Top technology
Linux 13140
Google 12530
Microsoft 12379
Oracle 6737
Apple 6692
Adobe 6387
Ibm 6330
Cisco 5757
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 8.8
CVE-2025-30037
The system exposes several endpoints, typically including "/int/" in their path, that should be restricted to internal services, but are instead publ…
Mitigation only
MEDIUM 6.8
CVE-2025-25736
Kapsch TrafficCom RIS-9260 RSU LEO v3.2.0.829.23, v3.8.0.1119.42, and v4.6.0.1211.28 were discovered to contain Android Debug Bridge (ADB) pre-instal…
Ris 9160 Firmware
No fix yet
HIGH 8.8
CVE-2025-8627
The TP-Link KP303 Smartplug can be issued unauthenticated protocol commands that may cause unintended power-off condition and potential information l…
Kp303 Firmware
1.1.0+
CRITICAL 9.8
CVE-2025-53118EPSS 29%
An authentication bypass vulnerability exists which allows an unauthenticated attacker to control administrator backup functions, leading to compromi…
Mitigation only
CRITICAL 9.8
CVE-2022-43110
Voltronic Power ViewPower through 1.04-21353 and PowerShield Netguard before 1.04-23292 allows a remote attacker to configure the system via an unspe…
Mitigation only
HIGH 7.3
CVE-2025-55581
D-Link DCS-825L firmware version 1.08.01 and possibly prior versions contain an insecure implementation in the mydlink-watch-dog.sh script. The scrip…
Dcs 825l Firmware
after 1.08.01
CRITICAL 9.8
CVE-2025-9254
WebITR developed by Uniong has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to log into the system as arbitrary …
Webitr
2_1_0_33+
CRITICAL 9.1
CVE-2024-45438
An issue was discovered in TitanHQ SpamTitan Email Security Gateway 8.00.x before 8.00.101 and 8.01.x before 8.01.14. The file quarantine.php within …
Mitigation only
CRITICAL 9.8
CVE-2025-27214
A Missing Authentication for Critical Function vulnerability in the UniFi Connect EV Station Pro may allow a malicious actor with physical or adjacen…
Mitigation only
CRITICAL 9.8
CVE-2025-8610
AOMEI Cyber Backup Missing Authentication for Critical Function Remote Code Execution Vulnerability. This vulnerability allows remote attackers to ex…
Cyber Backup
Mitigation only
CRITICAL 9.8
CVE-2025-8611
AOMEI Cyber Backup Missing Authentication for Critical Function Remote Code Execution Vulnerability. This vulnerability allows remote attackers to ex…
Cyber Backup
Mitigation only
CRITICAL 9.8
CVE-2025-51543
An issue was discovered in Cicool builder 3.4.4 allowing attackers to reset the administrator's password via the /administrator/auth/reset_password e…
Mitigation only
HIGH 8.2
CVE-2025-8450
Improper Access Control issue in the Workflow component of Fortra's FileCatalyst allows unauthenticated users to upload arbitrary files via the order…
Mitigation only
HIGH 7.5
CVE-2025-41689
An unauthenticated remote attacker can get access without password protection to the affected device. This enables the unprotected read-only access t…
Mitigation only
CRITICAL 9.8
CVE-2025-8995
Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Authenticator Login allows Authentication Bypass.This issue affects …
Authenticator Login
2.1.4+
CRITICAL 9.1
CVE-2025-43983
KuWFi CPF908-CP5 WEB5.0_LCD_20210125 devices have multiple unauthenticated access control vulnerabilities within goform/goform_set_cmd_process and go…
Mitigation only
HIGH 8.8
CVE-2025-7774
A security issue exists within the 5032 16pt Digital Configurable module’s web server. Intercepted session credentials can be used within a 3-minute …
Mitigation only
CRITICAL 9.8
CVE-2025-8943EPSS 72%
The Custom MCPs feature is designed to execute OS commands, for instance, using tools like `npx` to spin up local MCP Servers. However, Flowise's inh…
Flowise
3.0.1+
CRITICAL 10.0
CVE-2011-10013
Traq versions 2.0 through 2.3 contain a remote code execution vulnerability in the admincp/common.php script. The flawed authorization logic fails to…
Mitigation only
HIGH 7.5
CVE-2025-8754
Missing Authentication for Critical Function vulnerability in ABB ABB AbilityTM zenon.This issue affects ABB AbilityTM zenon: from 7.50 through 14.
Mitigation only
HIGH 7.8
CVE-2025-53789
Missing authentication for critical function in Windows StateRepository API allows an authorized attacker to elevate privileges locally.
Windows 10 1507
10.0.10240.21073 / 10.0.14393.8246+
HIGH 7.5
CVE-2025-54864
Hydra is a continuous integration service for Nix based projects. Prior to commit f7bda02, /api/push-github and /api/push-gitea are called by the cor…
Hydra
2025-08-12+
HIGH 7.8
CVE-2025-41686
A low-privileged local attacker can exploit improper permissions on nssm.exe to escalate their privileges and gain administrative access.
Mitigation only
MEDIUM 5.3
CVE-2025-54478
Mattermost Confluence Plugin version <1.5.0 fails to enforce authentication of the user to the Mattermost instance which allows unauthenticated attac…
Confluence
1.5.0+
HIGH 8.1
CVE-2025-7679
The ASPECT system allows users to bypass authentication.
This issue affects all versions of ASPECT
No fix yet
HIGH 7.2
CVE-2025-44004
Mattermost Confluence Plugin version <1.5.0 fails to check the authorization of the user to the Mattermost instance which allows attackers to create …
Confluence
1.5.0+
CRITICAL 9.8
CVE-2025-5095
Burk Technology ARC Solo's password change mechanism can be utilized without proper
authentication procedures, allowing an attacker to take over the…
Mitigation only
CRITICAL 9.8
CVE-2025-8284
By default, the Packet Power Monitoring and Control Web Interface do not
enforce authentication mechanisms. This vulnerability could allow
unauthor…
Mitigation only
CRITICAL 9.3
CVE-2014-125113
An unrestricted file upload vulnerability exists in Dell (acquired by Quest) KACE K1000 System Management Appliance version 5.0 - 5.3, 5.4 prior to 5…
No fix yet
CRITICAL 9.8
CVE-2012-10030
FreeFloat FTP Server contains multiple critical design flaws that allow unauthenticated remote attackers to upload arbitrary files to sensitive syste…
Freefloat Ftp Server
Mitigation only