Vulnerability index

Browse CVEs

2,855 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthenticationCWE-306 × clear
Unclassified CRITICAL 9.2
CVE-2026-71878

Missing authentication in initial setup functionality left exposed after initial setup is completed in GBIF Integrated Publishing Toolkit versions be…

Fix unknown
Fix from $5,750 2026-08-18
Unclassified CRITICAL 9.8
CVE-2026-75852

ArcadeDB versions before 26.8.1 fail to enforce SASL authentication on data commands in the MongoDB wire-protocol plugin. Unauthenticated attackers c…

Fix unknown
Fix from $5,750 2026-08-18
Unclassified CRITICAL 9.8
CVE-2026-75854

ArcadeDB versions before 26.8.1 contain a missing authentication vulnerability in the Redis wire-protocol plugin that allows unauthenticated attacker…

Fix unknown
Fix from $5,750 2026-08-18
Unclassified HIGH 8.6
CVE-2026-56677

9Router is an AI router & token saver. In 0.5.4 and earlier, the POST /api/auth/oidc/test endpoint in src/app/api/auth/oidc/test/route.js passes the …

Fix unknown
Fix from $4,900 2026-08-17
Unclassified HIGH 7.5
CVE-2026-75479

JimuReport contains an authentication bypass vulnerability in the report folder template listing endpoint that allows unauthenticated attackers to en…

Fix unknown
Fix from $4,900 2026-08-17
Unclassified CRITICAL 9.8
CVE-2026-67966

Tenda W20E V16.01.0.6(2782) /goform/telnet endpoint allows unauthenticated remote attackers to activate the Telnet daemon and obtain root shell acces…

Fix unknown
Fix from $5,750 2026-08-17
Unclassified HIGH 8.4
CVE-2026-75060

In JetBrains PyCharm before 2026.2.1 code execution was possible via unauthenticated Jupyter MCP tools

Fix unknown
Fix from $4,900 2026-08-17
Unclassified CRITICAL 9.3
CVE-2026-71566

FakeFish handles incoming credentials by passing them down to scripts. This works for real hardware because in the end it's up to the BMC to valida…

Fix unknown
Fix from $5,750 2026-08-17
Unclassified MEDIUM 6.5
CVE-2026-74243

A flaw was found in Red Hat Quay. When the SECURITY_SCANNER_V4_PSK (pre-shared key) is not set, a remote unauthenticated attacker can send POST reque…

No fix yet
Fix from $4,000 2026-08-14
Unclassified MEDIUM 5.9
CVE-2026-74245

A flaw was found in Red Hat Quay's exported logs feature. An unauthenticated attacker with a valid file ID could download exported action logs withou…

No fix yet
Fix from $4,000 2026-08-14
Unclassified HIGH 7.1
CVE-2026-19908

PAX Technology Q80 XCB Daemon Missing Authentication Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive inform…

No fix yet
Fix from $4,900 2026-08-14
Unclassified CRITICAL 9.8
CVE-2026-50027

mcp-memory-service is a semantic memory layer for AI applications. Prior to 10.67.1, all HTTP routes under /api/documents/* in mcp-memory-service are…

No fix yet
Fix from $5,750 2026-08-14
Unclassified CRITICAL 9.8
CVE-2026-73849

Emlog is an open source website building system. In 2.6.26 and earlier, install.php accepts action=reinstall without authentication and deliberately …

No fix yet
Fix from $5,750 2026-08-14
Unclassified HIGH 8.8
CVE-2026-73673

Netis NC63 router firmware V3.0.0.3327 contains an unauthenticated firmware update vulnerability that allows unauthenticated attackers to submit unsi…

No fix yet
Fix from $4,900 2026-08-14
Unclassified CRITICAL 9.8
CVE-2026-72822

The getgrav/grav-plugin-api Composer package before 1.0.13 (affected <= 1.0.12) fails to enforce API key scope caps on the disable2fa endpoint. Unlik…

No fix yet
Fix from $5,750 2026-08-14
Unclassified CRITICAL 9.0
CVE-2026-73842

OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.0.3, 1.1.3, and 1.2.0-rc.2, internal/cluster-gateway/server.go ex…

No fix yet
Fix from $5,750 2026-08-13
Unclassified CRITICAL 9.6
CVE-2026-73843

OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.0.2 and 1.1.2, internal/cluster-gateway/server.go served caller-f…

No fix yet
Fix from $5,750 2026-08-13
Unclassified HIGH 8.2
CVE-2026-73666

OpenChoreo is a developer platform for Kubernetes. Prior to 1.0.4, 1.1.4, and 1.2.1, the OpenChoreo Backstage backend hardcoded backend.auth.dangerou…

No fix yet
Fix from $4,900 2026-08-13
Unclassified CRITICAL 9.8
CVE-2026-72776

AgenticSeek (commit fc242c7) contains an unauthenticated remote code execution vulnerability that allows any network-adjacent attacker to execute arb…

No fix yet
Fix from $5,750 2026-08-13
Unclassified HIGH 7.3
CVE-2026-73669

The Signify Philips Hue Bridge Pro firmware embeds a Mosquitto MQTT broker service that listens on all network interfaces without authentication. An …

No fix yet
Fix from $4,900 2026-08-13
Websphere Application Server CRITICAL 9.4
CVE-2026-14525

IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 IBM WebSphere Application Server Liberty is vulnerable to an authentication bypa…

No fix yet
Fix from $5,750 2026-08-13
Unclassified CRITICAL 9.8
CVE-2026-49827

WebErpMesv2 is a Resource Management and Manufacturing execution system Web for industry. Versions 1.19 and prior allow any self-registered user to u…

No fix yet
Fix from $5,750 2026-08-13
Unclassified CRITICAL 9.3
CVE-2026-59506

CWE-306: Missing Authentication for Critical Function

No fix yet
Fix from $5,750 2026-08-13
Unclassified CRITICAL 9.8
CVE-2026-49819

UpSnap is a wake on lan web app. Versions 4.4.1 through 5.3.5 are vulnerable to a missing-authentication / privilege-escalation chain in `pb.HandlerI…

No fix yet
Fix from $5,750 2026-08-13
Unclassified MEDIUM 5.3
CVE-2026-18673

When kuma-dp is configured with the Envoy admin API on a Unix domain socket, which is the default, its readiness service on TCP port 9902 - bound to …

No fix yet
Fix from $4,000 2026-08-12
Unclassified CRITICAL 9.4
CVE-2026-73296

Microsoft UFO open-source framework for intelligent automation across devices and platforms. Prior to 3.0.8, create_mobile_data_collection_server and…

No fix yet
Fix from $5,750 2026-08-12
Unclassified HIGH 8.8
CVE-2026-65941

In WhatsUp Gold versions released before 2026.0.2, an unauthenticated remote attacker with network access to the affected service can execute arbitra…

No fix yet
Fix from $4,900 2026-08-12
Unclassified HIGH 8.2
CVE-2026-19426

POS System developed by FitSoft has a Missing Authentication vulnerability. Unauthenticated remote attackers can directly access and operate the syst…

No fix yet
Fix from $4,900 2026-08-12
Unclassified MEDIUM 6.5
CVE-2026-73245

Kestra is an open-source, event-driven orchestration platform. Prior to 2.0.0-rc6, Kestra's cli/src/main/resources/application.yml serves Micronaut m…

No fix yet
Fix from $4,000 2026-08-11
Unclassified HIGH 7.5
CVE-2026-73246

Kestra is an open-source, event-driven orchestration platform. Prior to 2.0.0-rc6, Kestra's worker/src/main/java/io/kestra/worker/endpoint/WorkerEndp…

No fix yet
Fix from $4,900 2026-08-11