Vulnerability index

Browse CVEs

2,866 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthenticationCWE-306 × clear
Unclassified MEDIUM 5.5
CVE-2026-6511

During an internal security assessment, a potential improper access control vulnerability was discovered in Lenovo Smart Connect for Windows that cou…

No fix yet
Fix from $1,600 2026-07-16
Unclassified HIGH 8.6
CVE-2026-57206

SimpleChat is a secure AI conversation application with personal and group workspaces for document-grounded interactions. Prior to 0.241.206, several…

No fix yet
Fix from $1,950 2026-07-16
Unclassified CRITICAL 9.8
CVE-2026-45695

Kopia is a cross-platform backup tool for Windows, macOS, and Linux with fast incremental backups, client-side end-to-end encryption, compression, an…

Patch available
Fix from $2,300 2026-07-16
Unclassified CRITICAL 10.0
CVE-2026-46339

9Router is an AI router & token saver. From 0.4.30 until 0.4.37, 9Router's src/proxy.js middleware did not protect /api/cli-tools/* and /api/mcp/*, a…

Patch available
Fix from $2,300 2026-07-15
Unclassified HIGH 8.2
CVE-2026-58658

GPUStack through 2.2.1, fixed in commit 4e20551, contains an unauthenticated information disclosure vulnerability that allows unauthenticated attacke…

Patch available
Fix from $1,950 2026-07-15
Better Auth CRITICAL 9.1
CVE-2026-53512

Better Auth is an authentication and authorization library for TypeScript. Prior to 1.6.11, the legacy oidcProvider and mcp plugins expose OAuth toke…

Fix: 1.6.11+
Fix from $2,300 2026-07-15
Unclassified HIGH 7.7
CVE-2026-61613

Cursor is a code editor built for programming with AI. Prior to the Cloud Agent fix on 03/31/2026, browser-enabled Cursor Cloud Agent sessions allowe…

Mitigation only
Fix from $1,950 2026-07-15
Coldfusion CRITICAL 9.3
CVE-2026-48325

ColdFusion is affected by a Missing Authentication for Critical Function vulnerability that could result in arbitrary code execution in the context o…

Mitigation only
Fix from $2,300 2026-07-14
Unclassified HIGH 7.3
CVE-2026-24229

NVIDIA TensorRT-LLM for Linux contains a vulnerability in the disaggregated orchestrator component, where an attacker could read, write, or delete in…

Mitigation only
Fix from $1,950 2026-07-14
Unclassified MEDIUM 6.4
CVE-2026-24259

NVIDIA TensorRT-LLM for Linux contains a vulnerability where an attacker could cause missing authentication for a critical function. A successful exp…

Mitigation only
Fix from $1,600 2026-07-14
Experience Manager HIGH 8.6
CVE-2026-48252

Adobe Experience Manager is affected by a Missing Authentication for Critical Function vulnerability that could result in a Security feature bypass. …

Fix: after 2020.5.0
Fix from $1,950 2026-07-14
Symfony MEDIUM 5.3
CVE-2026-47212

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 6.4.40, 7.4.12, and 8.0.12, TwilioRequestP…

Fix: 6.4.40 / 7.4.12+
Fix from $1,600 2026-07-14
Symfony MEDIUM 5.3
CVE-2026-45754

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 6.4.40, 7.4.12, and 8.0.12, the Mailjet ma…

Fix: 6.4.40 / 7.4.12+
Fix from $1,600 2026-07-14
Symfony MEDIUM 5.3
CVE-2026-45755

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 7.4.12 and 8.0.12, MailtrapRequestParser::…

Fix: 7.4.12 / 8.0.12+
Fix from $1,600 2026-07-14
Windows 10 1607 HIGH 7.8
CVE-2026-50451

Missing authentication for critical function in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges …

Fix: 10.0.14393.9339 / 10.0.17763.9020+
Fix from $1,950 2026-07-14
Windows 10 1607 HIGH 8.8
CVE-2026-50444

Missing authentication for critical function in Windows Server Update Service allows an authorized attacker to elevate privileges over a network.

Fix: 10.0.14393.9339 / 10.0.17763.9020+
Fix from $1,950 2026-07-14
Azure Cyclecloud HIGH 8.8
CVE-2026-57969

Missing authentication for critical function in Azure CycleCloud allows an authorized attacker to elevate privileges over a network.

Fix: 8.9.1+
Fix from $1,950 2026-07-14
Sharepoint Server CRITICAL 9.8
CVE-2026-56164 KEVEPSS 22%

Missing authentication for critical function in Microsoft Office SharePoint allows an unauthorized attacker to elevate privileges over a network.

Fix: 16.0.19725.20434+
Fix from $2,300 2026-07-14
Windows 10 1607 HIGH 7.8
CVE-2026-50333

Missing authentication for critical function in Windows Spaceport.sys allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.9339 / 10.0.17763.9020+
Fix from $1,950 2026-07-14
Windows 10 1809 MEDIUM 6.1
CVE-2026-49174

Missing authentication for critical function in Microsoft Windows DNS allows an authorized attacker to perform tampering locally.

Fix: 10.0.17763.9020 / 10.0.19044.7548+
Fix from $1,600 2026-07-14
Unclassified CRITICAL 10.0
CVE-2026-10577

A security issue exists within the 1715-AENTR EtherNet/IP Adapter. The affected product exposes a network-accessible debug port that does not enforce…

Mitigation only
Fix from $2,300 2026-07-14
Youtrack CRITICAL 9.8
CVE-2026-62422

In JetBrains YouTrack before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 authentication bypass via direct…

Fix: 2024.2.148429 / 2024.3.148430+
Fix from $2,300 2026-07-14
Doris CRITICAL 9.1
CVE-2026-58319

Certain Apache Doris FE HTTP REST administrative APIs were accessible without proper authentication. An unauthenticated attacker with network access …

Fix: 3.1.0+
Fix from $2,300 2026-07-14
Unclassified HIGH 8.9
CVE-2026-15416

A flaw was identified in Argo CD, the GitOps engine used by Red Hat OpenShift GitOps, that could allow an unauthenticated attacker with network acces…

Patch available
Fix from $1,950 2026-07-14
Unclassified CRITICAL 9.1
CVE-2026-62327

9Router through version 0.4.41 contains an unauthenticated information disclosure vulnerability that allows remote attackers to retrieve plaintext AP…

Mitigation only
Fix from $2,300 2026-07-13
Unclassified CRITICAL 9.8
CVE-2026-59801

9Router through version 0.4.41 contains an unauthenticated access vulnerability that allows remote attackers to interact with provider management API…

Mitigation only
Fix from $2,300 2026-07-13
Unclassified CRITICAL 9.3
CVE-2026-6847

Remote Code Execution vulnerability exists in ThemisNETPanel due to missing authentication for a critical file upload function. The application expos…

Mitigation only
Fix from $2,300 2026-07-13
Unclassified CRITICAL 9.3
CVE-2026-22096

The webserver running on port 8090 does not require authentication. This allows for sensitive information leakage such as configured passwords, or up…

Mitigation only
Fix from $2,300 2026-07-13
Unclassified HIGH 7.3
CVE-2026-15491

A weakness has been identified in RafyMrX TOKO-ONLINE-ROTI up to ddfe1cd587be0a0b5135d8b6e85cce2ec3aece99. This affects an unknown part. This manipul…

No fix yet
Fix from $1,950 2026-07-12
Unclassified CRITICAL 9.2
CVE-2026-55884

Tilt defines dev environments as code for microservice apps on Kubernetes. From 0.20.8 through 0.37.3, the Tilt HUD HTTP server registers handlers on…

Patch available
Fix from $2,300 2026-07-10