Vulnerabilities (CVE)

Filtered by CWE-306
Total 2860 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-4008 1 Smartbedded 2 Meteobridge Firmware, Meteobridge Vm 2026-06-17 N/A 8.8 HIGH
The Meteobridge web interface let meteobridge administrator manage their weather station data collection and administer their meteobridge system through a web application written in CGI shell scripts and C. This web interface exposes an endpoint that is vulnerable to command injection. Remote unauthenticated attackers can gain arbitrary command execution with elevated privileges ( root ) on affected devices.
CVE-2025-49652 2026-06-17 N/A 9.8 CRITICAL
Missing Authentication in the registration feature of Lablup's BackendAI allows arbitrary users to create user accounts that can access private data even when registration is disabled.
CVE-2025-49596 2026-06-17 N/A N/A
The MCP inspector is a developer tool for testing and debugging MCP servers. Versions of MCP Inspector below 0.14.1 are vulnerable to remote code execution due to lack of authentication between the Inspector client and proxy, allowing unauthenticated requests to launch MCP commands over stdio. Users should immediately upgrade to version 0.14.1 or later to address these vulnerabilities.
CVE-2025-48814 1 Microsoft 14 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 11 more 2026-06-17 N/A 7.5 HIGH
Missing authentication for critical function in Windows Remote Desktop Licensing Service allows an unauthorized attacker to bypass a security feature over a network.
CVE-2025-48742 1 Sigb 1 Pmb 2026-06-17 N/A 5.4 MEDIUM
The installer in SIGB PMB before and fixed in v.8.0.1.2 allows remote code execution.
CVE-2025-48733 2026-06-17 N/A 7.5 HIGH
DuraComm SPM-500 DP-10iN-100-MU lacks access controls for a function that should require user authentication. This could allow an attacker to repeatedly reboot the device.
CVE-2025-48608 1 Google 1 Android 2026-06-17 N/A 5.5 MEDIUM
In isValidMediaUri of SettingsProvider.java, there is a possible cross user media read due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
CVE-2025-48572 1 Google 1 Android 2026-06-17 N/A 7.8 HIGH
In multiple locations, there is a possible way to launch activities from the background due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
CVE-2025-48469 1 Advantech 6 Wise-4010lan, Wise-4010lan Firmware, Wise-4050lan and 3 more 2026-06-17 N/A 9.6 CRITICAL
Successful exploitation of the vulnerability could allow an unauthenticated attacker to upload firmware through a public update page, potentially leading to backdoor installation or privilege escalation.
CVE-2025-48397 2026-06-17 N/A 7.1 HIGH
The privileged user could log in without sufficient credentials after enabling an application protocol. This security issue has been fixed in the latest script patch latest version of of Eaton BLSS (7.3.0.SCP004).
CVE-2025-48391 1 Jetbrains 1 Youtrack 2026-06-17 N/A 7.7 HIGH
In JetBrains YouTrack before 2025.1.76253 deletion of issues was possible due to missing permission checks in API
CVE-2025-47870 1 Mattermost 1 Mattermost Server 2026-06-17 N/A 4.3 MEDIUM
Mattermost versions 10.8.x <= 10.8.3, 10.5.x <= 10.5.8, 9.11.x <= 9.11.17, 10.9.x <= 10.9.2 fail to sanitize the team invite ID in the POST /api/v4/teams/:teamId/restore endpoint which allows an team admin with no member invite privileges to get the team’s invite id.
CVE-2025-47850 1 Jetbrains 1 Youtrack 2026-06-17 N/A 4.3 MEDIUM
In JetBrains YouTrack before 2025.1.74704 restricted attachments could become visible after issue cloning
CVE-2025-47357 1 Qualcomm 48 Qam8255p, Qam8255p Firmware, Qam8620p and 45 more 2026-06-17 N/A 8.0 HIGH
Information Disclosure when a user-level driver performs QFPROM read or write operations on Fuse regions.
CVE-2025-47272 2026-06-17 N/A 5.5 MEDIUM
The CE Phoenix eCommerce platform, starting in version 1.0.9.7 and prior to version 1.1.0.3, allowed logged-in users to delete their accounts without requiring password re-authentication. An attacker with temporary access to an authenticated session (e.g., on a shared/public machine) could permanently delete the user’s account without knowledge of the password. This bypass of re-authentication puts users at risk of account loss and data disruption. Version 1.1.0.3 contains a patch for the issue.
CVE-2025-46275 2026-06-17 N/A 9.8 CRITICAL
WGS-80HPT-V2 and WGS-4215-8T2S are missing authentication that could allow an attacker to create an administrator account without knowing any existing credentials.
CVE-2025-45814 1 Novelsat 4 Ns2000, Ns2000 Firmware, Ns3000 and 1 more 2026-06-17 N/A 9.8 CRITICAL
Missing authentication checks in the query.fcgi endpoint of NS3000 v8.1.1.125110 , v7.2.8.124852 , and v7.x and NS2000 v7.02.08 allows attackers to execute a session hijacking attack.
CVE-2025-44039 1 Cpplusworld 2 Cp-xr-de21-s, Cp-xr-de21-s Firmware 2026-06-17 N/A 5.1 MEDIUM
CP-XR-DE21-S -4G Router Firmware version 1.031.022 was discovered to contain insecure protections for its UART console. This vulnerability allows local attackers to connect to the UART port via a serial connection, read all boot sequence, and revealing internal system details and sensitive information without any authentication.
CVE-2025-44004 1 Mattermost 1 Confluence 2026-06-17 N/A 7.2 HIGH
Mattermost Confluence Plugin version <1.5.0 fails to check the authorization of the user to the Mattermost instance which allows attackers to create a channel subscription without proper authorization via API call to the create channel subscription endpoint.
CVE-2025-43994 1 Dell 1 Storage Manager 2026-06-17 N/A 8.6 HIGH
Dell Storage Center - Dell Storage Manager, version(s) DSM 20.1.21, contain(s) a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure.