2.5.11, and OTP-25.3.2.20, a SSH server ma…

Fix: 5.7.19.1 / 6.1.16.2+
Fix from $2,300 2025-04-16
Unclassified CRITICAL 9.6
CVE-2025-30215

NATS-Server is a High-Performance server for NATS.io, the cloud and edge native messaging system. In versions starting from 2.2.0 but prior to 2.10.2…

Mitigation only
Fix from $2,300 2025-04-16
Unclassified MEDIUM 5.3
CVE-2025-32782

Ash Authentication provides authentication for the Ash framework. The confirmation flow for account creation currently uses a GET request triggered b…

Patch available
Fix from $1,600 2025-04-15
E Business Suite CRITICAL 9.8
CVE-2025-30727

Vulnerability in the Oracle Scripting product of Oracle E-Business Suite (component: iSurvey Module). Supported versions that are affected are 12.2.…

Fix: after 12.2.14
Fix from $2,300 2025-04-15
Unclassified CRITICAL 9.8
CVE-2025-2567

An attacker could modify or disable settings, disrupt fuel monitoring and supply chain operations, leading to disabling of ATG monitoring. This wou…

Mitigation only
Fix from $2,300 2025-04-15
Unclassified CRITICAL 9.3
CVE-2025-0129

An improper exception check in Palo Alto Networks Prisma Access Browser allows a low privileged user to prevent Prisma Access Browser from applying i…

Mitigation only
Fix from $2,300 2025-04-11
Panels MEDIUM 6.5
CVE-2025-3474

Missing Authentication for Critical Function vulnerability in Drupal Panels allows Exploiting Incorrectly Configured Access Control Security Levels.T…

Fix: 4.9+
Fix from $1,600 2025-04-09
Unclassified HIGH 7.5
CVE-2025-29870

Missing authentication for critical function vulnerability exists in Wi-Fi AP UNIT 'AC-WPS-11ac series'. If exploited, a remote unauthenticated attac…

Mitigation only
Fix from $1,950 2025-04-09
7kt Pac1260 Data Manager Firmware HIGH 7.5
CVE-2024-41793

A vulnerability has been identified in SENTRON 7KT PAC1260 Data Manager (All versions). The web interface of affected devices provides an endpoint th…

Mitigation only
Fix from $1,950 2025-04-08
7kt Pac1260 Data Manager Firmware MEDIUM 6.5
CVE-2024-41791

A vulnerability has been identified in SENTRON 7KT PAC1260 Data Manager (All versions). The web interface of affected devices does not authenticate r…

Mitigation only
Fix from $1,600 2025-04-08
Langflow CRITICAL 9.8
CVE-2025-3248 KEVEPSS 100%

Langflow versions prior to 1.3.0 are susceptible to code injection in the /api/v1/validate/code endpoint. A remote and unauthenticated attacker can …

Fix: 1.3.0+
Fix from $2,300 2025-04-07
Hcl Devops Deploy HIGH 7.5
CVE-2025-0257

HCL DevOps Deploy / HCL Launch could allow unauthorized access to other services or potential exposure of sensitive data due to missing authenticatio…

Fix: 7.1.2.23 / 7.2.3.16+
Fix from $1,950 2025-04-02
Unclassified HIGH 8.2
CVE-2025-25060

Missing authentication for critical function vulnerability exists in AssetView and AssetView CLOUD. If exploited, the files on the server where the p…

Mitigation only
Fix from $1,950 2025-04-02
Sms Alert Order Notifications CRITICAL 9.8
CVE-2024-13553

The SMS Alert Order Notifications – WooCommerce plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to…

Fix: 3.8.0+
Fix from $2,300 2025-04-01
Devops Deploy MEDIUM 6.3
CVE-2024-56469

IBM UrbanCode Deploy (UCD) 7.1 through 7.1.2.22, 7.2 through 7.2.3.15, and 7.3 through 7.3.2.10 / IBM DevOps Deploy 8.0 through 8.0.1.5 and 8.1 throu…

Fix: 7.1.2.23 / 7.2.3.16+
Fix from $1,600 2025-03-27
Unclassified HIGH 7.3
CVE-2024-45356

A unauthorized access vulnerability exists in the Xiaomi phone framework. The vulnerability is caused by improper validation and can be exploited by …

No fix yet
Fix from $1,950 2025-03-27
Unclassified MEDIUM 5.5
CVE-2024-45355

A unauthorized access vulnerability exists in the Xiaomi phone framework. The vulnerability is caused by improper validation and can be exploited by …

Mitigation only
Fix from $1,600 2025-03-27
Unclassified HIGH 7.0
CVE-2024-45483

A Missing Authentication for Critical Function vulnerability in the GRUB configuration used B&R APROL <4.4-01 may allow an unauthenticated physical a…

Mitigation only
Fix from $1,950 2025-03-25
Hcl Devops Deploy MEDIUM 6.5
CVE-2025-0256

HCL DevOps Deploy / HCL Launch could allow an authenticated user to obtain sensitive information about other users on the system due to missing autho…

Fix: 7.0.5.26 / 7.1.2.22+
Fix from $1,600 2025-03-24
Mattermost Server HIGH 8.8
CVE-2025-25068

Mattermost versions 10.4.x <= 10.4.2, 10.3.x <= 10.3.3, 9.11.x <= 9.11.8, 10.5.x <= 10.5.0 fail to enforce MFA on plugin endpoints, which allows auth…

Fix: 9.11.9 / 10.3.4+
Fix from $1,950 2025-03-21
Lollms Web Ui HIGH 8.4
CVE-2024-9919

A missing authentication check in the uninstall endpoint of parisneo/lollms-webui V13 allows attackers to perform unauthorized directory deletions. T…

No fix yet
Fix from $1,950 2025-03-20
Anythingllm Desktop CRITICAL 9.8
CVE-2024-8196

In mintplex-labs/anything-llm v1.5.11 desktop version for Windows, the application opens server port 3001 on 0.0.0.0 with no authentication by defaul…

Fix: 1.6.5+
Fix from $2,300 2025-03-20
Open Webui HIGH 8.2
CVE-2024-8053

In version v0.3.10 of open-webui/open-webui, the `api/v1/utils/pdf` endpoint lacks authentication mechanisms, allowing unauthenticated attackers to a…

No fix yet
Fix from $1,950 2025-03-20
Anythingllm HIGH 7.5
CVE-2024-6842EPSS 31%

In version 1.5.5 of mintplex-labs/anything-llm, the `/setup-complete` API endpoint allows unauthorized users to access sensitive system settings. The…

Patch available
Fix from $1,950 2025-03-20