Vulnerability index

Browse CVEs

2,866 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthenticationCWE-306 × clear
MEDIUM 6.5 CVE-2022-50979 An unauthenticated adjacent attacker could potentially disrupt operations by switching between multiple configuration presets via Modbus (RS485). No fix yet Fix from $1,6002026-02-02 CRITICAL 9.3 CVE-2026-24728 A missing authentication for critical function vulnerability in the /servlet/baServer3 endpoint of Interinfo DreamMaker versions before 2025/10/22 al… Mitigation only Fix from $2,3002026-01-30 HIGH 8.8 CVE-2026-25116 Runtipi is a personal homeserver orchestrator. Starting in version 4.5.0 and prior to version 4.7.2, an unauthenticated Path Traversal vulnerability … Runtipi 4.7.2+ Fix from $1,9502026-01-29 CRITICAL 9.8 CVE-2026-1453 A missing authentication for critical function vulnerability in KiloView Encoder Series could allow an unauthenticated attacker to create or delete a… Mitigation only Fix from $2,3002026-01-29 HIGH 7.5 CVE-2020-36963 Intelbras Router RF 301K firmware version 1.1.2 contains an authentication bypass vulnerability that allows unauthenticated attackers to download rou… No fix yet Fix from $1,9502026-01-28 MEDIUM 6.9 CVE-2025-12386 Pix-Link LV-WR21Q does not enforce any form of authentication for endpoint /goform/getHomePageInfo. Remote unauthenticated attacker is able to use th… Mitigation only Fix from $1,6002026-01-27 CRITICAL 9.3 CVE-2025-59097 The exos 9300 application can be used to configure Access Managers (e.g. 92xx, 9230 and 9290). The configuration is done in a graphical user interfac… Mitigation only Fix from $2,3002026-01-26 CRITICAL 9.3 CVE-2025-59090 On the exos 9300 server, a SOAP API is reachable on port 8002. This API does not require any authentication prior to sending requests. Therefore, net… Mitigation only Fix from $2,3002026-01-26 MEDIUM 6.4 CVE-2026-1410 A vulnerability was detected in Beetel 777VR1 up to 01.00.09/01.00.09_55. Impacted is an unknown function of the component UART Interface. The manipu… 777vr1 Firmware after 01.00.09_55 Fix from $1,6002026-01-26 CRITICAL 9.4 CVE-2025-52024 A vulnerability exists in the Aptsys POS Platform Web Services module thru 2025-05-28, which exposes internal API testing tools to unauthenticated us… Gemscms Backend after 2025-05-28 Fix from $2,3002026-01-23 CRITICAL 9.8 CVE-2026-24423 KEVEPSS 88% SmarterTools SmarterMail versions prior to build 9511 contain an unauthenticated remote code execution vulnerability in the ConnectToHub API method. … Smartermail 100.0.9511+ Fix from $2,3002026-01-23 CRITICAL 9.8 CVE-2021-47891 Unified Remote 3.9.0.2463 contains a remote code execution vulnerability that allows attackers to send crafted network packets to execute arbitrary c… Mitigation only Fix from $2,3002026-01-23 CRITICAL 9.8 CVE-2026-1364 IAQS and I6 developed by JNC has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to directly operate system adminis… Mitigation only Fix from $2,3002026-01-23 HIGH 8.8 CVE-2026-0778 Enel X JuiceBox 40 Telnet Service Missing Authentication Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to… Mitigation only Fix from $1,9502026-01-23 CRITICAL 9.8 CVE-2026-24124 Dragonfly is an open source P2P-based file distribution and image acceleration system. In versions 2.4.1-rc.0 and below, the Job API endpoints (/api/… Dragonfly 2.4.1+ Fix from $2,3002026-01-22 CRITICAL 9.8 CVE-2025-54816 This vulnerability occurs when a WebSocket endpoint does not enforce proper authentication mechanisms, allowing unauthorized users to establish con… Evmapa Mitigation only Fix from $2,3002026-01-22 MEDIUM 5.3 CVE-2026-1332 MeetingHub developed by HAMASTAR Technology has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to access specific … Meetinghub Paperless Meetings 2025-12-10+ Fix from $1,6002026-01-22 MEDIUM 6.1 CVE-2025-69285 SQLBot is an intelligent data query system based on a large language model and RAG. Versions prior to 1.5.0 contain a missing authentication vulnerab… Sqlbot 1.5.0+ Fix from $1,6002026-01-21 HIGH 7.5 CVE-2021-47802 Tenda D151 and D301 routers contain an unauthenticated configuration download vulnerability that allows remote attackers to retrieve router configura… D301 Firmware No fix yet Fix from $1,9502026-01-21 CRITICAL 9.8 CVE-2026-23944 Arcane is an interface for managing Docker containers, images, networks, and volumes. Prior to version 1.13.2, unauthenticated requests could be prox… Arcane 1.13.2+ Fix from $2,3002026-01-19 CRITICAL 9.8 CVE-2026-23744EPSS 45% MCPJam inspector is the local-first development platform for MCP servers. Versions 1.4.2 and earlier are vulnerable to remote code execution (RCE) vu… Inspector 1.4.3+ Fix from $2,3002026-01-16 MEDIUM 5.3 CVE-2026-0942 The Rede Itaú for WooCommerce — Payment PIX, Credit Card and Debit plugin for WordPress is vulnerable to unauthorized modification of data due to a m… Mitigation only Fix from $1,6002026-01-16 HIGH 7.5 CVE-2026-1023 Statistics Database System developed by Gotac has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to directly explo… Statistics Database System 1.0.4+ Fix from $1,9502026-01-16 CRITICAL 9.8 CVE-2026-1019 Police Statistics Database System developed by Gotac has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to read, m… Police Statistics Database System after 1.0.3 Fix from $2,3002026-01-16 CRITICAL 9.8 CVE-2025-62582 Delta Electronics DIAView has multiple vulnerabilities. Diaview 4.4.0+ Fix from $2,3002026-01-16 CRITICAL 9.3 CVE-2026-23746 Entrust Instant Financial Issuance (IFI) On Premise software (formerly referred to as CardWizard) versions 5.x, prior to 6.10.5, and prior to 6.11.1 … Mitigation only Fix from $2,3002026-01-15 CRITICAL 9.8 CVE-2026-22238 The vulnerability exists in BLUVOYIX due to improper authentication in the BLUVOYIX admin APIs. An unauthenticated remote attacker could exploit this… Bluvoyix Mitigation only Fix from $2,3002026-01-14 CRITICAL 9.8 CVE-2023-54335EPSS 5% eXtplorer 2.1.14 contains an authentication bypass vulnerability that allows attackers to login without a password by manipulating the login request.… Extplorer after 2.1.14 Fix from $2,3002026-01-13 HIGH 7.2 CVE-2026-20803 Missing authentication for critical function in SQL Server allows an authorized attacker to elevate privileges over a network. Sql Server 2022 16.0.1165.1 / 16.0.4230.2+ Fix from $1,9502026-01-13 CRITICAL 9.0 CVE-2025-12548 A flaw was found in Eclipse Che che-machine-exec. This vulnerability allows unauthenticated remote arbitrary command execution and secret exfiltratio… Mitigation only Fix from $2,3002026-01-13