Vulnerability index

Browse CVEs

4,327 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
MEDIUM 5.3 CVE-2025-68640 The Apple Find My backend service through 2025-12-17 allows an attacker in possession of a valid PET (Private Endpoint Token) to enumerate devices an… No fix yet Fix from $1,6002026-07-21 CRITICAL 9.4 CVE-2026-53595 FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.224, the public endpoint `POST /user-setup/{h… No fix yet Fix from $2,3002026-07-20 HIGH 8.6 CVE-2026-53591 FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.223, an unauthenticated attacker can inject m… No fix yet Fix from $1,9502026-07-20 CRITICAL 9.8 CVE-2026-12341 This vulnerability impacts all versions of IdentityIQ and allows an unauthenticated attacker unauthorized access to protected APIs and data due to im… Identityiq 8.3+ Fix from $2,3002026-07-20 HIGH 7.3 CVE-2026-55626 xrdp is an open source RDP server. In versions 0.10.6 and prior, when an authenticated user session is initialized using the Xvnc backend over UNIX d… Xrdp 0.10.6.1+ Fix from $1,9502026-07-20 HIGH 7.5 CVE-2026-48812 FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.221, FreeScout's attachment download route sk… No fix yet Fix from $1,9502026-07-20 MEDIUM 5.3 CVE-2026-46715 Flask-Security-Too allows users to add security features to their Flask applicationa. Version 5.8.0's OAuth reauthentication flow can mark a session … No fix yet Fix from $1,6002026-07-20 MEDIUM 5.3 CVE-2026-42210 Webmin is a web-based system administration tool for Unix-like servers. Prior to version 2.640, for Webmin accounts that require a second authenticat… No fix yet Fix from $1,6002026-07-20 HIGH 7.3 CVE-2026-16210 A vulnerability was found in newpanjing simpleui 2026.01.13. This affects the function self.get_action of the file simpleui/admin.py of the component… No fix yet Fix from $1,9502026-07-19 HIGH 7.3 CVE-2026-16209 A vulnerability has been found in Gerapy up to 0.9.13. The impacted element is an unknown function of the file gerapy/server/core/views.py of the com… No fix yet Fix from $1,9502026-07-19 MEDIUM 5.6 CVE-2026-16198 A vulnerability was detected in Sipeed PicoClaw up to 0.2.9. The impacted element is an unknown function of the file web/backend/middleware/access_co… No fix yet Fix from $1,6002026-07-19 MEDIUM 6.3 CVE-2024-58363 SurrealDB before 1.5.4 fails to properly validate authentication when a scope user switches databases using the USE clause or use method. Attackers w… Surrealdb 1.5.4+ Fix from $1,6002026-07-18 CRITICAL 9.8 CVE-2026-47865 VMware Avi Load Balancer contains an authentication bypass vulnerability. A malicious user with network access may be able to access the Avi Control … No fix yet Fix from $2,3002026-07-18 MEDIUM 5.3 CVE-2026-16083 A security flaw has been discovered in Sipeed PicoClaw up to 0.2.9. This affects the function webhook.ParseRequest of the file pkg/channels/line/line… No fix yet Fix from $1,6002026-07-18 MEDIUM 6.3 CVE-2026-16076 A vulnerability has been found in AstrBotDevs AstrBot up to 4.25.5. This issue affects the function OpenApiRoute.chat_send of the file astrbot/dashbo… No fix yet Fix from $1,6002026-07-18 HIGH 8.7 CVE-2026-49852 joserfc is a Python library that provides an implementation of several JSON Object Signing and Encryption (JOSE) standards. Prior to 1.6.8, joserfc.j… No fix yet Fix from $1,9502026-07-17 MEDIUM 6.3 CVE-2026-16015 A vulnerability was determined in poco-ai poco-claw up to 0.5.4. This vulnerability affects the function create_task of the file executor_manager/app… No fix yet Fix from $1,6002026-07-17 CRITICAL 9.6 CVE-2026-22752 Authentication bypass by primary weakness vulnerability in Spring Security Spring Authorization Server. This issue affects Spring Authorization Serv… No fix yet Fix from $2,3002026-07-16 HIGH 8.1 CVE-2026-12585 The Abandoned Cart Lite for WooCommerce WordPress plugin before 6.8.2 does not protect the integrity of its cart-recovery tokens or bind them to the … No fix yet Fix from $1,9502026-07-16 CRITICAL 9.8 CVE-2026-12492 The Happy Coders OTP Login for WooCommerce WordPress plugin before 2.8 does not verify that a one-time password was actually validated before authent… No fix yet Fix from $2,3002026-07-16 CRITICAL 9.3 CVE-2026-55445 Qinglong is a timed task management platform supporting Python3, JavaScript, Shell, and Typescript. Prior to 2.20.1, the init guard middleware in bac… Mitigation only Fix from $2,3002026-07-15 CRITICAL 9.8 CVE-2026-55652 Wekan is open source kanban built with Meteor. Prior to 9.46, header-login with HEADER_LOGIN_TRUSTED_IPS uses getRequestIp() in server/lib/headerLogi… No fix yet Fix from $2,3002026-07-15 CRITICAL 9.2 CVE-2026-52893 Wekan is open source kanban built with Meteor. Prior to 9.32, the Wekan Accounts.onCreateUser hook in server/models/users.js merges OIDC logins into … Mitigation only Fix from $2,3002026-07-15 HIGH 8.2 CVE-2026-46485 Dashy is a self-hostable personal dashboard. Prior to 4.0.8, Dashy deployments using OIDC can allow unauthenticated users or non-admin authenticated … Mitigation only Fix from $1,9502026-07-15 CRITICAL 9.1 CVE-2026-53512 Better Auth is an authentication and authorization library for TypeScript. Prior to 1.6.11, the legacy oidcProvider and mcp plugins expose OAuth toke… Better Auth 1.6.11+ Fix from $2,3002026-07-15 HIGH 7.7 CVE-2026-53514 Better Auth is an authentication and authorization library for TypeScript. Prior to 1.6.11, and in 1.6.14 and later when invitation IDs can be obtain… Better Auth 1.6.11+ Fix from $1,9502026-07-15 HIGH 8.3 CVE-2026-53516 Better Auth is an authentication and authorization library for TypeScript. Prior to 1.6.11, Better Auth's OAuth callback auto-link gate in handleOAut… Better Auth 1.6.11+ Fix from $1,9502026-07-15 HIGH 7.5 CVE-2026-59955 Apollo is a reliable configuration management system suitable for microservice configuration management scenarios. Prior to 2.5.2, Apollo ConfigServi… Mitigation only Fix from $1,9502026-07-15 HIGH 7.5 CVE-2026-59954 Apollo is a reliable configuration management system suitable for microservice configuration management scenarios. Prior to 2.5.2, Apollo ConfigServi… Mitigation only Fix from $1,9502026-07-15 MEDIUM 6.9 CVE-2026-47159 Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.36.0, Vaultwarden's SSO discovery and pre-validation flow returned organizat… Mitigation only Fix from $1,6002026-07-15