Top technology
Linux 13140
Google 12530
Microsoft 12379
Oracle 6737
Apple 6692
Adobe 6387
Ibm 6330
Cisco 5757
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 5.5
CVE-2025-47272
The CE Phoenix eCommerce platform, starting in version 1.0.9.7 and prior to version 1.1.0.3, allowed logged-in users to delete their accounts without…
Patch available
CRITICAL 9.8
CVE-2025-1907
Instantel Micromate lacks authentication on a configuration port which could allow an attacker to execute commands if connected.
Mitigation only
HIGH 7.2
CVE-2025-22252
A missing authentication for critical function in Fortinet FortiProxy versions 7.6.0 through 7.6.1, FortiSwitchManager version 7.2.5, and FortiOS ver…
Fortiproxy
7.4.7+
CRITICAL 9.8
CVE-2025-32440
NetAlertX is a network, presence scanner and alert framework. Prior to version 25.4.14, it is possible to bypass the authentication mechanism of NetA…
Netalertx
25.4.14+
CRITICAL 9.8
CVE-2025-41651
Due to missing authentication on a critical function of the devices an unauthenticated remote attacker can execute arbitrary commands, potentially en…
Mitigation only
CRITICAL 9.3
CVE-2025-2407
Missing Authentication & Authorization in Web-API in Mobatime AMX MTAPI v6 on IIS allows adversaries to unrestricted access via the network. The vuln…
Mitigation only
CRITICAL 9.8
CVE-2025-48742
The installer in SIGB PMB before and fixed in v.8.0.1.2 allows remote code execution.
Pmb
8.0.1.2+
CRITICAL 9.1
CVE-2025-40664
Missing authentication vulnerability in TCMAN GIM v11. This allows an unauthenticated attacker to access the resources /frmGestionUser.aspx/GetData, …
Gim
Mitigation only
HIGH 7.5
CVE-2025-41655
An unauthenticated remote attacker can access a URL which causes the device to reboot.
Mitigation only
HIGH 8.2
CVE-2025-41654
An unauthenticated remote attacker can access information about running processes via the SNMP protocol. The amount of returned data can trigger a re…
Mitigation only
CRITICAL 10.0
CVE-2025-36535
The embedded web server lacks authentication and access controls, allowing unrestricted remote access. This could lead to configuration changes, oper…
Mitigation only
HIGH 8.8
CVE-2025-4008 KEVEPSS 94%
The Meteobridge web interface let meteobridge administrator manage their weather station data collection and administer their meteobridge system thro…
Meteobridge Vm
6.2+
MEDIUM 6.5
CVE-2025-27803
The devices do not implement any authentication for the web interface or the MQTT server. An attacker who has network access to the device immediatel…
Mitigation only
HIGH 7.5
CVE-2025-48391
In JetBrains YouTrack before 2025.1.76253 deletion of issues was possible due to missing permission checks in API
Youtrack
2025.1.76253+
MEDIUM 5.3
CVE-2025-47850
In JetBrains YouTrack before 2025.1.74704 restricted attachments could become visible after issue cloning
Youtrack
2025.1.74704+
MEDIUM 5.3
CVE-2025-32738
Missing authentication for critical function issue exists in I-O DATA network attached hard disk 'HDL-T Series' firmware Ver.1.21 and earlier. If exp…
Mitigation only
MEDIUM 6.9
CVE-2025-0132
A missing authentication vulnerability in Palo Alto Networks Cortex XDR® Broker VM allows an unauthenticated user to disable certain internal service…
Mitigation only
CRITICAL 10.0
CVE-2024-46506EPSS 62%
NetAlertX 23.01.14 through 24.x before 24.10.12 allows unauthenticated command injection via settings update because function=savesettings lacks an a…
Netalertx
24.10.12+
MEDIUM 5.1
CVE-2025-44039
CP-XR-DE21-S -4G Router Firmware version 1.031.022 was discovered to contain insecure protections for its UART console. This vulnerability allows loc…
Cp Xr De21 S Firmware
No fix yet
HIGH 7.5
CVE-2024-23815
A vulnerability has been identified in Desigo CC (All versions if access from Installed Clients to Desigo CC server is allowed from networks outside …
Mitigation only
MEDIUM 6.5
CVE-2025-4560
The ISOinsight from Netvision has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to access certain system function…
Mitigation only
CRITICAL 9.1
CVE-2025-4557
The specific APIs of Parking Management System from ZONG YU has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to …
Mitigation only
CRITICAL 9.8
CVE-2025-4555
The web management interface of Okcat Parking Management Platform from ZONG YU has a Missing Authentication vulnerability, allowing unauthenticated r…
Mitigation only
MEDIUM 5.9
CVE-2025-4382
A flaw was found in systems utilizing LUKS-encrypted disks with GRUB configured for TPM-based auto-decryption. When GRUB is set to automatically decr…
Mitigation only
HIGH 8.7
CVE-2025-3758
WF2220 exposes endpoint /cgi-bin-igd/netcore_get.cgi that returns configuration of the device to unauthorized users. Returned configuration includes …
Mitigation only
HIGH 8.7
CVE-2025-3759
Endpoint /cgi-bin-igd/netcore_set.cgi which is used for changing device configuration is accessible without authentication. This poses a significant …
Mitigation only
HIGH 7.3
CVE-2025-20210
A vulnerability in the management API of Cisco Catalyst Center, formerly Cisco DNA Center, could allow an unauthenticated, remote attacker to read an…
Catalyst Center
2.3.7.9+
MEDIUM 5.3
CVE-2025-4268
A vulnerability has been found in TOTOLINK A720R 4.1.5cu.374 and classified as critical. This vulnerability affects unknown code of the file /cgi-bin…
A720r Firmware
No fix yet
MEDIUM 5.4
CVE-2025-24271
An access issue was addressed with improved access restrictions. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, …
Ipados
2.4 / 13.7.5+
CRITICAL 9.8
CVE-2025-4019
A vulnerability, which was classified as critical, was found in 20120630 Novel-Plus up to 0e156c04b4b7ce0563bef6c97af4476fcda8f160. Affected is the f…
Novel Plus
5.1.1+