Vulnerability index

Browse CVEs

4,327 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
CRITICAL 9.8 CVE-2026-66014 JFrog Artifactory contains an authentication handling weakness in internal request processing that, under specific conditions, may allow an attacker … Artifactory 7.111.18 / 7.117.25+ Fix from $2,3002026-07-27 HIGH 8.2 CVE-2026-9830 The bookingpress-appointment-booking-pro WordPress plugin before 5.7.3 does not correctly invoke its REST permission callback, leaving every route in… Mitigation only Fix from $1,9502026-07-27 CRITICAL 9.1 CVE-2026-13597 The 微信二维码登陆 WordPress plugin through 1.3 does not properly validate WeChat webhook requests, as its signature check always passes, and it disc… No fix yet Fix from $2,3002026-07-27 MEDIUM 6.5 CVE-2026-14568 The User Frontend: AI Powered Frontend Post Submission, User Directory, User Profile, Membership & User Registration WordPress plugin before 4.3.8 do… No fix yet Fix from $1,6002026-07-27 HIGH 8.1 CVE-2026-12255 The MainWP Child WordPress plugin before 6.1.2 does not verify the requester's identity in its site-registration request handler when password authe… No fix yet Fix from $1,9502026-07-27 HIGH 7.5 CVE-2026-12493 The Clover Payment Gateway by Zaytech for WooCommerce WordPress plugin before 1.3.6 does not verify that an approved external payment record actually… No fix yet Fix from $1,9502026-07-27 CRITICAL 9.1 CVE-2026-13332 The Masteriyo LMS WordPress plugin before 2.3.1 does not correctly verify authorization on an unauthenticated AJAX action used to clear user session… No fix yet Fix from $2,3002026-07-27 HIGH 8.4 CVE-2026-12504 Improper Authentication (CWE-287) in the PAM configuration in Loytec LIP-ME201C, L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS and L-PAD through 8.4.16 … No fix yet Fix from $1,9502026-07-24 CRITICAL 9.1 CVE-2026-12877 The Project Management, Bug and Issue Tracking Plugin WordPress plugin before 5.1.0 does not sanitise and escape user supplied input before using it… No fix yet Fix from $2,3002026-07-24 CRITICAL 9.8 CVE-2026-62825 Improper authentication in Azure Key Vault allows an unauthorized attacker to elevate privileges over a network. Azure Key Vault No fix yet Fix from $2,3002026-07-24 CRITICAL 10.0 CVE-2026-56191 Improper authentication in Microsoft Exchange Online allows an unauthorized attacker to perform tampering over a network. Exchange Online No fix yet Fix from $2,3002026-07-24 CRITICAL 9.8 CVE-2026-15981 The SAML Single Sign On – SSO Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 5.4.4. This is … No fix yet Fix from $2,3002026-07-23 CRITICAL 9.8 CVE-2026-10697 Improper Authentication vulnerability in Progress MOVEit Transfer. This issue affects MOVEit Transfer: before 2025.1.5, from 2026.0.0 before 2026.0.… Moveit Transfer 2025.1.5 / 2026.0.3+ Fix from $2,3002026-07-23 CRITICAL 9.1 CVE-2026-15611 Logto allows unverified email-based SSO account linking, enabling an attacker to register an identity at a permissive IdP using a victim’s email and … No fix yet Fix from $2,3002026-07-23 MEDIUM 6.3 CVE-2026-15348 The Premium Packages – Sell Digital Products Securely plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and includin… No fix yet Fix from $1,6002026-07-23 HIGH 7.5 CVE-2026-14291 The security-ninja-premium WordPress plugin before 5.290 does not verify the second authentication factor in one of its two-factor authentication cod… No fix yet Fix from $1,9502026-07-23 CRITICAL 9.8 CVE-2026-60367 Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versi… Platform Security For Java No fix yet Fix from $2,3002026-07-22 CRITICAL 9.1 CVE-2026-62144EPSS 21% An authentication bypass vulnerability in Check Point Security Management and Multi-Domain Security Management allows an unauthenticated remote attac… No fix yet Fix from $2,3002026-07-22 CRITICAL 9.8 CVE-2026-16232 KEVEPSS 73% An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an applicati… Multi Domain Security Management No fix yet Fix from $2,3002026-07-22 HIGH 8.1 CVE-2026-62547 Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (component: Workflow Notification Mailer). Supported versions that are affec… Workflow after 12.2.15 Fix from $1,9502026-07-21 HIGH 8.8 CVE-2026-62534 Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Web Utilities). Supported versions that are affect… Applications Framework after 12.2.15 Fix from $1,9502026-07-21 HIGH 7.5 CVE-2026-62493 Vulnerability in the Oracle Purchasing product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are… E Business Suite after 12.2.15 Fix from $1,9502026-07-21 HIGH 8.8 CVE-2026-62496 Vulnerability in the Oracle Yard Management product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affecte… Yard Management after 12.2.15 Fix from $1,9502026-07-21 HIGH 8.8 CVE-2026-62498 Vulnerability in the Oracle Flow Manufacturing product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affe… Flow Manufacturing after 12.2.15 Fix from $1,9502026-07-21 HIGH 8.8 CVE-2026-62478 Vulnerability in the Oracle Public Sector Financials product of Oracle E-Business Suite (component: Internal Operations). Supported versions that ar… Public Sector Financials after 12.2.15 Fix from $1,9502026-07-21 HIGH 8.8 CVE-2026-62476 Vulnerability in the Oracle Public Sector Payroll product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are a… Public Sector Payroll after 12.2.15 Fix from $1,9502026-07-21 HIGH 8.8 CVE-2026-62447 Vulnerability in the Oracle Trade Management product of Oracle E-Business Suite (component: Claim LOV). Supported versions that are affected are 12.… Trade Management No fix yet Fix from $1,9502026-07-21 HIGH 8.8 CVE-2026-62464 Vulnerability in the Oracle Payroll product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12… Payroll after 12.2.15 Fix from $1,9502026-07-21 HIGH 8.8 CVE-2026-61320 Vulnerability in the Oracle Payables product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 1… E Business Suite after 12.2.15 Fix from $1,9502026-07-21 HIGH 8.8 CVE-2026-61322 Vulnerability in the TeleSales product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-… Telesales after 12.2.15 Fix from $1,9502026-07-21