Vulnerability index

Browse CVEs

4,327 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
CRITICAL 9.8 CVE-2026-16867 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to access server resources with the privileges of an authenticated user due to improper au… I No fix yet Fix from $5,7502026-08-13 CRITICAL 9.8 CVE-2026-17197 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to bypass security restrictions due to improper validation of client-asserted identity. I No fix yet Fix from $5,7502026-08-13 CRITICAL 10.0 CVE-2026-59500 CWE-287: Improper Authentication No fix yet Fix from $5,7502026-08-13 CRITICAL 9.8 CVE-2026-14182 The Customer Email Verification for WooCommerce WordPress plugin before 3.2.6 does not correctly validate the email-verification activation code, rel… No fix yet Fix from $5,7502026-08-13 MEDIUM 5.5 CVE-2026-47718 FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. When `secureEnabled=true`, FUXA `1.3.0-2773` still allows guest and invalid… No fix yet Fix from $4,0002026-08-12 CRITICAL 9.1 CVE-2026-73501 kin-openapi is a Go project for handling OpenAPI files. Prior to 0.144.0, ValidationHandler.Load() in openapi3filter/validation_handler.go silently r… No fix yet Fix from $5,7502026-08-12 CRITICAL 10.0 CVE-2024-27253 IBM DOORS Next 7.0.3 through 7.0.3 Interim Fix 018 could allow an authenticated user to bypass security logic to perform unauthorized activities. No fix yet Fix from $5,7502026-08-12 HIGH 7.4 CVE-2026-11923 IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 thr… Security Verify Access No fix yet Fix from $4,9002026-08-12 HIGH 8.1 CVE-2026-12359 IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 thr… Security Verify Access No fix yet Fix from $4,9002026-08-12 HIGH 7.5 CVE-2026-42018 JFrog Artifactory could return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled, potentially exposing … No fix yet Fix from $4,9002026-08-12 MEDIUM 5.3 CVE-2026-68760 An unauthenticated user may bypass authentication under specific cache conditions. No fix yet Fix from $4,0002026-08-12 CRITICAL 9.4 CVE-2026-50561 Yuxi is a large-model-based intelligent knowledge base and knowledge graph agent development platform. Prior to version 0.6.2, the project's authenti… No fix yet Fix from $5,7502026-08-12 CRITICAL 9.8 CVE-2026-26035 An Improper Authentication vulnerability [CWE-287] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4… No fix yet Fix from $5,7502026-08-12 MEDIUM 6.1 CVE-2026-17013 The WP Photo Album Plus WordPress plugin before 9.2.07.002 does not sanitise and escape a parameter before reflecting it into an inline script block,… No fix yet Fix from $4,0002026-08-12 HIGH 8.1 CVE-2026-18961 The Social Login, Passkeys, Magic Link & Email OTP – Passwordless Login by VentraConnect plugin for WordPress is vulnerable to Authentication Bypass … No fix yet Fix from $4,9002026-08-12 HIGH 8.3 CVE-2026-73241 FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.30.0, FreeRDP server-side RDSTLS in libfreerdp/core/rdstls.c accepts an a… No fix yet Fix from $4,9002026-08-11 HIGH 7.5 CVE-2026-71467 A flaw was found in search-v2-api. The authentication middleware in the affected component unconditionally skips authentication when a request includ… No fix yet Fix from $4,9002026-08-11 MEDIUM 5.3 CVE-2026-73085 Audiobookshelf is a self-hosted audiobook and podcast server. Prior to 2.36.0, the jwtAuthCheck function in server/auth/TokenManager.js treats JWTs w… No fix yet Fix from $4,0002026-08-11 HIGH 8.8 CVE-2026-62827 Improper authentication in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network. Sharepoint Server 16.0.19725.20522+ Fix from $4,9002026-08-11 MEDIUM 6.3 CVE-2026-20891 Improper authentication for some Intel(R) PROSet/Wireless WiFi Software for Windows within Ring 2: Device Drivers may allow an escalation of privileg… No fix yet Fix from $4,0002026-08-11 HIGH 7.0 CVE-2026-20885 Improper authentication in the Intel(R) TDX module for some Intel(R) platforms within Ring 0: Trust Domain may allow an information disclosure and es… No fix yet Fix from $4,9002026-08-11 MEDIUM 6.7 CVE-2026-20752 Improper authentication for some Intel(R) PROSet/Wireless WiFi Software within Ring 0: Kernel may allow an information disclosure. System software ad… No fix yet Fix from $4,0002026-08-11 CRITICAL 9.8 CVE-2026-12571 An authentication bypass in ManageEngine DDI Central's password-reset workflow allows account takeover. No fix yet Fix from $5,7502026-08-11 HIGH 8.2 CVE-2026-72922 AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. Prior to 0.6.70, AutoGPT's… No fix yet Fix from $4,9002026-08-11 CRITICAL 9.8 CVE-2026-51584 An issue in usememos v0.27.1 allows a remote attacker to achieve account takeover via the ssoCredentials branch of the SignIn handler in server/route… No fix yet Fix from $5,7502026-08-11 HIGH 7.5 CVE-2026-72746 FreeRDP before 3.30.0 contains a server-side authentication bypass in the RDSTLS handshake. When a server is configured with RdstlsSecurity = TRUE, t… No fix yet Fix from $4,9002026-08-11 HIGH 8.8 CVE-2026-72533 An authentication bypass vulnerability in Portainer CE through 2.44.0 allows authenticated low-privileged users to bypass Docker proxy authorization … No fix yet Fix from $4,9002026-08-11 MEDIUM 5.9 CVE-2026-72917 AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. From 1.0.0 to 1.15.0, Any… No fix yet Fix from $4,0002026-08-10 CRITICAL 9.8 CVE-2026-40920 Privilege Escalation via URL Parameter is reported in Apache Ranger versions <= 2.8.0. Users are recommended to upgrade to version 2.9.0, which fixe… Ranger No fix yet Fix from $5,7502026-08-10 HIGH 8.1 CVE-2026-18468 The Login & Register Forms WordPress plugin before 4.0.2 does not bind the password reset verification state to the account being reset or to the pa… No fix yet Fix from $4,9002026-08-10