Vulnerability index

Browse CVEs

4,327 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
Freeswitch MEDIUM 5.3
CVE-2026-49843

FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation tha…

Fix: 1.11.1+
Fix from $1,600 2026-06-09
Windows 11 23h2 HIGH 7.8
CVE-2026-44810

Improper authentication in Windows Cryptographic Services allows an unauthorized attacker to elevate privileges locally.

Fix: 10.0.20348.5256 / 10.0.22631.7219+
Fix from $1,950 2026-06-09
Unclassified HIGH 7.4
CVE-2026-41720

Spring LDAP's DirContextAuthenticationStrategy implementations do not reject a bind request where a non-empty username is paired with an empty or nul…

No fix yet
Fix from $1,950 2026-06-09
Unclassified HIGH 7.3
CVE-2026-11618

A vulnerability was determined in DTStack Taier up to 1.4.0. The affected element is the function preHandle of the file taier-data-develop/src/main/j…

Patch available
Fix from $1,950 2026-06-09
Gaia Os CRITICAL 9.3
CVE-2026-50751 KEVEPSS 83%

A logic flow weakness in Remote Access and Mobile Access certificate validation in deprecated IKEv1 key exchange allows an unauthenticated remote att…

Patch available
Fix from $2,300 2026-06-08
Unclassified HIGH 7.0
CVE-2026-34123

On Tapo C520WS v2, restricted accounts (for example, hub users) are intended to execute only a limited set of low‑sensitivity operations. Due to a lo…

Mitigation only
Fix from $1,950 2026-06-06
Uds Identity Config CRITICAL 9.8
CVE-2026-46389

UDS Identity Config builds the Keycloak configuration image (realm, plugins, theme, truststore, JARs) consumed by UDS Core's Identity deployment. In …

Fix: 0.26.1+
Fix from $2,300 2026-06-05
Unclassified MEDIUM 6.9
CVE-2026-11345

An Improper Authentication vulnerability in the /api/Cdn/GetFile endpoint of linqi allows unauthenticated, remote attackers to bypass file access con…

Mitigation only
Fix from $1,600 2026-06-05
Unclassified CRITICAL 9.8
CVE-2026-6274

Improper Authentication, Missing authentication for critical function, Weak Authentication vulnerability in DTS Electronics Industry and Trade Ltd. C…

Mitigation only
Fix from $2,300 2026-06-05
Unclassified MEDIUM 5.9
CVE-2023-5502

On affected platforms running Arista EOS with 802.1x authentication configured on the access/trunk ports, and routing enabled on the access VLAN of t…

Mitigation only
Fix from $1,600 2026-06-04
Connect M6e 5g Firmware CRITICAL 9.8
CVE-2026-49191

The production build of the M3WebServer hard-codes its backend API keys, which can be easily intercepted through verbose error handling pages.

Mitigation only
Fix from $2,300 2026-06-04
Connect M6e 5g Firmware HIGH 8.8
CVE-2026-49194

The debugging routine SCREEN_CLICK(5053) enables a connection to skip the standard device login prompt entirely and directly enter an interactive she…

Mitigation only
Fix from $1,950 2026-06-04
Connect M6e 5g Firmware HIGH 8.6
CVE-2026-49202

Internal multimedia session archives are accessible without authentication, exacerbated by loose Cross-Origin Resource Sharing (CORS) rules that allo…

Mitigation only
Fix from $1,950 2026-06-04
Connect M6e 5g Firmware HIGH 8.3
CVE-2026-49203

Crucial management API endpoints for cellular eSIM allocation do not validate caller authorization, allowing remote profiles to be rewritten or delet…

Mitigation only
Fix from $1,950 2026-06-04
Connect M6e 5g Firmware CRITICAL 9.8
CVE-2026-49186

The local MQTT broker does not enforce topic-level Access Control Lists (ACLs). This allows any client to subscribe using wildcard characters (# or +…

Mitigation only
Fix from $2,300 2026-06-04
Unclassified HIGH 7.3
CVE-2026-10777

A vulnerability was identified in ealpha072 Student-Management-System up to 01451bd7a2f58cdda07bd0b86e3967582e3ecd08. Affected by this issue is some …

Mitigation only
Fix from $1,950 2026-06-03
Authentik HIGH 8.8
CVE-2026-49443

authentik is an open-source identity provider. Prior to versions 2025.12.6, 2026.2.4, and 2026.5.1, an attacker with the ability to change a source c…

Fix: 2025.12.6 / 2026.2.4+
Fix from $1,950 2026-06-02
Authentik CRITICAL 9.8
CVE-2026-49448

authentik is an open-source identity provider. Prior to versions 2025.12.6, 2026.2.4, and 2026.5.1, the Source stage can be bypassed by sending an em…

Fix: 2025.12.6 / 2026.2.4+
Fix from $2,300 2026-06-02
Unclassified MEDIUM 5.3
CVE-2026-45289

CloudburstMC Protocol is a protocol library for Minecraft Bedrock Edition. Prior to version 3.0.0.Beta12-20260420.182526-15, CloudburstMC Protocol is…

Mitigation only
Fix from $1,600 2026-06-02
Unclassified HIGH 7.3
CVE-2026-10619

A vulnerability was detected in sayan365 student-management-system up to 7f3c9ce7d410332335c2affac93a385485051800. This impacts an unknown function. …

Mitigation only
Fix from $1,950 2026-06-02
Unclassified CRITICAL 9.8
CVE-2026-5076

The ARMember Premium plugin for WordPress is vulnerable to an insecure password reset mechanism in all versions up to, and including, 7.3.1. The plug…

Mitigation only
Fix from $2,300 2026-06-02
Unclassified HIGH 7.3
CVE-2026-10617

A security vulnerability has been detected in nextlevelbuilder GoClaw up to 3.11.3. This affects the function resolveAuth of the file internal/http/a…

Mitigation only
Fix from $1,950 2026-06-02
Misp CRITICAL 10.0
CVE-2026-10611

An authentication bypass vulnerability exists in MISP when LDAP mixed authentication is enabled with OTP enforcement. In deployments configured with …

Fix: 2.5.39+
Fix from $2,300 2026-06-02
Unclassified HIGH 7.5
CVE-2026-8293

The Really Simple Security WordPress plugin before 9.5.10.1 does not enforce the second-factor challenge in two of its two-factor authentication RES…

Mitigation only
Fix from $1,950 2026-06-02
Unclassified MEDIUM 5.3
CVE-2026-10548

A security flaw has been discovered in NousResearch hermes-agent up to 2026.4.23. This affects the function _sync_anthropic_entry_from_credentials_fi…

Mitigation only
Fix from $1,600 2026-06-02
Unclassified HIGH 7.5
CVE-2026-40964

Authentication Bypass in cf-auth-proxy in Cloud Foundry Foundation all installations allows an unauthenticated remote attacker to gain read access to…

Mitigation only
Fix from $1,950 2026-06-01
Unclassified HIGH 7.3
CVE-2026-10288

A vulnerability was identified in code-projects Hotel and Tourism Reservation System 1.0. This issue affects the function password_verify of the file…

Mitigation only
Fix from $1,950 2026-06-01
Nextcloud Server MEDIUM 5.9
CVE-2026-45690

Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 32.0.0 to before 32.0.9, and 33.0.0 to before 33.0.3, a…

Fix: 29.0.16.16 / 30.0.17.9+
Fix from $1,600 2026-06-01
Nextcloud Server MEDIUM 5.9
CVE-2026-45691

Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 32.0.0 to before 32.0.9, and 33.0.0 to before 33.0.3, a…

Fix: 29.0.16.16 / 30.0.17.9+
Fix from $1,600 2026-06-01
Unclassified HIGH 7.3
CVE-2026-10281

A weakness has been identified in Enderfga claw-orchestrator up to 3.5.5. This affects the function EmbeddedServer of the file src/embedded-server.ts…

Patch available
Fix from $1,950 2026-06-01