Vulnerability index

Browse CVEs

2,893 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthenticationCWE-306 × clear
MEDIUM 5.9 CVE-2025-12436 Policy bypass in Extensions in Google Chrome prior to 142.0.7444.59 allowed an attacker who convinced a user to install a malicious extension to obta… Chrome 142.0.7444.59+ Fix from $1,6002025-11-10 HIGH 7.2 CVE-2022-50595 Advantech iView versions prior to v5.7.04 build 6425 contain a vulnerability within the SNMP management tool that allows for remote attackers to bypa… Iview 5.7.04.6425+ Fix from $1,9502025-11-06 CRITICAL 9.8 CVE-2022-50591 Advantech iView versions prior to v5.7.04 build 6425 contain a vulnerability within the SNMP management tool that allows for remote attackers to bypa… Iview 5.7.04.6425+ Fix from $2,3002025-11-06 HIGH 7.2 CVE-2022-50592 Advantech iView versions prior to v5.7.04 build 6425 contain a vulnerability within the SNMP management tool that allows for remote attackers to bypa… Iview 5.7.04.6425+ Fix from $1,9502025-11-06 CRITICAL 9.8 CVE-2022-50593 Advantech iView versions prior to v5.7.04 build 6425 contain a vulnerability within the SNMP management tool that allows for remote attackers to bypa… Iview 5.7.04.6425+ Fix from $2,3002025-11-06 HIGH 7.5 CVE-2022-50594 Advantech iView versions prior to v5.7.04 build 6425 contain a vulnerability within the SNMP management tool that allows for remote attackers to bypa… Iview 5.7.04.6425+ Fix from $1,9502025-11-06 CRITICAL 9.8 CVE-2025-20358 A vulnerability in the Contact Center Express (CCX) Editor application of Cisco Unified CCX could allow an unauthenticated, remote attacker to bypass… Unified Contact Center Express 12.5+ Fix from $2,3002025-11-05 CRITICAL 10.0 CVE-2025-55108 The Control-M/Agent is vulnerable to unauthenticated remote code execution, arbitrary file read and write and similar unauthorized actions when mutua… Mitigation only Fix from $2,3002025-11-05 CRITICAL 9.3 CVE-2025-12108 The Survision LPR Camera system does not enforce password protection by default. This allows access to the configuration wizard immediately without a… Mitigation only Fix from $2,3002025-11-04 CRITICAL 9.8 CVE-2025-61945 Radiometrics VizAir is vulnerable to any remote attacker via access to the admin panel of the VizAir system without authentication. Once inside, the … Vizair 2025-08+ Fix from $2,3002025-11-04 CRITICAL 9.8 CVE-2025-61956 Radiometrics VizAir is vulnerable to a lack of authentication mechanisms for critical functions, such as admin access and API requests. Attackers can… Vizair 2025-08+ Fix from $2,3002025-11-04 HIGH 7.8 CVE-2025-47357 Information Disclosure when a user-level driver performs QFPROM read or write operations on Fuse regions. Qam8255p Firmware Mitigation only Fix from $1,9502025-11-04 CRITICAL 9.8 CVE-2025-11007 The CE21 Suite plugin for WordPress is vulnerable to unauthorized plugin settings update due to a missing capability check on the wp_ajax_nopriv_ce21… Mitigation only Fix from $2,3002025-11-04 MEDIUM 5.4 CVE-2025-8558 Insider Threat Management (ITM) Server versions prior to 7.17.2 contain an authentication bypass vulnerability that allows unauthenticated users on a… Insider Threat Management Server 7.17.2+ Fix from $1,6002025-11-03 HIGH 7.1 CVE-2025-48397 The privileged user could log in without sufficient credentials after enabling an application protocol. This security issue has been fixed in the lat… Mitigation only Fix from $1,9502025-11-03 CRITICAL 10.0 CVE-2025-52665EPSS 41% A malicious actor with access to the management network could exploit a misconfiguration in UniFi’s door access application, UniFi Access, that expos… Unifi Access 4.0.21+ Fix from $2,3002025-10-31 CRITICAL 9.3 CVE-2023-7325 Anheng Mingyu Operation and Maintenance Audit and Risk Control System up to 2023-08-10 contains a server-side request forgery (SSRF) vulnerability in… Mitigation only Fix from $2,3002025-10-30 CRITICAL 9.3 CVE-2021-4461 Seeyon Zhiyuan OA Web Application System versions up to and including 7.0 SP1 improperly decode and parse the `enc` parameter in thirdpartyController… No fix yet Fix from $2,3002025-10-30 CRITICAL 9.8 CVE-2025-12476 Resource Lacking AuthN.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5 . Blu Ic2 Firmware 1.20+ Fix from $2,3002025-10-29 CRITICAL 9.8 CVE-2025-12477 Server Version Disclosure.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5 . Blu Ic2 Firmware 1.20+ Fix from $2,3002025-10-29 HIGH 7.6 CVE-2025-41090 microCLAUDIA in v3.2.0 and prior has an improper access control vulnerability. This flaw allows an authenticated user to perform unauthorized action… Mitigation only Fix from $1,9502025-10-28 HIGH 7.5 CVE-2025-43994 Dell Storage Center - Dell Storage Manager, version(s) DSM 20.1.21, contain(s) a Missing Authentication for Critical Function vulnerability. An unaut… Storage Manager 2020+ Fix from $1,9502025-10-24 MEDIUM 5.3 CVE-2025-62607 Nautobot Single Source of Truth (SSoT) is an app for Nautobot. Prior to version 3.10.0, an unauthenticated attacker could access this page to view th… Patch available Fix from $1,6002025-10-22 HIGH 8.8 CVE-2025-41110 Encrypted WiFi and SSH credentials were found in the Ghost Robotics Vision 60 v0.27.2 APK. This vulnerability allows an attacker to connect to the ro… Vision 60 Firmware Mitigation only Fix from $1,9502025-10-22 HIGH 7.5 CVE-2025-61756 Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: S… Financial Services Analytical Applications Infrastructure Mitigation only Fix from $1,9502025-10-21 CRITICAL 9.8 CVE-2025-62481 Vulnerability in the Oracle Marketing product of Oracle E-Business Suite (component: Marketing Administration). Supported versions that are affected… Marketing after 12.2.14 Fix from $2,3002025-10-21 MEDIUM 6.1 CVE-2025-62287 Vulnerability in the Oracle Life Sciences InForm product of Oracle Health Sciences Applications (component: Web Server). The supported version that… Life Sciences Inform Mitigation only Fix from $1,6002025-10-21 CRITICAL 9.8 CVE-2025-61757 KEVEPSS 88% Vulnerability in the Identity Manager product of Oracle Fusion Middleware (component: REST WebServices). Supported versions that are affected are 12… Identity Manager Mitigation only Fix from $2,3002025-10-21 HIGH 7.5 CVE-2025-61752 Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 14.1.1.0… Weblogic Server Mitigation only Fix from $1,9502025-10-21 CRITICAL 9.8 CVE-2025-53072 Vulnerability in the Oracle Marketing product of Oracle E-Business Suite (component: Marketing Administration). Supported versions that are affected… Marketing after 12.2.14 Fix from $2,3002025-10-21