Vulnerability index

Browse CVEs

4,327 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
I CRITICAL 9.8
CVE-2026-16867

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to access server resources with the privileges of an authenticated user due to improper au…

No fix yet
Fix from $5,750 2026-08-13
I CRITICAL 9.8
CVE-2026-17197

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to bypass security restrictions due to improper validation of client-asserted identity.

No fix yet
Fix from $5,750 2026-08-13
Unclassified CRITICAL 10.0
CVE-2026-59500

CWE-287: Improper Authentication

No fix yet
Fix from $5,750 2026-08-13
Unclassified CRITICAL 9.8
CVE-2026-14182

The Customer Email Verification for WooCommerce WordPress plugin before 3.2.6 does not correctly validate the email-verification activation code, rel…

No fix yet
Fix from $5,750 2026-08-13
Unclassified MEDIUM 5.5
CVE-2026-47718

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. When `secureEnabled=true`, FUXA `1.3.0-2773` still allows guest and invalid…

No fix yet
Fix from $4,000 2026-08-12
Unclassified CRITICAL 9.1
CVE-2026-73501

kin-openapi is a Go project for handling OpenAPI files. Prior to 0.144.0, ValidationHandler.Load() in openapi3filter/validation_handler.go silently r…

No fix yet
Fix from $5,750 2026-08-12
Unclassified CRITICAL 10.0
CVE-2024-27253

IBM DOORS Next 7.0.3 through 7.0.3 Interim Fix 018 could allow an authenticated user to bypass security logic to perform unauthorized activities.

No fix yet
Fix from $5,750 2026-08-12
Security Verify Access HIGH 7.4
CVE-2026-11923

IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 thr…

No fix yet
Fix from $4,900 2026-08-12
Security Verify Access HIGH 8.1
CVE-2026-12359

IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 thr…

No fix yet
Fix from $4,900 2026-08-12
Unclassified HIGH 7.5
CVE-2026-42018

JFrog Artifactory could return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled, potentially exposing …

No fix yet
Fix from $4,900 2026-08-12
Unclassified MEDIUM 5.3
CVE-2026-68760

An unauthenticated user may bypass authentication under specific cache conditions.

No fix yet
Fix from $4,000 2026-08-12
Unclassified CRITICAL 9.4
CVE-2026-50561

Yuxi is a large-model-based intelligent knowledge base and knowledge graph agent development platform. Prior to version 0.6.2, the project's authenti…

No fix yet
Fix from $5,750 2026-08-12
Unclassified CRITICAL 9.8
CVE-2026-26035

An Improper Authentication vulnerability [CWE-287] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4…

No fix yet
Fix from $5,750 2026-08-12
Unclassified MEDIUM 6.1
CVE-2026-17013

The WP Photo Album Plus WordPress plugin before 9.2.07.002 does not sanitise and escape a parameter before reflecting it into an inline script block,…

No fix yet
Fix from $4,000 2026-08-12
Unclassified HIGH 8.1
CVE-2026-18961

The Social Login, Passkeys, Magic Link & Email OTP – Passwordless Login by VentraConnect plugin for WordPress is vulnerable to Authentication Bypass …

No fix yet
Fix from $4,900 2026-08-12
Unclassified HIGH 8.3
CVE-2026-73241

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.30.0, FreeRDP server-side RDSTLS in libfreerdp/core/rdstls.c accepts an a…

No fix yet
Fix from $4,900 2026-08-11
Unclassified HIGH 7.5
CVE-2026-71467

A flaw was found in search-v2-api. The authentication middleware in the affected component unconditionally skips authentication when a request includ…

No fix yet
Fix from $4,900 2026-08-11
Unclassified MEDIUM 5.3
CVE-2026-73085

Audiobookshelf is a self-hosted audiobook and podcast server. Prior to 2.36.0, the jwtAuthCheck function in server/auth/TokenManager.js treats JWTs w…

No fix yet
Fix from $4,000 2026-08-11
Sharepoint Server HIGH 8.8
CVE-2026-62827

Improper authentication in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.

Fix: 16.0.19725.20522+
Fix from $4,900 2026-08-11
Unclassified MEDIUM 6.3
CVE-2026-20891

Improper authentication for some Intel(R) PROSet/Wireless WiFi Software for Windows within Ring 2: Device Drivers may allow an escalation of privileg…

No fix yet
Fix from $4,000 2026-08-11
Unclassified HIGH 7.0
CVE-2026-20885

Improper authentication in the Intel(R) TDX module for some Intel(R) platforms within Ring 0: Trust Domain may allow an information disclosure and es…

No fix yet
Fix from $4,900 2026-08-11
Unclassified MEDIUM 6.7
CVE-2026-20752

Improper authentication for some Intel(R) PROSet/Wireless WiFi Software within Ring 0: Kernel may allow an information disclosure. System software ad…

No fix yet
Fix from $4,000 2026-08-11
Unclassified CRITICAL 9.8
CVE-2026-12571

An authentication bypass in ManageEngine DDI Central's password-reset workflow allows account takeover.

No fix yet
Fix from $5,750 2026-08-11
Unclassified HIGH 8.2
CVE-2026-72922

AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. Prior to 0.6.70, AutoGPT's…

No fix yet
Fix from $4,900 2026-08-11
Unclassified CRITICAL 9.8
CVE-2026-51584

An issue in usememos v0.27.1 allows a remote attacker to achieve account takeover via the ssoCredentials branch of the SignIn handler in server/route…

No fix yet
Fix from $5,750 2026-08-11
Unclassified HIGH 7.5
CVE-2026-72746

FreeRDP before 3.30.0 contains a server-side authentication bypass in the RDSTLS handshake. When a server is configured with RdstlsSecurity = TRUE, t…

No fix yet
Fix from $4,900 2026-08-11
Unclassified HIGH 8.8
CVE-2026-72533

An authentication bypass vulnerability in Portainer CE through 2.44.0 allows authenticated low-privileged users to bypass Docker proxy authorization …

No fix yet
Fix from $4,900 2026-08-11
Unclassified MEDIUM 5.9
CVE-2026-72917

AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. From 1.0.0 to 1.15.0, Any…

No fix yet
Fix from $4,000 2026-08-10
Ranger CRITICAL 9.8
CVE-2026-40920

Privilege Escalation via URL Parameter is reported in Apache Ranger versions <= 2.8.0. Users are recommended to upgrade to version 2.9.0, which fixe…

No fix yet
Fix from $5,750 2026-08-10
Unclassified HIGH 8.1
CVE-2026-18468

The Login & Register Forms WordPress plugin before 4.0.2 does not bind the password reset verification state to the account being reset or to the pa…

No fix yet
Fix from $4,900 2026-08-10