Vulnerability index

Browse CVEs

4,327 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
HIGH 8.0 CVE-2026-59224 Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.10.0, backend/open_webui/routers/terminals.py built … Open Webui 0.10.0+ Fix from $1,9502026-07-09 MEDIUM 6.5 CVE-2026-15192 A vulnerability has been found in mettle sendportal up to 3.0.1. This issue affects the function sendgrid/postmark/postal/mailjet of the component AP… Mitigation only Fix from $1,6002026-07-09 MEDIUM 6.8 CVE-2026-59208 n8n is an open source workflow automation platform. Prior to 2.27.4 and from 2.28.0 prior to 2.28.1, n8n instances configured with more than one trus… N8n 2.27.4+ Fix from $1,6002026-07-09 HIGH 7.4 CVE-2026-54781 CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, CoreWCF SAML token validation… Patch available Fix from $1,9502026-07-08 HIGH 8.2 CVE-2026-59822 LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.84.0, LiteLLM's MCP Streamable HTTP endpoint allowed… Litellm 1.84.0+ Fix from $1,9502026-07-08 HIGH 8.8 CVE-2026-58253 NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.0, 2.12.7, and 2.11.16, when no_auth_… Nats Server 2.11.16 / 2.12.7+ Fix from $1,9502026-07-08 MEDIUM 5.9 CVE-2026-55761 Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage Docker, Swarm, Kuber… Portainer 2.39.4 / 2.43.0+ Fix from $1,6002026-07-08 CRITICAL 9.8 CVE-2026-9695 An Improper Authentication vulnerability affecting DELMIA Apriso from Release 2020 through Release 2026 could allow an attacker to gain privileged ac… Mitigation only Fix from $2,3002026-07-08 HIGH 7.4 CVE-2026-55076 Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2, Coder's … Coder 2.29.17 / 2.32.7+ Fix from $1,9502026-07-07 CRITICAL 9.8 CVE-2026-37270 Trueview Security camera T18161- AF v4.9.60.0 contains an authentication bypass vulnerability caused by improper password validation and the presence… Mitigation only Fix from $2,3002026-07-07 CRITICAL 9.8 CVE-2026-37271 Fire-Boltt Smartwatch FB BGS001 Firmware: MOY-JS14-2.0.4 is vulnerable to Improper Authentication, The device accepts GATT Write Request commands wit… Mitigation only Fix from $2,3002026-07-07 HIGH 7.4 CVE-2026-55075 Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2, two flaw… Coder 2.29.17 / 2.32.7+ Fix from $1,9502026-07-07 CRITICAL 9.8 CVE-2026-53483 Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 throug… Data Domain Operating System 7.13.1.80 / 8.3.1.40+ Fix from $2,3002026-07-07 HIGH 7.5 CVE-2026-55727 A flaw in the authentication mechanism for video stream requests in Genetec Security Center 5.14.0.0 prior to build 5.14.178.18 may allow an unauthen… Mitigation only Fix from $1,9502026-07-06 HIGH 8.1 CVE-2026-40138 A critical pre-authentication vulnerability exists in the authentication subsystem of BeyondTrust Remote Support and Privileged Remote Access. Improp… Privileged Remote Access 25.3.3+ Fix from $1,9502026-07-06 CRITICAL 9.8 CVE-2026-40139 A critical pre-authentication vulnerability exists in the authentication subsystem of BeyondTrust Remote Support. Improper processing of authenticati… Privileged Remote Access 25.3.3+ Fix from $2,3002026-07-06 CRITICAL 9.8 CVE-2026-53913 Improper Authentication, Missing Authentication for Critical Function, Not Failing Securely ('Failing Open') vulnerability in Apache Camel Keycloak C… Camel 4.18.3 / 4.21.0+ Fix from $2,3002026-07-06 MEDIUM 6.5 CVE-2026-14714 A weakness has been identified in zhayujie chatgpt-on-wechat CowAgent 2.1.0. This issue affects the function verify_server of the file channel/wechat… Patch available Fix from $1,6002026-07-05 MEDIUM 5.6 CVE-2026-14627 A security vulnerability has been detected in NousResearch hermes-agent up to 0.15.2. This affects the function DiscordAdapter._is_allowed_user of th… Mitigation only Fix from $1,6002026-07-04 HIGH 8.3 CVE-2026-12196 HestiaCP panel cronjob feature is affected by a broken access control vulnerability. Low privilege users can modify the panel cronjob to execute scri… Patch available Fix from $1,9502026-07-04 HIGH 7.3 CVE-2026-14622 A vulnerability was found in jairiidriss restaurant-website-php-mysql up to 521428b5b612449df0cf4a5d15ee40cba67f3d35. This vulnerability affects unkn… Mitigation only Fix from $1,9502026-07-04 HIGH 7.7 CVE-2026-58423 LFS authentication bypass via malformed SSH sub-verb allows unauthorized read access to private repositories Patch available Fix from $1,9502026-07-03 CRITICAL 9.4 CVE-2026-52830 fast-mcp-telegram is a Telegram MCP Server. Prior to 0.19.1, fast-mcp-telegram validates HTTP Bearer tokens by joining the raw token string into a se… No fix yet Fix from $2,3002026-07-02 MEDIUM 6.5 CVE-2026-58029 Vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/Api/ApiChangeAuthenticationData.Php, … Mediawiki 1.43.9 / 1.44.6+ Fix from $1,6002026-07-01 HIGH 8.7 CVE-2026-58399 @acastellon/auth is an authentication control system for microservices. Versions prior to 2.3.0 appear to allow an unauthenticated authentication byp… Mitigation only Fix from $1,9502026-07-01 CRITICAL 9.8 CVE-2026-11387 The SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery plugin for WordPress is vulnerable to privilege escalation v… Mitigation only Fix from $2,3002026-07-01 HIGH 7.5 CVE-2026-56219 Capgo before 12.128.2 contains a NULL-auth bypass vulnerability in the public.get_org_user_access_rbac function that allows unauthenticated attackers… Mitigation only Fix from $1,9502026-06-30 CRITICAL 9.1 CVE-2026-10560 IBM Langflow OSS 1.0.0 through 1.9.6 contains a missing authentication vulnerability in /api/v1/build_public_tmp/ endpoints that allows an unauthenti… Langflow after 1.9.6 Fix from $2,3002026-06-30 MEDIUM 6.5 CVE-2026-55955 Improper Authentication vulnerability in Apache Tomcat allowed a replay attack against the EncryptionInterceptor in the cluster component. This issu… Tomcat 9.0.119 / 10.1.56+ Fix from $1,6002026-06-29 HIGH 7.5 CVE-2026-41896 Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.474, the HMAC key is the appl… Mitigation only Fix from $1,9502026-06-29