Vulnerability index

Browse CVEs

4,327 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
Unclassified HIGH 8.7
CVE-2026-58075

A vulnerability allowing an unauthenticated attacker to read arbitrary files from the host, which can be further leveraged toescalate privileges loca…

No fix yet
Fix from $1,950 2026-08-04
Unclassified CRITICAL 9.8
CVE-2026-63456

Multiple vulnerabilities in the REST API interface of HPE Networking SD-WAN Orchestrator could allow an unauthenticated remote attacker to bypass web…

No fix yet
Fix from $2,300 2026-08-04
Unclassified HIGH 8.5
CVE-2026-18759

The background service of ABP or AES runs as NT AUTHORITY\SYSTEM and implements a file-based inter-process communication (IPC) mechanism protected by…

No fix yet
Fix from $1,950 2026-08-04
Unclassified MEDIUM 6.5
CVE-2026-8508

An improper authentication vulnerability in the "social_login.cgi" CGI program in Zyxel WAX650S firmware versions through 7.10(ABRM.4)C0 could allow …

No fix yet
Fix from $1,600 2026-08-04
Unclassified MEDIUM 5.3
CVE-2026-18610

A vulnerability was detected in NewType WebEIP up to 3.0. This affects an unknown part of the file /EIP_Com_FileList.aspx. The manipulation results i…

No fix yet
Fix from $1,600 2026-08-03
Directory Server MEDIUM 5.4
CVE-2026-18651

A flaw was found in 389 Directory Server. During SASL PLAIN authentication, the server installs connection-level bind credentials before performing t…

No fix yet
Fix from $1,600 2026-08-03
Unclassified CRITICAL 9.1
CVE-2026-14557

The SoftMarket — Digital Marketplace WordPress plugin through 1.0.0 does not properly validate an authentication token in one branch of its email-ver…

Mitigation only
Fix from $2,300 2026-08-03
Unclassified HIGH 7.5
CVE-2026-16261

The login-social WordPress plugin through 1.0.4 does not validate password-reset requests against a reset key or the requester's identity, and it iss…

No fix yet
Fix from $1,950 2026-08-02
Unclassified HIGH 7.5
CVE-2026-15206

The SMS Alert WordPress plugin before 3.9.8 does not bind its "mobile verified" session flag to the phone number that was actually verified: after a…

No fix yet
Fix from $1,950 2026-08-02
Unclassified HIGH 8.1
CVE-2026-12586

The Lenxel WP WordPress theme through 1.0.31 does not perform any authorization or ownership check on its password-reset action, validating only a CS…

No fix yet
Fix from $1,950 2026-08-02
Unclassified MEDIUM 5.3
CVE-2026-67335

better-auth versions before 1.6.2 fail to validate the OAuth state parameter against the stored nonce when using cookie-backed state storage without …

No fix yet
Fix from $1,600 2026-08-01
Unclassified HIGH 8.3
CVE-2026-67327

better-auth versions >= 1.1.3 and < 1.6.22 (and pre-release versions >= 1.7.0-beta.0 and < 1.7.0-beta.10) are vulnerable to account takeover via pre-…

No fix yet
Fix from $1,950 2026-08-01
Unclassified HIGH 8.1
CVE-2026-14309

The Chat On Desk Order Notifications WordPress plugin before 1.0.9 does not verify that the one-time password has been validated before processing a…

No fix yet
Fix from $1,950 2026-08-01
Unclassified MEDIUM 6.5
CVE-2026-14561

The Authora : Easy login with mobile number WordPress plugin before 1.7.7 does not keep its one-time login code confidential, returning the code and …

No fix yet
Fix from $1,600 2026-08-01
Unclassified HIGH 8.8
CVE-2026-14596

The DynamicKit for Elementor WordPress plugin before 1.0.3 does not validate the host of a user-supplied URL used as the base of the password-reset l…

No fix yet
Fix from $1,950 2026-08-01
Unclassified HIGH 8.1
CVE-2026-14836

The Login & Register Forms WordPress plugin before 3.2.5 does not properly enforce the rate limit on its password-reset verification-code flow, keyi…

No fix yet
Fix from $1,950 2026-08-01
Build Of Keycloak HIGH 8.1
CVE-2026-18215

Keycloak provides a way to let users log in using Microsoft accounts while restricting access to a specific organization (tenant). A flaw was discove…

No fix yet
Fix from $1,950 2026-07-31
Unclassified HIGH 7.5
CVE-2026-14830

The FlxWoo WordPress plugin before 3.1.1 does not verify with the payment processor that a checkout session was actually paid before marking the asso…

No fix yet
Fix from $1,950 2026-07-31
Unclassified CRITICAL 9.8
CVE-2026-14919

The ShopMonitor.io WordPress plugin before 1.2.0 does not properly restrict its email-rerouting test mode, gating it behind a trusted-source check t…

No fix yet
Fix from $2,300 2026-07-31
Unclassified HIGH 8.1
CVE-2026-12695

The miniOrange 2FA WordPress plugin before 6.2.6 does not validate the submitted one-time password against the targeted user's stored secret, instea…

No fix yet
Fix from $1,950 2026-07-31
Mcp Toolbox For Databases HIGH 7.5
CVE-2026-14541

An authentication bypass and audience confusion vulnerability exists in the Google OAuth provider component of Google mcp-toolbox version 1.4.0. When…

No fix yet
Fix from $1,950 2026-07-31
Web Help Desk CRITICAL 9.8
CVE-2026-28323

SolarWinds Web Help Desk is found to be affected by a SAML authentication bypass vulnerability. This requires the SAML 2.0 authentication method to b…

No fix yet
Fix from $2,300 2026-07-30
Unclassified CRITICAL 9.8
CVE-2026-58066

Rocket.Chat's SAML SSO before versions 8.7.0, 8.6.1, 8.5.2, 8.4.5, 8.3.7, 8.2.7, 8.1.7, 8.0.8, and 7.10.14 verified XML signatures but did not bind t…

Mitigation only
Fix from $2,300 2026-07-30
Unclassified HIGH 7.5
CVE-2026-15240

The Customer Switching WordPress plugin before 2.1.3 does not securely bind an active user-switching session to the operator who initiated it, allowi…

No fix yet
Fix from $1,950 2026-07-30
Unclassified MEDIUM 5.3
CVE-2026-14305

The WP Delicious WordPress plugin before 1.10.2 does not perform an authorization check on one of its AJAX actions, allowing unauthenticated users t…

No fix yet
Fix from $1,600 2026-07-30
Unclassified MEDIUM 6.5
CVE-2026-63238

An authentication bypass vulnerability in Koollab LMS allowed an unauthenticated attacker to take over any account, including administrator accounts,…

No fix yet
Fix from $1,600 2026-07-29
Unclassified HIGH 7.4
CVE-2026-13690

The UsersWP WordPress plugin before 1.2.67 does not validate the selected authentication provider in its two-factor login handler, allowing an attac…

No fix yet
Fix from $1,950 2026-07-29
Unclassified HIGH 8.1
CVE-2026-14300

The miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) WordPress plugin before 7.8.0 does not bind the one-time code used by i…

No fix yet
Fix from $1,950 2026-07-29
Unclassified MEDIUM 5.3
CVE-2026-49447

Cosmos provides users the ability self-host a home server by acting as a secure gateway to your application, as well as a server manager. In 0.22.18,…

No fix yet
Fix from $1,600 2026-07-28
Unclassified HIGH 7.5
CVE-2026-54635

pytonapi is a Python SDK for TONAPI that provides REST API, streaming, and webhook access to the TON blockchain. From 2.0.0 to 2.2.0, TonapiWebhookDi…

No fix yet
Fix from $1,950 2026-07-28