Vulnerability index

Browse CVEs

4,327 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
MEDIUM 5.3 CVE-2026-49843 FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation tha… Freeswitch 1.11.1+ Fix from $1,6002026-06-09 HIGH 7.8 CVE-2026-44810 Improper authentication in Windows Cryptographic Services allows an unauthorized attacker to elevate privileges locally. Windows 11 23h2 10.0.20348.5256 / 10.0.22631.7219+ Fix from $1,9502026-06-09 HIGH 7.4 CVE-2026-41720 Spring LDAP's DirContextAuthenticationStrategy implementations do not reject a bind request where a non-empty username is paired with an empty or nul… No fix yet Fix from $1,9502026-06-09 HIGH 7.3 CVE-2026-11618 A vulnerability was determined in DTStack Taier up to 1.4.0. The affected element is the function preHandle of the file taier-data-develop/src/main/j… Patch available Fix from $1,9502026-06-09 CRITICAL 9.3 CVE-2026-50751 KEVEPSS 83% A logic flow weakness in Remote Access and Mobile Access certificate validation in deprecated IKEv1 key exchange allows an unauthenticated remote att… Gaia Os Patch available Fix from $2,3002026-06-08 HIGH 7.0 CVE-2026-34123 On Tapo C520WS v2, restricted accounts (for example, hub users) are intended to execute only a limited set of low‑sensitivity operations. Due to a lo… Mitigation only Fix from $1,9502026-06-06 CRITICAL 9.8 CVE-2026-46389 UDS Identity Config builds the Keycloak configuration image (realm, plugins, theme, truststore, JARs) consumed by UDS Core's Identity deployment. In … Uds Identity Config 0.26.1+ Fix from $2,3002026-06-05 MEDIUM 6.9 CVE-2026-11345 An Improper Authentication vulnerability in the /api/Cdn/GetFile endpoint of linqi allows unauthenticated, remote attackers to bypass file access con… Mitigation only Fix from $1,6002026-06-05 CRITICAL 9.8 CVE-2026-6274 Improper Authentication, Missing authentication for critical function, Weak Authentication vulnerability in DTS Electronics Industry and Trade Ltd. C… Mitigation only Fix from $2,3002026-06-05 MEDIUM 5.9 CVE-2023-5502 On affected platforms running Arista EOS with 802.1x authentication configured on the access/trunk ports, and routing enabled on the access VLAN of t… Mitigation only Fix from $1,6002026-06-04 CRITICAL 9.8 CVE-2026-49191 The production build of the M3WebServer hard-codes its backend API keys, which can be easily intercepted through verbose error handling pages. Connect M6e 5g Firmware Mitigation only Fix from $2,3002026-06-04 HIGH 8.8 CVE-2026-49194 The debugging routine SCREEN_CLICK(5053) enables a connection to skip the standard device login prompt entirely and directly enter an interactive she… Connect M6e 5g Firmware Mitigation only Fix from $1,9502026-06-04 HIGH 8.6 CVE-2026-49202 Internal multimedia session archives are accessible without authentication, exacerbated by loose Cross-Origin Resource Sharing (CORS) rules that allo… Connect M6e 5g Firmware Mitigation only Fix from $1,9502026-06-04 HIGH 8.3 CVE-2026-49203 Crucial management API endpoints for cellular eSIM allocation do not validate caller authorization, allowing remote profiles to be rewritten or delet… Connect M6e 5g Firmware Mitigation only Fix from $1,9502026-06-04 CRITICAL 9.8 CVE-2026-49186 The local MQTT broker does not enforce topic-level Access Control Lists (ACLs). This allows any client to subscribe using wildcard characters (# or +… Connect M6e 5g Firmware Mitigation only Fix from $2,3002026-06-04 HIGH 7.3 CVE-2026-10777 A vulnerability was identified in ealpha072 Student-Management-System up to 01451bd7a2f58cdda07bd0b86e3967582e3ecd08. Affected by this issue is some … Mitigation only Fix from $1,9502026-06-03 HIGH 8.8 CVE-2026-49443 authentik is an open-source identity provider. Prior to versions 2025.12.6, 2026.2.4, and 2026.5.1, an attacker with the ability to change a source c… Authentik 2025.12.6 / 2026.2.4+ Fix from $1,9502026-06-02 CRITICAL 9.8 CVE-2026-49448 authentik is an open-source identity provider. Prior to versions 2025.12.6, 2026.2.4, and 2026.5.1, the Source stage can be bypassed by sending an em… Authentik 2025.12.6 / 2026.2.4+ Fix from $2,3002026-06-02 MEDIUM 5.3 CVE-2026-45289 CloudburstMC Protocol is a protocol library for Minecraft Bedrock Edition. Prior to version 3.0.0.Beta12-20260420.182526-15, CloudburstMC Protocol is… Mitigation only Fix from $1,6002026-06-02 HIGH 7.3 CVE-2026-10619 A vulnerability was detected in sayan365 student-management-system up to 7f3c9ce7d410332335c2affac93a385485051800. This impacts an unknown function. … Mitigation only Fix from $1,9502026-06-02 CRITICAL 9.8 CVE-2026-5076 The ARMember Premium plugin for WordPress is vulnerable to an insecure password reset mechanism in all versions up to, and including, 7.3.1. The plug… Mitigation only Fix from $2,3002026-06-02 HIGH 7.3 CVE-2026-10617 A security vulnerability has been detected in nextlevelbuilder GoClaw up to 3.11.3. This affects the function resolveAuth of the file internal/http/a… Mitigation only Fix from $1,9502026-06-02 CRITICAL 10.0 CVE-2026-10611 An authentication bypass vulnerability exists in MISP when LDAP mixed authentication is enabled with OTP enforcement. In deployments configured with … Misp 2.5.39+ Fix from $2,3002026-06-02 HIGH 7.5 CVE-2026-8293 The Really Simple Security WordPress plugin before 9.5.10.1 does not enforce the second-factor challenge in two of its two-factor authentication RES… Mitigation only Fix from $1,9502026-06-02 MEDIUM 5.3 CVE-2026-10548 A security flaw has been discovered in NousResearch hermes-agent up to 2026.4.23. This affects the function _sync_anthropic_entry_from_credentials_fi… Mitigation only Fix from $1,6002026-06-02 HIGH 7.5 CVE-2026-40964 Authentication Bypass in cf-auth-proxy in Cloud Foundry Foundation all installations allows an unauthenticated remote attacker to gain read access to… Mitigation only Fix from $1,9502026-06-01 HIGH 7.3 CVE-2026-10288 A vulnerability was identified in code-projects Hotel and Tourism Reservation System 1.0. This issue affects the function password_verify of the file… Mitigation only Fix from $1,9502026-06-01 MEDIUM 5.9 CVE-2026-45690 Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 32.0.0 to before 32.0.9, and 33.0.0 to before 33.0.3, a… Nextcloud Server 29.0.16.16 / 30.0.17.9+ Fix from $1,6002026-06-01 MEDIUM 5.9 CVE-2026-45691 Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 32.0.0 to before 32.0.9, and 33.0.0 to before 33.0.3, a… Nextcloud Server 29.0.16.16 / 30.0.17.9+ Fix from $1,6002026-06-01 HIGH 7.3 CVE-2026-10281 A weakness has been identified in Enderfga claw-orchestrator up to 3.5.5. This affects the function EmbeddedServer of the file src/embedded-server.ts… Patch available Fix from $1,9502026-06-01