Vulnerability index

Browse CVEs

4,337 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
Unclassified MEDIUM 5.6
CVE-2026-7112

A vulnerability has been found in NousResearch hermes-agent 0.8.0. Affected by this vulnerability is the function _check_auth of the file gateway/pla…

Patch available
Fix from $1,600 2026-04-27
Unclassified HIGH 7.3
CVE-2026-7042

A flaw has been found in 666ghj MiroFish up to 0.1.2. This affects the function create_app of the file backend/app/__init__.py of the component REST …

Mitigation only
Fix from $1,950 2026-04-26
Unclassified HIGH 7.3
CVE-2026-7022

A security vulnerability has been detected in SmythOS sre up to 0.0.15. Affected is the function AgentRuntime of the file packages/core/src/subsystem…

Mitigation only
Fix from $1,950 2026-04-26
Budibase CRITICAL 9.1
CVE-2026-41428

Budibase is an open-source low-code platform. Prior to 3.35.4, the authenticated middleware uses unanchored regular expressions to match public (no-a…

Fix: 3.35.4+
Fix from $2,300 2026-04-24
Axios MEDIUM 6.5
CVE-2026-42041

Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, the Axios library is vulnerable to a Prototype Pollutio…

Fix: 0.31.1 / 1.15.1+
Fix from $1,600 2026-04-24
Flowise CRITICAL 9.8
CVE-2026-41276EPSS 7%

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, this vulnerability allows remote attackers t…

Fix: 3.1.0+
Fix from $2,300 2026-04-23
Paperclipai CRITICAL 10.0
CVE-2026-41679

Paperclip is a Node.js server and React UI that orchestrates a team of AI agents to run a business. Prior to version 2026.416.0, an unauthenticated a…

Fix: 2026.416.0+
Fix from $2,300 2026-04-23
Minio HIGH 8.2
CVE-2026-40344

MinIO is a high-performance object storage system. Starting in RELEASE.2023-05-18T00-05-36Z and prior to RELEASE.2026-04-11T03-20-12Z, an authenticat…

Fix: 2026-04-11T03-20-12Z+
Fix from $1,950 2026-04-22
Minio HIGH 8.2
CVE-2026-41145

MinIO is a high-performance object storage system. Starting in RELEASE.2023-05-18T00-05-36Z and prior to RELEASE.2026-04-11T03-20-12Z, an authenticat…

Fix: 2026-04-11T03-20-12Z+
Fix from $1,950 2026-04-22
Unclassified CRITICAL 9.2
CVE-2026-40946

Oxia is a metadata store and coordination system. Prior to 0.16.2, the OIDC authentication provider unconditionally sets SkipClientIDCheck: true in t…

Mitigation only
Fix from $2,300 2026-04-21
Frp CRITICAL 9.1
CVE-2026-40910

frp is a fast reverse proxy. From 0.43.0 to 0.68.0, frp contains an authentication bypass in the HTTP vhost routing path when routeByHTTPUser is used…

Fix: 0.68.1+
Fix from $2,300 2026-04-21
Openharness HIGH 7.6
CVE-2026-6729

HKUDS OpenHarness prior to PR #159 remediation contains a session key derivation vulnerability that allows authenticated participants in shared chats…

Fix: 0.1.7+
Fix from $1,950 2026-04-20
Roxy Wi CRITICAL 9.1
CVE-2026-33432

Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions up to and including 8.2.8.2, when LDAP authenticat…

Fix: after 8.2.8.2
Fix from $2,300 2026-04-20
Unclassified HIGH 7.3
CVE-2026-6635

A security vulnerability has been detected in rowboatlabs rowboat up to 0.1.67. This impacts the function tool_call of the file apps/experimental/too…

Mitigation only
Fix from $1,950 2026-04-20
Unclassified MEDIUM 6.5
CVE-2026-6588

A weakness has been identified in serge-chat serge up to 1.4TB. The impacted element is the function download_model/delete_model of the file api/src/…

Mitigation only
Fix from $1,600 2026-04-20
Unclassified HIGH 7.3
CVE-2026-6582

A flaw has been found in TransformerOptimus SuperAGI up to 0.0.14. Affected by this issue is the function get_vector_db_details of the file superagi/…

Mitigation only
Fix from $1,950 2026-04-19
Unclassified MEDIUM 6.5
CVE-2026-6579

A weakness has been identified in liangliangyy DjangoBlog up to 2.1.0.0. This impacts an unknown function of the file blog/views.py of the component …

Mitigation only
Fix from $1,600 2026-04-19
Unclassified HIGH 7.3
CVE-2026-6577

A vulnerability was identified in liangliangyy DjangoBlog up to 2.1.0.0. The impacted element is an unknown function of the file owntracks/views.py o…

Mitigation only
Fix from $1,950 2026-04-19
Unclassified HIGH 7.3
CVE-2026-6569

A vulnerability was identified in kodcloud KodExplorer up to 4.52. This impacts the function fileGet of the file /app/controller/share.class.php of t…

Mitigation only
Fix from $1,950 2026-04-19
Data Domain Operating System HIGH 7.2
CVE-2025-46607

Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 8.4 through 8.5 contain an improper authenticatio…

Fix: after 8.5.0.0
Fix from $1,950 2026-04-17
Data Domain Operating System MEDIUM 6.6
CVE-2025-46641

Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 8.4 through 8.5 contain an improper authenticatio…

Fix: after 8.5.0.0
Fix from $1,600 2026-04-17
Windows 10 1607 MEDIUM 6.2
CVE-2026-32072

Improper authentication in Windows Active Directory allows an unauthorized attacker to perform spoofing locally.

Fix: 10.0.14393.9060 / 10.0.17763.8644+
Fix from $1,600 2026-04-14
Fortisoar HIGH 8.1
CVE-2026-23708

A improper authentication vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.3, FortiSOAR PaaS 7.5.0 through 7.5.2, FortiSOAR on-premise 7.6.…

Fix: 7.5.3 / 7.6.4+
Fix from $1,950 2026-04-14
Unclassified HIGH 7.3
CVE-2026-6129

A vulnerability was detected in zhayujie chatgpt-on-wechat CowAgent up to 2.0.4. This affects an unknown function of the component Agent Mode Service…

Mitigation only
Fix from $1,950 2026-04-12
Unclassified HIGH 7.3
CVE-2026-6126

A weakness has been identified in zhayujie chatgpt-on-wechat CowAgent 2.0.4. The affected element is an unknown function of the component Administrat…

Mitigation only
Fix from $1,950 2026-04-12
Ajenti Plugin Core MEDIUM 5.9
CVE-2026-40178

ajenti.plugin.core defines all necessary core elements to allow Ajenti to run properly. Prior to 0.112, if the 2FA was activated, it was possible dur…

Fix: 0.112+
Fix from $1,600 2026-04-10
Ajenti Plugin Core HIGH 7.5
CVE-2026-40177

ajenti.plugin.core defines all necessary core elements to allow Ajenti to run properly. Prior to 0.112, if the 2FA was activated, it was possible to …

Fix: 0.112+
Fix from $1,950 2026-04-10
Vikunja CRITICAL 9.1
CVE-2026-34727

Vikunja is an open-source self-hosted task management platform. Prior to 2.3.0, the OIDC callback handler issues a full JWT token without checking wh…

Fix: 2.3.0+
Fix from $2,300 2026-04-10
Unclassified MEDIUM 5.3
CVE-2026-4664

The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 5.103.0. This …

Mitigation only
Fix from $1,600 2026-04-10
Tomcat MEDIUM 6.5
CVE-2026-34500

CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled and FFM is used in Apache Tomcat. This issue affe…

Fix: 9.0.117 / 10.1.54+
Fix from $1,600 2026-04-09