Vulnerability index

Browse CVEs

2,893 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthenticationCWE-306 × clear
HIGH 8.7 CVE-2020-36873 Astak CM-818T3 2.4GHz wireless security surveillance cameras contain an unauthenticated configuration disclosure vulnerability in the /web/cgi-bin/hi… Mitigation only Fix from $1,9502025-11-26 HIGH 8.7 CVE-2020-36874 ACE SECURITY WIP-90113 HD cameras contain an unauthenticated configuration disclosure vulnerability in the /web/cgi-bin/hi3510/backup.cgi endpoint. T… Mitigation only Fix from $1,9502025-11-26 HIGH 8.7 CVE-2019-25227 Tellion HN-2204AP routers contain an unauthenticated configuration disclosure vulnerability in the /cgi-bin/system_config_file management endpoint. T… Mitigation only Fix from $1,9502025-11-26 HIGH 8.7 CVE-2019-25226 Dongyoung Media DM-AP240T/W wireless access points contain an unauthenticated configuration disclosure vulnerability in the /cgi-bin/sys_system_confi… Mitigation only Fix from $1,9502025-11-26 HIGH 8.8 CVE-2025-13483 SiRcom SMART Alert (SiSA) allows unauthorized access to backend APIs. This allows an unauthenticated attacker to bypass the login screen using browse… Mitigation only Fix from $1,9502025-11-25 HIGH 8.2 CVE-2025-12003 A path traversal vulnerability has been identified in WebDAV, which may allow unauthenticated remote attackers to impact the integrity of the device.… Mitigation only Fix from $1,9502025-11-25 HIGH 8.7 CVE-2024-14007 Shenzhen TVT Digital Technology Co., Ltd. NVMS-9000 firmware (used by many white-labeled DVR/NVR/IPC products) versions prior to 1.3.4 contain an aut… Mitigation only Fix from $1,9502025-11-24 CRITICAL 9.8 CVE-2025-63958 MILLENSYS Vision Tools Workspace 6.5.0.2585 exposes a sensitive configuration endpoint (/MILLENSYS/settings) that is accessible without authenticatio… Vision Tools Workspace Mitigation only Fix from $2,3002025-11-24 MEDIUM 6.5 CVE-2025-12969 Fluent Bit in_forward input plugin does not properly enforce the security.users authentication mechanism under certain configuration conditions. This… Fluent Bit Mitigation only Fix from $1,6002025-11-24 MEDIUM 5.3 CVE-2025-11771 The Cryptocurrency (Token), Launchpad (Presale), ICO & IDO, Airdrop by TokenICO plugin for WordPress is vulnerable to unauthenticated and unauthorize… Mitigation only Fix from $1,6002025-11-21 MEDIUM 6.8 CVE-2025-64770 The affected products allow unauthenticated access to Open Network Video Interface Forum (ONVIF) services, which may allow an attacker unauthorized a… Mitigation only Fix from $1,6002025-11-20 MEDIUM 6.8 CVE-2025-62674 The affected product allows unauthenticated access to Real Time Streaming Protocol (RTSP) services, which may allow an attacker unauthorized access t… Mitigation only Fix from $1,6002025-11-20 CRITICAL 9.8 CVE-2025-63206 An authentication bypass issue was discovered in Dasan Switch DS2924 web based interface, firmware versions 1.01.18 and 1.02.00, allowing attackers t… Ds2924 Firmware Mitigation only Fix from $2,3002025-11-19 HIGH 7.5 CVE-2025-34331 AudioCodes Fax Server and Auto-Attendant IVR appliances versions up to and including 2.6.23 contain an unauthenticated file read vulnerability via th… Fax Server after 2.6.23 Fix from $1,9502025-11-19 MEDIUM 5.3 CVE-2025-12349 The Icegram Express - Email Subscribers, Newsletters and Marketing Automation Plugin for WordPress is vulnerable to Authorization in versions up to, … Mitigation only Fix from $1,6002025-11-19 CRITICAL 9.8 CVE-2025-9312 A missing authentication enforcement vulnerability exists in the mutual TLS (mTLS) implementation used by System REST APIs and SOAP services in multi… Api Control Plane Mitigation only Fix from $2,3002025-11-18 CRITICAL 10.0 CVE-2025-58083 General Industrial Controls Lynx+ Gateway  is missing critical authentication in the embedded web server which could allow an attacker to remotely r… Mitigation only Fix from $2,3002025-11-15 HIGH 7.5 CVE-2025-59780 General Industrial Controls Lynx+ Gateway is missing critical authentication in the embedded web server which could allow an attacker to send GET re… Mitigation only Fix from $1,9502025-11-15 MEDIUM 6.5 CVE-2025-64307 The Brightpick Internal Logic Control web interface is accessible without requiring user authentication. An unauthorized user could exploit this inte… Mitigation only Fix from $1,6002025-11-15 MEDIUM 5.3 CVE-2023-7328 Screen SFT DAB 600/C firmware versions up to and including 1.9.3 contain an improper access control on the user management API allows unauthenticated… Sft Dab 600\/c Firmware after 1.9.3 Fix from $1,6002025-11-14 HIGH 8.7 CVE-2021-4468 PLANEX CS-QP50F-ING2 smart cameras expose a configuration backup interface over HTTP that does not require authentication. A remote, unauthenticated … Mitigation only Fix from $1,9502025-11-14 HIGH 8.7 CVE-2021-4469 Denver SHO-110 IP cameras expose a secondary HTTP service on TCP port 8001 that provides access to a '/snapshot' endpoint without authentication. Whi… No fix yet Fix from $1,9502025-11-14 HIGH 7.5 CVE-2025-55070 Mattermost versions <11 fail to enforce multi-factor authentication on WebSocket connections which allows unauthenticated users to access sensitive i… Mattermost Server 11.0.0+ Fix from $1,9502025-11-14 MEDIUM 5.3 CVE-2025-55073 Mattermost versions 10.11.x <= 10.11.3, 10.5.x <= 10.5.11, 10.12.x <= 10.12.0 fail to validate the relationship between the post being updated and th… Mattermost Server 10.5.12 / 10.11.4+ Fix from $1,6002025-11-14 CRITICAL 9.8 CVE-2025-59367 An authentication bypass vulnerability has been identified in certain DSL series routers, may allow remote attackers to gain unauthorized access into… Dsl Ac51 Firmware 1.1.2.3_1010+ Fix from $2,3002025-11-13 HIGH 8.7 CVE-2023-7329 Tinycontrol LAN Controller v3 (LK3) firmware versions up to 1.58a (hardware v3.8) contain a missing authentication vulnerability in the stm.cgi endpo… No fix yet Fix from $1,9502025-11-12 HIGH 7.6 CVE-2025-40816 A vulnerability has been identified in LOGO! 12/24RCE (6ED1052-1MD08-0BA2) (All versions), LOGO! 12/24RCEo (6ED1052-2MD08-0BA2) (All versions), LOGO!… Mitigation only Fix from $1,9502025-11-11 MEDIUM 6.5 CVE-2025-40817 A vulnerability has been identified in LOGO! 12/24RCE (6ED1052-1MD08-0BA2) (All versions), LOGO! 12/24RCEo (6ED1052-2MD08-0BA2) (All versions), LOGO!… Mitigation only Fix from $1,6002025-11-11 MEDIUM 5.3 CVE-2025-11986 The Crypto plugin for WordPress is vulnerable to Information exposure in all versions up to, and including, 2.22. This is due to the plugin registeri… Mitigation only Fix from $1,6002025-11-11 MEDIUM 5.8 CVE-2025-42885 Due to missing authentication, SAP HANA 2.0 (hdbrss) allows an unauthenticated attacker to call a remote-enabled function that will enable them to vi… Mitigation only Fix from $1,6002025-11-11