Vulnerability index

Browse CVEs

4,337 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
MEDIUM 6.5 CVE-2025-14716 Improper Authentication vulnerability in Secomea GateManager (webserver modules) allows Authentication Bypass.This issue affects GateManager: 11.4;0. Mitigation only Fix from $1,6002026-03-19 HIGH 8.1 CVE-2026-32730 ApostropheCMS is an open-source content management framework. Prior to version 4.28.0, the bearer token authentication middleware in `@apostrophecms/… Apostrophecms 4.28.0+ Fix from $1,9502026-03-18 MEDIUM 5.3 CVE-2026-33042 Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.29 and 8.6.49, a user ca… Parse Server 8.6.49 / 9.6.0+ Fix from $1,6002026-03-18 HIGH 7.3 CVE-2026-2991 The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and includ… Mitigation only Fix from $1,9502026-03-18 MEDIUM 6.5 CVE-2026-25937 GLPI is a free Asset and IT management software package. Starting in version 11.0.0 and prior to version 11.0.6, a malicious actor with knowledge of … Glpi 11.0.6+ Fix from $1,6002026-03-18 MEDIUM 5.6 CVE-2026-4349 A vulnerability was determined in Duende IdentityServer4 up to 4.1.2. The affected element is an unknown function of the file /connect/authorize of t… Mitigation only Fix from $1,6002026-03-17 CRITICAL 9.8 CVE-2026-4252 A vulnerability was identified in Tenda AC8 16.03.50.11. Affected by this issue is the function check_is_ipv6 of the component IPv6 Handler. The mani… Ac8 Firmware Mitigation only Fix from $2,3002026-03-16 MEDIUM 5.3 CVE-2026-4187 A vulnerability was identified in Tiandy Easy7 Integrated Management Platform 7.17.0. Impacted is an unknown function of the file /WebService/UpdateL… Mitigation only Fix from $1,6002026-03-16 MEDIUM 6.5 CVE-2026-21004 Improper authentication in Smart Switch prior to version 3.7.69.15 allows adjacent attackers to trigger a denial of service. Smart Switch 3.7.69.15+ Fix from $1,6002026-03-16 HIGH 7.1 CVE-2026-32246 Tinyauth is an authentication and authorization server. Prior to 5.0.3, the OIDC authorization endpoint allows users with a TOTP-pending session (pas… Tinyauth after 5.0.2 Fix from $1,9502026-03-12 CRITICAL 9.8 CVE-2026-32136 AdGuard Home is a network-wide software for blocking ads and tracking. Prior to 0.107.73, an unauthenticated remote attacker can bypass all authentic… Adguardhome 0.107.73+ Fix from $2,3002026-03-11 CRITICAL 9.8 CVE-2026-1524 An edgecase in SSO implementation in Neo4j Enterprise edition versions prior to version 2026.02 can lead to unauthorised access under the following c… Neo4j 5.26.22 / 2026.02+ Fix from $2,3002026-03-11 CRITICAL 9.8 CVE-2026-23813 A vulnerability has been identified in the web-based management interface of AOS-CX switches that could potentially allow an unauthenticated remote a… Arubaos Cx after 10.17.0001 Fix from $2,3002026-03-11 HIGH 8.8 CVE-2026-30967 Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.5.2-alpha.9. and 8.6.22, the OAuth… Parse Server 8.6.22 / 9.5.2+ Fix from $1,9502026-03-10 HIGH 8.8 CVE-2026-30949 Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.5.2-alpha.5 and 8.6.18, the Keyclo… Parse Server 8.6.18 / 9.5.2+ Fix from $1,9502026-03-10 CRITICAL 9.8 CVE-2026-29792 Feathersjs is a framework for creating web APIs and real-time applications with TypeScript or JavaScript. From 5.0.0 to before 5.0.42, an unauthentic… Feathers 5.0.42+ Fix from $2,3002026-03-10 HIGH 7.8 CVE-2026-26141 Improper authentication in Azure Arc allows an authorized attacker to elevate privileges locally. Azure Automation Hybrid Worker Windows Extension 1.3.74+ Fix from $1,9502026-03-10 HIGH 7.8 CVE-2026-26128 Improper authentication in Windows SMB Server allows an authorized attacker to elevate privileges locally. Windows 10 1607 10.0.14393.8957 / 10.0.17763.8511+ Fix from $1,9502026-03-10 HIGH 7.8 CVE-2026-24294 Improper authentication in Windows SMB Server allows an authorized attacker to elevate privileges locally. Windows 10 1607 10.0.14393.8957 / 10.0.17763.8511+ Fix from $1,9502026-03-10 CRITICAL 9.8 CVE-2026-0953 The Tutor LMS Pro plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 3.9.5 via the Social Login addon.… Mitigation only Fix from $2,3002026-03-10 HIGH 8.2 CVE-2025-68402 FreshRSS is a free, self-hostable RSS aggregator. From 57e1a37 - 00f2f04, the lengths of the nonce was changed from 40 chars to 64. password_verify()… Patch available Fix from $1,9502026-03-09 CRITICAL 9.8 CVE-2026-3794 A vulnerability was identified in doramart DoraCMS 3.0.x. This issue affects some unknown processing of the file /api/v1/mail/send of the component E… Doracms Mitigation only Fix from $2,3002026-03-09 MEDIUM 6.3 CVE-2026-3739 A security flaw has been discovered in suitenumerique messages 0.2.0. This issue affects the function ThreadAccessSerializer of the file src/backend/… Patch available Fix from $1,6002026-03-08 CRITICAL 9.8 CVE-2026-30863 Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.10 and 9.5.0-alpha.11, … Parse Server 8.6.10 / 9.5.0+ Fix from $2,3002026-03-07 HIGH 8.8 CVE-2026-30851 Caddy is an extensible server platform that uses TLS by default. From version 2.10.0 to before version 2.11.2, forward_auth copy_headers does not str… Caddy 2.11.2+ Fix from $1,9502026-03-07 HIGH 8.2 CVE-2026-29193 ZITADEL is an open source identity management platform. From version 4.0.0 to 4.12.0, a vulnerability in Zitadel's login V2 UI allowed users to bypas… Zitadel 4.12.1+ Fix from $1,9502026-03-07 HIGH 8.8 CVE-2026-30223 OliveTin gives access to predefined shell commands from a web interface. Prior to version 3000.11.1, when JWT authentication is configured using eith… Olivetin 3000.11.1+ Fix from $1,9502026-03-06 CRITICAL 9.8 CVE-2026-30831 Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to versions 7.10.8, 7.11.5, 7.12.5, 7.13.4, 8.0.2, 8.1.1, an… Rocket.chat 7.10.8 / 7.11.5+ Fix from $2,3002026-03-06 CRITICAL 9.8 CVE-2026-28514 Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to versions 7.8.6, 7.9.8, 7.10.7, 7.11.4, 7.12.4, 7.13.3, an… Rocket.chat 7.8.6 / 7.9.8+ Fix from $2,3002026-03-06 HIGH 8.0 CVE-2026-28800 Natro Macro is an open-source Bee Swarm Simulator macro written in AutoHotkey. Prior to version 1.1.0, anyone with Discord Remote Control set up in a… Natro Macro 1.1.0+ Fix from $1,9502026-03-06