Vulnerability index

Browse CVEs

4,337 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
Oneuptime CRITICAL 9.0
CVE-2026-28787

OneUptime is a solution for monitoring and managing online services. In version 10.0.11 and prior, the WebAuthn authentication implementation does no…

Fix: after 10.0.11
Fix from $2,300 2026-03-06
Talishar MEDIUM 5.3
CVE-2026-28428

Talishar is a fan-made Flesh and Blood project. Prior to commit a9c218e, an authentication bypass vulnerability in Talishar's game endpoint validatio…

Fix: 2026-02-22+
Fix from $1,600 2026-03-06
Avideo CRITICAL 9.8
CVE-2026-29093

WWBN AVideo is an open source video platform. Prior to version 24.0, the official docker-compose.yml publishes the memcached service on host port 112…

Fix: 24.0+
Fix from $2,300 2026-03-06
Openclaw MEDIUM 5.3
CVE-2026-28471

OpenClaw version 2026.1.14-1 prior to 2026.2.2, with the Matrix plugin installed and enabled, contain a vulnerability in which DM allowlist matching …

Fix: 2026.2.2+
Fix from $1,600 2026-03-05
Devolutions Server CRITICAL 9.8
CVE-2026-3224

Authentication bypass in the Microsoft Entra ID (Azure AD) authentication mode in Devolutions Server 2025.3.15.0 and earlier allows an unauthenticate…

Fix: 2025.3.16.0+
Fix from $2,300 2026-03-03
Openemr CRITICAL 9.8
CVE-2026-24898

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0, an unauthenticated token dis…

Fix: 8.0.0+
Fix from $2,300 2026-03-03
Autopass License Server CRITICAL 9.8
CVE-2026-23600

A remote authentication bypass vulnerability  exists in HPE AutoPass License Server (APLS).

Fix: 9.19+
Fix from $2,300 2026-03-02
Wegia CRITICAL 9.8
CVE-2026-28408

WeGIA is a web manager for charitable institutions. Prior to version 3.6.5, the script in adicionar_tipo_docs_atendido.php does not go through the pr…

Fix: 3.6.5+
Fix from $2,300 2026-02-27
Statamic HIGH 8.8
CVE-2026-27939

Statmatic is a Laravel and Git powered content management system (CMS). Starting in version 6.0.0 and prior to version 6.4.0, Authenticated Control P…

Fix: 6.4.0+
Fix from $1,950 2026-02-27
Unclassified MEDIUM 5.3
CVE-2026-1305

The Japanized for WooCommerce plugin for WordPress is vulnerable to Improper Authentication in versions up to, and including, 2.8.4. This is due to a…

Mitigation only
Fix from $1,600 2026-02-27
Hoppscotch CRITICAL 9.1
CVE-2026-28215

hoppscotch is an open source API development ecosystem. Prior to version 2026.2.0, an unauthenticated attacker can overwrite the entire infrastructur…

Fix: 2026.2.0+
Fix from $2,300 2026-02-26
Unclassified HIGH 8.2
CVE-2025-71057

Improper session management in D-Link Wireless N 300 ADSL2+ Modem Router DSL-124 ME_1.00 allows attackers to execute a session hijacking attack via s…

Mitigation only
Fix from $1,950 2026-02-26
Discourse MEDIUM 6.5
CVE-2026-26077

Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, several webhook endpoints (SendGrid, Mailjet, M…

Fix: 2025.12.0 / 2026.1.1+
Fix from $1,600 2026-02-26
Blockchain HIGH 7.0
CVE-2026-3194

A flaw has been found in Chia Blockchain 2.1.0. The affected element is the function send_transaction/get_private_key of the component RPC Server Mas…

No fix yet
Fix from $1,950 2026-02-25
Blockchain HIGH 8.1
CVE-2026-3192

A security vulnerability has been detected in Chia Blockchain 2.1.0. This issue affects the function _authenticate of the file rpc_server_base.py of …

No fix yet
Fix from $1,950 2026-02-25
Catalyst Sd Wan Manager CRITICAL 9.8
CVE-2026-20129

A vulnerability in the API user authentication of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to gain access to an …

Fix: 20.9.8.2 / 20.12.5.3+
Fix from $2,300 2026-02-25
Catalyst Sd Wan Manager CRITICAL 10.0
CVE-2026-20127 KEVEPSS 88%

A vulnerability in the peering authentication in Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, Cisco Catalyst SD-WAN Manager, formerly SD…

Fix: 20.9.8.2 / 20.12.5.3+
Fix from $2,300 2026-02-25
Filebrowser Quantum MEDIUM 6.5
CVE-2026-27611

FileBrowser Quantum is a free, self-hosted, web-based file manager. Prior to versions 1.1.3-stable and 1.2.6-beta, when users share password-protecte…

Fix: 1.1.3 / 1.2.6+
Fix from $1,600 2026-02-25
Delegated License Service HIGH 7.5
CVE-2026-24241

NVIDIA Delegated Licensing Service for all appliance platforms contains a vulnerability where an attacker could exploit an improper authentication is…

Fix: 3.1.8 / 3.6.0+
Fix from $1,950 2026-02-24
Dinky CRITICAL 9.8
CVE-2026-3053

A vulnerability was determined in DataLinkDC dinky up to 1.2.5. This affects the function addInterceptors of the file dinky-admin/src/main/java/org/d…

Fix: after 1.2.5
Fix from $2,300 2026-02-24
Sentry CRITICAL 9.1
CVE-2026-27197

Sentry is a developer-first error tracking and performance monitoring tool. Versions 21.12.0 through 26.1.0 have a critical vulnerability in its SAML…

Fix: 26.2.0+
Fix from $2,300 2026-02-21
Strimzi Kafka Operator HIGH 8.1
CVE-2026-27134

Strimzi provides a way to run an Apache Kafka cluster on Kubernetes or OpenShift in various deployment configurations. In versions 0.49.0 through 0.…

Fix: 0.50.1+
Fix from $1,950 2026-02-21
Smanga CRITICAL 9.4
CVE-2025-70833

An Authentication Bypass vulnerability in Smanga 3.2.7 allows an unauthenticated attacker to reset the password of any user (including the administra…

Mitigation only
Fix from $2,300 2026-02-20
Unclassified MEDIUM 6.9
CVE-2025-41023

An authentication bypass vulnerability has been found in Thesamur's AutoGPT. This vulnerability allows an attacker to bypass authentication mechanism…

No fix yet
Fix from $1,600 2026-02-19
Unclassified CRITICAL 10.0
CVE-2025-15586

OGP-Website installs prior git commit 52f865a4fba763594453068acf8fa9e3fc38d663 are affected by a type juggling flaw which if exploited can result in …

Patch available
Fix from $2,300 2026-02-19
Unclassified MEDIUM 5.3
CVE-2025-7630

Improper Restriction of Excessive Authentication Attempts, Improper Authentication vulnerability in Doruk Communication and Automation Industry and T…

Mitigation only
Fix from $1,600 2026-02-18
Unclassified HIGH 7.5
CVE-2026-1368

The Video Conferencing with Zoom WordPress plugin before 4.6.6 contains an AJAX handler that has its nonce verification commented out, allowing unaut…

Mitigation only
Fix from $1,950 2026-02-18
Windows Admin Center HIGH 8.8
CVE-2026-26119

Improper authentication in Windows Admin Center allows an authorized attacker to elevate privileges over a network.

Fix: 2511+
Fix from $1,950 2026-02-17
Authentik HIGH 7.5
CVE-2026-25748

authentik is an open-source identity provider. Prior to 2025.10.4 and 2025.12.4, with a malformed cookie it was possible to bypass authentication whe…

Fix: 2025.10.4 / 2025.12.4+
Fix from $1,950 2026-02-12
Authentik HIGH 8.8
CVE-2026-25922

authentik is an open-source identity provider. Prior to 2025.8.6, 2025.10.4, and 2025.12.4, when using a SAML Source that has the option Verify Asser…

Fix: 2025.8.6 / 2025.10.4+
Fix from $1,950 2026-02-12