Vulnerability index

Browse CVEs

2,866 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthenticationCWE-306 × clear
Unclassified HIGH 8.8
CVE-2026-10054

In affected versions of Eclipse Theia (1.8.1 and later), the browser backend exposes privileged terminal RPC over WebSocket (/services/shell-terminal…

Mitigation only
Fix from $1,950 2026-07-03
Unclassified CRITICAL 9.8
CVE-2026-4767

Missing authentication for critical function vulnerability in TR7 Cyber ​​Defense Inc. WAF-ASP allows Authentication Abuse. This issue affects WAF-A…

Mitigation only
Fix from $2,300 2026-07-02
Unclassified HIGH 8.8
CVE-2026-13125

GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is an addon that can be installed with various GeoV…

Mitigation only
Fix from $1,950 2026-07-02
Pacsgear CRITICAL 9.8
CVE-2026-58126

PACSgear PACS Scan 5.2.1 contains an unauthenticated remote code execution vulnerability that allows remote attackers to read and write arbitrary fil…

Fix: after 5.2.1
Fix from $2,300 2026-07-01
Pacsgear CRITICAL 9.8
CVE-2026-58127

PACSgear MediaWriter 5.2.1 exposes a .NET Remoting TCP service on port 9000 via PacsgearMediaServerEngine.dll, registered with ObjectURIs RemoteObj a…

Fix: after 5.2.1
Fix from $2,300 2026-07-01
Unclassified HIGH 8.1
CVE-2026-56286

Capgo before 12.128.2 contains an authentication bypass vulnerability in the account deletion endpoint that allows deletion without password re-authe…

Mitigation only
Fix from $1,950 2026-06-30
Unclassified MEDIUM 6.5
CVE-2026-58446

Presenton before 0.8.8-beta bundles an MCP server that, on server/Docker deployments configured with session authentication (AUTH_USERNAME/AUTH_PASSW…

Patch available
Fix from $1,600 2026-06-30
Unclassified HIGH 7.5
CVE-2026-58375

JimuReport through 2.5.0 exposes the POST /jmreport/auto/export endpoint without authentication: the handler is annotated @JimuNoLoginRequired, so Ji…

Mitigation only
Fix from $1,950 2026-06-30
Unclassified HIGH 7.0
CVE-2026-44949

A Rancher FleetWorkspace admission path allowed side effects to occur in the Rancher webhook handler for versions 0.7.0 up to 0.7.10, 0.8.0 up to 0.…

Mitigation only
Fix from $1,950 2026-06-30
Unclassified CRITICAL 9.8
CVE-2026-14162

Hospital Queuing Management developed by Advantech has a Sensitive Data Exposure vulnerability, allowing unauthenticated remote attackers to access a…

Mitigation only
Fix from $2,300 2026-06-30
Unclassified CRITICAL 9.3
CVE-2026-12819

Delta Electronics DVP12SE PLC exposes a Modbus TCP service over a specified port without authentication or access control, permitting unauthenticated…

Mitigation only
Fix from $2,300 2026-06-30
Unclassified CRITICAL 9.8
CVE-2026-56782

Gorse before 0.5.10 contains an authentication bypass vulnerability in the /api/dump and /api/restore endpoints that allows unauthenticated attackers…

Patch available
Fix from $2,300 2026-06-29
Unclassified HIGH 7.3
CVE-2026-13546

A vulnerability was found in Feehi CMS up to 2.1.1. This vulnerability affects unknown code of the file /api/articles of the component REST API Endpo…

Mitigation only
Fix from $1,950 2026-06-29
Budibase MEDIUM 5.3
CVE-2026-50136

Budibase is an open-source low-code platform. Prior to 3.39.3, the application server exposes an unauthenticated endpoint that generates S3 PutObject…

Fix: 3.39.3+
Fix from $1,600 2026-06-26
Kubevirt HIGH 8.5
CVE-2026-13325

A flaw was found in KubeVirt's migration proxy. When spec.configuration.migrations.disableTLS is set to true on the KubeVirt custom resource, the tar…

Fix: after 4.22.0
Fix from $1,950 2026-06-26
Unclassified MEDIUM 6.9
CVE-2026-43920

FOSSBilling is a free, open-source billing and client management system. In versions 0.5.4 through 0.7.2, the /run-patcher maintenance endpoint in FO…

Mitigation only
Fix from $1,600 2026-06-26
Unclassified CRITICAL 9.4
CVE-2026-40702

WebSocket endpoints lack proper authentication mechanisms, enabling attackers to impersonate charging stations. As a result, attackers can exploit th…

Mitigation only
Fix from $2,300 2026-06-25
Flowise CRITICAL 9.1
CVE-2025-71327

Flowise contains an authentication bypass vulnerability in the unprotected /api/v1/account/register endpoint that allows unauthenticated attackers to…

No fix yet
Fix from $2,300 2026-06-25
Unclassified CRITICAL 9.3
CVE-2026-54088

File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.6…

Mitigation only
Fix from $2,300 2026-06-25
Librechat HIGH 7.1
CVE-2026-54040

LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. Prior to 0.8.4-rc1, the POST /api/auth/2fa/backup/regenerate endpoint reg…

Fix: after 0.8.3
Fix from $1,950 2026-06-25
Librechat HIGH 8.1
CVE-2026-54036

LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. Prior to 0.8.4-rc1, the GET /api/auth/2fa/enable endpoint can be called b…

Fix: after 0.8.3
Fix from $1,950 2026-06-25
Unclassified MEDIUM 6.7
CVE-2026-4522

Missing authentication for critical function vulnerability in HYPR Passwordless on Windows allows Credentials Interception. This issue affects HYPR …

Mitigation only
Fix from $1,600 2026-06-25
Nsd HIGH 7.5
CVE-2026-12490

When a provide-xfr is given with a tls-auth-name, a secondary requesting a transfer should provide a client certificate with that name. However, no c…

Fix: 4.14.3+
Fix from $1,950 2026-06-25
Unclassified MEDIUM 5.9
CVE-2026-54068

SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, the /api/icon/getDynamicIcon endpoint is explicitly excluded from auth…

Mitigation only
Fix from $1,600 2026-06-24
Unclassified CRITICAL 9.3
CVE-2026-33543

FOSSBilling is a free, open-source billing and client management system. Versions 0.7.2 and prior expose a guest API endpoint, /api/guest/staff/creat…

Mitigation only
Fix from $2,300 2026-06-24
Unclassified HIGH 7.5
CVE-2026-1840

The Aclara Metrum Cellular Web Interface is vulnerable to unauthorized access due to the absence of authentication controls on critical system functi…

Mitigation only
Fix from $1,950 2026-06-24
Rclone CRITICAL 9.8
CVE-2026-49980

Rclone is a command-line program to sync files and directories to and from different cloud storage providers. From 1.46.0 until 1.74.3, rclone rcd --…

Fix: 1.74.3+
Fix from $2,300 2026-06-24
Unclassified HIGH 8.8
CVE-2026-13164

Missing Authentication for Critical Function (CWE-306) in the RegisterView (apps/accounts/views.py), exposed at POST /api/auth/register/, in MailerUp…

Patch available
Fix from $1,950 2026-06-24
Crawl4ai MEDIUM 6.5
CVE-2026-56262

Crawl4AI before 0.8.7 contains an authentication bypass vulnerability in the monitor router endpoints that allows unauthenticated attackers to access…

Fix: 0.8.7+
Fix from $1,600 2026-06-24
Flowise HIGH 7.5
CVE-2026-56270

Flowise before 3.1.0 (versions 3.0.13 and earlier) contains a missing authentication vulnerability in the /api/v1/loginmethod endpoint that allows un…

Fix: 3.1.0+
Fix from $1,950 2026-06-24