Vulnerability index

Browse CVEs

2,893 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthenticationCWE-306 × clear
HIGH 8.7 CVE-2025-34113 An authenticated command injection vulnerability exists in Tiki Wiki CMS versions ≤14.1, ≤12.4 LTS, ≤9.10 LTS, and ≤6.14 via the `viewmode` GET param… No fix yet Fix from $1,9502025-07-15 HIGH 8.7 CVE-2025-34115 An authenticated command injection vulnerability exists in OP5 Monitor through version 7.1.9 via the 'cmd_str' parameter in the command_test.php endp… No fix yet Fix from $1,9502025-07-15 CRITICAL 9.3 CVE-2025-34110 A directory traversal vulnerability exists in ColoradoFTP Server ≤ 1.3 Build 8 for Windows, allowing unauthenticated attackers to read or write arbit… Patch available Fix from $2,3002025-07-15 CRITICAL 9.8 CVE-2025-34111 An unauthenticated arbitrary file upload vulnerability exists in Tiki Wiki CMS Groupware version 15.1 and earlier via the ELFinder component's defaul… Tikiwiki Cms\/groupware after 15.1 Fix from $2,3002025-07-15 CRITICAL 9.3 CVE-2025-34068 An unauthenticated remote command execution vulnerability exists in Samsung WLAN AP WEA453e firmware prior to version 5.2.4.T1 via improper input val… Mitigation only Fix from $2,3002025-07-15 CRITICAL 9.3 CVE-2025-34103 An unauthenticated command injection vulnerability exists in WePresent WiPG-1000 firmware versions prior to 2.2.3.0, due to improper input handling i… No fix yet Fix from $2,3002025-07-15 CRITICAL 9.4 CVE-2025-34104 An authenticated remote code execution vulnerability exists in Piwik (now Matomo) versions prior to 3.0.3 via the plugin upload mechanism. In vulnera… Mitigation only Fix from $2,3002025-07-15 HIGH 8.8 CVE-2025-52089EPSS 8% A hidden remote support feature protected by a static secret in TOTOLINK N300RB firmware version 8.54 allows an authenticated attacker to execute arb… N300rb Firmware No fix yet Fix from $1,9502025-07-11 CRITICAL 9.3 CVE-2025-34102EPSS 7% A remote code execution vulnerability exists in CryptoLog (PHP version, discontinued since 2009) due to a chained exploitation of SQL injection and c… No fix yet Fix from $2,3002025-07-10 CRITICAL 9.3 CVE-2025-34100 An unrestricted file upload vulnerability exists in BuilderEngine 3.5.0 via the integration of the elFinder 2.0 file manager and its use of the jQuer… No fix yet Fix from $2,3002025-07-10 CRITICAL 9.3 CVE-2025-34101 An unauthenticated command injection vulnerability exists in Serviio Media Server versions 1.4 through 1.8 on Windows, in the /rest/action API endpoi… No fix yet Fix from $2,3002025-07-10 CRITICAL 9.8 CVE-2025-53378 A missing authentication vulnerability in Trend Micro Worry-Free Business Security Services (WFBSS) agent could have allowed an unauthenticated attac… Worry Free Business Security Services 6.7.3954 / 14.3.1299+ Fix from $2,3002025-07-10 CRITICAL 9.9 CVE-2025-3498 An unauthenticated user with management network access can get and modify the Radiflow iSAP Smart Collector (CentOS 7 - VSAP 1.20) configuration. T… Mitigation only Fix from $2,3002025-07-09 CRITICAL 10.0 CVE-2025-34077EPSS 10% An authentication bypass vulnerability exists in the WordPress Pie Register plugin ≤ 3.7.1.4 that allows unauthenticated attackers to impersonate arb… Mitigation only Fix from $2,3002025-07-09 MEDIUM 5.3 CVE-2025-7031 Missing Authentication for Critical Function vulnerability in Drupal Config Pages Viewer allows Exploiting Incorrectly Configured Access Control Secu… Config Pages Viewer 1.0.4+ Fix from $1,6002025-07-08 HIGH 7.5 CVE-2025-48814 Missing authentication for critical function in Windows Remote Desktop Licensing Service allows an unauthorized attacker to bypass a security feature… Windows 10 1607 10.0.14393.8246 / 10.0.17763.7558+ Fix from $1,9502025-07-08 CRITICAL 9.8 CVE-2025-40736 A vulnerability has been identified in SINEC NMS (All versions < V4.0). The affected application exposes an endpoint that allows an unauthorized modi… Sinec Nms 4.0+ Fix from $2,3002025-07-08 HIGH 8.8 CVE-2025-25268 An unauthenticated adjacent attacker can modify configuration by sending specific requests to an API-endpoint resulting in read and write access due … Charx Sec 3000 Firmware 1.7.3+ Fix from $1,9502025-07-08 HIGH 7.5 CVE-2025-7114 A vulnerability was found in SimStudioAI sim up to 37786d371e17d35e0764e1b5cd519d873d90d97b. It has been declared as critical. Affected by this vulne… Sim after 0.2.1 Fix from $1,9502025-07-07 HIGH 7.3 CVE-2025-7115 A vulnerability was found in rowboatlabs rowboat up to 8096eaf63b5a0732edd8f812bee05b78e214ee97. It has been rated as critical. Affected by this issu… Mitigation only Fix from $1,9502025-07-07 CRITICAL 9.3 CVE-2025-34089 An unauthenticated remote code execution vulnerability exists in Remote for Mac, a macOS remote control utility developed by Aexol Studio, in version… No fix yet Fix from $2,3002025-07-03 HIGH 7.8 CVE-2025-34079 An authenticated remote code execution vulnerability exists in NSClient++ version 0.5.2.35 when the web interface and ExternalScripts module are enab… Nsclient\+\+ No fix yet Fix from $1,9502025-07-02 CRITICAL 9.8 CVE-2025-45814 Missing authentication checks in the query.fcgi endpoint of NS3000 v8.1.1.125110 , v7.2.8.124852 , and v7.x and NS2000 v7.02.08 allows attackers to e… Ns3000 Firmware Mitigation only Fix from $2,3002025-07-02 HIGH 8.7 CVE-2025-34057EPSS 8% An information disclosure vulnerability exists in Ruijie NBR series routers (known to affect NBR2000G, NBR1300G, and NBR1000 models) via the /WEB_VMS… Mitigation only Fix from $1,9502025-07-02 CRITICAL 9.8 CVE-2025-34069 An authentication bypass vulnerability exists in GFI Kerio Control 9.4.5 due to insecure default proxy configuration and weak access control in the G… Kerio Control Mitigation only Fix from $2,3002025-07-02 CRITICAL 9.8 CVE-2025-34070 A missing authentication vulnerability in the GFIAgent component of GFI Kerio Control 9.4.5 allows unauthenticated remote attackers to perform privil… Kerio Control Mitigation only Fix from $2,3002025-07-02 CRITICAL 9.8 CVE-2025-34071 A remote code execution vulnerability in GFI Kerio Control 9.4.5 allows attackers with administrative access to upload and execute arbitrary code thr… Kerio Control Mitigation only Fix from $2,3002025-07-02 CRITICAL 10.0 CVE-2025-34073 An unauthenticated command injection vulnerability exists in stamparm/maltrail (Maltrail) versions <=0.54. A remote attacker can execute arbitrary op… Mitigation only Fix from $2,3002025-07-02 MEDIUM 5.3 CVE-2025-6920 A flaw was found in the authentication enforcement mechanism of a model inference API in ai-inference-server. All /v1/* endpoints are expected to enf… Ai Inference Server Mitigation only Fix from $1,6002025-07-01 CRITICAL 10.0 CVE-2025-41656EPSS 12% An unauthenticated remote attacker can run arbitrary commands on the affected devices with high privileges because the authentication for the Node_RE… Mitigation only Fix from $2,3002025-07-01