Vulnerability index

Browse CVEs

2,893 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthenticationCWE-306 × clear
HIGH 7.5 CVE-2025-4018 A vulnerability, which was classified as critical, has been found in 20120630 Novel-Plus up to 0e156c04b4b7ce0563bef6c97af4476fcda8f160. This issue a… Novel Plus 5.1.1+ Fix from $1,9502025-04-28 HIGH 7.5 CVE-2025-4015 A vulnerability was found in 20120630 Novel-Plus up to 0e156c04b4b7ce0563bef6c97af4476fcda8f160. It has been rated as critical. Affected by this issu… Novel Plus 5.1.1+ Fix from $1,9502025-04-28 CRITICAL 9.8 CVE-2025-46275 WGS-80HPT-V2 and WGS-4215-8T2S are missing authentication that could allow an attacker to create an administrator account without knowing any exist… Mitigation only Fix from $2,3002025-04-24 CRITICAL 10.0 CVE-2025-34028 KEVEPSS 98% The Commvault Command Center Innovation Release allows an unauthenticated actor to upload ZIP files that represent install packages that, when expand… Commvault 11.38.20+ Fix from $2,3002025-04-22 MEDIUM 6.5 CVE-2025-32377 Rasa Pro is a framework for building scalable, dynamic conversational AI assistants that integrate large language models (LLMs). A vulnerability has … Mitigation only Fix from $1,6002025-04-18 HIGH 7.5 CVE-2024-42178 HCL MyXalytics is affected by a failure to restrict URL access vulnerability. Unauthenticated users might gain unauthorized access to potentially con… Dryice Myxalytics Mitigation only Fix from $1,9502025-04-17 CRITICAL 10.0 CVE-2025-32433 KEVEPSS 99% Erlang/OTP is a set of libraries for the Erlang programming language. Prior to versions OTP-27.3.3, OTP-26.2.5.11, and OTP-25.3.2.20, a SSH server ma… Confd Basic 5.7.19.1 / 6.1.16.2+ Fix from $2,3002025-04-16 CRITICAL 9.6 CVE-2025-30215 NATS-Server is a High-Performance server for NATS.io, the cloud and edge native messaging system. In versions starting from 2.2.0 but prior to 2.10.2… Mitigation only Fix from $2,3002025-04-16 MEDIUM 5.3 CVE-2025-32782 Ash Authentication provides authentication for the Ash framework. The confirmation flow for account creation currently uses a GET request triggered b… Patch available Fix from $1,6002025-04-15 CRITICAL 9.8 CVE-2025-30727 Vulnerability in the Oracle Scripting product of Oracle E-Business Suite (component: iSurvey Module). Supported versions that are affected are 12.2.… E Business Suite after 12.2.14 Fix from $2,3002025-04-15 CRITICAL 9.8 CVE-2025-2567 An attacker could modify or disable settings, disrupt fuel monitoring and supply chain operations, leading to disabling of ATG monitoring. This wou… Mitigation only Fix from $2,3002025-04-15 CRITICAL 9.3 CVE-2025-0129 An improper exception check in Palo Alto Networks Prisma Access Browser allows a low privileged user to prevent Prisma Access Browser from applying i… Mitigation only Fix from $2,3002025-04-11 MEDIUM 6.5 CVE-2025-3474 Missing Authentication for Critical Function vulnerability in Drupal Panels allows Exploiting Incorrectly Configured Access Control Security Levels.T… Panels 4.9+ Fix from $1,6002025-04-09 HIGH 7.5 CVE-2025-29870 Missing authentication for critical function vulnerability exists in Wi-Fi AP UNIT 'AC-WPS-11ac series'. If exploited, a remote unauthenticated attac… Mitigation only Fix from $1,9502025-04-09 HIGH 7.5 CVE-2024-41793 A vulnerability has been identified in SENTRON 7KT PAC1260 Data Manager (All versions). The web interface of affected devices provides an endpoint th… 7kt Pac1260 Data Manager Firmware Mitigation only Fix from $1,9502025-04-08 MEDIUM 6.5 CVE-2024-41791 A vulnerability has been identified in SENTRON 7KT PAC1260 Data Manager (All versions). The web interface of affected devices does not authenticate r… 7kt Pac1260 Data Manager Firmware Mitigation only Fix from $1,6002025-04-08 CRITICAL 9.8 CVE-2025-3248 KEVEPSS 100% Langflow versions prior to 1.3.0 are susceptible to code injection in the /api/v1/validate/code endpoint. A remote and unauthenticated attacker can … Langflow 1.3.0+ Fix from $2,3002025-04-07 HIGH 7.5 CVE-2025-0257 HCL DevOps Deploy / HCL Launch could allow unauthorized access to other services or potential exposure of sensitive data due to missing authenticatio… Hcl Devops Deploy 7.1.2.23 / 7.2.3.16+ Fix from $1,9502025-04-02 HIGH 8.2 CVE-2025-25060 Missing authentication for critical function vulnerability exists in AssetView and AssetView CLOUD. If exploited, the files on the server where the p… Mitigation only Fix from $1,9502025-04-02 CRITICAL 9.8 CVE-2024-13553 The SMS Alert Order Notifications – WooCommerce plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to… Sms Alert Order Notifications 3.8.0+ Fix from $2,3002025-04-01 MEDIUM 6.3 CVE-2024-56469 IBM UrbanCode Deploy (UCD) 7.1 through 7.1.2.22, 7.2 through 7.2.3.15, and 7.3 through 7.3.2.10 / IBM DevOps Deploy 8.0 through 8.0.1.5 and 8.1 throu… Devops Deploy 7.1.2.23 / 7.2.3.16+ Fix from $1,6002025-03-27 HIGH 7.3 CVE-2024-45356 A unauthorized access vulnerability exists in the Xiaomi phone framework. The vulnerability is caused by improper validation and can be exploited by … No fix yet Fix from $1,9502025-03-27 MEDIUM 5.5 CVE-2024-45355 A unauthorized access vulnerability exists in the Xiaomi phone framework. The vulnerability is caused by improper validation and can be exploited by … Mitigation only Fix from $1,6002025-03-27 HIGH 7.0 CVE-2024-45483 A Missing Authentication for Critical Function vulnerability in the GRUB configuration used B&R APROL <4.4-01 may allow an unauthenticated physical a… Mitigation only Fix from $1,9502025-03-25 MEDIUM 6.5 CVE-2025-0256 HCL DevOps Deploy / HCL Launch could allow an authenticated user to obtain sensitive information about other users on the system due to missing autho… Hcl Devops Deploy 7.0.5.26 / 7.1.2.22+ Fix from $1,6002025-03-24 HIGH 8.8 CVE-2025-25068 Mattermost versions 10.4.x <= 10.4.2, 10.3.x <= 10.3.3, 9.11.x <= 9.11.8, 10.5.x <= 10.5.0 fail to enforce MFA on plugin endpoints, which allows auth… Mattermost Server 9.11.9 / 10.3.4+ Fix from $1,9502025-03-21 HIGH 8.4 CVE-2024-9919 A missing authentication check in the uninstall endpoint of parisneo/lollms-webui V13 allows attackers to perform unauthorized directory deletions. T… Lollms Web Ui No fix yet Fix from $1,9502025-03-20 CRITICAL 9.8 CVE-2024-8196 In mintplex-labs/anything-llm v1.5.11 desktop version for Windows, the application opens server port 3001 on 0.0.0.0 with no authentication by defaul… Anythingllm Desktop 1.6.5+ Fix from $2,3002025-03-20 HIGH 8.2 CVE-2024-8053 In version v0.3.10 of open-webui/open-webui, the `api/v1/utils/pdf` endpoint lacks authentication mechanisms, allowing unauthenticated attackers to a… Open Webui No fix yet Fix from $1,9502025-03-20 HIGH 7.5 CVE-2024-6842EPSS 31% In version 1.5.5 of mintplex-labs/anything-llm, the `/setup-complete` API endpoint allows unauthorized users to access sensitive system settings. The… Anythingllm Patch available Fix from $1,9502025-03-20