Vulnerability index

Browse CVEs

4,337 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
HIGH 7.5 CVE-2026-42855 arduino-esp32 is an Arduino core for the ESP32, ESP32-S2, ESP32-S3, ESP32-C3, ESP32-C6 and ESP32-H2 microcontrollers. Prior to 3.3.8, the WebServer D… Arduino Esp32 3.3.8+ Fix from $1,9502026-05-12 HIGH 7.6 CVE-2026-44166 Pocketbase is an open source web backend written in go. Prior to 0.22.42 and 0.37.4, in some situations, if an attacker knows the email address of th… Pocketbase 0.22.42 / 0.37.4+ Fix from $1,9502026-05-12 CRITICAL 9.1 CVE-2026-44196 Pingvin Share X is a secure and easy self-hosted file sharing platform. From 1.14.1 to 1.16.2, a critical authentication bypass vulnerability allows … Mitigation only Fix from $2,3002026-05-12 CRITICAL 9.1 CVE-2026-33117 The Java Key Vault Keys library in the Azure SDK for Java contains an issue in the local cryptographic verification path where authentication tag com… Azure Sdk For Java 4.10.6+ Fix from $2,3002026-05-12 HIGH 7.3 CVE-2026-8321 A vulnerability was detected in inkeep agents 0.58.14. This vulnerability affects the function createDevContext of the file agents-api/src/middleware… Mitigation only Fix from $1,9502026-05-11 CRITICAL 10.0 CVE-2026-42869 SOCFortress CoPilot focuses on providing a single pane of glass for all your security operations needs. Prior to 0.1.57, SOCFortress CoPilot ships a … Patch available Fix from $2,3002026-05-11 CRITICAL 9.8 CVE-2026-8305 A vulnerability was detected in OpenClaw up to 2026.1.24. The impacted element is the function handleBlueBubblesWebhookRequest of the file extensions… Openclaw 2026.2.12+ Fix from $2,3002026-05-11 MEDIUM 5.3 CVE-2026-8244 A vulnerability was identified in Industrial Application Software IAS Canias ERP 8.03. This impacts an unknown function of the component Login RMI In… Mitigation only Fix from $1,6002026-05-10 HIGH 7.3 CVE-2026-8216 A vulnerability was identified in Industrial Application Software IAS Canias ERP 8.03. This issue affects the function iasServerRemoteInterface.doAct… Mitigation only Fix from $1,9502026-05-10 MEDIUM 5.3 CVE-2026-8214 A vulnerability was found in Industrial Application Software IAS Canias ERP 8.03. This affects the function doAction of the component RMI Interface. … Mitigation only Fix from $1,6002026-05-10 MEDIUM 6.3 CVE-2026-8185 A security vulnerability has been detected in UGREEN CM933 1.1.59.4319. The impacted element is an unknown function of the component Administrative I… Mitigation only Fix from $1,6002026-05-09 CRITICAL 9.1 CVE-2026-42560 auth provides authentication via oauth2, direct and email. From versions 1.18.0 to before 1.25.2 and 2.0.0 to before 2.1.2, the Patreon OAuth provide… Patch available Fix from $2,3002026-05-09 CRITICAL 10.0 CVE-2026-41070 openvpn-auth-oauth2 is a plugin/management interface client for OpenVPN server to handle an OIDC based single sign-on (SSO) auth flows. From version … Patch available Fix from $2,3002026-05-08 CRITICAL 9.8 CVE-2026-41574 Nhost is an open source Firebase alternative with GraphQL. Prior to version 0.49.1, Nhost automatically links an incoming OAuth identity to an existi… Nhost\/auth 0.49.1+ Fix from $2,3002026-05-08 MEDIUM 6.8 CVE-2026-41671 Admidio is an open-source user management solution. Prior to version 5.0.9, the OIDC token introspection endpoint (/modules/sso/index.php/oidc/intros… Mitigation only Fix from $1,6002026-05-07 MEDIUM 5.3 CVE-2026-8031 A vulnerability was detected in PicoTronica e-Clinic Healthcare System ECHS 5.7. The affected element is an unknown function of the file /cdemos/echs… Mitigation only Fix from $1,6002026-05-06 CRITICAL 9.8 CVE-2026-35579 CoreDNS is a DNS server written in Go. In versions prior to 1.14.3, the gRPC, QUIC, DoH, and DoH3 transport implementations incorrectly handle TSIG a… Coredns 1.14.3+ Fix from $2,3002026-05-05 CRITICAL 9.8 CVE-2026-27960 OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. In versions 6.6.0 through 6.9.12, there is a pri… Opencti 6.9.13+ Fix from $2,3002026-05-05 MEDIUM 6.3 CVE-2026-7844 A vulnerability was detected in chatchat-space Langchain-Chatchat up to 0.3.1.3. This vulnerability affects the function files/list_files/retrieve_fi… Mitigation only Fix from $1,6002026-05-05 CRITICAL 9.8 CVE-2026-5722 The MoreConvert Pro plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.9.14. This is due to the gues… Mitigation only Fix from $2,3002026-05-05 CRITICAL 9.4 CVE-2026-41571 Note Mark is an open-source note-taking application. In version 0.19.2, IsPasswordMatch in backend/db/models.go falls back to a hard-coded bcrypt("nu… Mitigation only Fix from $2,3002026-05-04 HIGH 7.3 CVE-2026-7723 A flaw has been found in PrefectHQ prefect up to 3.6.13. Affected is an unknown function of the file /api/events/in of the component WebSocket Endpoi… Patch available Fix from $1,9502026-05-04 MEDIUM 5.3 CVE-2026-7722 A vulnerability was detected in PrefectHQ prefect up to 3.6.21. This impacts the function endswith of the file /api/health of the component Health Ch… Patch available Fix from $1,6002026-05-04 MEDIUM 6.5 CVE-2026-7714 A flaw has been found in crocodilestick Calibre-Web-Automated up to 4.0.6. Affected by this issue is some unknown functionality of the file cps/cwa_f… Patch available Fix from $1,6002026-05-04 HIGH 7.3 CVE-2026-7710 A security flaw has been discovered in YunaiV yudao-cloud up to 3.8.0. This affects the function doFilterInternal of the file JwtAuthenticationTokenF… Mitigation only Fix from $1,9502026-05-04 HIGH 7.3 CVE-2026-7679 A security flaw has been discovered in YunaiV yudao-cloud up to 2026.01. This impacts the function getAccessToken of the file yudao-module-system-biz… Mitigation only Fix from $1,9502026-05-03 HIGH 7.3 CVE-2026-7630 A vulnerability has been found in innocommerce InnoShop up to 0.7.8. The affected element is the function InstallServiceProvider::boot of the file in… Patch available Fix from $1,9502026-05-02 CRITICAL 9.8 CVE-2026-35903 MERCURY MIPC252W IP camera 1.0.5 Build 230306 Rel.79931n contains an improper authentication vulnerability in the RTSP service. After successful Dige… Mipc252w Firmware Mitigation only Fix from $2,3002026-04-27 MEDIUM 6.5 CVE-2026-41081 Improper Handling of TLS Client Authentication Failure Leading to Anonymous Principal Assignment in Apache Storm Versions Affected: up to 2.8.7 Des… Storm 2.8.7+ Fix from $1,6002026-04-27 MEDIUM 5.6 CVE-2026-7113 A vulnerability was found in NousResearch hermes-agent 0.8.0. Affected by this issue is some unknown functionality of the file gateway/platforms/webh… Patch available Fix from $1,6002026-04-27