Vulnerability index

Browse CVEs

4,327 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
HIGH 7.2 CVE-2026-44058 An authentication bypass vulnerability in Netatalk 2.2.2 through 4.4.2 allows a remote privileged user to authenticate as an arbitrary user via the a… Mitigation only Fix from $1,9502026-05-21 HIGH 8.7 CVE-2026-40165 authentik is an open-source identity provider. Versions 2025.12.4 and prior, and versions 2026.2.0-rc1 through 2026.2.2 were vulnerable to Authentica… Patch available Fix from $1,9502026-05-21 MEDIUM 5.3 CVE-2026-2812 ArcGIS Server contains an improper authentication vulnerability in an undocumented administrative endpoint. An unauthenticated attacker could exploit… Arcgis Server after 12.0 Fix from $1,6002026-05-20 MEDIUM 6.0 CVE-2026-9084 MISP’s OIDC authentication plugin allowed automatic linking of an OIDC identity to an existing local user account based on the email claim when the l… Patch available Fix from $1,6002026-05-20 HIGH 8.8 CVE-2026-6456 The Account Switcher plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.0.2. This is due to the `reme… Mitigation only Fix from $1,9502026-05-20 CRITICAL 9.8 CVE-2026-36829 An authentication bypass vulnerability exists in the embedded HTTP server of Panabit PAP-XM320 up to and including v7.7. The server validates session… Mitigation only Fix from $2,3002026-05-19 CRITICAL 9.8 CVE-2026-45434EPSS 22% Improper Authentication vulnerability in Apache OFBiz via Password-Change Logic Flaw Leading to Remote Code Execution This issue affects Apache OFBi… Ofbiz 24.09.06+ Fix from $2,3002026-05-19 MEDIUM 5.3 CVE-2026-31387 Improper Authentication vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade to versio… Ofbiz 24.09.06+ Fix from $1,6002026-05-19 CRITICAL 10.0 CVE-2026-42822 Improper authentication in Azure Local Disconnected Operations allows an unauthorized attacker to elevate privileges over a network. Azure Local 2604.2.25645+ Fix from $2,3002026-05-18 MEDIUM 5.3 CVE-2026-8737 A weakness has been identified in Sanluan PublicCMS 5.202506.d. This issue affects the function execute of the file publiccms-trade/src/main/java/com… Mitigation only Fix from $1,6002026-05-17 CRITICAL 9.1 CVE-2026-44551 Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, the LDAP authentication endpoint d… Open Webui 0.9.0+ Fix from $2,3002026-05-15 CRITICAL 9.8 CVE-2026-5229 The Form Notify plugin for WordPress is vulnerable to Authentication Bypass in versions up to and including 1.1.10. This is due to the plugin trustin… Patch available Fix from $2,3002026-05-15 HIGH 8.8 CVE-2026-8621 Crabbox prior to v0.12.0 contains an authentication bypass vulnerability that allows non-admin shared-token callers to impersonate other owners or or… Patch available Fix from $1,9502026-05-14 CRITICAL 10.0 CVE-2026-20182 KEVEPSS 92% May 2026: This security advisory provides the details and fix information for a vulnerability that was discovered and fixed after the was disclosed … Catalyst Sd Wan Manager 20.9.9.1 / 20.12.5.4+ Fix from $2,3002026-05-14 CRITICAL 9.8 CVE-2026-8181EPSS 15% The Burst Statistics – Privacy-Friendly WordPress Analytics (Google Analytics Alternative) plugin for WordPress is vulnerable to Authentication Bypas… Mitigation only Fix from $2,3002026-05-14 HIGH 7.5 CVE-2026-44478 hoppscotch is an open source API development ecosystem. The fix for CVE-2026-28215 in version 2026.2.0 addresses the unauthenticated POST /v1/onboard… Mitigation only Fix from $1,9502026-05-13 HIGH 8.1 CVE-2026-42602 azureauthextension is the Azure Authenticator Extension. From 0.124.0 to 0.150.0, a server-side authentication bypass in azureauthextension allows an… Opentelemetry Collector Contrib after 0.150.0 Fix from $1,9502026-05-13 CRITICAL 9.1 CVE-2026-44351 fast-jwt provides fast JSON Web Token (JWT) implementation. Prior to 6.2.4, a critical authentication-bypass vulnerability in fast-jwt's async key-re… Mitigation only Fix from $2,3002026-05-13 HIGH 7.1 CVE-2026-33377 An Editor can overwrite a dashboard not owned by them to acquire admin on that specific dashboard. The user must have write access to the dashboard t… Grafana 11.6.14 / 12.2.8+ Fix from $1,9502026-05-13 CRITICAL 9.6 CVE-2026-44547 ChurchCRM is an open-source church management system. From 7.2.0 to 7.2.2, The fix for CVE-2026-4058 is incomplete. The hardening commit was merged a… Patch available Fix from $2,3002026-05-12 HIGH 7.5 CVE-2026-42855 arduino-esp32 is an Arduino core for the ESP32, ESP32-S2, ESP32-S3, ESP32-C3, ESP32-C6 and ESP32-H2 microcontrollers. Prior to 3.3.8, the WebServer D… Arduino Esp32 3.3.8+ Fix from $1,9502026-05-12 HIGH 7.6 CVE-2026-44166 Pocketbase is an open source web backend written in go. Prior to 0.22.42 and 0.37.4, in some situations, if an attacker knows the email address of th… Pocketbase 0.22.42 / 0.37.4+ Fix from $1,9502026-05-12 CRITICAL 9.1 CVE-2026-44196 Pingvin Share X is a secure and easy self-hosted file sharing platform. From 1.14.1 to 1.16.2, a critical authentication bypass vulnerability allows … Mitigation only Fix from $2,3002026-05-12 CRITICAL 9.1 CVE-2026-33117 The Java Key Vault Keys library in the Azure SDK for Java contains an issue in the local cryptographic verification path where authentication tag com… Azure Sdk For Java 4.10.6+ Fix from $2,3002026-05-12 HIGH 7.3 CVE-2026-8321 A vulnerability was detected in inkeep agents 0.58.14. This vulnerability affects the function createDevContext of the file agents-api/src/middleware… Mitigation only Fix from $1,9502026-05-11 CRITICAL 10.0 CVE-2026-42869 SOCFortress CoPilot focuses on providing a single pane of glass for all your security operations needs. Prior to 0.1.57, SOCFortress CoPilot ships a … Patch available Fix from $2,3002026-05-11 CRITICAL 9.8 CVE-2026-8305 A vulnerability was detected in OpenClaw up to 2026.1.24. The impacted element is the function handleBlueBubblesWebhookRequest of the file extensions… Openclaw 2026.2.12+ Fix from $2,3002026-05-11 MEDIUM 5.3 CVE-2026-8244 A vulnerability was identified in Industrial Application Software IAS Canias ERP 8.03. This impacts an unknown function of the component Login RMI In… Mitigation only Fix from $1,6002026-05-10 HIGH 7.3 CVE-2026-8216 A vulnerability was identified in Industrial Application Software IAS Canias ERP 8.03. This issue affects the function iasServerRemoteInterface.doAct… Mitigation only Fix from $1,9502026-05-10 MEDIUM 5.3 CVE-2026-8214 A vulnerability was found in Industrial Application Software IAS Canias ERP 8.03. This affects the function doAction of the component RMI Interface. … Mitigation only Fix from $1,6002026-05-10