Vulnerability index

Browse CVEs

2,866 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthenticationCWE-306 × clear
HIGH 7.5 CVE-2026-26235 JUNG Smart Visu Server 1.1.1050 contains a denial of service vulnerability that allows unauthenticated attackers to remotely shutdown or reboot the s… Smart Visu Server Firmware after 1.1.1050 Fix from $1,9502026-02-12 CRITICAL 9.8 CVE-2026-1729 The AdForest theme for WordPress is vulnerable to authentication bypass in all versions up to, and including, 6.0.12. This is due to the plugin not p… Mitigation only Fix from $2,3002026-02-12 CRITICAL 9.8 CVE-2026-24789 An unprotected API endpoint allows an attacker to remotely change the device password without providing authentication. Mitigation only Fix from $2,3002026-02-11 CRITICAL 9.8 CVE-2026-25084 Authentication for ZLAN5143D can be bypassed by directly accessing internal URLs. Mitigation only Fix from $2,3002026-02-11 CRITICAL 9.8 CVE-2026-2248 METIS WIC devices (versions <= oscore 2.1.234-r18) expose a web-based shell at the /console endpoint that does not require authentication. Accessing … Mitigation only Fix from $2,3002026-02-11 CRITICAL 9.8 CVE-2026-2249 METIS DFS devices (versions <= oscore 2.1.234-r18) expose a web-based shell at the /console endpoint that does not require authentication. Accessing … Mitigation only Fix from $2,3002026-02-11 CRITICAL 9.8 CVE-2025-8025 Missing Authentication for Critical Function, Improper Access Control vulnerability in Dinosoft Business Solutions Dinosoft ERP allows Accessing Func… Mitigation only Fix from $2,3002026-02-11 HIGH 7.5 CVE-2026-1603 KEVEPSS 81% An authentication bypass in Ivanti Endpoint Manager before version 2024 SU5 allows a remote unauthenticated attacker to leak specific stored credenti… Endpoint Manager 2024+ Fix from $1,9502026-02-10 CRITICAL 9.8 CVE-2026-25938 FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. From 1.2.8 through 1.2.10, an authentication bypass vulnerability in FUXA a… Fuxa 1.2.11+ Fix from $2,3002026-02-09 CRITICAL 9.8 CVE-2026-25895 FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. A path traversal vulnerability in FUXA allows an unauthenticated, remote at… Fuxa 1.2.10+ Fix from $2,3002026-02-09 HIGH 7.5 CVE-2026-25885 PolarLearn is a free and open-source learning program. In 0-PRERELEASE-16 and earlier, the group chat WebSocket at wss://polarlearn.nl/api/v1/ws can … Polarlearn Patch available Fix from $1,9502026-02-09 MEDIUM 5.3 CVE-2026-25878 FroshAdminer is the Adminer plugin for Shopware Platform. Prior to 2.2.1, the Adminer route (/admin/adminer) was accessible without Shopware admin au… Froshadminer 2.2.1+ Fix from $1,6002026-02-09 HIGH 7.5 CVE-2026-25791 Sliver is a command and control framework that uses a custom Wireguard netstack. Prior to 1.7.0, the DNS C2 listener accepts unauthenticated TOTP boo… Sliver 1.7.0+ Fix from $1,9502026-02-09 CRITICAL 9.8 CVE-2026-25848 In JetBrains Hub before 2025.3.119807 authentication bypass allowing administrative actions was possible Hub 2025.3.119807+ Fix from $2,3002026-02-09 CRITICAL 9.1 CVE-2026-2234 C&Cm@il developed by HGiga has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to read and modify any user's mail … Mitigation only Fix from $2,3002026-02-09 CRITICAL 9.8 CVE-2026-2165 A weakness has been identified in detronetdip E-commerce 1.0.0. Impacted is an unknown function of the file /Admin/assets/backend/seller/add_seller.p… E Commerce Mitigation only Fix from $2,3002026-02-08 HIGH 7.5 CVE-2020-37146 ACE Security WiP-90113 HD Camera contains a configuration disclosure vulnerability that allows unauthenticated attackers to retrieve sensitive config… No fix yet Fix from $1,9502026-02-07 HIGH 7.5 CVE-2020-37157 DBPower C300 HD Camera contains a configuration disclosure vulnerability that allows unauthenticated attackers to retrieve sensitive credentials thro… No fix yet Fix from $1,9502026-02-07 HIGH 8.4 CVE-2026-25593 OpenClaw is a personal AI assistant. Prior to 2026.1.20, an unauthenticated local client could use the Gateway WebSocket API to write config via conf… Openclaw 2026.1.20+ Fix from $1,9502026-02-06 HIGH 8.8 CVE-2026-2065 A security flaw has been discovered in Flycatcher Toys smART Pixelator 2.0. Affected by this issue is some unknown functionality of the component Blu… Smart Pixelator Firmware No fix yet Fix from $1,9502026-02-06 HIGH 7.5 CVE-2026-25751 FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. An information disclosure vulnerability in FUXA allows an unauthenticated, … Fuxa 1.2.10+ Fix from $1,9502026-02-06 CRITICAL 9.8 CVE-2026-25505 Bambuddy is a self-hosted print archive and management system for Bambu Lab 3D printers. Prior to version 0.1.7, a hardcoded secret key used for sign… Bambuddy 0.1.7+ Fix from $2,3002026-02-04 CRITICAL 10.0 CVE-2026-1633 The Synectix LAN 232 TRIO 3-Port serial to ethernet adapter exposes its web management interface without requiring authentication, allowing unauthent… Mitigation only Fix from $2,3002026-02-04 CRITICAL 9.1 CVE-2026-1632 MOMA Seismic Station Version v2.4.2520 and prior exposes its web management interface without requiring authentication, which could allow an unauthen… Mitigation only Fix from $2,3002026-02-03 CRITICAL 9.3 CVE-2026-1341 Avation Light Engine Pro exposes its configuration and control interface without any authentication or access control. Mitigation only Fix from $2,3002026-02-03 CRITICAL 9.1 CVE-2026-25137EPSS 10% The NixOs Odoo package is an open source ERP and CRM system. From 21.11 to before 25.11 and 26.05, every NixOS based Odoo setup publicly exposes the … Patch available Fix from $2,3002026-02-02 MEDIUM 6.5 CVE-2022-50980 A unauthenticated adjacent attacker could potentially disrupt operations by switching between multiple configuration presets via CAN. Mitigation only Fix from $1,6002026-02-02 CRITICAL 9.8 CVE-2022-50981 An unauthenticated remote attacker can gain full access on the affected devices as they are shipped without a password by default and setting one is … Mitigation only Fix from $2,3002026-02-02 HIGH 7.5 CVE-2022-50977 An unauthenticated remote attacker could potentially disrupt operations by switching between multiple configuration presets via HTTP. Mitigation only Fix from $1,9502026-02-02 HIGH 7.5 CVE-2022-50978 An unauthenticated remote attacker could potentially disrupt operations by switching between multiple configuration presets via Modbus (TCP). Mitigation only Fix from $1,9502026-02-02