Vulnerability index

Browse CVEs

4,327 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
Powerflex Manager HIGH 8.1
CVE-2026-32804

Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) an Improper Authentication vulnerability. An unauthenticated attacker with adjacent n…

Fix: 4.5.5.2 / 5.1.0.1+
Fix from $1,950 2026-06-17
Rocket.chat HIGH 7.5
CVE-2026-48929

Rocket.Chat in versions <8.5.1, <8.4.4, <8.3.6, <8.2.6, <8.1.6, <8.0.7, <7.13.9, and <7.10.13 is vulnerable to unauthenticated file deletion. The del…

Fix: 7.10.13 / 7.13.9+
Fix from $1,950 2026-06-17
Outsourced Manufacturing For Discrete Industries HIGH 8.8
CVE-2026-46972

Vulnerability in the Oracle Outsourced Mfg for Discrete Industries product of Oracle E-Business Suite (component: Internal Operations). Supported ve…

Fix: after 12.2.15
Fix from $1,950 2026-06-17
Outsourced Manufacturing For Discrete Industries HIGH 8.8
CVE-2026-46973

Vulnerability in the Oracle Outsourced Mfg for Discrete Industries product of Oracle E-Business Suite (component: Internal Operations). Supported ve…

Fix: after 12.2.15
Fix from $1,950 2026-06-17
Project Portfolio Analysis HIGH 8.8
CVE-2026-46961

Vulnerability in the Oracle Project Portfolio Analysis product of Oracle E-Business Suite (component: Internal Operations). Supported versions that …

Fix: after 12.2.15
Fix from $1,950 2026-06-17
Project Portfolio Analysis HIGH 8.8
CVE-2026-46962

Vulnerability in the Oracle Project Portfolio Analysis product of Oracle E-Business Suite (component: Internal Operations). Supported versions that …

Fix: after 12.2.15
Fix from $1,950 2026-06-17
Quality HIGH 8.8
CVE-2026-46951

Vulnerability in the Oracle Quality product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12…

Fix: after 12.2.15
Fix from $1,950 2026-06-17
Quality HIGH 8.8
CVE-2026-46952

Vulnerability in the Oracle Quality product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12…

Fix: after 12.2.15
Fix from $1,950 2026-06-17
Isetup HIGH 8.8
CVE-2026-46937

Vulnerability in the Oracle iSetup product of Oracle E-Business Suite (component: General Ledger Update Transform, Reports). Supported versions that…

Fix: after 12.2.15
Fix from $1,950 2026-06-17
Cost Management HIGH 8.8
CVE-2026-46940

Vulnerability in the Oracle Cost Management product of Oracle E-Business Suite (component: Cost Planning). Supported versions that are affected are …

Fix: after 12.2.15
Fix from $1,950 2026-06-17
Process Manufacturing Process Planning HIGH 8.8
CVE-2026-46942

Vulnerability in the Oracle Process Manufacturing Process Planning product of Oracle E-Business Suite (component: Internal Operations). Supported ve…

Fix: after 12.2.15
Fix from $1,950 2026-06-17
Spares Management HIGH 8.8
CVE-2026-46928

Vulnerability in the Oracle Spares Management product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affec…

Fix: after 12.2.15
Fix from $1,950 2026-06-17
Cost Management HIGH 8.8
CVE-2026-46929

Vulnerability in the Oracle Cost Management product of Oracle E-Business Suite (component: Cost Planning). Supported versions that are affected are …

Fix: after 12.2.15
Fix from $1,950 2026-06-17
Process Manufacturing Product Development HIGH 8.8
CVE-2026-46916

Vulnerability in the Oracle Process Manufacturing Product Development product of Oracle E-Business Suite (component: Quality Management Specs). Supp…

Fix: after 12.2.15
Fix from $1,950 2026-06-17
Siebel Crm CRITICAL 9.8
CVE-2026-46919

Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager). Supported versions that are affec…

Fix: after 26.5
Fix from $2,300 2026-06-17
Siebel Crm HIGH 8.8
CVE-2026-46921

Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager). Supported versions that are affec…

Fix: after 26.5
Fix from $1,950 2026-06-17
Jd Edwards Enterpriseone Tools HIGH 8.8
CVE-2026-46903

Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Business Logic Infrastructure Security). Supported vers…

Fix: after 9.2.26.2
Fix from $1,950 2026-06-17
Siebel Apps Marketing CRITICAL 9.8
CVE-2026-46890

Vulnerability in the Siebel Apps - Marketing product of Oracle Siebel CRM (component: Marketing). Supported versions that are affected are 17.0-26.5…

Fix: after 26.5
Fix from $2,300 2026-06-17
Agile Plm CRITICAL 9.8
CVE-2026-46859

Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Security). The supported version that is affected is 9.3.6. Easily…

Mitigation only
Fix from $2,300 2026-06-17
Access Manager MEDIUM 6.5
CVE-2026-35261

Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that are affec…

Mitigation only
Fix from $1,600 2026-06-17
Unclassified HIGH 8.2
CVE-2026-48780

Forem is open source software for building communities. Prior to commit a2ab6d4, a maliciously crafted email address could allow an attacker to bypas…

Patch available
Fix from $1,950 2026-06-16
Unclassified CRITICAL 9.8
CVE-2026-48114

Metacat is data repository software that helps researchers preserve, share, and discover data. Versions 2.0.0 and and above contain an unauthenticate…

Patch available
Fix from $2,300 2026-06-15
Unclassified CRITICAL 9.8
CVE-2026-12183

Nefteprodukttekhnika BUK TS-G Gas Station Automation System 2.9.1 through 2.10.2 on Linux contains an Improper Authentication vulnerability (CWE-287)…

Mitigation only
Fix from $2,300 2026-06-13
Unclassified CRITICAL 9.8
CVE-2026-48611

Improper authentication checks in the OAuth implementation allow account hijacking even when OAuth is not configured or enabled leading to unauthoriz…

Mitigation only
Fix from $2,300 2026-06-12
Unclassified MEDIUM 5.4
CVE-2026-40995

X509AuthenticationProvider could issue a fully authenticated X509AuthenticationToken when a presented certificate mapped to UserDetails, without appl…

Mitigation only
Fix from $1,600 2026-06-11
Imagemagick MEDIUM 5.7
CVE-2026-47166

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-48 and 7.1.2-23, an attacker …

Fix: 6.9.13-48 / 7.1.2-23+
Fix from $1,600 2026-06-10
Unclassified MEDIUM 5.3
CVE-2026-46705

Russh is a Rust SSH client & server library. From version 0.34.0-beta.1 to before version 0.61.0, the russh server authentication path keeps internal…

Mitigation only
Fix from $1,600 2026-06-10
Unclassified HIGH 8.3
CVE-2026-45567

Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, there is an authentication bypa…

Mitigation only
Fix from $1,950 2026-06-10
Spring Security HIGH 8.1
CVE-2026-47838

SubjectDnX509PrincipalExtractor does not correctly handle certain malformed X.509 certificate CN values, which can lead to reading the wrong value fo…

Fix: 5.7.25 / 5.8.27+
Fix from $1,950 2026-06-10
Unclassified CRITICAL 9.1
CVE-2026-36727

An insecure authentication vulnerability in the /api/social-sign-in endpoint of bookcars v8.3 allows attackers to bypass authentication via a forged …

Mitigation only
Fix from $2,300 2026-06-09