Vulnerability index

Browse CVEs

4,327 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
Unclassified HIGH 8.1
CVE-2026-18469

The Login & Register Forms WordPress plugin before 4.0.2 does not enforce its password reset attempt limit against a server-derived value, keying bo…

No fix yet
Fix from $4,900 2026-08-10
Unclassified HIGH 8.8
CVE-2026-18786

The CheckView WordPress plugin before 2.3.2 does not restrict its REST API authentication filter to its own routes and unconditionally discards the …

No fix yet
Fix from $4,900 2026-08-10
Unclassified MEDIUM 5.4
CVE-2026-18960

The Block User Account WordPress plugin before 2.0.1 does not enforce its account block on every authentication path, allowing a blocked user who hol…

No fix yet
Fix from $4,000 2026-08-10
Unclassified CRITICAL 9.8
CVE-2026-16299

The Single Sign On For TNG WordPress plugin before 2.2.0 does not properly validate a password reset request, allowing unauthenticated attackers to r…

No fix yet
Fix from $5,750 2026-08-10
Unclassified HIGH 8.2
CVE-2026-16257

The Arvow AI SEO Writer WordPress plugin before 1.5.4 does not properly restrict access to one of its REST endpoints, whose only access control can b…

No fix yet
Fix from $4,900 2026-08-10
Unclassified HIGH 8.1
CVE-2026-13600

The AutoNetTV Relay WordPress plugin before 3.0.14 does not perform any capability or authentication check before setting a WordPress administrator a…

No fix yet
Fix from $4,900 2026-08-10
Unclassified HIGH 7.3
CVE-2026-19342

A vulnerability was detected in code-projects Task Management System 1.0. Affected is an unknown function of the file /index.php of the component Log…

No fix yet
Fix from $4,900 2026-08-09
Unclassified CRITICAL 9.8
CVE-2026-15038

The InfiniteWP Client WordPress plugin before 1.13.6 does not properly verify the site-connection state and the authenticity of requests to its remot…

No fix yet
Fix from $5,750 2026-08-09
Unclassified MEDIUM 5.3
CVE-2026-16282

The Appointment Hour Booking WordPress plugin before 1.5.88 does not validate a client-supplied booking price against the server-side configured ser…

No fix yet
Fix from $1,600 2026-08-08
Unclassified CRITICAL 9.1
CVE-2026-48039

Meta Ads MCP is a Model Context Protocol (MCP) server that lets AI assistants run Meta Ads. Prior to version 1.0.109, `AuthInjectionMiddleware.dispat…

No fix yet
Fix from $2,300 2026-08-07
Openmanage Server Administrator CRITICAL 9.8
CVE-2026-56793

Dell OpenManage Server Administrator, versions prior to 11.1.0.2, contains an Improper Authentication vulnerability. An unauthenticated attacker with…

Fix: 11.1.0.2+
Fix from $2,300 2026-08-07
Unclassified HIGH 8.1
CVE-2026-16030

The MStore API WordPress plugin before 4.21.0 does not correctly verify the cryptographic signature of the token used to authenticate its phone-base…

No fix yet
Fix from $1,950 2026-08-07
Unclassified CRITICAL 9.8
CVE-2026-14205

The WP Events Manager WordPress plugin before 2.2.5 does not validate the requested quantity when registering for a paid event and computes the price…

No fix yet
Fix from $2,300 2026-08-07
Teams CRITICAL 9.6
CVE-2026-62896

Improper authentication in Microsoft Teams allows an authorized attacker to elevate privileges over a network.

No fix yet
Fix from $2,300 2026-08-07
Azure Sql Database CRITICAL 10.0
CVE-2026-56162

Improper authentication in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network.

No fix yet
Fix from $2,300 2026-08-07
Unclassified HIGH 8.1
CVE-2026-64665

Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.1 and 6.24.0, when OAuth login was enabled with a provider that …

No fix yet
Fix from $1,950 2026-08-06
macOS CRITICAL 9.8
CVE-2026-65400 KEV

An authentication issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.9, macOS Sonoma 14.8.9, macOS Tahoe 2…

Fix: 14.8.9 / 15.7.9+
Fix from $2,300 2026-08-06
Unclassified CRITICAL 9.8
CVE-2026-48087

OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.2, the registration …

No fix yet
Fix from $2,300 2026-08-06
Unclassified MEDIUM 5.3
CVE-2026-14547

The Estatik Real Estate Plugin WordPress plugin before 4.3.3 does not properly enforce its anti-spam check or restrict the recipient routing of its p…

No fix yet
Fix from $1,600 2026-08-06
Unclassified HIGH 8.1
CVE-2026-15459

The WPMU DEV Dashboard plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 5.0.0. On sites not yet conn…

No fix yet
Fix from $1,950 2026-08-06
Unclassified HIGH 7.3
CVE-2026-18990

A vulnerability was detected in letta-ai LettaBot 0.2.0. Impacted is an unknown function of the file src/api/server.ts of the component API Status Ro…

No fix yet
Fix from $1,950 2026-08-06
Unclassified CRITICAL 9.8
CVE-2026-9192

An authentication bypass vulnerability in the ODBC App Server of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an unauthenticated remote …

No fix yet
Fix from $2,300 2026-08-05
Unclassified CRITICAL 9.1
CVE-2026-71277

rust-iot-platform's AuthToken request-guard implementation (api/src/main.rs) only checks whether the Authorization HTTP header is present, and never …

No fix yet
Fix from $2,300 2026-08-05
Unclassified HIGH 7.5
CVE-2026-15372

The WP 2FA WordPress plugin before 4.1.0 does not validate the second authentication factor when one of its supported methods is selected at login, …

No fix yet
Fix from $1,950 2026-08-05
Unclassified HIGH 7.5
CVE-2026-16036

The miniOrange 2FA WordPress plugin before 6.2.7 does not bind the second factor being configured during the pre-login two-factor challenge to the t…

No fix yet
Fix from $1,950 2026-08-05
Unclassified HIGH 7.5
CVE-2026-16055

The Contest Gallery WordPress plugin before 30.0.7 does not route its front-end login through the standard WordPress authentication flow, issuing an…

No fix yet
Fix from $1,950 2026-08-05
Unclassified CRITICAL 9.1
CVE-2026-15210

The OTP Login With Phone Number, OTP Verification WordPress plugin before 1.8.71 does not limit the number of OTP verification attempts or invalidate…

No fix yet
Fix from $2,300 2026-08-05
Unclassified MEDIUM 5.0
CVE-2026-18816

A vulnerability was identified in Baserow up to 2.3.2. Affected by this vulnerability is the function verify of the file backend/src/baserow/api/two_…

No fix yet
Fix from $1,600 2026-08-04
Unclassified HIGH 8.1
CVE-2026-70482

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.0 until 0.11.0, when ENABLE_OAUTH_TOKEN_EXCHANGE=True,…

No fix yet
Fix from $1,950 2026-08-04
Unclassified HIGH 7.3
CVE-2026-18810

A security vulnerability has been detected in H3C NX15 V100R017. Impacted is an unknown function of the file /api/wizard/networkSetup. Such manipulat…

No fix yet
Fix from $1,950 2026-08-04