Vulnerability index

Browse CVEs

4,337 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
CRITICAL 9.0 CVE-2026-28787 OneUptime is a solution for monitoring and managing online services. In version 10.0.11 and prior, the WebAuthn authentication implementation does no… Oneuptime after 10.0.11 Fix from $2,3002026-03-06 MEDIUM 5.3 CVE-2026-28428 Talishar is a fan-made Flesh and Blood project. Prior to commit a9c218e, an authentication bypass vulnerability in Talishar's game endpoint validatio… Talishar 2026-02-22+ Fix from $1,6002026-03-06 CRITICAL 9.8 CVE-2026-29093 WWBN AVideo is an open source video platform. Prior to version 24.0, the official docker-compose.yml publishes the memcached service on host port 112… Avideo 24.0+ Fix from $2,3002026-03-06 MEDIUM 5.3 CVE-2026-28471 OpenClaw version 2026.1.14-1 prior to 2026.2.2, with the Matrix plugin installed and enabled, contain a vulnerability in which DM allowlist matching … Openclaw 2026.2.2+ Fix from $1,6002026-03-05 CRITICAL 9.8 CVE-2026-3224 Authentication bypass in the Microsoft Entra ID (Azure AD) authentication mode in Devolutions Server 2025.3.15.0 and earlier allows an unauthenticate… Devolutions Server 2025.3.16.0+ Fix from $2,3002026-03-03 CRITICAL 9.8 CVE-2026-24898 OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0, an unauthenticated token dis… Openemr 8.0.0+ Fix from $2,3002026-03-03 CRITICAL 9.8 CVE-2026-23600 A remote authentication bypass vulnerability  exists in HPE AutoPass License Server (APLS). Autopass License Server 9.19+ Fix from $2,3002026-03-02 CRITICAL 9.8 CVE-2026-28408 WeGIA is a web manager for charitable institutions. Prior to version 3.6.5, the script in adicionar_tipo_docs_atendido.php does not go through the pr… Wegia 3.6.5+ Fix from $2,3002026-02-27 HIGH 8.8 CVE-2026-27939 Statmatic is a Laravel and Git powered content management system (CMS). Starting in version 6.0.0 and prior to version 6.4.0, Authenticated Control P… Statamic 6.4.0+ Fix from $1,9502026-02-27 MEDIUM 5.3 CVE-2026-1305 The Japanized for WooCommerce plugin for WordPress is vulnerable to Improper Authentication in versions up to, and including, 2.8.4. This is due to a… Mitigation only Fix from $1,6002026-02-27 CRITICAL 9.1 CVE-2026-28215 hoppscotch is an open source API development ecosystem. Prior to version 2026.2.0, an unauthenticated attacker can overwrite the entire infrastructur… Hoppscotch 2026.2.0+ Fix from $2,3002026-02-26 HIGH 8.2 CVE-2025-71057 Improper session management in D-Link Wireless N 300 ADSL2+ Modem Router DSL-124 ME_1.00 allows attackers to execute a session hijacking attack via s… Mitigation only Fix from $1,9502026-02-26 MEDIUM 6.5 CVE-2026-26077 Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, several webhook endpoints (SendGrid, Mailjet, M… Discourse 2025.12.0 / 2026.1.1+ Fix from $1,6002026-02-26 HIGH 7.0 CVE-2026-3194 A flaw has been found in Chia Blockchain 2.1.0. The affected element is the function send_transaction/get_private_key of the component RPC Server Mas… Blockchain No fix yet Fix from $1,9502026-02-25 HIGH 8.1 CVE-2026-3192 A security vulnerability has been detected in Chia Blockchain 2.1.0. This issue affects the function _authenticate of the file rpc_server_base.py of … Blockchain No fix yet Fix from $1,9502026-02-25 CRITICAL 9.8 CVE-2026-20129 A vulnerability in the API user authentication of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to gain access to an … Catalyst Sd Wan Manager 20.9.8.2 / 20.12.5.3+ Fix from $2,3002026-02-25 CRITICAL 10.0 CVE-2026-20127 KEVEPSS 88% A vulnerability in the peering authentication in Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, Cisco Catalyst SD-WAN Manager, formerly SD… Catalyst Sd Wan Manager 20.9.8.2 / 20.12.5.3+ Fix from $2,3002026-02-25 MEDIUM 6.5 CVE-2026-27611 FileBrowser Quantum is a free, self-hosted, web-based file manager. Prior to versions 1.1.3-stable and 1.2.6-beta, when users share password-protecte… Filebrowser Quantum 1.1.3 / 1.2.6+ Fix from $1,6002026-02-25 HIGH 7.5 CVE-2026-24241 NVIDIA Delegated Licensing Service for all appliance platforms contains a vulnerability where an attacker could exploit an improper authentication is… Delegated License Service 3.1.8 / 3.6.0+ Fix from $1,9502026-02-24 CRITICAL 9.8 CVE-2026-3053 A vulnerability was determined in DataLinkDC dinky up to 1.2.5. This affects the function addInterceptors of the file dinky-admin/src/main/java/org/d… Dinky after 1.2.5 Fix from $2,3002026-02-24 CRITICAL 9.1 CVE-2026-27197 Sentry is a developer-first error tracking and performance monitoring tool. Versions 21.12.0 through 26.1.0 have a critical vulnerability in its SAML… Sentry 26.2.0+ Fix from $2,3002026-02-21 HIGH 8.1 CVE-2026-27134 Strimzi provides a way to run an Apache Kafka cluster on Kubernetes or OpenShift in various deployment configurations. In versions 0.49.0 through 0.… Strimzi Kafka Operator 0.50.1+ Fix from $1,9502026-02-21 CRITICAL 9.4 CVE-2025-70833 An Authentication Bypass vulnerability in Smanga 3.2.7 allows an unauthenticated attacker to reset the password of any user (including the administra… Smanga Mitigation only Fix from $2,3002026-02-20 MEDIUM 6.9 CVE-2025-41023 An authentication bypass vulnerability has been found in Thesamur's AutoGPT. This vulnerability allows an attacker to bypass authentication mechanism… No fix yet Fix from $1,6002026-02-19 CRITICAL 10.0 CVE-2025-15586 OGP-Website installs prior git commit 52f865a4fba763594453068acf8fa9e3fc38d663 are affected by a type juggling flaw which if exploited can result in … Patch available Fix from $2,3002026-02-19 MEDIUM 5.3 CVE-2025-7630 Improper Restriction of Excessive Authentication Attempts, Improper Authentication vulnerability in Doruk Communication and Automation Industry and T… Mitigation only Fix from $1,6002026-02-18 HIGH 7.5 CVE-2026-1368 The Video Conferencing with Zoom WordPress plugin before 4.6.6 contains an AJAX handler that has its nonce verification commented out, allowing unaut… Mitigation only Fix from $1,9502026-02-18 HIGH 8.8 CVE-2026-26119 Improper authentication in Windows Admin Center allows an authorized attacker to elevate privileges over a network. Windows Admin Center 2511+ Fix from $1,9502026-02-17 HIGH 7.5 CVE-2026-25748 authentik is an open-source identity provider. Prior to 2025.10.4 and 2025.12.4, with a malformed cookie it was possible to bypass authentication whe… Authentik 2025.10.4 / 2025.12.4+ Fix from $1,9502026-02-12 HIGH 8.8 CVE-2026-25922 authentik is an open-source identity provider. Prior to 2025.8.6, 2025.10.4, and 2025.12.4, when using a SAML Source that has the option Verify Asser… Authentik 2025.8.6 / 2025.10.4+ Fix from $1,9502026-02-12