Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 7.5
CVE-2018-25137
FLIR Brickstream 3D+ 2.1.742.1842 contains an unauthenticated vulnerability in the ExportConfig REST API that allows attackers to download sensitive …
No fix yet
HIGH 7.5
CVE-2018-25139
FLIR AX8 Thermal Camera 1.32.16 contains an unauthenticated vulnerability that allows remote attackers to access live video streams without credentia…
Flir Ax8 Firmware
No fix yet
HIGH 7.1
CVE-2025-66445
Authorization bypass vulnerability in Hitachi Infrastructure Analytics Advisor (Data Center Analytics component) and Hitachi Ops Center Analyzer (Hit…
Mitigation only
CRITICAL 9.8
CVE-2025-65856
Authentication bypass vulnerability in Xiongmai XM530 IP cameras on Firmware V5.00.R02.000807D8.10010.346624.S.ONVIF 21.06 allows unauthenticated rem…
Xm530v200 X6 Weq 8m Firmware
Mitigation only
HIGH 7.5
CVE-2023-53974
D-Link DSL-124 ME_1.00 contains a configuration file disclosure vulnerability that allows unauthenticated attackers to retrieve router settings throu…
Dsl 124 Firmware
No fix yet
HIGH 7.5
CVE-2023-53967
Screen SFT DAB 600/C firmware 1.9.3 contains an authentication bypass vulnerability that allows attackers to change the admin password without requir…
Sft Dab 600\/c Firmware
No fix yet
CRITICAL 9.8
CVE-2023-53968
Screen SFT DAB 600/C Firmware 1.9.3 contains a session management vulnerability that allows attackers to bypass authentication controls by exploiting…
Sft Dab 600\/c Firmware
Mitigation only
HIGH 7.5
CVE-2023-53969
Screen SFT DAB 600/C firmware 1.9.3 contains a session management vulnerability that allows attackers to bypass authentication controls by exploiting…
Sft Dab 600\/c Firmware
No fix yet
HIGH 7.5
CVE-2023-53970
Screen SFT DAB 600/C Firmware 1.9.3 contains a weak session management vulnerability that allows attackers to bypass authentication controls by reusi…
Sft Dab 600\/c Firmware
No fix yet
CRITICAL 9.8
CVE-2023-53964
SOUND4 IMPACT/FIRST/PULSE/Eco v2.x contains an unauthenticated vulnerability in the /usr/cgi-bin/restorefactory.cgi endpoint that allows remote attac…
Impact Firmware
Mitigation only
CRITICAL 9.8
CVE-2025-12049
Missing Authentication for Critical Function vulnerability in Sharp Display Solutions Media Player MP-01 All Verisons allows a attacker may access to…
Mp 01 Firmware
Mitigation only
HIGH 8.1
CVE-2025-14300
The HTTPS service on Tapo C200 v3, v5, C425 v1.2 and C100 v5 exposes a connectAP interface without proper authentication. An unauthenticated attacke…
Tapo C200 Firmware
Mitigation only
HIGH 8.8
CVE-2025-52692EPSS 6%
Successful exploitation of the vulnerability could allow an attacker with local network access to send a specially crafted URL to access certain admi…
E9450 Sg Firmware
No fix yet
CRITICAL 9.8
CVE-2025-63389
A critical authentication bypass vulnerability exists in Ollama platform's API endpoints in versions prior to and including v0.12.3. The platform exp…
Ollama
after 0.12.3
MEDIUM 5.3
CVE-2025-63390
An authentication bypass vulnerability exists in AnythingLLM v1.8.5 in via the /api/workspaces endpoint. The endpoint fails to implement proper authe…
Anythingllm
Mitigation only
HIGH 7.1
CVE-2025-65010
WODESYS WD-R608U router (also known as WDR122B V2.0 and WDR28) is vulnerable to Broken Access Control in initial configuration wizard.cgi endpoint. M…
Mitigation only
HIGH 8.7
CVE-2025-65007
In WODESYS WD-R608U router (also known as WDR122B V2.0 and WDR28) due to lack of authentication in the configuration change module in the adm.cgi end…
Mitigation only
CRITICAL 9.8
CVE-2025-43428
A configuration issue was addressed with additional restrictions. This issue is fixed in iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2, visionOS 26.2. P…
Ipados
26.2+
CRITICAL 9.1
CVE-2025-34434
AVideo versions prior to 20.1 with the ImageGallery plugin enabled is vulnerable to unauthenticated file upload and deletion. Plugin endpoints respon…
Avideo
20.0+
HIGH 7.5
CVE-2023-53896
D-Link DAP-1325 firmware version 1.01 contains a broken access control vulnerability that allows unauthenticated attackers to download device configu…
Dap 1325 Firmware
No fix yet
HIGH 7.0
CVE-2025-14038
EDB Hybrid Manager contains a flaw that allows an unauthenticated attacker to directly access certain gRPC endpoints. This could allow an attacker to…
Hybrid Manager
1.3.3 / 2025.12.0+
HIGH 7.5
CVE-2025-14567
A weakness has been identified in haxxorsid Stock-Management-System up to fbbbf213e9c93b87183a3891f77e3cc7095f22b0. This affects an unknown function …
Stock Management System
after 2018-01-27
MEDIUM 5.3
CVE-2025-12348
The Icegram Express - Email Subscribers, Newsletters and Marketing Automation Plugin for WordPress is vulnerable to Missing Authorization in versions…
Mitigation only
HIGH 8.7
CVE-2024-58300
Siklu MultiHaul TG series devices before version 2.0.0 contain an unauthenticated vulnerability that allows remote attackers to retrieve randomly gen…
No fix yet
HIGH 8.8
CVE-2025-65824
An unauthenticated attacker within proximity of the Meatmeet device can perform an unauthorized Over The Air (OTA) firmware upgrade using Bluetooth L…
Meatmeet Pro Wifi \& Bluetooth Meat Thermometer Firmware
No fix yet
MEDIUM 6.5
CVE-2025-65828
An unauthenticated attacker within proximity of the Meatmeet device can issue several commands over Bluetooth Low Energy (BLE) to these devices which…
Meatmeet Pro Wifi \& Bluetooth Meat Thermometer Firmware
No fix yet
CRITICAL 9.8
CVE-2020-36892
Eibiz i-Media Server Digital Signage 3.8.0 contains an unauthenticated privilege escalation vulnerability in the updateUser object that allows attack…
I Media Server Digital Signage
Mitigation only
HIGH 7.5
CVE-2020-36894
Eibiz i-Media Server Digital Signage 3.8.0 contains an authentication bypass vulnerability that allows unauthenticated attackers to create admin user…
I Media Server Digital Signage
No fix yet
CRITICAL 9.4
CVE-2025-13607
A malicious actor can access camera configuration information, including account credentials, without authenticating when accessing a vulnerable URL.
Mitigation only
HIGH 8.8
CVE-2024-2104
Due to improper BLE security configurations on the device's GATT server, an adjacent unauthenticated attacker can read and write device control comma…
Mitigation only