Vulnerability index

Browse CVEs

4,327 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
Unclassified HIGH 7.2
CVE-2026-44058

An authentication bypass vulnerability in Netatalk 2.2.2 through 4.4.2 allows a remote privileged user to authenticate as an arbitrary user via the a…

Mitigation only
Fix from $1,950 2026-05-21
Unclassified HIGH 8.7
CVE-2026-40165

authentik is an open-source identity provider. Versions 2025.12.4 and prior, and versions 2026.2.0-rc1 through 2026.2.2 were vulnerable to Authentica…

Patch available
Fix from $1,950 2026-05-21
Arcgis Server MEDIUM 5.3
CVE-2026-2812

ArcGIS Server contains an improper authentication vulnerability in an undocumented administrative endpoint. An unauthenticated attacker could exploit…

Fix: after 12.0
Fix from $1,600 2026-05-20
Unclassified MEDIUM 6.0
CVE-2026-9084

MISP’s OIDC authentication plugin allowed automatic linking of an OIDC identity to an existing local user account based on the email claim when the l…

Patch available
Fix from $1,600 2026-05-20
Unclassified HIGH 8.8
CVE-2026-6456

The Account Switcher plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.0.2. This is due to the `reme…

Mitigation only
Fix from $1,950 2026-05-20
Unclassified CRITICAL 9.8
CVE-2026-36829

An authentication bypass vulnerability exists in the embedded HTTP server of Panabit PAP-XM320 up to and including v7.7. The server validates session…

Mitigation only
Fix from $2,300 2026-05-19
Ofbiz CRITICAL 9.8
CVE-2026-45434EPSS 22%

Improper Authentication vulnerability in Apache OFBiz via Password-Change Logic Flaw Leading to Remote Code Execution This issue affects Apache OFBi…

Fix: 24.09.06+
Fix from $2,300 2026-05-19
Ofbiz MEDIUM 5.3
CVE-2026-31387

Improper Authentication vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade to versio…

Fix: 24.09.06+
Fix from $1,600 2026-05-19
Azure Local CRITICAL 10.0
CVE-2026-42822

Improper authentication in Azure Local Disconnected Operations allows an unauthorized attacker to elevate privileges over a network.

Fix: 2604.2.25645+
Fix from $2,300 2026-05-18
Unclassified MEDIUM 5.3
CVE-2026-8737

A weakness has been identified in Sanluan PublicCMS 5.202506.d. This issue affects the function execute of the file publiccms-trade/src/main/java/com…

Mitigation only
Fix from $1,600 2026-05-17
Open Webui CRITICAL 9.1
CVE-2026-44551

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, the LDAP authentication endpoint d…

Fix: 0.9.0+
Fix from $2,300 2026-05-15
Unclassified CRITICAL 9.8
CVE-2026-5229

The Form Notify plugin for WordPress is vulnerable to Authentication Bypass in versions up to and including 1.1.10. This is due to the plugin trustin…

Patch available
Fix from $2,300 2026-05-15
Unclassified HIGH 8.8
CVE-2026-8621

Crabbox prior to v0.12.0 contains an authentication bypass vulnerability that allows non-admin shared-token callers to impersonate other owners or or…

Patch available
Fix from $1,950 2026-05-14
Catalyst Sd Wan Manager CRITICAL 10.0
CVE-2026-20182 KEVEPSS 92%

May 2026: This security advisory provides the details and fix information for a vulnerability that was discovered and fixed after the was disclosed …

Fix: 20.9.9.1 / 20.12.5.4+
Fix from $2,300 2026-05-14
Unclassified CRITICAL 9.8
CVE-2026-8181EPSS 15%

The Burst Statistics – Privacy-Friendly WordPress Analytics (Google Analytics Alternative) plugin for WordPress is vulnerable to Authentication Bypas…

Mitigation only
Fix from $2,300 2026-05-14
Unclassified HIGH 7.5
CVE-2026-44478

hoppscotch is an open source API development ecosystem. The fix for CVE-2026-28215 in version 2026.2.0 addresses the unauthenticated POST /v1/onboard…

Mitigation only
Fix from $1,950 2026-05-13
Opentelemetry Collector Contrib HIGH 8.1
CVE-2026-42602

azureauthextension is the Azure Authenticator Extension. From 0.124.0 to 0.150.0, a server-side authentication bypass in azureauthextension allows an…

Fix: after 0.150.0
Fix from $1,950 2026-05-13
Unclassified CRITICAL 9.1
CVE-2026-44351

fast-jwt provides fast JSON Web Token (JWT) implementation. Prior to 6.2.4, a critical authentication-bypass vulnerability in fast-jwt's async key-re…

Mitigation only
Fix from $2,300 2026-05-13
Grafana HIGH 7.1
CVE-2026-33377

An Editor can overwrite a dashboard not owned by them to acquire admin on that specific dashboard. The user must have write access to the dashboard t…

Fix: 11.6.14 / 12.2.8+
Fix from $1,950 2026-05-13
Unclassified CRITICAL 9.6
CVE-2026-44547

ChurchCRM is an open-source church management system. From 7.2.0 to 7.2.2, The fix for CVE-2026-4058 is incomplete. The hardening commit was merged a…

Patch available
Fix from $2,300 2026-05-12
Arduino Esp32 HIGH 7.5
CVE-2026-42855

arduino-esp32 is an Arduino core for the ESP32, ESP32-S2, ESP32-S3, ESP32-C3, ESP32-C6 and ESP32-H2 microcontrollers. Prior to 3.3.8, the WebServer D…

Fix: 3.3.8+
Fix from $1,950 2026-05-12
Pocketbase HIGH 7.6
CVE-2026-44166

Pocketbase is an open source web backend written in go. Prior to 0.22.42 and 0.37.4, in some situations, if an attacker knows the email address of th…

Fix: 0.22.42 / 0.37.4+
Fix from $1,950 2026-05-12
Unclassified CRITICAL 9.1
CVE-2026-44196

Pingvin Share X is a secure and easy self-hosted file sharing platform. From 1.14.1 to 1.16.2, a critical authentication bypass vulnerability allows …

Mitigation only
Fix from $2,300 2026-05-12
Azure Sdk For Java CRITICAL 9.1
CVE-2026-33117

The Java Key Vault Keys library in the Azure SDK for Java contains an issue in the local cryptographic verification path where authentication tag com…

Fix: 4.10.6+
Fix from $2,300 2026-05-12
Unclassified HIGH 7.3
CVE-2026-8321

A vulnerability was detected in inkeep agents 0.58.14. This vulnerability affects the function createDevContext of the file agents-api/src/middleware…

Mitigation only
Fix from $1,950 2026-05-11
Unclassified CRITICAL 10.0
CVE-2026-42869

SOCFortress CoPilot focuses on providing a single pane of glass for all your security operations needs. Prior to 0.1.57, SOCFortress CoPilot ships a …

Patch available
Fix from $2,300 2026-05-11
Openclaw CRITICAL 9.8
CVE-2026-8305

A vulnerability was detected in OpenClaw up to 2026.1.24. The impacted element is the function handleBlueBubblesWebhookRequest of the file extensions…

Fix: 2026.2.12+
Fix from $2,300 2026-05-11
Unclassified MEDIUM 5.3
CVE-2026-8244

A vulnerability was identified in Industrial Application Software IAS Canias ERP 8.03. This impacts an unknown function of the component Login RMI In…

Mitigation only
Fix from $1,600 2026-05-10
Unclassified HIGH 7.3
CVE-2026-8216

A vulnerability was identified in Industrial Application Software IAS Canias ERP 8.03. This issue affects the function iasServerRemoteInterface.doAct…

Mitigation only
Fix from $1,950 2026-05-10
Unclassified MEDIUM 5.3
CVE-2026-8214

A vulnerability was found in Industrial Application Software IAS Canias ERP 8.03. This affects the function doAction of the component RMI Interface. …

Mitigation only
Fix from $1,600 2026-05-10