Vulnerability index

Browse CVEs

2,893 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthenticationCWE-306 × clear
MEDIUM 5.4 CVE-2025-53034 Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: P… Financial Services Analytical Applications Infrastructure Mitigation only Fix from $1,6002025-10-21 CRITICAL 9.8 CVE-2025-53037 Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: P… Financial Services Analytical Applications Infrastructure Mitigation only Fix from $2,3002025-10-21 HIGH 7.5 CVE-2025-11949 EasyFlow .NET and EasyFlow AiNet, developed by Digiwin, has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to obta… Mitigation only Fix from $1,9502025-10-21 CRITICAL 10.0 CVE-2025-9574 Missing Authentication for Critical Function vulnerability in ABB ALS-mini-s4 IP, ABB ALS-mini-s8 IP.This issue affects .  All firmware versions wit… Mitigation only Fix from $2,3002025-10-20 MEDIUM 6.8 CVE-2025-60856 Reolink Video Doorbell WiFi DB_566128M5MP_W allows root shell access through an unsecured UART/serial console. An attacker with physical access can c… Mitigation only Fix from $1,6002025-10-20 CRITICAL 9.8 CVE-2025-11942 A flaw has been found in 70mai X200 up to 20251010. Affected is an unknown function of the component Pairing. Executing manipulation can lead to miss… X200 Firmware after 2025-10-10 Fix from $2,3002025-10-19 MEDIUM 5.3 CVE-2025-11852 A vulnerability was found in Apeman ID71 218.53.203.117. The impacted element is an unknown function of the file /onvif/device_service of the compone… Mitigation only Fix from $1,6002025-10-16 CRITICAL 9.8 CVE-2025-62586 OPEXUS FOIAXpress allows a remote, unauthenticated attacker to reset the administrator password. Fixed in FOIAXpress version 11.13.2.0. Foiaxpress 11.13.2.0+ Fix from $2,3002025-10-16 CRITICAL 9.8 CVE-2025-9152 An improper privilege management vulnerability exists in WSO2 API Manager due to missing authentication and authorization checks in the keymanager-op… Api Control Plane Mitigation only Fix from $2,3002025-10-16 MEDIUM 5.3 CVE-2025-11728 The Oceanpayment CreditCard Gateway plugin for WordPress is vulnerable to unauthenticated and unauthorized modification of data due to missing authen… Mitigation only Fix from $1,6002025-10-15 HIGH 8.4 CVE-2025-23356 NVIDIA Isaac Lab contains a vulnerability in SB3 configuration parsing. A successful exploit of this vulnerability might lead to code execution, deni… Mitigation only Fix from $1,9502025-10-14 CRITICAL 9.8 CVE-2025-7328 Multiple Broken Authentication security issues exist in the affected product. The security issues are due to missing authentication checks on critica… 1783 Natr Firmware 1.007+ Fix from $2,3002025-10-14 CRITICAL 9.8 CVE-2025-40765 A vulnerability has been identified in TeleControl Server Basic V3.1 (All versions >= V3.1.2.2 < V3.1.2.3). The affected application contains an info… Telecontrol Server Basic Mitigation only Fix from $2,3002025-10-14 CRITICAL 9.8 CVE-2025-40771 A vulnerability has been identified in SIMATIC CP 1542SP-1 (6GK7542-6UX00-0XE0) (All versions < V2.4.24), SIMATIC CP 1542SP-1 IRC (6GK7542-6VX00-0XE0… Mitigation only Fix from $2,3002025-10-14 HIGH 7.5 CVE-2025-41703 An unauthenticated remote attacker can cause a Denial of Service by turning off the output of the UPS via Modbus command. Mitigation only Fix from $1,9502025-10-14 MEDIUM 5.3 CVE-2025-11671 Uniweb/SoliPACS WebServer developed by EBM Technologies has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to acce… Mitigation only Fix from $1,6002025-10-13 MEDIUM 5.3 CVE-2025-11672 Uniweb/SoliPACS WebServer developed by EBM Technologies has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to acce… Mitigation only Fix from $1,6002025-10-13 CRITICAL 9.8 CVE-2025-11661 A vulnerability was found in ProjectsAndPrograms School Management System up to 6b6fae5426044f89c08d0dd101c7fa71f9042a59. This affects an unknown par… School Management System Mitigation only Fix from $2,3002025-10-13 CRITICAL 9.3 CVE-2025-61928EPSS 18% Better Auth is an authentication and authorization library for TypeScript. In versions prior to 1.3.26, unauthenticated attackers can create or modif… Patch available Fix from $2,3002025-10-09 CRITICAL 9.8 CVE-2025-59246EPSS 7% Azure Entra ID Elevation of Privilege Vulnerability Entra Id No fix yet Fix from $2,3002025-10-09 CRITICAL 9.8 CVE-2025-35050 Newforma Info Exchange (NIX) accepts serialized .NET data via the '/remoteweb/remote.rem' endpoint, allowing a remote, unauthenticated attacker to ex… Project Center Mitigation only Fix from $2,3002025-10-09 CRITICAL 9.8 CVE-2025-35051 Newforma Project Center Server (NPCS) accepts serialized .NET data via the '/ProjectCenter.rem' endpoint on 9003/tcp, allowing a remote, unauthentica… Project Center Mitigation only Fix from $2,3002025-10-09 HIGH 7.4 CVE-2025-11198 A Missing Authentication for Critical Function vulnerability in Juniper Networks Security Director Policy Enforcer allows an unauthenticated, network… Security Director Policy Enforcer 23.1+ Fix from $1,9502025-10-09 CRITICAL 9.8 CVE-2025-11529 A security flaw has been discovered in ChurchCRM up to 5.18.0. This impacts the function AuthMiddleware of the file src/ChurchCRM/Slim/Middleware/Aut… Churchcrm 5.19.0+ Fix from $2,3002025-10-09 MEDIUM 5.3 CVE-2025-11171 The Chartify – WordPress Chart Plugin for WordPress is vulnerable to Missing Authentication for Critical Function in all versions up to, and includin… Mitigation only Fix from $1,6002025-10-08 HIGH 7.2 CVE-2023-6215 A potential security vulnerability has been identified in HP Sure Start’s protection of the Intel Flash Descriptor in certain HP PC products, which m… Mitigation only Fix from $1,9502025-10-07 CRITICAL 9.1 CVE-2025-61777 Flag Forge is a Capture The Flag (CTF) platform. Starting in version 2.0.0 and prior to version 2.3.2, the `/api/admin/badge-templates` (GET) and `/a… Flagforge 2.3.2+ Fix from $2,3002025-10-06 CRITICAL 9.3 CVE-2025-61778 Akka.NET is a .NET port of the Akka project from the Scala / Java community. In all versions of Akka.Remote from v1.2.0 to v1.5.51, TLS could be enab… Patch available Fix from $2,3002025-10-06 MEDIUM 6.5 CVE-2025-10746 The Integrate Dynamics 365 CRM plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 1.0.9. This is due to … Mitigation only Fix from $1,6002025-10-04 HIGH 8.6 CVE-2025-61673 Karapace is an open-source implementation of Kafka REST and Schema Registry. Versions 5.0.0 and 5.0.1 contain an authentication bypass vulnerability … Patch available Fix from $1,9502025-10-03