Vulnerability index

Browse CVEs

2,893 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthenticationCWE-306 × clear
HIGH 7.5 CVE-2025-56562 An incorrect API discovered in Signify Wiz Connected 1.9.1 allows attackers to remotely launch a DoS on Wiz devices only requiring the MAC address. Wiz Connected Mitigation only Fix from $1,9502025-09-16 HIGH 7.5 CVE-2025-59358 The Chaos Controller Manager in Chaos Mesh exposes a GraphQL debugging server without authentication to the entire Kubernetes cluster, which provides… Chaos Mesh 2.7.3+ Fix from $1,9502025-09-15 CRITICAL 9.8 CVE-2025-10452 Statistical Database System developed by Gotac has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to read, modify,… Mitigation only Fix from $2,3002025-09-15 HIGH 7.1 CVE-2025-10204 A vulnerability has been discovered in AC Smart II where passwords can be changed without authorization. This page contains a hidden form for resetti… Mitigation only Fix from $1,9502025-09-14 CRITICAL 9.8 CVE-2025-58434EPSS 50% Flowise is a drag & drop user interface to build a customized large language model flow. In version 3.0.5 and earlier, the `forgot-password` endpoint… Flowise 3.0.6+ Fix from $2,3002025-09-12 MEDIUM 5.3 CVE-2025-10267 NUP Portal developed by NewType Infortech has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to directly upload fi… Mitigation only Fix from $1,6002025-09-12 MEDIUM 5.4 CVE-2025-9214 A missing authentication vulnerability was reported in some Lenovo printers that could allow a user to view limited device information or modify netw… Mitigation only Fix from $1,6002025-09-11 HIGH 7.5 CVE-2025-56405 An issue was discovered in litmusautomation litmus-mcp-server thru 0.0.1 allowing unauthorized attackers to control the target's MCP service through … Mcp Server No fix yet Fix from $1,9502025-09-10 MEDIUM 6.3 CVE-2025-36757 It is possible to bypass the administrator login screen on SolaX Cloud. An attacker could use parameter tampering to bypass the login screen and gain… Mitigation only Fix from $1,6002025-09-10 MEDIUM 5.8 CVE-2025-36756 A problem with missing authorization on SolaX Cloud platform allows taking over any SolaX solarpanel inverter of which the serial number is known. Mitigation only Fix from $1,6002025-09-10 HIGH 7.7 CVE-2025-7635 Unauthenticated Telnet access vulnerability in Calix GigaCenter ONT allows root access.This issue affects GigaCenter ONT: 844E, 844G, 844GE, 854GE. Calix Gigacenter Ont No fix yet Fix from $1,9502025-09-09 CRITICAL 9.8 CVE-2025-9994 The Amp’ed RF BT-AP 111 Bluetooth access point's HTTP admin interface does not have an authentication feature, allowing unauthorized access to anyone… Mitigation only Fix from $2,3002025-09-09 HIGH 7.0 CVE-2025-9160 A code execution security issue exists in the affected product. An attacker with physical access could abuse the maintenance menu of the controller w… Mitigation only Fix from $1,9502025-09-09 HIGH 7.5 CVE-2025-7970 A security issue exists within FactoryTalk Activation Manager. An error in the implementation of cryptography within the software could allow attack… Factorytalk Activation Manager after 5.01.01 Fix from $1,9502025-09-09 MEDIUM 5.3 CVE-2025-42926 SAP NetWeaver Application Server Java does not perform an authentication check when an attacker attempts to access internal files within the web appl… Netweaver Application Server Java Patch available Fix from $1,6002025-09-09 CRITICAL 9.1 CVE-2025-58443EPSS 19% FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Versions 1.5.10.1673 and below contain an authentication bypass v… Fogproject after 1.5.10.1673 Fix from $2,3002025-09-06 MEDIUM 6.5 CVE-2025-7045 The Cloud SAML SSO plugin for WordPress is vulnerable to Identity Provider Deletion due to a missing capability check on the delete_config action of … Mitigation only Fix from $1,6002025-09-06 CRITICAL 9.3 CVE-2025-52551 E2 Facility Management Systems use a proprietary protocol that allows for unauthenticated file operations on any file in the file system. Mitigation only Fix from $2,3002025-09-02 HIGH 7.8 CVE-2025-9815 A weakness has been identified in alaneuler batteryKid up to 2.1 on macOS. The affected element is an unknown function of the file PrivilegeHelper/Pr… Batterykid after 2.1 Fix from $1,9502025-09-02 MEDIUM 5.9 CVE-2025-58318 Delta Electronics DIAView has an authentication bypass vulnerability. No fix yet Fix from $1,6002025-09-01 HIGH 7.3 CVE-2025-7405 Missing Authentication for Critical Function vulnerability in Mitsubishi Electric Corporation MELSEC iQ-F Series CPU module allows a remote unauthent… Mitigation only Fix from $1,9502025-09-01 HIGH 8.7 CVE-2012-10062 A vulnerability in XAMPP, developed by Apache Friends, version 1.7.3's default WebDAV configuration allows remote authenticated attackers to upload a… No fix yet Fix from $1,9502025-08-30 CRITICAL 9.8 CVE-2025-54942 A missing authentication for critical function vulnerability in SUNNET Corporate Training Management System before 10.11 allows remote attackers to a… Ehrd Ctms 10.11+ Fix from $2,3002025-08-30 CRITICAL 9.8 CVE-2025-8861 TSA developed by Changing has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to read, modify, and delete database … Mitigation only Fix from $2,3002025-08-29 CRITICAL 9.8 CVE-2025-55583EPSS 6% D-Link DIR-868L B1 router firmware version FW2.05WWB02 contains an unauthenticated OS command injection vulnerability in the fileaccess.cgi component… Dir 868l Firmware Mitigation only Fix from $2,3002025-08-28 HIGH 7.5 CVE-2023-7308EPSS 7% SecGate3600, a network firewall product developed by NSFOCUS, contains a sensitive information disclosure vulnerability in the /cgi-bin/authUser/auth… Secgate3600 Firmware No fix yet Fix from $1,9502025-08-27 MEDIUM 5.3 CVE-2025-30048 The "serverConfig" endpoint, which returns the module configuration including credentials, is accessible without authentication. Mitigation only Fix from $1,6002025-08-27 CRITICAL 9.0 CVE-2025-30041 The paths "/cgi-bin/CliniNET.prd/utils/userlogstat.pl", "/cgi-bin/CliniNET.prd/utils/usrlogstat.pl", and "/cgi-bin/CliniNET.prd/utils/dblogstat.pl" e… Mitigation only Fix from $2,3002025-08-27 CRITICAL 9.0 CVE-2025-30039 Unauthenticated access to the "/cgi-bin/CliniNET.prd/GetActiveSessions.pl" endpoint allows takeover of any user session logged into the system, inclu… Mitigation only Fix from $2,3002025-08-27 CRITICAL 9.0 CVE-2025-30040 The vulnerability allows unauthenticated users to download a file containing session ID data by directly accessing the "/cgi-bin/CliniNET.prd/utils/u… Mitigation only Fix from $2,3002025-08-27