Vulnerability index

Browse CVEs

2,866 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthenticationCWE-306 × clear
Ai Assist For Customer MEDIUM 5.3
CVE-2026-57475

Deloitte AI Assist for Customer accepted unauthenticated POST requests through public-facing API endpoints that allowed a remote attacker to make lim…

Fix: 2026-03-25+
Fix from $1,600 2026-07-10
Unclassified HIGH 8.3
CVE-2026-56675

9Router is an AI router & token saver. Prior to 0.5.2, 9router treats loopback requests as trusted and allows /v1/* access without an API key, so a s…

Patch available
Fix from $1,950 2026-07-10
Unclassified HIGH 7.5
CVE-2026-38059

The iDirect iQ200 exposes the /api/identity and /api/ REST API endpoints without authentication. An unauthenticated attacker with network access can …

Mitigation only
Fix from $1,950 2026-07-10
Unclassified HIGH 7.5
CVE-2026-40006

Memory Allocation with Excessive Size Value, Allocation of Resources Without Limits or Throttling, Missing Authentication for Critical Function vulne…

Mitigation only
Fix from $1,950 2026-07-10
Unclassified CRITICAL 9.8
CVE-2026-58123

Hermes WebUI before 0.51.788 contains an unauthenticated remote code execution vulnerability that allows remote attackers to execute arbitrary shell …

Patch available
Fix from $2,300 2026-07-09
Unclassified MEDIUM 5.3
CVE-2026-55605

DeepSeek MCP Server is an MCP server for DeepSeek V4. Starting in version 1.4.2 and prior to version 1.8.0, the self-hosted HTTP transport of `@ariku…

Mitigation only
Fix from $1,600 2026-07-09
Unclassified HIGH 8.8
CVE-2026-59148

Mockoon provides way to design and run mock APIs. Prior to 9.7.0, Mockoon's admin API in commons-server/src/libs/server/admin-api.ts is mounted on th…

Patch available
Fix from $1,950 2026-07-09
Pan Os HIGH 7.2
CVE-2026-0283

An authentication bypass vulnerability in Large Scale VPN ( LSVPN) functionality of Palo Alto Networks PAN-OS software allows an attacker with networ…

Fix: 10.2.7 / 10.2.10+
Fix from $1,950 2026-07-09
Unclassified MEDIUM 5.3
CVE-2026-61344

The Superior Court of California Hearing Reminder Service at https://www.hrs.courts.ca.gov exposes an API endpoint that returns court reminder record…

Mitigation only
Fix from $1,600 2026-07-09
Unclassified CRITICAL 10.0
CVE-2026-59726

Ruflo is an agent meta-harness for Claude Code and Codex. Prior to 3.16.3, ruflo's default docker-compose deployment exposed the MCP bridge POST /mcp…

Patch available
Fix from $2,300 2026-07-09
Open Webui MEDIUM 6.5
CVE-2026-59715

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.6.16 before 0.10.0, the Socket.IO server is configured w…

Fix: 0.10.0+
Fix from $1,600 2026-07-09
Unclassified MEDIUM 6.5
CVE-2026-15192

A vulnerability has been found in mettle sendportal up to 3.0.1. This issue affects the function sendgrid/postmark/postal/mailjet of the component AP…

Mitigation only
Fix from $1,600 2026-07-09
Cmc MEDIUM 5.3
CVE-2026-31983

A Missing Authentication vulnerability was discovered in the SSH keys synchronization endpoint. An unauthenticated attacker can send a request to the…

Fix: 26.2.0+
Fix from $1,600 2026-07-09
Fluentd HIGH 7.5
CVE-2026-44025

Fluentd collects events from various data sources and writes them to files, RDBMS, NoSQL, IaaS, SaaS, Hadoop and so on. Prior to 1.19.3, Fluentd's Mo…

Fix: 1.19.3+
Fix from $1,950 2026-07-08
Litellm HIGH 8.2
CVE-2026-59822

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.84.0, LiteLLM's MCP Streamable HTTP endpoint allowed…

Fix: 1.84.0+
Fix from $1,950 2026-07-08
Unclassified MEDIUM 6.8
CVE-2026-59804

Midscene Bridge Server through 1.10.3, fixed in commit 86f4118, contains a missing authentication and CORS misconfiguration vulnerability that allows…

Patch available
Fix from $1,600 2026-07-08
Unclassified MEDIUM 6.3
CVE-2026-15063

A flaw was found in the gorch service template, which is part of the trustyai-service-operator. Even when authentication is enabled, the gorch servic…

Mitigation only
Fix from $1,600 2026-07-08
Unclassified CRITICAL 9.1
CVE-2026-54061

Dgraph is an open source distributed GraphQL database. Prior to version 25.3.5, Dgraph Alpha exposes the RPCs used for external snapshot import on th…

Mitigation only
Fix from $2,300 2026-07-08
Unclassified HIGH 7.5
CVE-2026-51937

An issue in Oneblog V2.3.9 allows a remote attacker to obtain sensitive information via the RestApiController.java, JsApiTicketComponent.java, and th…

Mitigation only
Fix from $1,950 2026-07-07
Unclassified CRITICAL 9.8
CVE-2026-59705

mem0's openmemory/api component contains an unauthenticated access vulnerability that allows unauthenticated attackers to read, write, and delete arb…

Patch available
Fix from $2,300 2026-07-07
Unclassified CRITICAL 9.3
CVE-2026-59706

mem0 contains unauthenticated config API endpoints that expose LLM API keys in plaintext and allow server-side request forgery via attacker-controlle…

Patch available
Fix from $2,300 2026-07-07
Unclassified CRITICAL 9.1
CVE-2026-58473

Cognee before 1.2.0 contains an improper access control vulnerability that allows unauthenticated attackers to overwrite the global LLM provider conf…

Patch available
Fix from $2,300 2026-07-07
Serena HIGH 8.3
CVE-2026-49471

Serena is a powerful MCP toolkit for coding that provides semantic retrieval and editing capabilities. Prior to v1.5.2, Serena's built-in web dashboa…

Fix: 1.5.2+
Fix from $1,950 2026-07-07
Unclassified MEDIUM 6.9
CVE-2026-53647

FOSSBilling is a free, open-source billing and client management system. In versions 0.5.3 through 0.7.2, the Guest `serviceapikey/get_info` API endp…

Mitigation only
Fix from $1,600 2026-07-07
Unclassified MEDIUM 6.5
CVE-2026-41899

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.474, POST /api/feedback has n…

Patch available
Fix from $1,600 2026-07-06
Unclassified HIGH 7.7
CVE-2026-42331

FOSSBilling is a free, open-source billing and client management system. Prior to version 0.8.0, the Guest API invoice/update endpoint is missing an …

Mitigation only
Fix from $1,950 2026-07-06
Unclassified CRITICAL 9.2
CVE-2026-42341

FOSSBilling is a free, open-source billing and client management system. Versions 0.6.0 through 0.7.2 have an unauthenticated payment bypass vulnerab…

Mitigation only
Fix from $2,300 2026-07-06
Camel CRITICAL 9.8
CVE-2026-53913

Improper Authentication, Missing Authentication for Critical Function, Not Failing Securely ('Failing Open') vulnerability in Apache Camel Keycloak C…

Fix: 4.18.3 / 4.21.0+
Fix from $2,300 2026-07-06
Unclassified MEDIUM 6.5
CVE-2026-14714

A weakness has been identified in zhayujie chatgpt-on-wechat CowAgent 2.1.0. This issue affects the function verify_server of the file channel/wechat…

Patch available
Fix from $1,600 2026-07-05
Unclassified HIGH 7.3
CVE-2026-14622

A vulnerability was found in jairiidriss restaurant-website-php-mysql up to 521428b5b612449df0cf4a5d15ee40cba67f3d35. This vulnerability affects unkn…

Mitigation only
Fix from $1,950 2026-07-04