Vulnerability index

Browse CVEs

4,327 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
Unclassified MEDIUM 6.3
CVE-2026-10283

A vulnerability was detected in Bottelet DaybydayCRM up to 2.2.1. Affected is an unknown function of the component Setting Handler. Performing a mani…

Patch available
Fix from $1,600 2026-06-01
Unclassified HIGH 8.1
CVE-2026-45156

Nextcloud is an open source content collaboration platform. From versions 0.3.0 to before 3.1.0, 5.0.0 to before 5.1.0, and 6.0.0 to before 6.4.0, a …

Patch available
Fix from $1,950 2026-06-01
Unclassified HIGH 7.3
CVE-2026-10243

A security vulnerability has been detected in code-projects Smart Parking System 1.0. Affected is an unknown function of the component Admin Endpoint…

Mitigation only
Fix from $1,950 2026-06-01
Unclassified HIGH 7.3
CVE-2026-10167

A weakness has been identified in OUSL-GROUP-BrinaryBrains School Student Management System up to 1e70e5ad1125b86dca4ee086eb6bb121f17708b6. This impa…

Mitigation only
Fix from $1,950 2026-05-31
Unclassified HIGH 7.3
CVE-2026-10157

A vulnerability was identified in Open5GS up to 2.7.6. This impacts an unknown function of the file src/amf/ngap-handler.c of the component NGAP Path…

Patch available
Fix from $1,950 2026-05-31
Openshift Container Platform HIGH 7.5
CVE-2026-46579

A flaw was found in the OpenShift Router. When a Route has `insecureEdgeTerminationPolicy` set to Allow, the HTTP frontend does not remove `X-SSL-Cli…

Mitigation only
Fix from $1,950 2026-05-29
Predator Connect W6x Firmware CRITICAL 9.8
CVE-2026-49197

Web endpoints intended for the Acer Connect app improperly validate the HTTP Authorization header, failing to block requests when Base64 decoding fai…

Mitigation only
Fix from $2,300 2026-05-29
Unclassified CRITICAL 9.8
CVE-2026-3655

The OTP Login With Phone Number, OTP Verification plugin for WordPress is vulnerable to authentication bypass in versions 1.8.50 through 1.8.60. This…

Mitigation only
Fix from $2,300 2026-05-29
Rest Data Services CRITICAL 10.0
CVE-2026-46840

Vulnerability in Oracle REST Data Services (component: Backend-as-a-Service). Supported versions that are affected are 24.2.0-26.1.0. Easily exploit…

Fix: after 26.1.0
Fix from $2,300 2026-05-28
E Business Suite HIGH 8.8
CVE-2026-46827

Vulnerability in the Oracle Payroll product of Oracle E-Business Suite (component: Self Service Manager). Supported versions that are affected are 1…

Fix: after 12.2.15
Fix from $1,950 2026-05-28
E Business Suite CRITICAL 9.8
CVE-2026-46817 KEVEPSS 13%

Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affected are 12.…

Fix: after 12.2.15
Fix from $2,300 2026-05-28
Pyjwt HIGH 7.4
CVE-2026-48526

PyJWT is a JSON Web Token implementation in Python. Prior to 2.13.0, when the verifier is decoding JSON Web Tokens, while supporting both asymmetric …

Fix: 2.13.0+
Fix from $1,950 2026-05-28
Unclassified CRITICAL 9.3
CVE-2026-8979

The Mennekes Amtron series (firmware versions ≤ 5.22.3) is vulnerable to an authentication bypass. An unauthenticated remote attacker can change the …

Mitigation only
Fix from $2,300 2026-05-28
Unclassified MEDIUM 6.9
CVE-2026-44720

OpenLearnX is an open-source, decentralized learning and assessment platform. Prior to 2.0.4, a critical authentication vulnerability was identified …

Mitigation only
Fix from $1,600 2026-05-27
Unclassified HIGH 7.9
CVE-2026-44711

pam_usb provides hardware authentication for Linux using ordinary removable media. Prior to 0.8.7, symlink attacks on pad directory and pad files ena…

Mitigation only
Fix from $1,950 2026-05-27
Unclassified HIGH 7.1
CVE-2026-47272

pam_usb provides hardware authentication for Linux using ordinary removable media. Prior to 0.9.0, the pusb_pad_compare() function in src/pad.c only …

Mitigation only
Fix from $1,950 2026-05-27
Unclassified HIGH 7.4
CVE-2026-44460

FileRise is a self-hosted web-based file manager with multi-file upload, editing, and batch operations. Prior to 3.12.0, /api/totp_setup.php is calla…

Mitigation only
Fix from $1,950 2026-05-27
Unclassified MEDIUM 5.5
CVE-2025-68712

SpSoft AppLock (com.sp.protector.free) 7.9.40 for Android allows a local attacker with physical access to bypass fingerprint or PIN authentication. A…

Mitigation only
Fix from $1,600 2026-05-27
Aspera High Speed Transfer Server For Cloud Pak For Integration CRITICAL 9.1
CVE-2026-7876

IBM Aspera HSTS for CP4I 1.5.1 through 1.5.19 is affected by an authentication bypass vulnerability. A transfer client may be able to take advantage …

Fix: 1.5.20+
Fix from $2,300 2026-05-27
Unclassified HIGH 8.1
CVE-2026-8994

The Login with NEAR plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 0.3.3. The `ajaxLoginWithNear()…

Mitigation only
Fix from $1,950 2026-05-27
Unclassified HIGH 7.5
CVE-2026-44847

MaxKB is an open-source AI assistant for enterprise. Prior to 2.9.0, MaxKB's webhook trigger endpoint (/api/trigger/v1/webhook/{trigger_id}) is acces…

Mitigation only
Fix from $1,950 2026-05-26
Unclassified CRITICAL 9.3
CVE-2026-47202

Kavita is a cross platform reading server. Prior to 0.9.0.2, an Improper Token validation flaw permits a remote and unauthenticated threat actor to r…

Mitigation only
Fix from $2,300 2026-05-26
Unclassified MEDIUM 6.8
CVE-2026-44707

Chatwoot is a customer engagement suite. From 2.14.0 to before 4.13.0, a Pre-Account Takeover (Pre-ATO) vulnerability existed in Chatwoot's authentic…

Patch available
Fix from $1,600 2026-05-26
Joomla\! HIGH 7.5
CVE-2026-48896

Insufficient state checks lead to a vector that allows to bypass 2FA checks.

Fix: 5.4.6 / 6.1.1+
Fix from $1,950 2026-05-26
Joomla\! HIGH 7.5
CVE-2026-48897

Insufficient state checks lead to a vector that allows to bypass 2FA checks.

Fix: 5.4.6 / 6.1.1+
Fix from $1,950 2026-05-26
Unclassified MEDIUM 5.6
CVE-2026-9371

A security vulnerability has been detected in ItzCrazyKns Vane up to 1.12.1. Affected by this issue is some unknown functionality of the file route.t…

Mitigation only
Fix from $1,600 2026-05-24
Azure Resource Manager CRITICAL 9.8
CVE-2026-47280

Improper authentication in Azure Resource Manager (ARM) allows an unauthorized attacker to elevate privileges over a network.

No fix yet
Fix from $2,300 2026-05-22
Unclassified HIGH 8.1
CVE-2026-41076

RT is an open source, enterprise-grade issue and ticket tracking system. Versions 5.0.9 and prior in addition to 6.0.0 through 6.0.2 contain an authe…

No fix yet
Fix from $1,950 2026-05-22
Unclassified MEDIUM 6.5
CVE-2026-39969

TypeBot is a chatbot builder tool. In versions 3.16.0 and prior, the WhatsApp Cloud API webhook endpoint (POST /v1/workspaces/{workspaceId}/whatsapp/…

Mitigation only
Fix from $1,600 2026-05-22
Sunshine CRITICAL 9.8
CVE-2026-32253

Sunshine is a self-hosted game stream host for Moonlight. In versions prior to 2026.516.143833, the client-certificate authentication can be bypassed…

Fix: 2026.516.143833+
Fix from $2,300 2026-05-22