Vulnerability index

Browse CVEs

4,337 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
CRITICAL 9.1 CVE-2026-29145 CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled vulnerability in Apache Tomcat, Apache Tomcat Nati… Tomcat 1.3.7 / 2.0.14+ Fix from $2,3002026-04-09 HIGH 7.1 CVE-2026-39976 Laravel Passport provides OAuth2 server support to Laravel. From 13.0.0 to before 13.7.1, there is an Authentication Bypass for client_credentials to… Passport 13.7.1+ Fix from $1,9502026-04-09 MEDIUM 6.6 CVE-2026-5959 A security flaw has been discovered in GL.iNet GL-RM1, GL-RM10, GL-RM10RC and GL-RM1PE 1.8.1. Affected by this issue is some unknown functionality of… Mitigation only Fix from $1,6002026-04-09 HIGH 7.1 CVE-2026-39411 LobeHub is a work-and-lifestyle space to find, build, and collaborate with agent teammates that grow with you. Prior to 2.1.48, the webapi authentica… Lobehub 2.1.48+ Fix from $1,9502026-04-08 HIGH 7.4 CVE-2026-5795 In Eclipse Jetty, the class JASPIAuthenticator initiates the authentication checks, which set two ThreadLocal variable. Upon returning from the ini… Jetty 12.0.34 / 12.1.8+ Fix from $1,9502026-04-08 HIGH 8.8 CVE-2026-39322 PolarLearn is a free and open-source learning program. In 0-PRERELEASE-15 and earlier, POST /api/v1/auth/sign-in creates a valid session for banned a… Polarlearn Mitigation only Fix from $1,9502026-04-07 CRITICAL 9.8 CVE-2026-39324 Rack::Session is a session management implementation for Rack. From 2.0.0 to before 2.1.2, Rack::Session::Cookie incorrectly handles decryption failu… Rack Session 2.1.2+ Fix from $2,3002026-04-07 HIGH 7.3 CVE-2026-5676 A vulnerability was identified in Totolink A8000R 5.9c.681_B20180413. This issue affects the function setLanguageCfg of the file /cgi-bin/cstecgi.cgi… Mitigation only Fix from $1,9502026-04-06 CRITICAL 9.1 CVE-2026-35030 LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.83.0, when JWT authentication is enabled (enable_jwt… Litellm 1.83.0+ Fix from $2,3002026-04-06 HIGH 7.3 CVE-2026-5632 A vulnerability was found in assafelovic gpt-researcher up to 3.4.3. This impacts an unknown function of the component HTTP REST API Endpoint. Perfor… Mitigation only Fix from $1,9502026-04-06 HIGH 7.3 CVE-2026-5616 A security vulnerability has been detected in JeecgBoot 3.9.0/3.9.1. The impacted element is an unknown function of the file jeecg-boot/jeecg-module-… Patch available Fix from $1,9502026-04-06 CRITICAL 9.8 CVE-2026-5570 A vulnerability was determined in Technostrobe HI-LED-WR120-G2 5.5.0.1R6.03.30. The affected element is the function index_config of the file /LoginC… Hi Led Wr120 G2 Firmware Mitigation only Fix from $2,3002026-04-05 MEDIUM 6.3 CVE-2026-5557 A vulnerability was detected in badlogic pi-mono up to 0.58.4. This issue affects some unknown processing of the file packages/mom/src/slack.ts of th… Mitigation only Fix from $1,6002026-04-05 CRITICAL 9.8 CVE-2017-20235 ProSoft Technology ICX35-HWC version 1.3 and prior cellular gateways contain an authentication bypass vulnerability in the web user interface that al… Icx35 Hwc Firmware 1.3+ Fix from $2,3002026-04-03 CRITICAL 9.8 CVE-2018-25236 Hirschmann HiOS and HiSecOS products RSP, RSPE, RSPS, RSPL, MSP, EES, EESX, GRS, OS, RED, EAGLE contain an authentication bypass vulnerability in the… Mitigation only Fix from $2,3002026-04-03 HIGH 7.8 CVE-2026-34990 OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.16 and prior, a local unprivileg… Cups after 2.4.16 Fix from $1,9502026-04-03 HIGH 8.8 CVE-2026-33175 OAuthenticator is software that allows OAuth2 identity providers to be plugged in and used with JupyterHub. Prior to version 17.4.0, an authenticatio… Oauthenticator 17.4.0+ Fix from $1,9502026-04-03 CRITICAL 9.8 CVE-2017-20237 Hirschmann Industrial HiVision versions prior to 06.0.07 and 07.0.03 contains an authentication bypass vulnerability in the master service that allow… Mitigation only Fix from $2,3002026-04-03 HIGH 7.5 CVE-2026-32173 Improper authentication in Azure SRE Agent allows an unauthorized attacker to disclose information over a network. Azure Sre Agent Mitigation only Fix from $1,9502026-04-03 HIGH 7.5 CVE-2026-34834 Bulwark Webmail is a self-hosted webmail client for Stalwart Mail Server. Prior to version 1.4.10, the verifyIdentity() function contained logic that… Webmail 1.4.10+ Fix from $1,9502026-04-02 CRITICAL 9.8 CVE-2024-14034 Hirschmann HiEOS devices versions prior to 01.1.00 contain an authentication bypass vulnerability in the HTTP(S) management module that allows unauth… Mitigation only Fix from $2,3002026-04-02 MEDIUM 5.3 CVE-2026-34736 Open edX Platform enables the authoring and delivery of online learning at any scale. From the maple release to before the ulmo release, an unauthent… Patch available Fix from $1,6002026-04-02 HIGH 8.8 CVE-2026-34121 An authentication bypass vulnerability within the HTTP handling of the DS configuration service in TP-Link Tapo C520WS v2.6 was identified, due to in… Tapo C520ws Firmware 1.2.4+ Fix from $1,9502026-04-02 CRITICAL 9.8 CVE-2026-33746 Convoy is a KVM server management panel for hosting businesses. From version 3.9.0-beta to before version 4.5.1, the JWTService::decode() method did … Convoy 4.5.1+ Fix from $2,3002026-04-02 HIGH 7.3 CVE-2026-5320 A vulnerability was detected in vanna-ai vanna up to 2.0.2. Affected by this vulnerability is an unknown functionality of the file /api/vanna/v2/ of … Mitigation only Fix from $1,9502026-04-02 CRITICAL 9.8 CVE-2026-4101 IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 and IBM Verify Identity Acces… Security Verify Access after 11.0.2.0 Fix from $2,3002026-04-01 HIGH 8.2 CVE-2026-34531 Flask-HTTPAuth provides Basic, Digest and Token HTTP authentication for Flask routes. Prior to version 4.8.1, in a situation where the client makes a… Flask Httpauth 4.8.1+ Fix from $1,9502026-04-01 CRITICAL 9.1 CVE-2026-34873 An issue was discovered in Mbed TLS 3.5.0 through 4.0.0. Client impersonation can occur while resuming a TLS 1.3 session. Mbed Tls 3.6.6 / 4.1.0+ Fix from $2,3002026-04-01 CRITICAL 9.8 CVE-2026-34072 Cr*nMaster (cronmaster) is a Cronjob management UI with human readable syntax, live logging and log history for cronjobs. Prior to version 2.2.0, an … Cronmaster 2.2.0+ Fix from $2,3002026-04-01 MEDIUM 5.4 CVE-2026-4829 Improper authentication in the external OAuth authentication flow in Devolutions Server 2026.1.11 and earlier allows an authenticated user to authent… Devolutions Server 2026.1.12.0+ Fix from $1,6002026-04-01