Vulnerability index

Browse CVEs

2,855 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthenticationCWE-306 × clear
Unclassified CRITICAL 9.8
CVE-2026-47391

PraisonAI is a multi-agent teams system. Prior to version 4.6.40, PraisonAI's first-party A2A server example exposes an unauthenticated A2A JSON-RPC …

Patch available
Fix from $2,300 2026-07-21
Unclassified HIGH 8.2
CVE-2026-57495

AgenticMail gives AI agents real email addresses and phone numbers. In @agenticmail/claudecode prior to version 0.2.39, @agenticmail/codex prior to v…

Mitigation only
Fix from $1,950 2026-07-20
Xrdp HIGH 7.3
CVE-2026-55626

xrdp is an open source RDP server. In versions 0.10.6 and prior, when an authenticated user session is initialized using the Xvnc backend over UNIX d…

Fix: 0.10.6.1+
Fix from $1,950 2026-07-20
Whatsapp Mcp Server HIGH 7.1
CVE-2026-46555

WhatsApp MCP Server is a Model Context Protocol (MCP) server for WhatsApp, enabling Claude to read and send WhatsApp messages. Prior to version 0.2.1…

Fix available
Fix from $1,950 2026-07-20
Unclassified HIGH 8.6
CVE-2026-63429

HeyForm is an open-source form builder. Prior to version 3.0.0-rc.9, `POST /api/upload` has no authentication guard, no global guard, no form-context…

Patch available
Fix from $1,950 2026-07-20
Surrealdb HIGH 8.8
CVE-2026-63757

SurrealDB versions before 3.1.0 contain a session hijacking vulnerability where the HTTP /rpc sessions method returns attached session UUIDs without …

Fix: 3.1.0+
Fix from $1,950 2026-07-20
Unclassified CRITICAL 9.4
CVE-2026-16242

A flaw was found in the Konnectivity proxy-server configuration for hosted control planes. The agent-facing listener was started without --cluster-ca…

Patch available
Fix from $2,300 2026-07-20
Unclassified HIGH 7.3
CVE-2026-16210

A vulnerability was found in newpanjing simpleui 2026.01.13. This affects the function self.get_action of the file simpleui/admin.py of the component…

No fix yet
Fix from $1,950 2026-07-19
Unclassified HIGH 7.3
CVE-2026-16209

A vulnerability has been found in Gerapy up to 0.9.13. The impacted element is an unknown function of the file gerapy/server/core/views.py of the com…

Patch available
Fix from $1,950 2026-07-19
Langflow CRITICAL 9.8
CVE-2026-8505

IBM Langflow OSS 1.0.0 through 1.10.0 has a vulnerability in Langflow's webhook authentication logic allows unauthenticated users to trigger the exec…

Fix: 1.10.1+
Fix from $2,300 2026-07-17
Langflow CRITICAL 9.8
CVE-2026-9103

IBM Langflow OSS 1.0.0 through 1.10.0 could allow a remote attacker to gain unauthorized access due to improper authentication in the /api/v1/login/a…

Fix: 1.10.1+
Fix from $2,300 2026-07-17
Langflow CRITICAL 9.8
CVE-2026-9202

IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to create unlimited user accounts on any Langflow instance; when NEW_USER_IS_A…

Fix: 1.10.1+
Fix from $2,300 2026-07-17
Unclassified HIGH 7.5
CVE-2026-63101

Open Event Server through 1.19.1 contains a missing authentication vulnerability that allows unauthenticated attackers to export the complete member …

No fix yet
Fix from $1,950 2026-07-17
Unclassified HIGH 7.5
CVE-2026-12691

Missing authentication for critical function vulnerability in Vimesoft Inc. Enterprise Video Platform allows Authentication Bypass. This issue affec…

No fix yet
Fix from $1,950 2026-07-17
Thehive MEDIUM 5.3
CVE-2026-63098

TheHive through 4.1.24 contains an unauthenticated information disclosure vulnerability that allows unauthenticated attackers to retrieve sensitive c…

Fix: after 4.1.24
Fix from $1,600 2026-07-17
Unclassified MEDIUM 6.3
CVE-2026-16015

A vulnerability was determined in poco-ai poco-claw up to 0.5.4. This vulnerability affects the function create_task of the file executor_manager/app…

Patch available
Fix from $1,600 2026-07-17
Clawvet CRITICAL 9.1
CVE-2026-62241EPSS 7%

clawvet self-hosted API server (apps/api) before 0.7.5 hard-codes a fallback JWT secret ('clawvet-dev-secret-change-me') in auth.ts and ships it as t…

Fix: 0.7.5+
Fix from $2,300 2026-07-17
Unclassified HIGH 7.1
CVE-2024-34268

EQ-3 Eqiva CC-RT-BLE Bluetooth Smart Radiator Thermostat Firmware up to the latest version 1.46 was discovered to allow unsecured bluetooth connectio…

No fix yet
Fix from $1,950 2026-07-16
Unclassified CRITICAL 9.8
CVE-2026-63087

Grafana OnCall through 1.16.11 contains an unauthenticated access vulnerability that allows remote attackers to obtain a valid PluginAuthToken by sen…

No fix yet
Fix from $2,300 2026-07-16
Unclassified MEDIUM 5.5
CVE-2026-6511

During an internal security assessment, a potential improper access control vulnerability was discovered in Lenovo Smart Connect for Windows that cou…

No fix yet
Fix from $1,600 2026-07-16
Unclassified HIGH 8.6
CVE-2026-57206

SimpleChat is a secure AI conversation application with personal and group workspaces for document-grounded interactions. Prior to 0.241.206, several…

No fix yet
Fix from $1,950 2026-07-16
Unclassified CRITICAL 9.8
CVE-2026-45695

Kopia is a cross-platform backup tool for Windows, macOS, and Linux with fast incremental backups, client-side end-to-end encryption, compression, an…

Patch available
Fix from $2,300 2026-07-16
Unclassified CRITICAL 10.0
CVE-2026-46339

9Router is an AI router & token saver. From 0.4.30 until 0.4.37, 9Router's src/proxy.js middleware did not protect /api/cli-tools/* and /api/mcp/*, a…

Patch available
Fix from $2,300 2026-07-15
Unclassified HIGH 8.2
CVE-2026-58658

GPUStack through 2.2.1, fixed in commit 4e20551, contains an unauthenticated information disclosure vulnerability that allows unauthenticated attacke…

Patch available
Fix from $1,950 2026-07-15
Better Auth CRITICAL 9.1
CVE-2026-53512

Better Auth is an authentication and authorization library for TypeScript. Prior to 1.6.11, the legacy oidcProvider and mcp plugins expose OAuth toke…

Fix: 1.6.11+
Fix from $2,300 2026-07-15
Unclassified HIGH 7.7
CVE-2026-61613

Cursor is a code editor built for programming with AI. Prior to the Cloud Agent fix on 03/31/2026, browser-enabled Cursor Cloud Agent sessions allowe…

Mitigation only
Fix from $1,950 2026-07-15
Coldfusion CRITICAL 9.3
CVE-2026-48325

ColdFusion is affected by a Missing Authentication for Critical Function vulnerability that could result in arbitrary code execution in the context o…

Mitigation only
Fix from $2,300 2026-07-14
Unclassified HIGH 7.3
CVE-2026-24229

NVIDIA TensorRT-LLM for Linux contains a vulnerability in the disaggregated orchestrator component, where an attacker could read, write, or delete in…

Mitigation only
Fix from $1,950 2026-07-14
Unclassified MEDIUM 6.4
CVE-2026-24259

NVIDIA TensorRT-LLM for Linux contains a vulnerability where an attacker could cause missing authentication for a critical function. A successful exp…

Mitigation only
Fix from $1,600 2026-07-14
Experience Manager HIGH 8.6
CVE-2026-48252

Adobe Experience Manager is affected by a Missing Authentication for Critical Function vulnerability that could result in a Security feature bypass. …

Fix: after 2020.5.0
Fix from $1,950 2026-07-14