Vulnerability index

Browse CVEs

4,327 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
HIGH 7.6 CVE-2026-53958 4gaBoards is a boards system for realtime project management. Prior to 3.3.9, 4gaBoards allows an authenticated user to modify ssoGoogleId, ssoGoogle… Fix unknown Fix from $4,9002026-08-18 HIGH 8.8 CVE-2026-50191 4gaBoards is a boards system for realtime project management. Prior to 3.3.8, 4gaBoards is vulnerable to pre-account takeover when registrationEnable… Fix unknown Fix from $4,9002026-08-18 HIGH 8.7 CVE-2026-15315 Tapo C200 v5 contains an improper authentication vulnerability within the login authentication verification module. An attacker on the local network … Fix unknown Fix from $4,9002026-08-18 HIGH 8.1 CVE-2026-52793 Froxlor is open source server administration software. Prior to 2.3.7, the API authentication path in lib/Froxlor/Api/FroxlorRPC.php and FroxlorRPC::… Fix unknown Fix from $4,9002026-08-18 HIGH 8.1 CVE-2026-44472 Saleor is an e-commerce platform. From 2.10.0rc1 until 3.21.67, 3.22.63, and 3.23.22, the account activation flow treats email verification as suffic… Fix unknown Fix from $4,9002026-08-18 HIGH 8.2 CVE-2026-73337 Joomla! Core - [20260807] - MFA Authentication Bypass in Joomla 4.0.0-5.4.7 and 6.0.0-6.1.2 - Insufficient state checks lead to a vector that allows … Fix unknown Fix from $4,9002026-08-18 MEDIUM 5.9 CVE-2026-65329 An authentication issue was addressed with improved state management. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1. An attacker in a privilege… Ipados Fix unknown Fix from $4,0002026-08-17 HIGH 7.7 CVE-2025-27621 UpTrain is an open-source platform to evaluate and improve generative AI applications. In version 0.7.1 and prior, the UpTrain backend creates a new … Fix unknown Fix from $4,9002026-08-17 CRITICAL 9.8 CVE-2026-74894 openssl_encrypt before 1.4.0 contains an authentication bypass vulnerability in the verify_api_token function that accepts any non-empty Bearer token… Fix unknown Fix from $5,7502026-08-17 CRITICAL 10.0 CVE-2026-19977 A vulnerability was detected in EFM ipTIME A3004T 14.19.0. The affected element is the function httpcon_check_session_url of the component Session Va… Fix unknown Fix from $5,7502026-08-17 MEDIUM 5.6 CVE-2026-19974 A security flaw has been discovered in treefrogframework treefrog-framework up to 2.11.2. This vulnerability affects the function std::strncmp of the… Fix unknown Fix from $4,0002026-08-17 CRITICAL 9.1 CVE-2026-19714 The Simple JWT Login WordPress plugin before 3.6.8 does not validate the audience of the Google identity tokens it accepts, allowing unauthenticated… Fix unknown Fix from $5,7502026-08-16 MEDIUM 5.7 CVE-2026-15384 The Manual Image Crop WordPress plugin before 1.15 does not perform any capability check or nonce verification on the authenticated AJAX action that … Fix unknown Fix from $4,0002026-08-16 CRITICAL 9.8 CVE-2026-19924 A security vulnerability has been detected in Tenda AC10 16.03.10.09_multi_TDE01. This vulnerability affects the function R7WebsSecurityHandler of th… No fix yet Fix from $5,7502026-08-16 HIGH 7.5 CVE-2026-73054 SiYuan versions before v3.7.4 contain an authentication bypass vulnerability in the WebSocket endpoint caused by differential parsing of query parame… No fix yet Fix from $4,9002026-08-15 MEDIUM 6.5 CVE-2026-18216 The Backup Migration WordPress plugin before 2.1.7 does not properly restrict a post-restore automatic login mechanism, allowing a user who administe… Fix unknown Fix from $4,0002026-08-15 CRITICAL 9.8 CVE-2026-15303 The 6Storage Rentals plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.27.0. This is due to the six_sto… No fix yet Fix from $5,7502026-08-15 CRITICAL 9.8 CVE-2026-15341 The User Session Synchronizer plugin for WordPress is vulnerable to Authentication Bypass leading to Account Takeover in all versions up to, and incl… No fix yet Fix from $5,7502026-08-15 MEDIUM 5.4 CVE-2026-74240 A flaw was found in Red Hat Quay's JWT (JSON Web Token) validation for federated robot accounts and single sign-on (SSO) authentication. Multiple iss… No fix yet Fix from $4,0002026-08-14 HIGH 7.5 CVE-2026-17175 IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to obtain sensitive information due to improper authentication enf… No fix yet Fix from $4,9002026-08-14 CRITICAL 9.8 CVE-2026-17182 IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to bypass authentication and obtain or alter sensitive information due to improp… No fix yet Fix from $5,7502026-08-14 MEDIUM 5.3 CVE-2026-16905 IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to obtain sensitive information due to improper authentication. No fix yet Fix from $4,0002026-08-14 CRITICAL 9.8 CVE-2026-48528 Metacat is data repository software that helps researchers preserve, share, and discover data. Metacat versions 2.0.0 through 3.4.0 contain an unauth… No fix yet Fix from $5,7502026-08-14 MEDIUM 5.9 CVE-2026-16739 The Epeken All Kurir for Woocommerce WordPress plugin through 2.1.2 does not verify that a payment-confirmation request originates from the owner of … No fix yet Fix from $4,0002026-08-14 MEDIUM 5.3 CVE-2026-73840 OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.0.3, 1.1.3, and 1.2.0-rc.2, the POST /api/v1alpha1/autobuild endp… No fix yet Fix from $4,0002026-08-13 CRITICAL 9.0 CVE-2026-73302 Budibase is an open-source low-code platform. Prior to 3.39.30, the OIDC flow in packages/backend-core/src/middleware/passport/sso/oidc.ts resolved a… No fix yet Fix from $5,7502026-08-13 HIGH 7.3 CVE-2026-17099 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to obtain sensitive information due to improper authentication. No fix yet Fix from $4,9002026-08-13 HIGH 8.3 CVE-2026-17101 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to execute arbitrary code or obtain sensitive information due to improper authentication. No fix yet Fix from $4,9002026-08-13 MEDIUM 6.5 CVE-2026-17075 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to obtain sensitive information and perform unauthorized operations due to improper valida… No fix yet Fix from $4,0002026-08-13 HIGH 7.4 CVE-2026-73655 Trigger.dev is a platform for building and deploying fully managed AI agents and workflows. Prior to 4.5.2, addGoogleStrategy() in apps/webapp/app/se… No fix yet Fix from $4,9002026-08-13