Vulnerability index

Browse CVEs

4,327 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
Unclassified HIGH 7.3
CVE-2026-13546

A vulnerability was found in Feehi CMS up to 2.1.1. This vulnerability affects unknown code of the file /api/articles of the component REST API Endpo…

Mitigation only
Fix from $1,950 2026-06-29
Unclassified MEDIUM 5.6
CVE-2026-13543

A vulnerability was detected in Documenso up to 2.11.0. Affected by this vulnerability is an unknown functionality of the file packages/auth/server/l…

Patch available
Fix from $1,600 2026-06-29
Kestra CRITICAL 10.0
CVE-2026-49869

Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.45 and 1.3.21, AuthenticationFilter in Kestra OSS uses request.getPath().…

Fix: 1.0.45 / 1.3.21+
Fix from $2,300 2026-06-26
Wolfssl MEDIUM 6.5
CVE-2026-55962

TLS 1.3 post-handshake authentication (PHA) issue where a server could accept a client's Finished message without the client having sent a Certificat…

Fix: 5.9.2+
Fix from $1,600 2026-06-25
Wolfssl HIGH 7.5
CVE-2026-11703

Missing SNI/ALPN binding on stateful (session-ID) resumption, which previously skipped the binding check performed for ticket-based resumption. A cac…

Fix: 5.9.2+
Fix from $1,950 2026-06-25
Unclassified CRITICAL 9.1
CVE-2026-54089

File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Starting wit…

Mitigation only
Fix from $2,300 2026-06-25
Unclassified CRITICAL 9.3
CVE-2026-55666

Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.1, 8.4.4, 8.3.6, 8.2.6, 8.1.6, 8.0.7, and 7.10.13, in…

Mitigation only
Fix from $2,300 2026-06-24
Unclassified HIGH 7.4
CVE-2026-55759

Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.1, 8.4.4, 8.3.6, 8.2.6, 8.1.6, 8.0.7, and 7.10.13, Ro…

Mitigation only
Fix from $1,950 2026-06-24
Kubevirt MEDIUM 6.5
CVE-2026-13208

A flaw was found in KubeVirt's virt-handler domain notify server. The gRPC handlers for HandleDomainEvent and HandleK8SEvent derive the VMI identity …

Fix: after 4.22.0
Fix from $1,600 2026-06-24
Unclassified HIGH 8.7
CVE-2026-56223

Capgo before 12.128.2 contains a cross-domain SSO account takeover vulnerability in the provision-user endpoint that allows attackers to merge arbitr…

Mitigation only
Fix from $1,950 2026-06-24
Unclassified CRITICAL 9.1
CVE-2026-56237

Capgo before 12.128.2 contains a broken authentication vulnerability in its API key generation mechanism. API keys are exposed in frontend requests, …

Mitigation only
Fix from $2,300 2026-06-24
Satellite HIGH 7.8
CVE-2026-12112

A flaw was found in the foreman-mcp-server. A session management vulnerability in the MCP Server allows unauthenticated attackers to hijack active ad…

Mitigation only
Fix from $1,950 2026-06-23
Unclassified HIGH 8.4
CVE-2026-54320

Daytona is a secure and elastic infrastructure runtime for AI-generated code execution and agent workflows. Prior to 0.184.0, organization invitation…

Mitigation only
Fix from $1,950 2026-06-23
Caddy HIGH 8.1
CVE-2026-52845

Caddy is an extensible server platform that uses TLS by default. Prior to 2.11.4, forward_auth copy_headers deletes the exact client-supplied identit…

Fix: 2.11.4+
Fix from $1,950 2026-06-23
Unclassified CRITICAL 9.0
CVE-2026-11374

In ManageEngine ADSelfService Plus, RecoveryManager Plus, M365 Manager Plus, and ADAudit Plus, the SSO tickets generated to authenticate that session…

Mitigation only
Fix from $2,300 2026-06-23
Langflow CRITICAL 9.8
CVE-2026-7664

IBM Langflow OSS 1.0.0 through 1.8.4 could allow unauthenticated attackers to access protected MCP project resources and execute MCP operations due t…

Fix: after 1.8.4
Fix from $2,300 2026-06-22
Websphere Application Server HIGH 7.3
CVE-2026-10845

IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to bypass authentication and gain unauthorized access to JAX-WS applicatio…

Fix: 8.5.5.30 / 9.0.5.29+
Fix from $1,950 2026-06-22
Litellm HIGH 7.3
CVE-2026-12795

A vulnerability was determined in BerriAI litellm up to 1.82.2. This affects the function json.dumps of the file litellm/proxy/management_endpoints/u…

Fix: after 1.82.2
Fix from $1,950 2026-06-21
Litellm CRITICAL 9.8
CVE-2026-12773

A weakness has been identified in BerriAI litellm up to 1.59.8. Affected is the function UserAPIKeyAuth of the file litellm/proxy/_experimental/mcp_s…

Fix: 1.59.9+
Fix from $2,300 2026-06-21
Unclassified HIGH 8.1
CVE-2026-56345

AVideo through 29.0 contains an authorization bypass vulnerability in the Meet plugin's uploadRecordedVideo.json.php endpoint that derives the target…

Mitigation only
Fix from $1,950 2026-06-20
Quarkus HIGH 7.5
CVE-2026-50559

Quarkus is a Java framework for building cloud-native applications. Prior to versions 3.37.0, 3.36.3, 3.33.2.1, 3.33.3, 3.27.4.1, 3.27.5, and 3.20.6.…

Fix: 3.20.6.2 / 3.27.4.1+
Fix from $1,950 2026-06-19
Azure Active Directory CRITICAL 10.0
CVE-2026-45480

Improper authentication in Azure Active Directory allows an unauthorized attacker to elevate privileges over a network.

No fix yet
Fix from $2,300 2026-06-19
Apisix HIGH 8.1
CVE-2026-49872

Improper Authentication vulnerability in Apache APISIX. When the cas-auth plugin is used in a route, an attacker can possibly authenticate itself wi…

Fix: 3.17.0+
Fix from $1,950 2026-06-19
Azure Ai Bot Service HIGH 8.8
CVE-2026-32174

Improper authentication in Azure Bot Service allows an authorized attacker to elevate privileges over a network.

Mitigation only
Fix from $1,950 2026-06-18
Unclassified CRITICAL 9.1
CVE-2026-49454

Relyra is a strict-by-default SAML 2.0 Service Provider library for Elixir and Phoenix. Versions 1.0.0 and 1.1.0 accept forged SAML signatures becaus…

Patch available
Fix from $2,300 2026-06-18
Mcp Toolbox For Databases CRITICAL 9.1
CVE-2026-11717

An authentication bypass vulnerability exists in the generic opaque token validation path (validateOpaqueToken) of googleapis/mcp-toolbox. When veri…

Patch available
Fix from $2,300 2026-06-18
Mcp Toolbox For Databases CRITICAL 9.1
CVE-2026-11718

An authentication bypass vulnerability exists in the generic opaque token validation path (validateOpaqueToken) of googleapis/mcp-toolbox. When the …

Patch available
Fix from $2,300 2026-06-18
Unclassified MEDIUM 5.5
CVE-2026-48991

XianYuLauncher is a Minecraft Java Edition launcher. In versions prior to 1.5.5, sensitive authentication artifacts could be exposed during a user-in…

Patch available
Fix from $1,600 2026-06-17
Powerflex Manager HIGH 8.1
CVE-2026-49502

Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) an Improper Authentication vulnerability. An unauthenticated attacker with adjacent n…

Fix: 4.5.5.2 / 5.1.0.1+
Fix from $1,950 2026-06-17
Unclassified MEDIUM 6.8
CVE-2026-48117

DroneAware is a drone detection platform. The centralized DroneAware server backing droneaware.io was vulnerable to an account pre-hijacking attack i…

Mitigation only
Fix from $1,600 2026-06-17