Vulnerability index

Browse CVEs

4,327 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
CRITICAL 9.9 CVE-2026-44986 Penpot is an open-source design tool for design and code collaboration. Prior to 2.14.5, Penpot exposed teams_invitations.clj invitation tokens from … Mitigation only Fix from $2,3002026-07-15 CRITICAL 9.3 CVE-2026-61740 LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.5.4, when LightRAG is deployed with LIGHTRAG_API_KEY set but AUTH_ACCOUN… Mitigation only Fix from $2,3002026-07-15 HIGH 8.2 CVE-2026-61435 PraisonAI before 4.6.78 contains an authentication bypass in the Call API agent invocation endpoints (src/praisonai/praisonai/api/agent_invoke.py) wh… Mitigation only Fix from $1,9502026-07-15 HIGH 8.6 CVE-2026-61436 PraisonAI before 4.6.78 fails to verify Svix webhook signatures in AgentMail webhook mode, allowing unauthenticated attackers to forge message.receiv… Mitigation only Fix from $1,9502026-07-15 HIGH 8.1 CVE-2026-12281 The Shibboleth WordPress plugin before 2.5.4 does not fail closed when its HTTP header identity mode is enabled without an anti-spoofing key, treatin… Mitigation only Fix from $1,9502026-07-15 CRITICAL 9.8 CVE-2026-5270 An authentication bypass vulnerability exists in certain releases of Ciena Navigator Network Control Suite (NCS), Manage Control Plan (MCP), and Blue… Mitigation only Fix from $2,3002026-07-14 CRITICAL 9.1 CVE-2026-45363 ruby-jwt is a Ruby implementation of the RFC 7519 OAuth JSON Web Token standard. Prior to 2.10.3 and 3.2.0, JWT.decode(token, '', true, algorithm: 'H… Mitigation only Fix from $2,3002026-07-14 MEDIUM 5.3 CVE-2026-45754 Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 6.4.40, 7.4.12, and 8.0.12, the Mailjet ma… Symfony 6.4.40 / 7.4.12+ Fix from $1,6002026-07-14 HIGH 8.0 CVE-2026-50365 Improper authentication in Windows RPC API allows an unauthorized attacker to elevate privileges over an adjacent network. Windows 10 1607 10.0.14393.9339 / 10.0.17763.9020+ Fix from $1,9502026-07-14 HIGH 8.8 CVE-2026-56169 Improper authentication in Windows Admin Center allows an authorized attacker to elevate privileges over a network. Windows Admin Center 2606+ Fix from $1,9502026-07-14 MEDIUM 6.5 CVE-2026-56185 Improper authentication in Windows Admin Center allows an authorized attacker to disclose information over a network. Windows Admin Center 2511+ Fix from $1,6002026-07-14 HIGH 7.8 CVE-2026-57107 Improper authentication in Windows Admin Center allows an authorized attacker to elevate privileges locally. Windows Admin Center 2606+ Fix from $1,9502026-07-14 HIGH 8.2 CVE-2026-50338 Improper authentication in Azure Spring Apps allows an authorized attacker to elevate privileges over a network. Azure Spring Cloud 7.3.0+ Fix from $1,9502026-07-14 HIGH 8.7 CVE-2026-22099 The charging station does not require authentication for Bluetooth commands to perform actions. The functionality exposed includes sensitive informat… Mitigation only Fix from $1,9502026-07-13 HIGH 7.3 CVE-2026-15557 A weakness has been identified in waooAI waoowaoo up to 0.4.1. Affected by this vulnerability is the function getInternalTaskSession/getAuthSession/r… Mitigation only Fix from $1,9502026-07-13 HIGH 7.3 CVE-2026-15542 A vulnerability has been found in will-moss Isaiah up to 1.36.9. This affects an unknown function of the file app/main.go of the component Websocket … Patch available Fix from $1,9502026-07-13 HIGH 7.3 CVE-2026-15491 A weakness has been identified in RafyMrX TOKO-ONLINE-ROTI up to ddfe1cd587be0a0b5135d8b6e85cce2ec3aece99. This affects an unknown part. This manipul… No fix yet Fix from $1,9502026-07-12 MEDIUM 5.9 CVE-2026-15087 vulnerability in Drupal Clean RESTful allows . This issue affects Clean RESTful versions: *.*. No fix yet Fix from $1,6002026-07-10 CRITICAL 9.1 CVE-2026-15089 vulnerability in Drupal Commerce guest registration allows . This issue affects Commerce guest registration versions: *.*. No fix yet Fix from $2,3002026-07-10 CRITICAL 10.0 CVE-2026-57216 RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.20, 4.1.11, and 4.2.6, AMQP 0-9-1, AMQP 1.0, and Stream Protocol authentication c… Rabbitmq Server 4.2.6+ Fix from $2,3002026-07-10 CRITICAL 9.8 CVE-2026-12761 The miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) plugin for WordPress is vulnerable to authentication bypass leading to … Mitigation only Fix from $2,3002026-07-10 HIGH 8.1 CVE-2026-55377 Logto is the modern, open-source auth infrastructure for SaaS and AI apps. Prior to 1.41.0, Logto's Account Center step-up check accepted any active … Patch available Fix from $1,9502026-07-10 CRITICAL 9.6 CVE-2026-59151 Prowler is a cloud security platform. Prior to 5.30.3, Prowler's SAML authentication flow trusted the email domain asserted in a SAMLResponse when de… Patch available Fix from $2,3002026-07-10 HIGH 7.4 CVE-2026-55672 ZITADEL is an open source identity management platform. Prior to 3.4.12 and 4.15.2, ZITADEL's OAuth2 and OIDC CodeExchange, RefreshToken, and device … Patch available Fix from $1,9502026-07-10 HIGH 8.3 CVE-2026-56675 9Router is an AI router & token saver. Prior to 0.5.2, 9router treats loopback requests as trusted and allows /v1/* access without an API key, so a s… Patch available Fix from $1,9502026-07-10 MEDIUM 6.5 CVE-2026-56312 Capgo before 12.128.2 contains an improper validation vulnerability in the accept_invitation endpoint that creates user accounts before captcha valid… Mitigation only Fix from $1,6002026-07-10 HIGH 8.1 CVE-2026-12595 The LoginPress Pro plugin for WordPress is vulnerable to Authentication Bypass via Unverified OAuth Email in all versions up to and including 6.2.3. … Mitigation only Fix from $1,9502026-07-10 HIGH 8.1 CVE-2026-12597 The LoginPress Pro plugin for WordPress is vulnerable to Authentication Bypass via the GitHub OAuth callback in versions up to, and including, 6.2.3.… Mitigation only Fix from $1,9502026-07-10 HIGH 8.1 CVE-2026-12598 The LoginPress Pro plugin for WordPress is vulnerable to authentication bypass in versions up to and including 6.2.3 via the Spotify Social Login add… Mitigation only Fix from $1,9502026-07-10 HIGH 8.1 CVE-2026-55689 OpenFGA is an authorization/permission engine built for developers. Prior to 1.18.0, OpenFGA's OIDC authenticator skipped JWT audience validation whe… Helm Charts 0.3.9 / 1.18.0+ Fix from $1,9502026-07-09