Vulnerability index

Browse CVEs

4,327 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
Unclassified HIGH 7.6
CVE-2026-53958

4gaBoards is a boards system for realtime project management. Prior to 3.3.9, 4gaBoards allows an authenticated user to modify ssoGoogleId, ssoGoogle…

Fix unknown
Fix from $4,900 2026-08-18
Unclassified HIGH 8.8
CVE-2026-50191

4gaBoards is a boards system for realtime project management. Prior to 3.3.8, 4gaBoards is vulnerable to pre-account takeover when registrationEnable…

Fix unknown
Fix from $4,900 2026-08-18
Unclassified HIGH 8.7
CVE-2026-15315

Tapo C200 v5 contains an improper authentication vulnerability within the login authentication verification module. An attacker on the local network …

Fix unknown
Fix from $4,900 2026-08-18
Unclassified HIGH 8.1
CVE-2026-52793

Froxlor is open source server administration software. Prior to 2.3.7, the API authentication path in lib/Froxlor/Api/FroxlorRPC.php and FroxlorRPC::…

Fix unknown
Fix from $4,900 2026-08-18
Unclassified HIGH 8.1
CVE-2026-44472

Saleor is an e-commerce platform. From 2.10.0rc1 until 3.21.67, 3.22.63, and 3.23.22, the account activation flow treats email verification as suffic…

Fix unknown
Fix from $4,900 2026-08-18
Unclassified HIGH 8.2
CVE-2026-73337

Joomla! Core - [20260807] - MFA Authentication Bypass in Joomla 4.0.0-5.4.7 and 6.0.0-6.1.2 - Insufficient state checks lead to a vector that allows …

Fix unknown
Fix from $4,900 2026-08-18
Ipados MEDIUM 5.9
CVE-2026-65329

An authentication issue was addressed with improved state management. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1. An attacker in a privilege…

Fix unknown
Fix from $4,000 2026-08-17
Unclassified HIGH 7.7
CVE-2025-27621

UpTrain is an open-source platform to evaluate and improve generative AI applications. In version 0.7.1 and prior, the UpTrain backend creates a new …

Fix unknown
Fix from $4,900 2026-08-17
Unclassified CRITICAL 9.8
CVE-2026-74894

openssl_encrypt before 1.4.0 contains an authentication bypass vulnerability in the verify_api_token function that accepts any non-empty Bearer token…

Fix unknown
Fix from $5,750 2026-08-17
Unclassified CRITICAL 10.0
CVE-2026-19977

A vulnerability was detected in EFM ipTIME A3004T 14.19.0. The affected element is the function httpcon_check_session_url of the component Session Va…

Fix unknown
Fix from $5,750 2026-08-17
Unclassified MEDIUM 5.6
CVE-2026-19974

A security flaw has been discovered in treefrogframework treefrog-framework up to 2.11.2. This vulnerability affects the function std::strncmp of the…

Fix unknown
Fix from $4,000 2026-08-17
Unclassified CRITICAL 9.1
CVE-2026-19714

The Simple JWT Login WordPress plugin before 3.6.8 does not validate the audience of the Google identity tokens it accepts, allowing unauthenticated…

Fix unknown
Fix from $5,750 2026-08-16
Unclassified MEDIUM 5.7
CVE-2026-15384

The Manual Image Crop WordPress plugin before 1.15 does not perform any capability check or nonce verification on the authenticated AJAX action that …

Fix unknown
Fix from $4,000 2026-08-16
Unclassified CRITICAL 9.8
CVE-2026-19924

A security vulnerability has been detected in Tenda AC10 16.03.10.09_multi_TDE01. This vulnerability affects the function R7WebsSecurityHandler of th…

No fix yet
Fix from $5,750 2026-08-16
Unclassified HIGH 7.5
CVE-2026-73054

SiYuan versions before v3.7.4 contain an authentication bypass vulnerability in the WebSocket endpoint caused by differential parsing of query parame…

No fix yet
Fix from $4,900 2026-08-15
Unclassified MEDIUM 6.5
CVE-2026-18216

The Backup Migration WordPress plugin before 2.1.7 does not properly restrict a post-restore automatic login mechanism, allowing a user who administe…

Fix unknown
Fix from $4,000 2026-08-15
Unclassified CRITICAL 9.8
CVE-2026-15303

The 6Storage Rentals plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.27.0. This is due to the six_sto…

No fix yet
Fix from $5,750 2026-08-15
Unclassified CRITICAL 9.8
CVE-2026-15341

The User Session Synchronizer plugin for WordPress is vulnerable to Authentication Bypass leading to Account Takeover in all versions up to, and incl…

No fix yet
Fix from $5,750 2026-08-15
Unclassified MEDIUM 5.4
CVE-2026-74240

A flaw was found in Red Hat Quay's JWT (JSON Web Token) validation for federated robot accounts and single sign-on (SSO) authentication. Multiple iss…

No fix yet
Fix from $4,000 2026-08-14
Unclassified HIGH 7.5
CVE-2026-17175

IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to obtain sensitive information due to improper authentication enf…

No fix yet
Fix from $4,900 2026-08-14
Unclassified CRITICAL 9.8
CVE-2026-17182

IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to bypass authentication and obtain or alter sensitive information due to improp…

No fix yet
Fix from $5,750 2026-08-14
Unclassified MEDIUM 5.3
CVE-2026-16905

IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to obtain sensitive information due to improper authentication.

No fix yet
Fix from $4,000 2026-08-14
Unclassified CRITICAL 9.8
CVE-2026-48528

Metacat is data repository software that helps researchers preserve, share, and discover data. Metacat versions 2.0.0 through 3.4.0 contain an unauth…

No fix yet
Fix from $5,750 2026-08-14
Unclassified MEDIUM 5.9
CVE-2026-16739

The Epeken All Kurir for Woocommerce WordPress plugin through 2.1.2 does not verify that a payment-confirmation request originates from the owner of …

No fix yet
Fix from $4,000 2026-08-14
Unclassified MEDIUM 5.3
CVE-2026-73840

OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.0.3, 1.1.3, and 1.2.0-rc.2, the POST /api/v1alpha1/autobuild endp…

No fix yet
Fix from $4,000 2026-08-13
Unclassified CRITICAL 9.0
CVE-2026-73302

Budibase is an open-source low-code platform. Prior to 3.39.30, the OIDC flow in packages/backend-core/src/middleware/passport/sso/oidc.ts resolved a…

No fix yet
Fix from $5,750 2026-08-13
Unclassified HIGH 7.3
CVE-2026-17099

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to obtain sensitive information due to improper authentication.

No fix yet
Fix from $4,900 2026-08-13
Unclassified HIGH 8.3
CVE-2026-17101

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to execute arbitrary code or obtain sensitive information due to improper authentication.

No fix yet
Fix from $4,900 2026-08-13
Unclassified MEDIUM 6.5
CVE-2026-17075

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to obtain sensitive information and perform unauthorized operations due to improper valida…

No fix yet
Fix from $4,000 2026-08-13
Unclassified HIGH 7.4
CVE-2026-73655

Trigger.dev is a platform for building and deploying fully managed AI agents and workflows. Prior to 4.5.2, addGoogleStrategy() in apps/webapp/app/se…

No fix yet
Fix from $4,900 2026-08-13