Vulnerability index

Browse CVEs

4,337 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
Unclassified MEDIUM 6.5
CVE-2025-14716

Improper Authentication vulnerability in Secomea GateManager (webserver modules) allows Authentication Bypass.This issue affects GateManager: 11.4;0.

Mitigation only
Fix from $1,600 2026-03-19
Apostrophecms HIGH 8.1
CVE-2026-32730

ApostropheCMS is an open-source content management framework. Prior to version 4.28.0, the bearer token authentication middleware in `@apostrophecms/…

Fix: 4.28.0+
Fix from $1,950 2026-03-18
Parse Server MEDIUM 5.3
CVE-2026-33042

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.29 and 8.6.49, a user ca…

Fix: 8.6.49 / 9.6.0+
Fix from $1,600 2026-03-18
Unclassified HIGH 7.3
CVE-2026-2991

The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and includ…

Mitigation only
Fix from $1,950 2026-03-18
Glpi MEDIUM 6.5
CVE-2026-25937

GLPI is a free Asset and IT management software package. Starting in version 11.0.0 and prior to version 11.0.6, a malicious actor with knowledge of …

Fix: 11.0.6+
Fix from $1,600 2026-03-18
Unclassified MEDIUM 5.6
CVE-2026-4349

A vulnerability was determined in Duende IdentityServer4 up to 4.1.2. The affected element is an unknown function of the file /connect/authorize of t…

Mitigation only
Fix from $1,600 2026-03-17
Ac8 Firmware CRITICAL 9.8
CVE-2026-4252

A vulnerability was identified in Tenda AC8 16.03.50.11. Affected by this issue is the function check_is_ipv6 of the component IPv6 Handler. The mani…

Mitigation only
Fix from $2,300 2026-03-16
Unclassified MEDIUM 5.3
CVE-2026-4187

A vulnerability was identified in Tiandy Easy7 Integrated Management Platform 7.17.0. Impacted is an unknown function of the file /WebService/UpdateL…

Mitigation only
Fix from $1,600 2026-03-16
Smart Switch MEDIUM 6.5
CVE-2026-21004

Improper authentication in Smart Switch prior to version 3.7.69.15 allows adjacent attackers to trigger a denial of service.

Fix: 3.7.69.15+
Fix from $1,600 2026-03-16
Tinyauth HIGH 7.1
CVE-2026-32246

Tinyauth is an authentication and authorization server. Prior to 5.0.3, the OIDC authorization endpoint allows users with a TOTP-pending session (pas…

Fix: after 5.0.2
Fix from $1,950 2026-03-12
Adguardhome CRITICAL 9.8
CVE-2026-32136

AdGuard Home is a network-wide software for blocking ads and tracking. Prior to 0.107.73, an unauthenticated remote attacker can bypass all authentic…

Fix: 0.107.73+
Fix from $2,300 2026-03-11
Neo4j CRITICAL 9.8
CVE-2026-1524

An edgecase in SSO implementation in Neo4j Enterprise edition versions prior to version 2026.02 can lead to unauthorised access under the following c…

Fix: 5.26.22 / 2026.02+
Fix from $2,300 2026-03-11
Arubaos Cx CRITICAL 9.8
CVE-2026-23813

A vulnerability has been identified in the web-based management interface of AOS-CX switches that could potentially allow an unauthenticated remote a…

Fix: after 10.17.0001
Fix from $2,300 2026-03-11
Parse Server HIGH 8.8
CVE-2026-30967

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.5.2-alpha.9. and 8.6.22, the OAuth…

Fix: 8.6.22 / 9.5.2+
Fix from $1,950 2026-03-10
Parse Server HIGH 8.8
CVE-2026-30949

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.5.2-alpha.5 and 8.6.18, the Keyclo…

Fix: 8.6.18 / 9.5.2+
Fix from $1,950 2026-03-10
Feathers CRITICAL 9.8
CVE-2026-29792

Feathersjs is a framework for creating web APIs and real-time applications with TypeScript or JavaScript. From 5.0.0 to before 5.0.42, an unauthentic…

Fix: 5.0.42+
Fix from $2,300 2026-03-10
Azure Automation Hybrid Worker Windows Extension HIGH 7.8
CVE-2026-26141

Improper authentication in Azure Arc allows an authorized attacker to elevate privileges locally.

Fix: 1.3.74+
Fix from $1,950 2026-03-10
Windows 10 1607 HIGH 7.8
CVE-2026-26128

Improper authentication in Windows SMB Server allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.8957 / 10.0.17763.8511+
Fix from $1,950 2026-03-10
Windows 10 1607 HIGH 7.8
CVE-2026-24294

Improper authentication in Windows SMB Server allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.8957 / 10.0.17763.8511+
Fix from $1,950 2026-03-10
Unclassified CRITICAL 9.8
CVE-2026-0953

The Tutor LMS Pro plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 3.9.5 via the Social Login addon.…

Mitigation only
Fix from $2,300 2026-03-10
Unclassified HIGH 8.2
CVE-2025-68402

FreshRSS is a free, self-hostable RSS aggregator. From 57e1a37 - 00f2f04, the lengths of the nonce was changed from 40 chars to 64. password_verify()…

Patch available
Fix from $1,950 2026-03-09
Doracms CRITICAL 9.8
CVE-2026-3794

A vulnerability was identified in doramart DoraCMS 3.0.x. This issue affects some unknown processing of the file /api/v1/mail/send of the component E…

Mitigation only
Fix from $2,300 2026-03-09
Unclassified MEDIUM 6.3
CVE-2026-3739

A security flaw has been discovered in suitenumerique messages 0.2.0. This issue affects the function ThreadAccessSerializer of the file src/backend/…

Patch available
Fix from $1,600 2026-03-08
Parse Server CRITICAL 9.8
CVE-2026-30863

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.10 and 9.5.0-alpha.11, …

Fix: 8.6.10 / 9.5.0+
Fix from $2,300 2026-03-07
Caddy HIGH 8.8
CVE-2026-30851

Caddy is an extensible server platform that uses TLS by default. From version 2.10.0 to before version 2.11.2, forward_auth copy_headers does not str…

Fix: 2.11.2+
Fix from $1,950 2026-03-07
Zitadel HIGH 8.2
CVE-2026-29193

ZITADEL is an open source identity management platform. From version 4.0.0 to 4.12.0, a vulnerability in Zitadel's login V2 UI allowed users to bypas…

Fix: 4.12.1+
Fix from $1,950 2026-03-07
Olivetin HIGH 8.8
CVE-2026-30223

OliveTin gives access to predefined shell commands from a web interface. Prior to version 3000.11.1, when JWT authentication is configured using eith…

Fix: 3000.11.1+
Fix from $1,950 2026-03-06
Rocket.chat CRITICAL 9.8
CVE-2026-30831

Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to versions 7.10.8, 7.11.5, 7.12.5, 7.13.4, 8.0.2, 8.1.1, an…

Fix: 7.10.8 / 7.11.5+
Fix from $2,300 2026-03-06
Rocket.chat CRITICAL 9.8
CVE-2026-28514

Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to versions 7.8.6, 7.9.8, 7.10.7, 7.11.4, 7.12.4, 7.13.3, an…

Fix: 7.8.6 / 7.9.8+
Fix from $2,300 2026-03-06
Natro Macro HIGH 8.0
CVE-2026-28800

Natro Macro is an open-source Bee Swarm Simulator macro written in AutoHotkey. Prior to version 1.1.0, anyone with Discord Remote Control set up in a…

Fix: 1.1.0+
Fix from $1,950 2026-03-06