Vulnerability index

Browse CVEs

4,327 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
Unclassified MEDIUM 5.3
CVE-2025-68640

The Apple Find My backend service through 2025-12-17 allows an attacker in possession of a valid PET (Private Endpoint Token) to enumerate devices an…

No fix yet
Fix from $1,600 2026-07-21
Unclassified CRITICAL 9.4
CVE-2026-53595

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.224, the public endpoint `POST /user-setup/{h…

No fix yet
Fix from $2,300 2026-07-20
Unclassified HIGH 8.6
CVE-2026-53591

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.223, an unauthenticated attacker can inject m…

No fix yet
Fix from $1,950 2026-07-20
Identityiq CRITICAL 9.8
CVE-2026-12341

This vulnerability impacts all versions of IdentityIQ and allows an unauthenticated attacker unauthorized access to protected APIs and data due to im…

Fix: 8.3+
Fix from $2,300 2026-07-20
Xrdp HIGH 7.3
CVE-2026-55626

xrdp is an open source RDP server. In versions 0.10.6 and prior, when an authenticated user session is initialized using the Xvnc backend over UNIX d…

Fix: 0.10.6.1+
Fix from $1,950 2026-07-20
Unclassified HIGH 7.5
CVE-2026-48812

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.221, FreeScout's attachment download route sk…

No fix yet
Fix from $1,950 2026-07-20
Unclassified MEDIUM 5.3
CVE-2026-46715

Flask-Security-Too allows users to add security features to their Flask applicationa. Version 5.8.0's OAuth reauthentication flow can mark a session …

No fix yet
Fix from $1,600 2026-07-20
Unclassified MEDIUM 5.3
CVE-2026-42210

Webmin is a web-based system administration tool for Unix-like servers. Prior to version 2.640, for Webmin accounts that require a second authenticat…

No fix yet
Fix from $1,600 2026-07-20
Unclassified HIGH 7.3
CVE-2026-16210

A vulnerability was found in newpanjing simpleui 2026.01.13. This affects the function self.get_action of the file simpleui/admin.py of the component…

No fix yet
Fix from $1,950 2026-07-19
Unclassified HIGH 7.3
CVE-2026-16209

A vulnerability has been found in Gerapy up to 0.9.13. The impacted element is an unknown function of the file gerapy/server/core/views.py of the com…

No fix yet
Fix from $1,950 2026-07-19
Unclassified MEDIUM 5.6
CVE-2026-16198

A vulnerability was detected in Sipeed PicoClaw up to 0.2.9. The impacted element is an unknown function of the file web/backend/middleware/access_co…

No fix yet
Fix from $1,600 2026-07-19
Surrealdb MEDIUM 6.3
CVE-2024-58363

SurrealDB before 1.5.4 fails to properly validate authentication when a scope user switches databases using the USE clause or use method. Attackers w…

Fix: 1.5.4+
Fix from $1,600 2026-07-18
Unclassified CRITICAL 9.8
CVE-2026-47865

VMware Avi Load Balancer contains an authentication bypass vulnerability. A malicious user with network access may be able to access the Avi Control …

No fix yet
Fix from $2,300 2026-07-18
Unclassified MEDIUM 5.3
CVE-2026-16083

A security flaw has been discovered in Sipeed PicoClaw up to 0.2.9. This affects the function webhook.ParseRequest of the file pkg/channels/line/line…

No fix yet
Fix from $1,600 2026-07-18
Unclassified MEDIUM 6.3
CVE-2026-16076

A vulnerability has been found in AstrBotDevs AstrBot up to 4.25.5. This issue affects the function OpenApiRoute.chat_send of the file astrbot/dashbo…

No fix yet
Fix from $1,600 2026-07-18
Unclassified HIGH 8.7
CVE-2026-49852

joserfc is a Python library that provides an implementation of several JSON Object Signing and Encryption (JOSE) standards. Prior to 1.6.8, joserfc.j…

No fix yet
Fix from $1,950 2026-07-17
Unclassified MEDIUM 6.3
CVE-2026-16015

A vulnerability was determined in poco-ai poco-claw up to 0.5.4. This vulnerability affects the function create_task of the file executor_manager/app…

No fix yet
Fix from $1,600 2026-07-17
Unclassified CRITICAL 9.6
CVE-2026-22752

Authentication bypass by primary weakness vulnerability in Spring Security Spring Authorization Server. This issue affects Spring Authorization Serv…

No fix yet
Fix from $2,300 2026-07-16
Unclassified HIGH 8.1
CVE-2026-12585

The Abandoned Cart Lite for WooCommerce WordPress plugin before 6.8.2 does not protect the integrity of its cart-recovery tokens or bind them to the …

No fix yet
Fix from $1,950 2026-07-16
Unclassified CRITICAL 9.8
CVE-2026-12492

The Happy Coders OTP Login for WooCommerce WordPress plugin before 2.8 does not verify that a one-time password was actually validated before authent…

No fix yet
Fix from $2,300 2026-07-16
Unclassified CRITICAL 9.3
CVE-2026-55445

Qinglong is a timed task management platform supporting Python3, JavaScript, Shell, and Typescript. Prior to 2.20.1, the init guard middleware in bac…

Mitigation only
Fix from $2,300 2026-07-15
Unclassified CRITICAL 9.8
CVE-2026-55652

Wekan is open source kanban built with Meteor. Prior to 9.46, header-login with HEADER_LOGIN_TRUSTED_IPS uses getRequestIp() in server/lib/headerLogi…

No fix yet
Fix from $2,300 2026-07-15
Unclassified CRITICAL 9.2
CVE-2026-52893

Wekan is open source kanban built with Meteor. Prior to 9.32, the Wekan Accounts.onCreateUser hook in server/models/users.js merges OIDC logins into …

Mitigation only
Fix from $2,300 2026-07-15
Unclassified HIGH 8.2
CVE-2026-46485

Dashy is a self-hostable personal dashboard. Prior to 4.0.8, Dashy deployments using OIDC can allow unauthenticated users or non-admin authenticated …

Mitigation only
Fix from $1,950 2026-07-15
Better Auth CRITICAL 9.1
CVE-2026-53512

Better Auth is an authentication and authorization library for TypeScript. Prior to 1.6.11, the legacy oidcProvider and mcp plugins expose OAuth toke…

Fix: 1.6.11+
Fix from $2,300 2026-07-15
Better Auth HIGH 7.7
CVE-2026-53514

Better Auth is an authentication and authorization library for TypeScript. Prior to 1.6.11, and in 1.6.14 and later when invitation IDs can be obtain…

Fix: 1.6.11+
Fix from $1,950 2026-07-15
Better Auth HIGH 8.3
CVE-2026-53516

Better Auth is an authentication and authorization library for TypeScript. Prior to 1.6.11, Better Auth's OAuth callback auto-link gate in handleOAut…

Fix: 1.6.11+
Fix from $1,950 2026-07-15
Unclassified HIGH 7.5
CVE-2026-59955

Apollo is a reliable configuration management system suitable for microservice configuration management scenarios. Prior to 2.5.2, Apollo ConfigServi…

Mitigation only
Fix from $1,950 2026-07-15
Unclassified HIGH 7.5
CVE-2026-59954

Apollo is a reliable configuration management system suitable for microservice configuration management scenarios. Prior to 2.5.2, Apollo ConfigServi…

Mitigation only
Fix from $1,950 2026-07-15
Unclassified MEDIUM 6.9
CVE-2026-47159

Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.36.0, Vaultwarden's SSO discovery and pre-validation flow returned organizat…

Mitigation only
Fix from $1,600 2026-07-15