Vulnerability index

Browse CVEs

4,337 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
Tomcat CRITICAL 9.1
CVE-2026-29145

CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled vulnerability in Apache Tomcat, Apache Tomcat Nati…

Fix: 1.3.7 / 2.0.14+
Fix from $2,300 2026-04-09
Passport HIGH 7.1
CVE-2026-39976

Laravel Passport provides OAuth2 server support to Laravel. From 13.0.0 to before 13.7.1, there is an Authentication Bypass for client_credentials to…

Fix: 13.7.1+
Fix from $1,950 2026-04-09
Unclassified MEDIUM 6.6
CVE-2026-5959

A security flaw has been discovered in GL.iNet GL-RM1, GL-RM10, GL-RM10RC and GL-RM1PE 1.8.1. Affected by this issue is some unknown functionality of…

Mitigation only
Fix from $1,600 2026-04-09
Lobehub HIGH 7.1
CVE-2026-39411

LobeHub is a work-and-lifestyle space to find, build, and collaborate with agent teammates that grow with you. Prior to 2.1.48, the webapi authentica…

Fix: 2.1.48+
Fix from $1,950 2026-04-08
Jetty HIGH 7.4
CVE-2026-5795

In Eclipse Jetty, the class JASPIAuthenticator initiates the authentication checks, which set two ThreadLocal variable. Upon returning from the ini…

Fix: 12.0.34 / 12.1.8+
Fix from $1,950 2026-04-08
Polarlearn HIGH 8.8
CVE-2026-39322

PolarLearn is a free and open-source learning program. In 0-PRERELEASE-15 and earlier, POST /api/v1/auth/sign-in creates a valid session for banned a…

Mitigation only
Fix from $1,950 2026-04-07
Rack Session CRITICAL 9.8
CVE-2026-39324

Rack::Session is a session management implementation for Rack. From 2.0.0 to before 2.1.2, Rack::Session::Cookie incorrectly handles decryption failu…

Fix: 2.1.2+
Fix from $2,300 2026-04-07
Unclassified HIGH 7.3
CVE-2026-5676

A vulnerability was identified in Totolink A8000R 5.9c.681_B20180413. This issue affects the function setLanguageCfg of the file /cgi-bin/cstecgi.cgi…

Mitigation only
Fix from $1,950 2026-04-06
Litellm CRITICAL 9.1
CVE-2026-35030

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.83.0, when JWT authentication is enabled (enable_jwt…

Fix: 1.83.0+
Fix from $2,300 2026-04-06
Unclassified HIGH 7.3
CVE-2026-5632

A vulnerability was found in assafelovic gpt-researcher up to 3.4.3. This impacts an unknown function of the component HTTP REST API Endpoint. Perfor…

Mitigation only
Fix from $1,950 2026-04-06
Unclassified HIGH 7.3
CVE-2026-5616

A security vulnerability has been detected in JeecgBoot 3.9.0/3.9.1. The impacted element is an unknown function of the file jeecg-boot/jeecg-module-…

Patch available
Fix from $1,950 2026-04-06
Hi Led Wr120 G2 Firmware CRITICAL 9.8
CVE-2026-5570

A vulnerability was determined in Technostrobe HI-LED-WR120-G2 5.5.0.1R6.03.30. The affected element is the function index_config of the file /LoginC…

Mitigation only
Fix from $2,300 2026-04-05
Unclassified MEDIUM 6.3
CVE-2026-5557

A vulnerability was detected in badlogic pi-mono up to 0.58.4. This issue affects some unknown processing of the file packages/mom/src/slack.ts of th…

Mitigation only
Fix from $1,600 2026-04-05
Icx35 Hwc Firmware CRITICAL 9.8
CVE-2017-20235

ProSoft Technology ICX35-HWC version 1.3 and prior cellular gateways contain an authentication bypass vulnerability in the web user interface that al…

Fix: 1.3+
Fix from $2,300 2026-04-03
Unclassified CRITICAL 9.8
CVE-2018-25236

Hirschmann HiOS and HiSecOS products RSP, RSPE, RSPS, RSPL, MSP, EES, EESX, GRS, OS, RED, EAGLE contain an authentication bypass vulnerability in the…

Mitigation only
Fix from $2,300 2026-04-03
Cups HIGH 7.8
CVE-2026-34990

OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.16 and prior, a local unprivileg…

Fix: after 2.4.16
Fix from $1,950 2026-04-03
Oauthenticator HIGH 8.8
CVE-2026-33175

OAuthenticator is software that allows OAuth2 identity providers to be plugged in and used with JupyterHub. Prior to version 17.4.0, an authenticatio…

Fix: 17.4.0+
Fix from $1,950 2026-04-03
Unclassified CRITICAL 9.8
CVE-2017-20237

Hirschmann Industrial HiVision versions prior to 06.0.07 and 07.0.03 contains an authentication bypass vulnerability in the master service that allow…

Mitigation only
Fix from $2,300 2026-04-03
Azure Sre Agent HIGH 7.5
CVE-2026-32173

Improper authentication in Azure SRE Agent allows an unauthorized attacker to disclose information over a network.

Mitigation only
Fix from $1,950 2026-04-03
Webmail HIGH 7.5
CVE-2026-34834

Bulwark Webmail is a self-hosted webmail client for Stalwart Mail Server. Prior to version 1.4.10, the verifyIdentity() function contained logic that…

Fix: 1.4.10+
Fix from $1,950 2026-04-02
Unclassified CRITICAL 9.8
CVE-2024-14034

Hirschmann HiEOS devices versions prior to 01.1.00 contain an authentication bypass vulnerability in the HTTP(S) management module that allows unauth…

Mitigation only
Fix from $2,300 2026-04-02
Unclassified MEDIUM 5.3
CVE-2026-34736

Open edX Platform enables the authoring and delivery of online learning at any scale. From the maple release to before the ulmo release, an unauthent…

Patch available
Fix from $1,600 2026-04-02
Tapo C520ws Firmware HIGH 8.8
CVE-2026-34121

An authentication bypass vulnerability within the HTTP handling of the DS configuration service in TP-Link Tapo C520WS v2.6 was identified, due to in…

Fix: 1.2.4+
Fix from $1,950 2026-04-02
Convoy CRITICAL 9.8
CVE-2026-33746

Convoy is a KVM server management panel for hosting businesses. From version 3.9.0-beta to before version 4.5.1, the JWTService::decode() method did …

Fix: 4.5.1+
Fix from $2,300 2026-04-02
Unclassified HIGH 7.3
CVE-2026-5320

A vulnerability was detected in vanna-ai vanna up to 2.0.2. Affected by this vulnerability is an unknown functionality of the file /api/vanna/v2/ of …

Mitigation only
Fix from $1,950 2026-04-02
Security Verify Access CRITICAL 9.8
CVE-2026-4101

IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 and IBM Verify Identity Acces…

Fix: after 11.0.2.0
Fix from $2,300 2026-04-01
Flask Httpauth HIGH 8.2
CVE-2026-34531

Flask-HTTPAuth provides Basic, Digest and Token HTTP authentication for Flask routes. Prior to version 4.8.1, in a situation where the client makes a…

Fix: 4.8.1+
Fix from $1,950 2026-04-01
Mbed Tls CRITICAL 9.1
CVE-2026-34873

An issue was discovered in Mbed TLS 3.5.0 through 4.0.0. Client impersonation can occur while resuming a TLS 1.3 session.

Fix: 3.6.6 / 4.1.0+
Fix from $2,300 2026-04-01
Cronmaster CRITICAL 9.8
CVE-2026-34072

Cr*nMaster (cronmaster) is a Cronjob management UI with human readable syntax, live logging and log history for cronjobs. Prior to version 2.2.0, an …

Fix: 2.2.0+
Fix from $2,300 2026-04-01
Devolutions Server MEDIUM 5.4
CVE-2026-4829

Improper authentication in the external OAuth authentication flow in Devolutions Server 2026.1.11 and earlier allows an authenticated user to authent…

Fix: 2026.1.12.0+
Fix from $1,600 2026-04-01