Vulnerability index

Browse CVEs

4,327 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
MEDIUM 6.3 CVE-2026-10283 A vulnerability was detected in Bottelet DaybydayCRM up to 2.2.1. Affected is an unknown function of the component Setting Handler. Performing a mani… Patch available Fix from $1,6002026-06-01 HIGH 8.1 CVE-2026-45156 Nextcloud is an open source content collaboration platform. From versions 0.3.0 to before 3.1.0, 5.0.0 to before 5.1.0, and 6.0.0 to before 6.4.0, a … Patch available Fix from $1,9502026-06-01 HIGH 7.3 CVE-2026-10243 A security vulnerability has been detected in code-projects Smart Parking System 1.0. Affected is an unknown function of the component Admin Endpoint… Mitigation only Fix from $1,9502026-06-01 HIGH 7.3 CVE-2026-10167 A weakness has been identified in OUSL-GROUP-BrinaryBrains School Student Management System up to 1e70e5ad1125b86dca4ee086eb6bb121f17708b6. This impa… Mitigation only Fix from $1,9502026-05-31 HIGH 7.3 CVE-2026-10157 A vulnerability was identified in Open5GS up to 2.7.6. This impacts an unknown function of the file src/amf/ngap-handler.c of the component NGAP Path… Patch available Fix from $1,9502026-05-31 HIGH 7.5 CVE-2026-46579 A flaw was found in the OpenShift Router. When a Route has `insecureEdgeTerminationPolicy` set to Allow, the HTTP frontend does not remove `X-SSL-Cli… Openshift Container Platform Mitigation only Fix from $1,9502026-05-29 CRITICAL 9.8 CVE-2026-49197 Web endpoints intended for the Acer Connect app improperly validate the HTTP Authorization header, failing to block requests when Base64 decoding fai… Predator Connect W6x Firmware Mitigation only Fix from $2,3002026-05-29 CRITICAL 9.8 CVE-2026-3655 The OTP Login With Phone Number, OTP Verification plugin for WordPress is vulnerable to authentication bypass in versions 1.8.50 through 1.8.60. This… Mitigation only Fix from $2,3002026-05-29 CRITICAL 10.0 CVE-2026-46840 Vulnerability in Oracle REST Data Services (component: Backend-as-a-Service). Supported versions that are affected are 24.2.0-26.1.0. Easily exploit… Rest Data Services after 26.1.0 Fix from $2,3002026-05-28 HIGH 8.8 CVE-2026-46827 Vulnerability in the Oracle Payroll product of Oracle E-Business Suite (component: Self Service Manager). Supported versions that are affected are 1… E Business Suite after 12.2.15 Fix from $1,9502026-05-28 CRITICAL 9.8 CVE-2026-46817 KEVEPSS 13% Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affected are 12.… E Business Suite after 12.2.15 Fix from $2,3002026-05-28 HIGH 7.4 CVE-2026-48526 PyJWT is a JSON Web Token implementation in Python. Prior to 2.13.0, when the verifier is decoding JSON Web Tokens, while supporting both asymmetric … Pyjwt 2.13.0+ Fix from $1,9502026-05-28 CRITICAL 9.3 CVE-2026-8979 The Mennekes Amtron series (firmware versions ≤ 5.22.3) is vulnerable to an authentication bypass. An unauthenticated remote attacker can change the … Mitigation only Fix from $2,3002026-05-28 MEDIUM 6.9 CVE-2026-44720 OpenLearnX is an open-source, decentralized learning and assessment platform. Prior to 2.0.4, a critical authentication vulnerability was identified … Mitigation only Fix from $1,6002026-05-27 HIGH 7.9 CVE-2026-44711 pam_usb provides hardware authentication for Linux using ordinary removable media. Prior to 0.8.7, symlink attacks on pad directory and pad files ena… Mitigation only Fix from $1,9502026-05-27 HIGH 7.1 CVE-2026-47272 pam_usb provides hardware authentication for Linux using ordinary removable media. Prior to 0.9.0, the pusb_pad_compare() function in src/pad.c only … Mitigation only Fix from $1,9502026-05-27 HIGH 7.4 CVE-2026-44460 FileRise is a self-hosted web-based file manager with multi-file upload, editing, and batch operations. Prior to 3.12.0, /api/totp_setup.php is calla… Mitigation only Fix from $1,9502026-05-27 MEDIUM 5.5 CVE-2025-68712 SpSoft AppLock (com.sp.protector.free) 7.9.40 for Android allows a local attacker with physical access to bypass fingerprint or PIN authentication. A… Mitigation only Fix from $1,6002026-05-27 CRITICAL 9.1 CVE-2026-7876 IBM Aspera HSTS for CP4I 1.5.1 through 1.5.19 is affected by an authentication bypass vulnerability. A transfer client may be able to take advantage … Aspera High Speed Transfer Server For Cloud Pak For Integration 1.5.20+ Fix from $2,3002026-05-27 HIGH 8.1 CVE-2026-8994 The Login with NEAR plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 0.3.3. The `ajaxLoginWithNear()… Mitigation only Fix from $1,9502026-05-27 HIGH 7.5 CVE-2026-44847 MaxKB is an open-source AI assistant for enterprise. Prior to 2.9.0, MaxKB's webhook trigger endpoint (/api/trigger/v1/webhook/{trigger_id}) is acces… Mitigation only Fix from $1,9502026-05-26 CRITICAL 9.3 CVE-2026-47202 Kavita is a cross platform reading server. Prior to 0.9.0.2, an Improper Token validation flaw permits a remote and unauthenticated threat actor to r… Mitigation only Fix from $2,3002026-05-26 MEDIUM 6.8 CVE-2026-44707 Chatwoot is a customer engagement suite. From 2.14.0 to before 4.13.0, a Pre-Account Takeover (Pre-ATO) vulnerability existed in Chatwoot's authentic… Patch available Fix from $1,6002026-05-26 HIGH 7.5 CVE-2026-48896 Insufficient state checks lead to a vector that allows to bypass 2FA checks. Joomla\! 5.4.6 / 6.1.1+ Fix from $1,9502026-05-26 HIGH 7.5 CVE-2026-48897 Insufficient state checks lead to a vector that allows to bypass 2FA checks. Joomla\! 5.4.6 / 6.1.1+ Fix from $1,9502026-05-26 MEDIUM 5.6 CVE-2026-9371 A security vulnerability has been detected in ItzCrazyKns Vane up to 1.12.1. Affected by this issue is some unknown functionality of the file route.t… Mitigation only Fix from $1,6002026-05-24 CRITICAL 9.8 CVE-2026-47280 Improper authentication in Azure Resource Manager (ARM) allows an unauthorized attacker to elevate privileges over a network. Azure Resource Manager No fix yet Fix from $2,3002026-05-22 HIGH 8.1 CVE-2026-41076 RT is an open source, enterprise-grade issue and ticket tracking system. Versions 5.0.9 and prior in addition to 6.0.0 through 6.0.2 contain an authe… No fix yet Fix from $1,9502026-05-22 MEDIUM 6.5 CVE-2026-39969 TypeBot is a chatbot builder tool. In versions 3.16.0 and prior, the WhatsApp Cloud API webhook endpoint (POST /v1/workspaces/{workspaceId}/whatsapp/… Mitigation only Fix from $1,6002026-05-22 CRITICAL 9.8 CVE-2026-32253 Sunshine is a self-hosted game stream host for Moonlight. In versions prior to 2026.516.143833, the client-certificate authentication can be bypassed… Sunshine 2026.516.143833+ Fix from $2,3002026-05-22