Vulnerability index

Browse CVEs

4,327 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
HIGH 8.1 CVE-2026-18469 The Login & Register Forms WordPress plugin before 4.0.2 does not enforce its password reset attempt limit against a server-derived value, keying bo… No fix yet Fix from $4,9002026-08-10 HIGH 8.8 CVE-2026-18786 The CheckView WordPress plugin before 2.3.2 does not restrict its REST API authentication filter to its own routes and unconditionally discards the … No fix yet Fix from $4,9002026-08-10 MEDIUM 5.4 CVE-2026-18960 The Block User Account WordPress plugin before 2.0.1 does not enforce its account block on every authentication path, allowing a blocked user who hol… No fix yet Fix from $4,0002026-08-10 CRITICAL 9.8 CVE-2026-16299 The Single Sign On For TNG WordPress plugin before 2.2.0 does not properly validate a password reset request, allowing unauthenticated attackers to r… No fix yet Fix from $5,7502026-08-10 HIGH 8.2 CVE-2026-16257 The Arvow AI SEO Writer WordPress plugin before 1.5.4 does not properly restrict access to one of its REST endpoints, whose only access control can b… No fix yet Fix from $4,9002026-08-10 HIGH 8.1 CVE-2026-13600 The AutoNetTV Relay WordPress plugin before 3.0.14 does not perform any capability or authentication check before setting a WordPress administrator a… No fix yet Fix from $4,9002026-08-10 HIGH 7.3 CVE-2026-19342 A vulnerability was detected in code-projects Task Management System 1.0. Affected is an unknown function of the file /index.php of the component Log… No fix yet Fix from $4,9002026-08-09 CRITICAL 9.8 CVE-2026-15038 The InfiniteWP Client WordPress plugin before 1.13.6 does not properly verify the site-connection state and the authenticity of requests to its remot… No fix yet Fix from $5,7502026-08-09 MEDIUM 5.3 CVE-2026-16282 The Appointment Hour Booking WordPress plugin before 1.5.88 does not validate a client-supplied booking price against the server-side configured ser… No fix yet Fix from $1,6002026-08-08 CRITICAL 9.1 CVE-2026-48039 Meta Ads MCP is a Model Context Protocol (MCP) server that lets AI assistants run Meta Ads. Prior to version 1.0.109, `AuthInjectionMiddleware.dispat… No fix yet Fix from $2,3002026-08-07 CRITICAL 9.8 CVE-2026-56793 Dell OpenManage Server Administrator, versions prior to 11.1.0.2, contains an Improper Authentication vulnerability. An unauthenticated attacker with… Openmanage Server Administrator 11.1.0.2+ Fix from $2,3002026-08-07 HIGH 8.1 CVE-2026-16030 The MStore API WordPress plugin before 4.21.0 does not correctly verify the cryptographic signature of the token used to authenticate its phone-base… No fix yet Fix from $1,9502026-08-07 CRITICAL 9.8 CVE-2026-14205 The WP Events Manager WordPress plugin before 2.2.5 does not validate the requested quantity when registering for a paid event and computes the price… No fix yet Fix from $2,3002026-08-07 CRITICAL 9.6 CVE-2026-62896 Improper authentication in Microsoft Teams allows an authorized attacker to elevate privileges over a network. Teams No fix yet Fix from $2,3002026-08-07 CRITICAL 10.0 CVE-2026-56162 Improper authentication in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network. Azure Sql Database No fix yet Fix from $2,3002026-08-07 HIGH 8.1 CVE-2026-64665 Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.1 and 6.24.0, when OAuth login was enabled with a provider that … No fix yet Fix from $1,9502026-08-06 CRITICAL 9.8 CVE-2026-65400 KEV An authentication issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.9, macOS Sonoma 14.8.9, macOS Tahoe 2… macOS 14.8.9 / 15.7.9+ Fix from $2,3002026-08-06 CRITICAL 9.8 CVE-2026-48087 OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.2, the registration … No fix yet Fix from $2,3002026-08-06 MEDIUM 5.3 CVE-2026-14547 The Estatik Real Estate Plugin WordPress plugin before 4.3.3 does not properly enforce its anti-spam check or restrict the recipient routing of its p… No fix yet Fix from $1,6002026-08-06 HIGH 8.1 CVE-2026-15459 The WPMU DEV Dashboard plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 5.0.0. On sites not yet conn… No fix yet Fix from $1,9502026-08-06 HIGH 7.3 CVE-2026-18990 A vulnerability was detected in letta-ai LettaBot 0.2.0. Impacted is an unknown function of the file src/api/server.ts of the component API Status Ro… No fix yet Fix from $1,9502026-08-06 CRITICAL 9.8 CVE-2026-9192 An authentication bypass vulnerability in the ODBC App Server of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an unauthenticated remote … No fix yet Fix from $2,3002026-08-05 CRITICAL 9.1 CVE-2026-71277 rust-iot-platform's AuthToken request-guard implementation (api/src/main.rs) only checks whether the Authorization HTTP header is present, and never … No fix yet Fix from $2,3002026-08-05 HIGH 7.5 CVE-2026-15372 The WP 2FA WordPress plugin before 4.1.0 does not validate the second authentication factor when one of its supported methods is selected at login, … No fix yet Fix from $1,9502026-08-05 HIGH 7.5 CVE-2026-16036 The miniOrange 2FA WordPress plugin before 6.2.7 does not bind the second factor being configured during the pre-login two-factor challenge to the t… No fix yet Fix from $1,9502026-08-05 HIGH 7.5 CVE-2026-16055 The Contest Gallery WordPress plugin before 30.0.7 does not route its front-end login through the standard WordPress authentication flow, issuing an… No fix yet Fix from $1,9502026-08-05 CRITICAL 9.1 CVE-2026-15210 The OTP Login With Phone Number, OTP Verification WordPress plugin before 1.8.71 does not limit the number of OTP verification attempts or invalidate… No fix yet Fix from $2,3002026-08-05 MEDIUM 5.0 CVE-2026-18816 A vulnerability was identified in Baserow up to 2.3.2. Affected by this vulnerability is the function verify of the file backend/src/baserow/api/two_… No fix yet Fix from $1,6002026-08-04 HIGH 8.1 CVE-2026-70482 Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.0 until 0.11.0, when ENABLE_OAUTH_TOKEN_EXCHANGE=True,… No fix yet Fix from $1,9502026-08-04 HIGH 7.3 CVE-2026-18810 A security vulnerability has been detected in H3C NX15 V100R017. Impacted is an unknown function of the file /api/wizard/networkSetup. Such manipulat… No fix yet Fix from $1,9502026-08-04