Vulnerability index

Browse CVEs

4,337 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
Arduino Esp32 HIGH 7.5
CVE-2026-42855

arduino-esp32 is an Arduino core for the ESP32, ESP32-S2, ESP32-S3, ESP32-C3, ESP32-C6 and ESP32-H2 microcontrollers. Prior to 3.3.8, the WebServer D…

Fix: 3.3.8+
Fix from $1,950 2026-05-12
Pocketbase HIGH 7.6
CVE-2026-44166

Pocketbase is an open source web backend written in go. Prior to 0.22.42 and 0.37.4, in some situations, if an attacker knows the email address of th…

Fix: 0.22.42 / 0.37.4+
Fix from $1,950 2026-05-12
Unclassified CRITICAL 9.1
CVE-2026-44196

Pingvin Share X is a secure and easy self-hosted file sharing platform. From 1.14.1 to 1.16.2, a critical authentication bypass vulnerability allows …

Mitigation only
Fix from $2,300 2026-05-12
Azure Sdk For Java CRITICAL 9.1
CVE-2026-33117

The Java Key Vault Keys library in the Azure SDK for Java contains an issue in the local cryptographic verification path where authentication tag com…

Fix: 4.10.6+
Fix from $2,300 2026-05-12
Unclassified HIGH 7.3
CVE-2026-8321

A vulnerability was detected in inkeep agents 0.58.14. This vulnerability affects the function createDevContext of the file agents-api/src/middleware…

Mitigation only
Fix from $1,950 2026-05-11
Unclassified CRITICAL 10.0
CVE-2026-42869

SOCFortress CoPilot focuses on providing a single pane of glass for all your security operations needs. Prior to 0.1.57, SOCFortress CoPilot ships a …

Patch available
Fix from $2,300 2026-05-11
Openclaw CRITICAL 9.8
CVE-2026-8305

A vulnerability was detected in OpenClaw up to 2026.1.24. The impacted element is the function handleBlueBubblesWebhookRequest of the file extensions…

Fix: 2026.2.12+
Fix from $2,300 2026-05-11
Unclassified MEDIUM 5.3
CVE-2026-8244

A vulnerability was identified in Industrial Application Software IAS Canias ERP 8.03. This impacts an unknown function of the component Login RMI In…

Mitigation only
Fix from $1,600 2026-05-10
Unclassified HIGH 7.3
CVE-2026-8216

A vulnerability was identified in Industrial Application Software IAS Canias ERP 8.03. This issue affects the function iasServerRemoteInterface.doAct…

Mitigation only
Fix from $1,950 2026-05-10
Unclassified MEDIUM 5.3
CVE-2026-8214

A vulnerability was found in Industrial Application Software IAS Canias ERP 8.03. This affects the function doAction of the component RMI Interface. …

Mitigation only
Fix from $1,600 2026-05-10
Unclassified MEDIUM 6.3
CVE-2026-8185

A security vulnerability has been detected in UGREEN CM933 1.1.59.4319. The impacted element is an unknown function of the component Administrative I…

Mitigation only
Fix from $1,600 2026-05-09
Unclassified CRITICAL 9.1
CVE-2026-42560

auth provides authentication via oauth2, direct and email. From versions 1.18.0 to before 1.25.2 and 2.0.0 to before 2.1.2, the Patreon OAuth provide…

Patch available
Fix from $2,300 2026-05-09
Unclassified CRITICAL 10.0
CVE-2026-41070

openvpn-auth-oauth2 is a plugin/management interface client for OpenVPN server to handle an OIDC based single sign-on (SSO) auth flows. From version …

Patch available
Fix from $2,300 2026-05-08
Nhost\/auth CRITICAL 9.8
CVE-2026-41574

Nhost is an open source Firebase alternative with GraphQL. Prior to version 0.49.1, Nhost automatically links an incoming OAuth identity to an existi…

Fix: 0.49.1+
Fix from $2,300 2026-05-08
Unclassified MEDIUM 6.8
CVE-2026-41671

Admidio is an open-source user management solution. Prior to version 5.0.9, the OIDC token introspection endpoint (/modules/sso/index.php/oidc/intros…

Mitigation only
Fix from $1,600 2026-05-07
Unclassified MEDIUM 5.3
CVE-2026-8031

A vulnerability was detected in PicoTronica e-Clinic Healthcare System ECHS 5.7. The affected element is an unknown function of the file /cdemos/echs…

Mitigation only
Fix from $1,600 2026-05-06
Coredns CRITICAL 9.8
CVE-2026-35579

CoreDNS is a DNS server written in Go. In versions prior to 1.14.3, the gRPC, QUIC, DoH, and DoH3 transport implementations incorrectly handle TSIG a…

Fix: 1.14.3+
Fix from $2,300 2026-05-05
Opencti CRITICAL 9.8
CVE-2026-27960

OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. In versions 6.6.0 through 6.9.12, there is a pri…

Fix: 6.9.13+
Fix from $2,300 2026-05-05
Unclassified MEDIUM 6.3
CVE-2026-7844

A vulnerability was detected in chatchat-space Langchain-Chatchat up to 0.3.1.3. This vulnerability affects the function files/list_files/retrieve_fi…

Mitigation only
Fix from $1,600 2026-05-05
Unclassified CRITICAL 9.8
CVE-2026-5722

The MoreConvert Pro plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.9.14. This is due to the gues…

Mitigation only
Fix from $2,300 2026-05-05
Unclassified CRITICAL 9.4
CVE-2026-41571

Note Mark is an open-source note-taking application. In version 0.19.2, IsPasswordMatch in backend/db/models.go falls back to a hard-coded bcrypt("nu…

Mitigation only
Fix from $2,300 2026-05-04
Unclassified HIGH 7.3
CVE-2026-7723

A flaw has been found in PrefectHQ prefect up to 3.6.13. Affected is an unknown function of the file /api/events/in of the component WebSocket Endpoi…

Patch available
Fix from $1,950 2026-05-04
Unclassified MEDIUM 5.3
CVE-2026-7722

A vulnerability was detected in PrefectHQ prefect up to 3.6.21. This impacts the function endswith of the file /api/health of the component Health Ch…

Patch available
Fix from $1,600 2026-05-04
Unclassified MEDIUM 6.5
CVE-2026-7714

A flaw has been found in crocodilestick Calibre-Web-Automated up to 4.0.6. Affected by this issue is some unknown functionality of the file cps/cwa_f…

Patch available
Fix from $1,600 2026-05-04
Unclassified HIGH 7.3
CVE-2026-7710

A security flaw has been discovered in YunaiV yudao-cloud up to 3.8.0. This affects the function doFilterInternal of the file JwtAuthenticationTokenF…

Mitigation only
Fix from $1,950 2026-05-04
Unclassified HIGH 7.3
CVE-2026-7679

A security flaw has been discovered in YunaiV yudao-cloud up to 2026.01. This impacts the function getAccessToken of the file yudao-module-system-biz…

Mitigation only
Fix from $1,950 2026-05-03
Unclassified HIGH 7.3
CVE-2026-7630

A vulnerability has been found in innocommerce InnoShop up to 0.7.8. The affected element is the function InstallServiceProvider::boot of the file in…

Patch available
Fix from $1,950 2026-05-02
Mipc252w Firmware CRITICAL 9.8
CVE-2026-35903

MERCURY MIPC252W IP camera 1.0.5 Build 230306 Rel.79931n contains an improper authentication vulnerability in the RTSP service. After successful Dige…

Mitigation only
Fix from $2,300 2026-04-27
Storm MEDIUM 6.5
CVE-2026-41081

Improper Handling of TLS Client Authentication Failure Leading to Anonymous Principal Assignment in Apache Storm Versions Affected: up to 2.8.7 Des…

Fix: 2.8.7+
Fix from $1,600 2026-04-27
Unclassified MEDIUM 5.6
CVE-2026-7113

A vulnerability was found in NousResearch hermes-agent 0.8.0. Affected by this issue is some unknown functionality of the file gateway/platforms/webh…

Patch available
Fix from $1,600 2026-04-27