Vulnerability index

Browse CVEs

2,893 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthenticationCWE-306 × clear
HIGH 8.8 CVE-2025-20702EPSS 8% In the Airoha Bluetooth audio SDK, there is a possible unauthorized access to the RACE protocol. This could lead to remote escalation of privilege wi… Mitigation only Fix from $1,9502025-08-04 HIGH 8.8 CVE-2025-20700EPSS 8% In the Airoha Bluetooth audio SDK, there is a possible permission bypass that allows access critical data of RACE protocol through Bluetooth LE GATT … Mitigation only Fix from $1,9502025-08-04 HIGH 8.5 CVE-2013-10046 A local privilege escalation vulnerability exists in Agnitum Outpost Internet Security 8.1 that allows an unprivileged user to execute arbitrary code… No fix yet Fix from $1,9502025-08-01 CRITICAL 9.3 CVE-2025-8286 The affected products expose an unauthenticated Telnet-based command line interface that could allow an attacker to modify hardware configurations, m… Mitigation only Fix from $2,3002025-07-31 CRITICAL 9.2 CVE-2014-125126 An unrestricted file upload vulnerability exists in Simple E-Document versions 3.0 to 3.1 that allows an unauthenticated attacker to bypass authentic… No fix yet Fix from $2,3002025-07-31 CRITICAL 10.0 CVE-2014-125124 An unauthenticated remote command execution vulnerability exists in Pandora FMS versions up to and including 5.0RC1 via the Anyterm web interface, wh… Mitigation only Fix from $2,3002025-07-31 CRITICAL 9.8 CVE-2025-8279 Insufficient input validation within GitLab Language Server 7.6.0 and later before 7.30.0 allows arbitrary GraphQL query execution Language Server 7.30.0+ Fix from $2,3002025-07-28 MEDIUM 5.3 CVE-2025-30126 An issue was discovered on Marbella KR8s Dashcam FF 2.0.8 devices. Via port 7777 without any need to pair or press a physical button, a remote attack… Mitigation only Fix from $1,6002025-07-28 CRITICAL 9.4 CVE-2025-30135 An issue was discovered on IROAD Dashcam FX2 devices. Dumping Files Over HTTP and RTSP Without Authentication can occur. It lacks authentication cont… Fx2 Firmware Mitigation only Fix from $2,3002025-07-25 CRITICAL 9.3 CVE-2014-125116 A remote code execution vulnerability exists in HybridAuth versions 2.0.9 through 2.2.2 due to insecure use of the install.php installation script. T… No fix yet Fix from $2,3002025-07-25 CRITICAL 9.4 CVE-2014-125118 A command injection vulnerability exists in the eScan Web Management Console version 5.5-2. The application fails to properly sanitize the 'pass' par… No fix yet Fix from $2,3002025-07-25 HIGH 8.6 CVE-2016-15046 A client-side remote code execution vulnerability exists in Hanwha Techwin Smart Security Manager (SSM) versions 1.32 and 1.4, due to improper restri… Mitigation only Fix from $1,9502025-07-25 HIGH 8.8 CVE-2013-10032 An authenticated remote code execution vulnerability exists in GetSimpleCMS version 3.2.1. The application’s upload.php endpoint allows authenticated… Getsimplecms No fix yet Fix from $1,9502025-07-25 CRITICAL 9.8 CVE-2025-6260 The embedded web server on the thermostat listed version ranges contain a vulnerability that allows unauthenticated attackers, either on the local ar… Mitigation only Fix from $2,3002025-07-24 CRITICAL 9.3 CVE-2022-4978 Remote Control Server, maintained by Steppschuh, 3.1.1.12 allows unauthenticated remote code execution when authentication is disabled, which is the … Mitigation only Fix from $2,3002025-07-23 CRITICAL 9.3 CVE-2015-10141EPSS 5% An unauthenticated OS command injection vulnerability exists within Xdebug versions 2.5.5 and earlier, a PHP debugging extension developed by Derick … No fix yet Fix from $2,3002025-07-23 HIGH 8.5 CVE-2016-15045 A local privilege escalation vulnerability exists in lastore-daemon, the system package manager daemon used in Deepin Linux (developed by Wuhan Deepi… No fix yet Fix from $1,9502025-07-23 HIGH 7.5 CVE-2025-48733 DuraComm SPM-500 DP-10iN-100-MU lacks access controls for a function that should require user authentication. This could allow an attacker to repea… Mitigation only Fix from $1,9502025-07-22 CRITICAL 9.8 CVE-2025-7897 A vulnerability was found in harry0703 MoneyPrinterTurbo up to 1.2.6 and classified as critical. Affected by this issue is the function verify_token … Moneyprinterturbo after 1.2.6 Fix from $2,3002025-07-20 CRITICAL 9.8 CVE-2025-7862 A vulnerability has been found in TOTOLINK T6 4.1.5cu.748_B20211015 and classified as critical. Affected by this vulnerability is the function setTel… T6 Firmware Mitigation only Fix from $2,3002025-07-20 MEDIUM 6.5 CVE-2025-6226 Mattermost versions 10.5.x <= 10.5.6, 10.8.x <= 10.8.1, 10.7.x <= 10.7.3, 9.11.x <= 9.11.16 fail to verify authorization when retrieving cached posts… Mattermost Server 9.11.17 / 10.5.7+ Fix from $1,6002025-07-18 HIGH 8.7 CVE-2025-34130 An unauthenticated arbitrary file read exists in LILIN Digital Video Recorder (DVR) devices prior to firmware version 2.0b60_20200207 via the /z/zbin… Mitigation only Fix from $1,9502025-07-16 CRITICAL 9.3 CVE-2025-34121 An unauthenticated arbitrary file upload vulnerability exists in Idera Up.Time Monitoring Station versions up to and including 7.2. The `wizards/post… No fix yet Fix from $2,3002025-07-16 CRITICAL 9.3 CVE-2025-34117EPSS 20% A remote code execution vulnerability exists in multiple Netcore and Netis routers models with firmware released prior to August 2014 due to the pres… No fix yet Fix from $2,3002025-07-16 HIGH 8.8 CVE-2025-34119 A remote file disclosure vulnerability exists in EasyCafe Server 2.2.14, exploitable by unauthenticated remote attackers via TCP port 831. The server… No fix yet Fix from $1,9502025-07-16 HIGH 8.7 CVE-2025-34120 An unauthenticated file download vulnerability exists in LimeSurvey versions from 2.0+ up to and including 2.06+ Build 151014. The application fails … Mitigation only Fix from $1,9502025-07-16 HIGH 7.5 CVE-2025-53938 WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. An Authentication Bypass vulnerability was i… Wegia 3.4.5+ Fix from $1,9502025-07-16 HIGH 7.5 CVE-2025-30762 Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4… Weblogic Server Patch available Fix from $1,9502025-07-15 HIGH 8.7 CVE-2025-34116 A remote command execution vulnerability exists in IPFire before version 2.19 Core Update 101 via the 'proxy.cgi' CGI interface. An authenticated att… No fix yet Fix from $1,9502025-07-15 CRITICAL 10.0 CVE-2025-34112 An authenticated multi-stage remote code execution vulnerability exists in Riverbed SteelCentral NetProfiler and NetExpress 10.8.7 virtual appliances… Mitigation only Fix from $2,3002025-07-15