Top technology
Linux 13140
Google 12530
Microsoft 12379
Oracle 6737
Apple 6692
Adobe 6387
Ibm 6330
Cisco 5757
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.5
CVE-2025-56562
An incorrect API discovered in Signify Wiz Connected 1.9.1 allows attackers to remotely launch a DoS on Wiz devices only requiring the MAC address.
Wiz Connected
Mitigation only
HIGH 7.5
CVE-2025-59358
The Chaos Controller Manager in Chaos Mesh exposes a GraphQL debugging server without authentication to the entire Kubernetes cluster, which provides…
Chaos Mesh
2.7.3+
CRITICAL 9.8
CVE-2025-10452
Statistical Database System developed by Gotac has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to read, modify,…
Mitigation only
HIGH 7.1
CVE-2025-10204
A vulnerability has been discovered in AC Smart II where passwords can be changed without authorization. This page contains a hidden form for resetti…
Mitigation only
CRITICAL 9.8
CVE-2025-58434EPSS 50%
Flowise is a drag & drop user interface to build a customized large language model flow. In version 3.0.5 and earlier, the `forgot-password` endpoint…
Flowise
3.0.6+
MEDIUM 5.3
CVE-2025-10267
NUP Portal developed by NewType Infortech has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to directly upload fi…
Mitigation only
MEDIUM 5.4
CVE-2025-9214
A missing authentication vulnerability was reported in some Lenovo printers that could allow a user to view limited device information or modify netw…
Mitigation only
HIGH 7.5
CVE-2025-56405
An issue was discovered in litmusautomation litmus-mcp-server thru 0.0.1 allowing unauthorized attackers to control the target's MCP service through …
Mcp Server
No fix yet
MEDIUM 6.3
CVE-2025-36757
It is possible to bypass the administrator login screen on SolaX Cloud. An attacker could use parameter tampering to bypass the login screen and gain…
Mitigation only
MEDIUM 5.8
CVE-2025-36756
A problem with missing authorization on SolaX Cloud platform allows taking over any SolaX solarpanel inverter of which the serial number is known.
Mitigation only
HIGH 7.7
CVE-2025-7635
Unauthenticated Telnet access vulnerability in Calix GigaCenter ONT allows root access.This issue affects GigaCenter ONT: 844E, 844G, 844GE, 854GE.
Calix Gigacenter Ont
No fix yet
CRITICAL 9.8
CVE-2025-9994
The Amp’ed RF BT-AP 111 Bluetooth access point's HTTP admin interface does not have an authentication feature, allowing unauthorized access to anyone…
Mitigation only
HIGH 7.0
CVE-2025-9160
A code execution security issue exists in the affected product. An attacker with physical access could abuse the maintenance menu of the controller w…
Mitigation only
HIGH 7.5
CVE-2025-7970
A security issue exists within FactoryTalk Activation Manager. An error in the implementation of cryptography within the software could allow attack…
Factorytalk Activation Manager
after 5.01.01
MEDIUM 5.3
CVE-2025-42926
SAP NetWeaver Application Server Java does not perform an authentication check when an attacker attempts to access internal files within the web appl…
Netweaver Application Server Java
Patch available
CRITICAL 9.1
CVE-2025-58443EPSS 19%
FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Versions 1.5.10.1673 and below contain an authentication bypass v…
Fogproject
after 1.5.10.1673
MEDIUM 6.5
CVE-2025-7045
The Cloud SAML SSO plugin for WordPress is vulnerable to Identity Provider Deletion due to a missing capability check on the delete_config action of …
Mitigation only
CRITICAL 9.3
CVE-2025-52551
E2 Facility Management Systems use a proprietary protocol that allows for unauthenticated file operations on any file in the file system.
Mitigation only
HIGH 7.8
CVE-2025-9815
A weakness has been identified in alaneuler batteryKid up to 2.1 on macOS. The affected element is an unknown function of the file PrivilegeHelper/Pr…
Batterykid
after 2.1
MEDIUM 5.9
CVE-2025-58318
Delta Electronics DIAView has an authentication bypass vulnerability.
No fix yet
HIGH 7.3
CVE-2025-7405
Missing Authentication for Critical Function vulnerability in Mitsubishi Electric Corporation MELSEC iQ-F Series CPU module allows a remote unauthent…
Mitigation only
HIGH 8.7
CVE-2012-10062
A vulnerability in XAMPP, developed by Apache Friends, version 1.7.3's default WebDAV configuration allows remote authenticated attackers to upload a…
No fix yet
CRITICAL 9.8
CVE-2025-54942
A missing authentication for critical function vulnerability in SUNNET Corporate Training Management System before 10.11 allows remote attackers to a…
Ehrd Ctms
10.11+
CRITICAL 9.8
CVE-2025-8861
TSA developed by Changing has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to read, modify, and delete database …
Mitigation only
CRITICAL 9.8
CVE-2025-55583EPSS 6%
D-Link DIR-868L B1 router firmware version FW2.05WWB02 contains an unauthenticated OS command injection vulnerability in the fileaccess.cgi component…
Dir 868l Firmware
Mitigation only
HIGH 7.5
CVE-2023-7308EPSS 7%
SecGate3600, a network firewall product developed by NSFOCUS, contains a sensitive information disclosure vulnerability in the /cgi-bin/authUser/auth…
Secgate3600 Firmware
No fix yet
MEDIUM 5.3
CVE-2025-30048
The "serverConfig" endpoint, which returns the module configuration including credentials, is accessible without authentication.
Mitigation only
CRITICAL 9.0
CVE-2025-30041
The paths "/cgi-bin/CliniNET.prd/utils/userlogstat.pl", "/cgi-bin/CliniNET.prd/utils/usrlogstat.pl", and "/cgi-bin/CliniNET.prd/utils/dblogstat.pl" e…
Mitigation only
CRITICAL 9.0
CVE-2025-30039
Unauthenticated access to the "/cgi-bin/CliniNET.prd/GetActiveSessions.pl" endpoint allows takeover of any user session logged into the system, inclu…
Mitigation only
CRITICAL 9.0
CVE-2025-30040
The vulnerability allows unauthenticated users to download a file containing session ID data by directly accessing the "/cgi-bin/CliniNET.prd/utils/u…
Mitigation only