Vulnerability index

Browse CVEs

2,893 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthenticationCWE-306 × clear
HIGH 8.8 CVE-2025-6916 A vulnerability, which was classified as critical, was found in TOTOLINK T6 4.1.5cu.748_B20211015. This affects the function Form_Login of the file /… T6 Firmware No fix yet Fix from $1,9502025-06-30 HIGH 7.5 CVE-2024-8419 The endpoint hosts a script that allows an unauthorized remote attacker to put the system in a fail-safe state over the network due to missing authen… Mitigation only Fix from $1,9502025-06-30 CRITICAL 9.8 CVE-2025-5310 Dover Fueling Solutions ProGauge MagLink LX Consoles expose an undocumented and unauthenticated target communication framework (TCF) interface on a s… Mitigation only Fix from $2,3002025-06-27 HIGH 8.1 CVE-2025-6763 A vulnerability was found in Comet System T0510, T3510, T3511, T4511, T6640, T7511, T7611, P8510, P8552 and H3531 1.60. Affected by this issue is som… T7611 Firmware No fix yet Fix from $1,9502025-06-27 CRITICAL 9.8 CVE-2025-3699 Missing Authentication for Critical Function vulnerability in Mitsubishi Electric Corporation G-50 all versions, G-50-W all versions, G-50A all versi… Mitigation only Fix from $2,3002025-06-26 MEDIUM 5.3 CVE-2025-1754 An issue has been discovered in GitLab CE/EE affecting all versions from 17.2 before 17.11.5, 18.0 before 18.0.3, and 18.1 before 18.1.1 that could h… GitLab 17.11.5 / 18.0.3+ Fix from $1,6002025-06-26 HIGH 7.5 CVE-2025-6678 Autel MaxiCharger AC Wallbox Commercial PIN Missing Authentication Information Disclosure Vulnerability. This vulnerability allows remote attackers t… Maxicharger Ac Elite Business C50 Firmware 1.39.51 / 1.56.51+ Fix from $1,9502025-06-25 HIGH 7.5 CVE-2025-32978 Quest KACE Systems Management Appliance (SMA) 13.0.x before 13.0.385, 13.1.x before 13.1.81, 13.2.x before 13.2.183, 14.0.x before 14.0.341 (Patch 5)… Mitigation only Fix from $1,9502025-06-24 HIGH 8.2 CVE-2025-3090 An unauthenticated remote attacker can obtain limited sensitive information and/or DoS the device due to missing authentication for critical function. Mitigation only Fix from $1,9502025-06-24 CRITICAL 9.6 CVE-2025-48469 Successful exploitation of the vulnerability could allow an unauthenticated attacker to upload firmware through a public update page, potentially lea… Wise 4060lan Firmware No fix yet Fix from $2,3002025-06-24 CRITICAL 10.0 CVE-2025-34039 A code injection vulnerability exists in Yonyou UFIDA NC v6.5 and prior due to the exposure of the BeanShell testing servlet (bsh.servlet.BshServlet)… Mitigation only Fix from $2,3002025-06-24 CRITICAL 9.8 CVE-2025-3319 IBM Spectrum Protect Server 8.1 through 8.1.26 could allow attacker to bypass authentication due to improper session authentication which can result … Spectrum Protect Server after 8.1.26 Fix from $2,3002025-06-20 HIGH 8.8 CVE-2025-32879 An issue was discovered on COROS PACE 3 devices through 3.0808.0. It starts advertising if no device is connected via Bluetooth. This allows an attac… Coros Pace 3 Firmware after 3.0808.0 Fix from $1,9502025-06-20 MEDIUM 6.8 CVE-2025-32876 An issue was discovered on COROS PACE 3 devices through 3.0808.0. The BLE implementation of the COROS smartwatch does not support LE Secure Connectio… Coros Pace 3 Firmware after 3.0808.0 Fix from $1,6002025-06-20 MEDIUM 6.5 CVE-2025-32896 # Summary Unauthorized users can perform Arbitrary File Read and Deserialization attack by submit job using restful api-v1. # Details Unauthorized … Seatunnel 2.3.11+ Fix from $1,6002025-06-19 CRITICAL 9.4 CVE-2025-49596EPSS 45% The MCP inspector is a developer tool for testing and debugging MCP servers. Versions of MCP Inspector below 0.14.1 are vulnerable to remote code exe… Patch available Fix from $2,3002025-06-13 MEDIUM 6.1 CVE-2024-35295 A vulnerability has been identified in Perfect Harmony GH180 (All versions >= V8.0 < V8.3.3 with NXGPro+ controller manufactured between April 2020 t… Mitigation only Fix from $1,6002025-06-11 HIGH 7.8 CVE-2024-9062 The Archify application contains a local privilege escalation vulnerability due to insufficient client validation in its privileged helper tool, com.… Mitigation only Fix from $1,9502025-06-11 CRITICAL 9.8 CVE-2025-5906 A vulnerability classified as critical has been found in code-projects Laundry System 1.0. This affects an unknown part of the file /data/. The manip… Laundry System Mitigation only Fix from $2,3002025-06-10 HIGH 7.5 CVE-2025-26468 CyberData  011209 Intercom exposes features that could allow an unauthenticated to gain access and cause a denial-of-service condition or system … 011209 Sip Emergency Intercom 22.0.1+ Fix from $1,9502025-06-09 CRITICAL 9.8 CVE-2025-49652 Missing Authentication in the registration feature of Lablup's BackendAI allows arbitrary users to create user accounts that can access private data … Mitigation only Fix from $2,3002025-06-09 MEDIUM 5.3 CVE-2025-5876 A vulnerability classified as problematic was found in Lucky LM-520-SC, LM-520-FSC and LM-520-FSC-SAM up to 20250321. Affected by this vulnerability … Mitigation only Fix from $1,6002025-06-09 MEDIUM 5.3 CVE-2025-5871 A vulnerability was found in Papendorf SOL Connect Center 3.3.0.0 and classified as problematic. Affected by this issue is some unknown functionality… Mitigation only Fix from $1,6002025-06-09 MEDIUM 5.3 CVE-2025-5872 A vulnerability was found in eGauge EG3000 Energy Monitor 3.6.3. It has been classified as problematic. This affects an unknown part of the component… Mitigation only Fix from $1,6002025-06-09 CRITICAL 9.8 CVE-2025-3461 The Quantenna Wi-Fi chips ship with an unauthenticated telnet interface by default. This is an instance of CWE-306, "Missing Authentication for Criti… Qhs710 Firmware Mitigation only Fix from $2,3002025-06-08 CRITICAL 9.0 CVE-2024-55585 In the moPS App through 1.8.618, all users can access administrative API endpoints without additional authentication, resulting in unrestricted read … Mitigation only Fix from $2,3002025-06-07 HIGH 7.5 CVE-2025-5192 A missing authentication for critical function vulnerability in the client application of Soar Cloud HRD Human Resource Management System through ver… Hr Portal after 7.3.2025.0408 Fix from $1,9502025-06-06 MEDIUM 5.1 CVE-2025-5719 The wallet has an authentication bypass vulnerability that allows access to specific pages. No fix yet Fix from $1,6002025-06-06 MEDIUM 6.4 CVE-2025-5715 A vulnerability was found in Signal App 7.41.4 on Android. It has been declared as problematic. This vulnerability affects unknown code of the compon… Signal No fix yet Fix from $1,6002025-06-06 HIGH 8.9 CVE-2025-1701 CVE-2025-1701 is a high-severity vulnerability in the MIM Admin service. An attacker could exploit this vulnerability by sending a specially crafted … Mitigation only Fix from $1,9502025-06-04