Vulnerability index

Browse CVEs

4,327 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
HIGH 7.3 CVE-2026-13546 A vulnerability was found in Feehi CMS up to 2.1.1. This vulnerability affects unknown code of the file /api/articles of the component REST API Endpo… Mitigation only Fix from $1,9502026-06-29 MEDIUM 5.6 CVE-2026-13543 A vulnerability was detected in Documenso up to 2.11.0. Affected by this vulnerability is an unknown functionality of the file packages/auth/server/l… Patch available Fix from $1,6002026-06-29 CRITICAL 10.0 CVE-2026-49869 Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.45 and 1.3.21, AuthenticationFilter in Kestra OSS uses request.getPath().… Kestra 1.0.45 / 1.3.21+ Fix from $2,3002026-06-26 MEDIUM 6.5 CVE-2026-55962 TLS 1.3 post-handshake authentication (PHA) issue where a server could accept a client's Finished message without the client having sent a Certificat… Wolfssl 5.9.2+ Fix from $1,6002026-06-25 HIGH 7.5 CVE-2026-11703 Missing SNI/ALPN binding on stateful (session-ID) resumption, which previously skipped the binding check performed for ticket-based resumption. A cac… Wolfssl 5.9.2+ Fix from $1,9502026-06-25 CRITICAL 9.1 CVE-2026-54089 File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Starting wit… Mitigation only Fix from $2,3002026-06-25 CRITICAL 9.3 CVE-2026-55666 Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.1, 8.4.4, 8.3.6, 8.2.6, 8.1.6, 8.0.7, and 7.10.13, in… Mitigation only Fix from $2,3002026-06-24 HIGH 7.4 CVE-2026-55759 Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.1, 8.4.4, 8.3.6, 8.2.6, 8.1.6, 8.0.7, and 7.10.13, Ro… Mitigation only Fix from $1,9502026-06-24 MEDIUM 6.5 CVE-2026-13208 A flaw was found in KubeVirt's virt-handler domain notify server. The gRPC handlers for HandleDomainEvent and HandleK8SEvent derive the VMI identity … Kubevirt after 4.22.0 Fix from $1,6002026-06-24 HIGH 8.7 CVE-2026-56223 Capgo before 12.128.2 contains a cross-domain SSO account takeover vulnerability in the provision-user endpoint that allows attackers to merge arbitr… Mitigation only Fix from $1,9502026-06-24 CRITICAL 9.1 CVE-2026-56237 Capgo before 12.128.2 contains a broken authentication vulnerability in its API key generation mechanism. API keys are exposed in frontend requests, … Mitigation only Fix from $2,3002026-06-24 HIGH 7.8 CVE-2026-12112 A flaw was found in the foreman-mcp-server. A session management vulnerability in the MCP Server allows unauthenticated attackers to hijack active ad… Satellite Mitigation only Fix from $1,9502026-06-23 HIGH 8.4 CVE-2026-54320 Daytona is a secure and elastic infrastructure runtime for AI-generated code execution and agent workflows. Prior to 0.184.0, organization invitation… Mitigation only Fix from $1,9502026-06-23 HIGH 8.1 CVE-2026-52845 Caddy is an extensible server platform that uses TLS by default. Prior to 2.11.4, forward_auth copy_headers deletes the exact client-supplied identit… Caddy 2.11.4+ Fix from $1,9502026-06-23 CRITICAL 9.0 CVE-2026-11374 In ManageEngine ADSelfService Plus, RecoveryManager Plus, M365 Manager Plus, and ADAudit Plus, the SSO tickets generated to authenticate that session… Mitigation only Fix from $2,3002026-06-23 CRITICAL 9.8 CVE-2026-7664 IBM Langflow OSS 1.0.0 through 1.8.4 could allow unauthenticated attackers to access protected MCP project resources and execute MCP operations due t… Langflow after 1.8.4 Fix from $2,3002026-06-22 HIGH 7.3 CVE-2026-10845 IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to bypass authentication and gain unauthorized access to JAX-WS applicatio… Websphere Application Server 8.5.5.30 / 9.0.5.29+ Fix from $1,9502026-06-22 HIGH 7.3 CVE-2026-12795 A vulnerability was determined in BerriAI litellm up to 1.82.2. This affects the function json.dumps of the file litellm/proxy/management_endpoints/u… Litellm after 1.82.2 Fix from $1,9502026-06-21 CRITICAL 9.8 CVE-2026-12773 A weakness has been identified in BerriAI litellm up to 1.59.8. Affected is the function UserAPIKeyAuth of the file litellm/proxy/_experimental/mcp_s… Litellm 1.59.9+ Fix from $2,3002026-06-21 HIGH 8.1 CVE-2026-56345 AVideo through 29.0 contains an authorization bypass vulnerability in the Meet plugin's uploadRecordedVideo.json.php endpoint that derives the target… Mitigation only Fix from $1,9502026-06-20 HIGH 7.5 CVE-2026-50559 Quarkus is a Java framework for building cloud-native applications. Prior to versions 3.37.0, 3.36.3, 3.33.2.1, 3.33.3, 3.27.4.1, 3.27.5, and 3.20.6.… Quarkus 3.20.6.2 / 3.27.4.1+ Fix from $1,9502026-06-19 CRITICAL 10.0 CVE-2026-45480 Improper authentication in Azure Active Directory allows an unauthorized attacker to elevate privileges over a network. Azure Active Directory No fix yet Fix from $2,3002026-06-19 HIGH 8.1 CVE-2026-49872 Improper Authentication vulnerability in Apache APISIX. When the cas-auth plugin is used in a route, an attacker can possibly authenticate itself wi… Apisix 3.17.0+ Fix from $1,9502026-06-19 HIGH 8.8 CVE-2026-32174 Improper authentication in Azure Bot Service allows an authorized attacker to elevate privileges over a network. Azure Ai Bot Service Mitigation only Fix from $1,9502026-06-18 CRITICAL 9.1 CVE-2026-49454 Relyra is a strict-by-default SAML 2.0 Service Provider library for Elixir and Phoenix. Versions 1.0.0 and 1.1.0 accept forged SAML signatures becaus… Patch available Fix from $2,3002026-06-18 CRITICAL 9.1 CVE-2026-11717 An authentication bypass vulnerability exists in the generic opaque token validation path (validateOpaqueToken) of googleapis/mcp-toolbox. When veri… Mcp Toolbox For Databases Patch available Fix from $2,3002026-06-18 CRITICAL 9.1 CVE-2026-11718 An authentication bypass vulnerability exists in the generic opaque token validation path (validateOpaqueToken) of googleapis/mcp-toolbox. When the … Mcp Toolbox For Databases Patch available Fix from $2,3002026-06-18 MEDIUM 5.5 CVE-2026-48991 XianYuLauncher is a Minecraft Java Edition launcher. In versions prior to 1.5.5, sensitive authentication artifacts could be exposed during a user-in… Patch available Fix from $1,6002026-06-17 HIGH 8.1 CVE-2026-49502 Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) an Improper Authentication vulnerability. An unauthenticated attacker with adjacent n… Powerflex Manager 4.5.5.2 / 5.1.0.1+ Fix from $1,9502026-06-17 MEDIUM 6.8 CVE-2026-48117 DroneAware is a drone detection platform. The centralized DroneAware server backing droneaware.io was vulnerable to an account pre-hijacking attack i… Mitigation only Fix from $1,6002026-06-17