Vulnerability index

Browse CVEs

2,893 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthenticationCWE-306 × clear
HIGH 8.8 CVE-2025-30037 The system exposes several endpoints, typically including "/int/" in their path, that should be restricted to internal services, but are instead publ… Mitigation only Fix from $1,9502025-08-27 MEDIUM 6.8 CVE-2025-25736 Kapsch TrafficCom RIS-9260 RSU LEO v3.2.0.829.23, v3.8.0.1119.42, and v4.6.0.1211.28 were discovered to contain Android Debug Bridge (ADB) pre-instal… Ris 9160 Firmware No fix yet Fix from $1,6002025-08-26 HIGH 8.8 CVE-2025-8627 The TP-Link KP303 Smartplug can be issued unauthenticated protocol commands that may cause unintended power-off condition and potential information l… Kp303 Firmware 1.1.0+ Fix from $1,9502025-08-25 CRITICAL 9.8 CVE-2025-53118EPSS 29% An authentication bypass vulnerability exists which allows an unauthenticated attacker to control administrator backup functions, leading to compromi… Mitigation only Fix from $2,3002025-08-25 CRITICAL 9.8 CVE-2022-43110 Voltronic Power ViewPower through 1.04-21353 and PowerShield Netguard before 1.04-23292 allows a remote attacker to configure the system via an unspe… Mitigation only Fix from $2,3002025-08-22 HIGH 7.3 CVE-2025-55581 D-Link DCS-825L firmware version 1.08.01 and possibly prior versions contain an insecure implementation in the mydlink-watch-dog.sh script. The scrip… Dcs 825l Firmware after 1.08.01 Fix from $1,9502025-08-22 CRITICAL 9.8 CVE-2025-9254 WebITR developed by Uniong has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to log into the system as arbitrary … Webitr 2_1_0_33+ Fix from $2,3002025-08-22 CRITICAL 9.1 CVE-2024-45438 An issue was discovered in TitanHQ SpamTitan Email Security Gateway 8.00.x before 8.00.101 and 8.01.x before 8.01.14. The file quarantine.php within … Mitigation only Fix from $2,3002025-08-21 CRITICAL 9.8 CVE-2025-27214 A Missing Authentication for Critical Function vulnerability in the UniFi Connect EV Station Pro may allow a malicious actor with physical or adjacen… Mitigation only Fix from $2,3002025-08-21 CRITICAL 9.8 CVE-2025-8610 AOMEI Cyber Backup Missing Authentication for Critical Function Remote Code Execution Vulnerability. This vulnerability allows remote attackers to ex… Cyber Backup Mitigation only Fix from $2,3002025-08-20 CRITICAL 9.8 CVE-2025-8611 AOMEI Cyber Backup Missing Authentication for Critical Function Remote Code Execution Vulnerability. This vulnerability allows remote attackers to ex… Cyber Backup Mitigation only Fix from $2,3002025-08-20 CRITICAL 9.8 CVE-2025-51543 An issue was discovered in Cicool builder 3.4.4 allowing attackers to reset the administrator's password via the /administrator/auth/reset_password e… Mitigation only Fix from $2,3002025-08-19 HIGH 8.2 CVE-2025-8450 Improper Access Control issue in the Workflow component of Fortra's FileCatalyst allows unauthenticated users to upload arbitrary files via the order… Mitigation only Fix from $1,9502025-08-19 HIGH 7.5 CVE-2025-41689 An unauthenticated remote attacker can get access without password protection to the affected device. This enables the unprotected read-only access t… Mitigation only Fix from $1,9502025-08-19 CRITICAL 9.8 CVE-2025-8995 Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Authenticator Login allows Authentication Bypass.This issue affects … Authenticator Login 2.1.4+ Fix from $2,3002025-08-15 CRITICAL 9.1 CVE-2025-43983 KuWFi CPF908-CP5 WEB5.0_LCD_20210125 devices have multiple unauthenticated access control vulnerabilities within goform/goform_set_cmd_process and go… Mitigation only Fix from $2,3002025-08-14 HIGH 8.8 CVE-2025-7774 A security issue exists within the 5032 16pt Digital Configurable module’s web server. Intercepted session credentials can be used within a 3-minute … Mitigation only Fix from $1,9502025-08-14 CRITICAL 9.8 CVE-2025-8943EPSS 72% The Custom MCPs feature is designed to execute OS commands, for instance, using tools like `npx` to spin up local MCP Servers. However, Flowise's inh… Flowise 3.0.1+ Fix from $2,3002025-08-14 CRITICAL 10.0 CVE-2011-10013 Traq versions 2.0 through 2.3 contain a remote code execution vulnerability in the admincp/common.php script. The flawed authorization logic fails to… Mitigation only Fix from $2,3002025-08-13 HIGH 7.5 CVE-2025-8754 Missing Authentication for Critical Function vulnerability in ABB ABB AbilityTM zenon.This issue affects ABB AbilityTM zenon: from 7.50 through 14. Mitigation only Fix from $1,9502025-08-13 HIGH 7.8 CVE-2025-53789 Missing authentication for critical function in Windows StateRepository API allows an authorized attacker to elevate privileges locally. Windows 10 1507 10.0.10240.21073 / 10.0.14393.8246+ Fix from $1,9502025-08-12 HIGH 7.5 CVE-2025-54864 Hydra is a continuous integration service for Nix based projects. Prior to commit f7bda02, /api/push-github and /api/push-gitea are called by the cor… Hydra 2025-08-12+ Fix from $1,9502025-08-12 HIGH 7.8 CVE-2025-41686 A low-privileged local attacker can exploit improper permissions on nssm.exe to escalate their privileges and gain administrative access. Mitigation only Fix from $1,9502025-08-12 MEDIUM 5.3 CVE-2025-54478 Mattermost Confluence Plugin version <1.5.0 fails to enforce authentication of the user to the Mattermost instance which allows unauthenticated attac… Confluence 1.5.0+ Fix from $1,6002025-08-11 HIGH 8.1 CVE-2025-7679 The ASPECT system allows users to bypass authentication. This issue affects all versions of ASPECT No fix yet Fix from $1,9502025-08-11 HIGH 7.2 CVE-2025-44004 Mattermost Confluence Plugin version <1.5.0 fails to check the authorization of the user to the Mattermost instance which allows attackers to create … Confluence 1.5.0+ Fix from $1,9502025-08-11 CRITICAL 9.8 CVE-2025-5095 Burk Technology ARC Solo's password change mechanism can be utilized without proper authentication procedures, allowing an attacker to take over the… Mitigation only Fix from $2,3002025-08-08 CRITICAL 9.8 CVE-2025-8284 By default, the Packet Power Monitoring and Control Web Interface do not enforce authentication mechanisms. This vulnerability could allow unauthor… Mitigation only Fix from $2,3002025-08-08 CRITICAL 9.3 CVE-2014-125113 An unrestricted file upload vulnerability exists in Dell (acquired by Quest) KACE K1000 System Management Appliance version 5.0 - 5.3, 5.4 prior to 5… No fix yet Fix from $2,3002025-08-05 CRITICAL 9.8 CVE-2012-10030 FreeFloat FTP Server contains multiple critical design flaws that allow unauthenticated remote attackers to upload arbitrary files to sensitive syste… Freefloat Ftp Server Mitigation only Fix from $2,3002025-08-05