Vulnerability index

Browse CVEs

4,327 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
HIGH 8.1 CVE-2026-32804 Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) an Improper Authentication vulnerability. An unauthenticated attacker with adjacent n… Powerflex Manager 4.5.5.2 / 5.1.0.1+ Fix from $1,9502026-06-17 HIGH 7.5 CVE-2026-48929 Rocket.Chat in versions <8.5.1, <8.4.4, <8.3.6, <8.2.6, <8.1.6, <8.0.7, <7.13.9, and <7.10.13 is vulnerable to unauthenticated file deletion. The del… Rocket.chat 7.10.13 / 7.13.9+ Fix from $1,9502026-06-17 HIGH 8.8 CVE-2026-46972 Vulnerability in the Oracle Outsourced Mfg for Discrete Industries product of Oracle E-Business Suite (component: Internal Operations). Supported ve… Outsourced Manufacturing For Discrete Industries after 12.2.15 Fix from $1,9502026-06-17 HIGH 8.8 CVE-2026-46973 Vulnerability in the Oracle Outsourced Mfg for Discrete Industries product of Oracle E-Business Suite (component: Internal Operations). Supported ve… Outsourced Manufacturing For Discrete Industries after 12.2.15 Fix from $1,9502026-06-17 HIGH 8.8 CVE-2026-46961 Vulnerability in the Oracle Project Portfolio Analysis product of Oracle E-Business Suite (component: Internal Operations). Supported versions that … Project Portfolio Analysis after 12.2.15 Fix from $1,9502026-06-17 HIGH 8.8 CVE-2026-46962 Vulnerability in the Oracle Project Portfolio Analysis product of Oracle E-Business Suite (component: Internal Operations). Supported versions that … Project Portfolio Analysis after 12.2.15 Fix from $1,9502026-06-17 HIGH 8.8 CVE-2026-46951 Vulnerability in the Oracle Quality product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12… Quality after 12.2.15 Fix from $1,9502026-06-17 HIGH 8.8 CVE-2026-46952 Vulnerability in the Oracle Quality product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12… Quality after 12.2.15 Fix from $1,9502026-06-17 HIGH 8.8 CVE-2026-46937 Vulnerability in the Oracle iSetup product of Oracle E-Business Suite (component: General Ledger Update Transform, Reports). Supported versions that… Isetup after 12.2.15 Fix from $1,9502026-06-17 HIGH 8.8 CVE-2026-46940 Vulnerability in the Oracle Cost Management product of Oracle E-Business Suite (component: Cost Planning). Supported versions that are affected are … Cost Management after 12.2.15 Fix from $1,9502026-06-17 HIGH 8.8 CVE-2026-46942 Vulnerability in the Oracle Process Manufacturing Process Planning product of Oracle E-Business Suite (component: Internal Operations). Supported ve… Process Manufacturing Process Planning after 12.2.15 Fix from $1,9502026-06-17 HIGH 8.8 CVE-2026-46928 Vulnerability in the Oracle Spares Management product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affec… Spares Management after 12.2.15 Fix from $1,9502026-06-17 HIGH 8.8 CVE-2026-46929 Vulnerability in the Oracle Cost Management product of Oracle E-Business Suite (component: Cost Planning). Supported versions that are affected are … Cost Management after 12.2.15 Fix from $1,9502026-06-17 HIGH 8.8 CVE-2026-46916 Vulnerability in the Oracle Process Manufacturing Product Development product of Oracle E-Business Suite (component: Quality Management Specs). Supp… Process Manufacturing Product Development after 12.2.15 Fix from $1,9502026-06-17 CRITICAL 9.8 CVE-2026-46919 Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager). Supported versions that are affec… Siebel Crm after 26.5 Fix from $2,3002026-06-17 HIGH 8.8 CVE-2026-46921 Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager). Supported versions that are affec… Siebel Crm after 26.5 Fix from $1,9502026-06-17 HIGH 8.8 CVE-2026-46903 Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Business Logic Infrastructure Security). Supported vers… Jd Edwards Enterpriseone Tools after 9.2.26.2 Fix from $1,9502026-06-17 CRITICAL 9.8 CVE-2026-46890 Vulnerability in the Siebel Apps - Marketing product of Oracle Siebel CRM (component: Marketing). Supported versions that are affected are 17.0-26.5… Siebel Apps Marketing after 26.5 Fix from $2,3002026-06-17 CRITICAL 9.8 CVE-2026-46859 Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Security). The supported version that is affected is 9.3.6. Easily… Agile Plm Mitigation only Fix from $2,3002026-06-17 MEDIUM 6.5 CVE-2026-35261 Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that are affec… Access Manager Mitigation only Fix from $1,6002026-06-17 HIGH 8.2 CVE-2026-48780 Forem is open source software for building communities. Prior to commit a2ab6d4, a maliciously crafted email address could allow an attacker to bypas… Patch available Fix from $1,9502026-06-16 CRITICAL 9.8 CVE-2026-48114 Metacat is data repository software that helps researchers preserve, share, and discover data. Versions 2.0.0 and and above contain an unauthenticate… Patch available Fix from $2,3002026-06-15 CRITICAL 9.8 CVE-2026-12183 Nefteprodukttekhnika BUK TS-G Gas Station Automation System 2.9.1 through 2.10.2 on Linux contains an Improper Authentication vulnerability (CWE-287)… Mitigation only Fix from $2,3002026-06-13 CRITICAL 9.8 CVE-2026-48611 Improper authentication checks in the OAuth implementation allow account hijacking even when OAuth is not configured or enabled leading to unauthoriz… Mitigation only Fix from $2,3002026-06-12 MEDIUM 5.4 CVE-2026-40995 X509AuthenticationProvider could issue a fully authenticated X509AuthenticationToken when a presented certificate mapped to UserDetails, without appl… Mitigation only Fix from $1,6002026-06-11 MEDIUM 5.7 CVE-2026-47166 ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-48 and 7.1.2-23, an attacker … Imagemagick 6.9.13-48 / 7.1.2-23+ Fix from $1,6002026-06-10 MEDIUM 5.3 CVE-2026-46705 Russh is a Rust SSH client & server library. From version 0.34.0-beta.1 to before version 0.61.0, the russh server authentication path keeps internal… Mitigation only Fix from $1,6002026-06-10 HIGH 8.3 CVE-2026-45567 Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, there is an authentication bypa… Mitigation only Fix from $1,9502026-06-10 HIGH 8.1 CVE-2026-47838 SubjectDnX509PrincipalExtractor does not correctly handle certain malformed X.509 certificate CN values, which can lead to reading the wrong value fo… Spring Security 5.7.25 / 5.8.27+ Fix from $1,9502026-06-10 CRITICAL 9.1 CVE-2026-36727 An insecure authentication vulnerability in the /api/social-sign-in endpoint of bookcars v8.3 allows attackers to bypass authentication via a forged … Mitigation only Fix from $2,3002026-06-09