Vulnerability index

Browse CVEs

2,866 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthenticationCWE-306 × clear
HIGH 8.8 CVE-2026-0492 SAP HANA database is vulnerable to privilege escalation allowing an attacker with valid credentials of any user to switch to another user potentially… Hana Database Patch available Fix from $1,9502026-01-13 HIGH 8.8 CVE-2026-22812EPSS 17% OpenCode is an open source AI coding agent. Prior to 1.0.216, OpenCode automatically starts an unauthenticated HTTP server that allows any local proc… Opencode 1.0.216+ Fix from $1,9502026-01-12 HIGH 8.2 CVE-2026-22788 WebErpMesv2 is a Resource Management and Manufacturing execution system Web for industry. Prior to 1.19, the WebErpMesV2 application exposes multiple… Wem 1.19+ Fix from $1,9502026-01-12 MEDIUM 6.3 CVE-2026-0842 A flaw has been found in Flycatcher Toys smART Sketcher up to 2.0. This affects an unknown part of the component Bluetooth Low Energy Interface. This… Mitigation only Fix from $1,6002026-01-11 CRITICAL 10.0 CVE-2025-69425 The Ruckus vRIoT IoT Controller firmware versions prior to 3.0.0.0 (GA) expose a command execution service on TCP port 2004 running with root privile… Mitigation only Fix from $2,3002026-01-09 HIGH 7.5 CVE-2025-66049 Vivotek IP7137 camera with firmware version 0200a is vulnerable to an information disclosure issue where live camera footage can be accessed through … Ip7137 Firmware Mitigation only Fix from $1,9502026-01-09 HIGH 8.4 CVE-2025-68716 KAYSUS KS-WR3600 routers with firmware 1.0.5.9.1 enable the SSH service enabled by default on the LAN interface. The root account is configured with … Ks Wr3600 Firmware Mitigation only Fix from $1,9502026-01-08 CRITICAL 9.1 CVE-2025-68715 An issue was discovered in Panda Wireless PWRU0 devices with firmware 2.2.9 that exposes multiple HTTP endpoints (/goform/setWan, /goform/setLan, /go… Pwru01 Firmware No fix yet Fix from $2,3002026-01-08 MEDIUM 6.8 CVE-2025-65731 An issue was discovered in D-Link Router DIR-605L (Hardware version F1; Firmware version: V6.02CN02) allowing an attacker with physical access to the… Dir 605l Firmware No fix yet Fix from $1,6002026-01-08 CRITICAL 9.3 CVE-2025-15346 A vulnerability in the handling of verify_mode = CERT_REQUIRED in the wolfssl Python package (wolfssl-py) causes client certificate requirements to n… Patch available Fix from $2,3002026-01-08 HIGH 7.5 CVE-2017-20213 FLIR Thermal Camera F/FC/PT/D Stream firmware version 8.0.0.64 contains an unauthenticated vulnerability that allows remote attackers to access live … No fix yet Fix from $1,9502026-01-08 CRITICAL 9.3 CVE-2026-0650 OpenFlagr versions prior to and including 1.1.18 contain an authentication bypass vulnerability in the HTTP middleware. Due to improper handling of p… Mitigation only Fix from $2,3002026-01-07 CRITICAL 9.3 CVE-2026-0625 Multiple D-Link DSL/DIR/DNS devices contain an authentication bypass and improper access control vulnerability in the dnscfg.cgi endpoint that allows… Mitigation only Fix from $2,3002026-01-05 CRITICAL 9.8 CVE-2025-14346EPSS 6% WHILL Model C2 Electric Wheelchairs and Model F Power Chairs do not enforce authentication for Bluetooth connections. An attacker within range can pa… Mitigation only Fix from $2,3002026-01-05 CRITICAL 9.8 CVE-2025-15026 Missing Authentication for Critical Function vulnerability in Centreon Infra Monitoring centreon-awie (Awie import module) allows Accessing Functiona… Awie 24.04.3 / 24.10.3+ Fix from $2,3002026-01-05 HIGH 8.2 CVE-2025-3646 Petlibro Smart Pet Feeder Platform versions up to 1.7.31 contains an authorization bypass vulnerability that allows unauthorized users to add users a… Petlibro after 1.7.31 Fix from $1,9502026-01-04 CRITICAL 9.8 CVE-2026-21446 Bagisto is an open source laravel eCommerce platform. In versions on the 2.3 branch prior to 2.3.10, API routes remain active even after initial inst… Bagisto 2.3.10+ Fix from $2,3002026-01-02 CRITICAL 9.1 CVE-2026-21445EPSS 34% Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to version 1.7.0.dev45, multiple critical API endpoints in Langf… Langflow 1.7.1+ Fix from $2,3002026-01-02 HIGH 7.5 CVE-2020-36904 Selea CarPlateServer 4.0.1.6 contains a remote program execution vulnerability that allows attackers to execute arbitrary Windows binaries by manipul… No fix yet Fix from $1,9502025-12-31 MEDIUM 5.3 CVE-2024-58336 Akuvox Smart Intercom S539 contains an unauthenticated vulnerability that allows remote attackers to access live video streams by requesting the vide… S539 Firmware No fix yet Fix from $1,6002025-12-30 HIGH 7.5 CVE-2022-50790 SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x and below contain an unauthenticated vulnerability that allows remote attackers to access live radio strea… Impact Firmware No fix yet Fix from $1,9502025-12-30 HIGH 7.5 CVE-2025-66377 Pexip Infinity before 39.0 has Missing Authentication for a Critical Function in a product-internal API, allowing an attacker (who already has access… Pexip Infinity 39.0+ Fix from $1,9502025-12-25 HIGH 7.5 CVE-2025-3232 A remote unauthenticated attacker may be able to bypass authentication by utilizing a specific API route to execute arbitrary OS commands. Mitigation only Fix from $1,9502025-12-24 HIGH 7.5 CVE-2019-25248 Beward N100 M2.1.6.04C014 contains an unauthenticated vulnerability that allows remote attackers to access live video streams without credentials. At… No fix yet Fix from $1,9502025-12-24 CRITICAL 9.8 CVE-2019-25236 iSeeQ Hybrid DVR WH-H4 1.03R contains an unauthenticated vulnerability in the get_jpeg script that allows unauthorized access to live video streams. … Mitigation only Fix from $2,3002025-12-24 CRITICAL 9.8 CVE-2019-25240 Rifatron 5brid DVR contains an unauthenticated vulnerability in the animate.cgi script that allows unauthorized access to live video streams. Attacke… Mitigation only Fix from $2,3002025-12-24 HIGH 7.5 CVE-2018-25140 FLIR thermal traffic cameras contain an unauthenticated device manipulation vulnerability in their WebSocket implementation that allows attackers to … No fix yet Fix from $1,9502025-12-24 HIGH 7.5 CVE-2018-25141 FLIR thermal traffic cameras contain an unauthenticated vulnerability that allows remote attackers to access live video streams without credentials. … No fix yet Fix from $1,9502025-12-24 CRITICAL 9.8 CVE-2018-25134 Synaccess netBooter NP-02x/NP-08x 6.8 contains an authentication bypass vulnerability in the webNewAcct.cgi script that allows unauthenticated attack… Mitigation only Fix from $2,3002025-12-24 HIGH 7.5 CVE-2018-25136 FLIR Brickstream 3D+ 2.1.742.1842 contains an unauthenticated vulnerability that allows remote attackers to access live video streams without credent… No fix yet Fix from $1,9502025-12-24