Vulnerability index

Browse CVEs

4,327 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
Unclassified CRITICAL 9.9
CVE-2026-44986

Penpot is an open-source design tool for design and code collaboration. Prior to 2.14.5, Penpot exposed teams_invitations.clj invitation tokens from …

Mitigation only
Fix from $2,300 2026-07-15
Unclassified CRITICAL 9.3
CVE-2026-61740

LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.5.4, when LightRAG is deployed with LIGHTRAG_API_KEY set but AUTH_ACCOUN…

Mitigation only
Fix from $2,300 2026-07-15
Unclassified HIGH 8.2
CVE-2026-61435

PraisonAI before 4.6.78 contains an authentication bypass in the Call API agent invocation endpoints (src/praisonai/praisonai/api/agent_invoke.py) wh…

Mitigation only
Fix from $1,950 2026-07-15
Unclassified HIGH 8.6
CVE-2026-61436

PraisonAI before 4.6.78 fails to verify Svix webhook signatures in AgentMail webhook mode, allowing unauthenticated attackers to forge message.receiv…

Mitigation only
Fix from $1,950 2026-07-15
Unclassified HIGH 8.1
CVE-2026-12281

The Shibboleth WordPress plugin before 2.5.4 does not fail closed when its HTTP header identity mode is enabled without an anti-spoofing key, treatin…

Mitigation only
Fix from $1,950 2026-07-15
Unclassified CRITICAL 9.8
CVE-2026-5270

An authentication bypass vulnerability exists in certain releases of Ciena Navigator Network Control Suite (NCS), Manage Control Plan (MCP), and Blue…

Mitigation only
Fix from $2,300 2026-07-14
Unclassified CRITICAL 9.1
CVE-2026-45363

ruby-jwt is a Ruby implementation of the RFC 7519 OAuth JSON Web Token standard. Prior to 2.10.3 and 3.2.0, JWT.decode(token, '', true, algorithm: 'H…

Mitigation only
Fix from $2,300 2026-07-14
Symfony MEDIUM 5.3
CVE-2026-45754

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 6.4.40, 7.4.12, and 8.0.12, the Mailjet ma…

Fix: 6.4.40 / 7.4.12+
Fix from $1,600 2026-07-14
Windows 10 1607 HIGH 8.0
CVE-2026-50365

Improper authentication in Windows RPC API allows an unauthorized attacker to elevate privileges over an adjacent network.

Fix: 10.0.14393.9339 / 10.0.17763.9020+
Fix from $1,950 2026-07-14
Windows Admin Center HIGH 8.8
CVE-2026-56169

Improper authentication in Windows Admin Center allows an authorized attacker to elevate privileges over a network.

Fix: 2606+
Fix from $1,950 2026-07-14
Windows Admin Center MEDIUM 6.5
CVE-2026-56185

Improper authentication in Windows Admin Center allows an authorized attacker to disclose information over a network.

Fix: 2511+
Fix from $1,600 2026-07-14
Windows Admin Center HIGH 7.8
CVE-2026-57107

Improper authentication in Windows Admin Center allows an authorized attacker to elevate privileges locally.

Fix: 2606+
Fix from $1,950 2026-07-14
Azure Spring Cloud HIGH 8.2
CVE-2026-50338

Improper authentication in Azure Spring Apps allows an authorized attacker to elevate privileges over a network.

Fix: 7.3.0+
Fix from $1,950 2026-07-14
Unclassified HIGH 8.7
CVE-2026-22099

The charging station does not require authentication for Bluetooth commands to perform actions. The functionality exposed includes sensitive informat…

Mitigation only
Fix from $1,950 2026-07-13
Unclassified HIGH 7.3
CVE-2026-15557

A weakness has been identified in waooAI waoowaoo up to 0.4.1. Affected by this vulnerability is the function getInternalTaskSession/getAuthSession/r…

Mitigation only
Fix from $1,950 2026-07-13
Unclassified HIGH 7.3
CVE-2026-15542

A vulnerability has been found in will-moss Isaiah up to 1.36.9. This affects an unknown function of the file app/main.go of the component Websocket …

Patch available
Fix from $1,950 2026-07-13
Unclassified HIGH 7.3
CVE-2026-15491

A weakness has been identified in RafyMrX TOKO-ONLINE-ROTI up to ddfe1cd587be0a0b5135d8b6e85cce2ec3aece99. This affects an unknown part. This manipul…

No fix yet
Fix from $1,950 2026-07-12
Unclassified MEDIUM 5.9
CVE-2026-15087

vulnerability in Drupal Clean RESTful allows . This issue affects Clean RESTful versions: *.*.

No fix yet
Fix from $1,600 2026-07-10
Unclassified CRITICAL 9.1
CVE-2026-15089

vulnerability in Drupal Commerce guest registration allows . This issue affects Commerce guest registration versions: *.*.

No fix yet
Fix from $2,300 2026-07-10
Rabbitmq Server CRITICAL 10.0
CVE-2026-57216

RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.20, 4.1.11, and 4.2.6, AMQP 0-9-1, AMQP 1.0, and Stream Protocol authentication c…

Fix: 4.2.6+
Fix from $2,300 2026-07-10
Unclassified CRITICAL 9.8
CVE-2026-12761

The miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) plugin for WordPress is vulnerable to authentication bypass leading to …

Mitigation only
Fix from $2,300 2026-07-10
Unclassified HIGH 8.1
CVE-2026-55377

Logto is the modern, open-source auth infrastructure for SaaS and AI apps. Prior to 1.41.0, Logto's Account Center step-up check accepted any active …

Patch available
Fix from $1,950 2026-07-10
Unclassified CRITICAL 9.6
CVE-2026-59151

Prowler is a cloud security platform. Prior to 5.30.3, Prowler's SAML authentication flow trusted the email domain asserted in a SAMLResponse when de…

Patch available
Fix from $2,300 2026-07-10
Unclassified HIGH 7.4
CVE-2026-55672

ZITADEL is an open source identity management platform. Prior to 3.4.12 and 4.15.2, ZITADEL's OAuth2 and OIDC CodeExchange, RefreshToken, and device …

Patch available
Fix from $1,950 2026-07-10
Unclassified HIGH 8.3
CVE-2026-56675

9Router is an AI router & token saver. Prior to 0.5.2, 9router treats loopback requests as trusted and allows /v1/* access without an API key, so a s…

Patch available
Fix from $1,950 2026-07-10
Unclassified MEDIUM 6.5
CVE-2026-56312

Capgo before 12.128.2 contains an improper validation vulnerability in the accept_invitation endpoint that creates user accounts before captcha valid…

Mitigation only
Fix from $1,600 2026-07-10
Unclassified HIGH 8.1
CVE-2026-12595

The LoginPress Pro plugin for WordPress is vulnerable to Authentication Bypass via Unverified OAuth Email in all versions up to and including 6.2.3. …

Mitigation only
Fix from $1,950 2026-07-10
Unclassified HIGH 8.1
CVE-2026-12597

The LoginPress Pro plugin for WordPress is vulnerable to Authentication Bypass via the GitHub OAuth callback in versions up to, and including, 6.2.3.…

Mitigation only
Fix from $1,950 2026-07-10
Unclassified HIGH 8.1
CVE-2026-12598

The LoginPress Pro plugin for WordPress is vulnerable to authentication bypass in versions up to and including 6.2.3 via the Spotify Social Login add…

Mitigation only
Fix from $1,950 2026-07-10
Helm Charts HIGH 8.1
CVE-2026-55689

OpenFGA is an authorization/permission engine built for developers. Prior to 1.18.0, OpenFGA's OIDC authenticator skipped JWT audience validation whe…

Fix: 0.3.9 / 1.18.0+
Fix from $1,950 2026-07-09