Vulnerability index

Browse CVEs

4,337 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
MEDIUM 5.6 CVE-2026-7112 A vulnerability has been found in NousResearch hermes-agent 0.8.0. Affected by this vulnerability is the function _check_auth of the file gateway/pla… Patch available Fix from $1,6002026-04-27 HIGH 7.3 CVE-2026-7042 A flaw has been found in 666ghj MiroFish up to 0.1.2. This affects the function create_app of the file backend/app/__init__.py of the component REST … Mitigation only Fix from $1,9502026-04-26 HIGH 7.3 CVE-2026-7022 A security vulnerability has been detected in SmythOS sre up to 0.0.15. Affected is the function AgentRuntime of the file packages/core/src/subsystem… Mitigation only Fix from $1,9502026-04-26 CRITICAL 9.1 CVE-2026-41428 Budibase is an open-source low-code platform. Prior to 3.35.4, the authenticated middleware uses unanchored regular expressions to match public (no-a… Budibase 3.35.4+ Fix from $2,3002026-04-24 MEDIUM 6.5 CVE-2026-42041 Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, the Axios library is vulnerable to a Prototype Pollutio… Axios 0.31.1 / 1.15.1+ Fix from $1,6002026-04-24 CRITICAL 9.8 CVE-2026-41276EPSS 7% Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, this vulnerability allows remote attackers t… Flowise 3.1.0+ Fix from $2,3002026-04-23 CRITICAL 10.0 CVE-2026-41679 Paperclip is a Node.js server and React UI that orchestrates a team of AI agents to run a business. Prior to version 2026.416.0, an unauthenticated a… Paperclipai 2026.416.0+ Fix from $2,3002026-04-23 HIGH 8.2 CVE-2026-40344 MinIO is a high-performance object storage system. Starting in RELEASE.2023-05-18T00-05-36Z and prior to RELEASE.2026-04-11T03-20-12Z, an authenticat… Minio 2026-04-11T03-20-12Z+ Fix from $1,9502026-04-22 HIGH 8.2 CVE-2026-41145 MinIO is a high-performance object storage system. Starting in RELEASE.2023-05-18T00-05-36Z and prior to RELEASE.2026-04-11T03-20-12Z, an authenticat… Minio 2026-04-11T03-20-12Z+ Fix from $1,9502026-04-22 CRITICAL 9.2 CVE-2026-40946 Oxia is a metadata store and coordination system. Prior to 0.16.2, the OIDC authentication provider unconditionally sets SkipClientIDCheck: true in t… Mitigation only Fix from $2,3002026-04-21 CRITICAL 9.1 CVE-2026-40910 frp is a fast reverse proxy. From 0.43.0 to 0.68.0, frp contains an authentication bypass in the HTTP vhost routing path when routeByHTTPUser is used… Frp 0.68.1+ Fix from $2,3002026-04-21 HIGH 7.6 CVE-2026-6729 HKUDS OpenHarness prior to PR #159 remediation contains a session key derivation vulnerability that allows authenticated participants in shared chats… Openharness 0.1.7+ Fix from $1,9502026-04-20 CRITICAL 9.1 CVE-2026-33432 Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions up to and including 8.2.8.2, when LDAP authenticat… Roxy Wi after 8.2.8.2 Fix from $2,3002026-04-20 HIGH 7.3 CVE-2026-6635 A security vulnerability has been detected in rowboatlabs rowboat up to 0.1.67. This impacts the function tool_call of the file apps/experimental/too… Mitigation only Fix from $1,9502026-04-20 MEDIUM 6.5 CVE-2026-6588 A weakness has been identified in serge-chat serge up to 1.4TB. The impacted element is the function download_model/delete_model of the file api/src/… Mitigation only Fix from $1,6002026-04-20 HIGH 7.3 CVE-2026-6582 A flaw has been found in TransformerOptimus SuperAGI up to 0.0.14. Affected by this issue is the function get_vector_db_details of the file superagi/… Mitigation only Fix from $1,9502026-04-19 MEDIUM 6.5 CVE-2026-6579 A weakness has been identified in liangliangyy DjangoBlog up to 2.1.0.0. This impacts an unknown function of the file blog/views.py of the component … Mitigation only Fix from $1,6002026-04-19 HIGH 7.3 CVE-2026-6577 A vulnerability was identified in liangliangyy DjangoBlog up to 2.1.0.0. The impacted element is an unknown function of the file owntracks/views.py o… Mitigation only Fix from $1,9502026-04-19 HIGH 7.3 CVE-2026-6569 A vulnerability was identified in kodcloud KodExplorer up to 4.52. This impacts the function fileGet of the file /app/controller/share.class.php of t… Mitigation only Fix from $1,9502026-04-19 HIGH 7.2 CVE-2025-46607 Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 8.4 through 8.5 contain an improper authenticatio… Data Domain Operating System after 8.5.0.0 Fix from $1,9502026-04-17 MEDIUM 6.6 CVE-2025-46641 Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 8.4 through 8.5 contain an improper authenticatio… Data Domain Operating System after 8.5.0.0 Fix from $1,6002026-04-17 MEDIUM 6.2 CVE-2026-32072 Improper authentication in Windows Active Directory allows an unauthorized attacker to perform spoofing locally. Windows 10 1607 10.0.14393.9060 / 10.0.17763.8644+ Fix from $1,6002026-04-14 HIGH 8.1 CVE-2026-23708 A improper authentication vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.3, FortiSOAR PaaS 7.5.0 through 7.5.2, FortiSOAR on-premise 7.6.… Fortisoar 7.5.3 / 7.6.4+ Fix from $1,9502026-04-14 HIGH 7.3 CVE-2026-6129 A vulnerability was detected in zhayujie chatgpt-on-wechat CowAgent up to 2.0.4. This affects an unknown function of the component Agent Mode Service… Mitigation only Fix from $1,9502026-04-12 HIGH 7.3 CVE-2026-6126 A weakness has been identified in zhayujie chatgpt-on-wechat CowAgent 2.0.4. The affected element is an unknown function of the component Administrat… Mitigation only Fix from $1,9502026-04-12 MEDIUM 5.9 CVE-2026-40178 ajenti.plugin.core defines all necessary core elements to allow Ajenti to run properly. Prior to 0.112, if the 2FA was activated, it was possible dur… Ajenti Plugin Core 0.112+ Fix from $1,6002026-04-10 HIGH 7.5 CVE-2026-40177 ajenti.plugin.core defines all necessary core elements to allow Ajenti to run properly. Prior to 0.112, if the 2FA was activated, it was possible to … Ajenti Plugin Core 0.112+ Fix from $1,9502026-04-10 CRITICAL 9.1 CVE-2026-34727 Vikunja is an open-source self-hosted task management platform. Prior to 2.3.0, the OIDC callback handler issues a full JWT token without checking wh… Vikunja 2.3.0+ Fix from $2,3002026-04-10 MEDIUM 5.3 CVE-2026-4664 The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 5.103.0. This … Mitigation only Fix from $1,6002026-04-10 MEDIUM 6.5 CVE-2026-34500 CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled and FFM is used in Apache Tomcat. This issue affe… Tomcat 9.0.117 / 10.1.54+ Fix from $1,6002026-04-09