Vulnerability index

Browse CVEs

2,866 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthenticationCWE-306 × clear
Home Assistant HIGH 7.6
CVE-2026-54317

Home Assistant is open source home automation software that puts local control and privacy first. Prior to 2026.6.0, the Konnected integration regist…

Fix: 2026.6.0+
Fix from $1,950 2026-06-23
Langflow CRITICAL 9.3
CVE-2026-55450EPSS 12%

Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.1, unauthenticated users can upload any amount of data to…

Fix: 1.9.1+
Fix from $2,300 2026-06-23
Identity Exposure HIGH 7.5
CVE-2026-13007

Tenable Identity Exposure contains multiple unauthenticated API endpoints under /w/api/* that expose sensitive application configuration data includi…

Fix: 3.93.5+
Fix from $1,950 2026-06-23
N8n CRITICAL 10.0
CVE-2026-54309

n8n is an open source workflow automation platform. Prior to 2.25.7 and 2.26.2, when @n8n/mcp-browser is run in HTTP transport mode, the MCP endpoint…

Fix: 2.25.7 / 2.26.2+
Fix from $2,300 2026-06-23
Unclassified CRITICAL 10.0
CVE-2026-27604

FOSSBilling is a free, open-source billing and client management system. Starting in version 0.5.4 and prior to version 0.8.0, an authorization bypas…

Mitigation only
Fix from $2,300 2026-06-23
Unclassified HIGH 8.8
CVE-2026-10711

Missing authentication for critical function vulnerability in AKIN Software Computer Import Export Industry and Trade Ltd. CafePlus allows Accessing …

Mitigation only
Fix from $1,950 2026-06-23
Unclassified MEDIUM 5.3
CVE-2026-56321

Capgo (backend Supabase edge functions) before 12.128.2 does not apply the global authentication middleware to the GET /private/role_bindings/:org_id…

No fix yet
Fix from $1,600 2026-06-22
Qsnapper MEDIUM 5.5
CVE-2026-41047

Lack of authentication when using the "snapshot diff" functions in qSnapper before version 1.3.3 allowed a local attacker to see otherwise read prote…

Fix: 1.3.3+
Fix from $1,600 2026-06-22
Mattermost Server MEDIUM 6.4
CVE-2026-6673

Mattermost versions 11.7.x <= 11.7.0, 11.6.x <= 11.6.2, 11.5.x <= 11.5.5, 10.11.x <= 10.11.17 fail to authenticate Atlassian Connect installed callba…

Fix: 10.11.18 / 11.5.6+
Fix from $1,600 2026-06-22
Unclassified MEDIUM 5.3
CVE-2026-56299

Capgo before 12.128.2 contains an authentication bypass vulnerability in the /build/upload/:jobId/* endpoint that allows unauthenticated attackers to…

Mitigation only
Fix from $1,600 2026-06-21
Litellm HIGH 7.3
CVE-2026-12795

A vulnerability was determined in BerriAI litellm up to 1.82.2. This affects the function json.dumps of the file litellm/proxy/management_endpoints/u…

Fix: after 1.82.2
Fix from $1,950 2026-06-21
Unclassified MEDIUM 6.5
CVE-2026-56346

AVideo through version 25.0 contains an authentication bypass vulnerability in the decryptMessage.json.php endpoint that allows unauthenticated users…

Mitigation only
Fix from $1,600 2026-06-20
Instrumentstudio CRITICAL 9.1
CVE-2026-9142

There is an insecure default credentials vulnerability in NI grpc-device when TLS configuration is not present and the server is bound beyond loopbac…

Fix: 2.18.0+
Fix from $2,300 2026-06-19
Unclassified HIGH 8.8
CVE-2026-49357

Line Desktop MCP is a project that, while unaffiliated with the official line-bot-mcp-server, allows users to directly operate the LINE Desktop appli…

Patch available
Fix from $1,950 2026-06-19
Hub CRITICAL 9.8
CVE-2026-50242

In JetBrains Hub before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 authentication bypass via direct data…

Fix: 2024.2.148429 / 2024.3.148430+
Fix from $2,300 2026-06-19
Pgadmin 4 CRITICAL 9.0
CVE-2026-12046

Two state-mutating endpoints in pgAdmin 4's SQL Editor blueprint -- DELETE /sqleditor/close/<trans_id> and POST /sqleditor/initialize/sqleditor/updat…

Fix: 9.16+
Fix from $2,300 2026-06-19
365 Copilot HIGH 7.5
CVE-2026-54130

Missing authentication for critical function in M365 Copilot allows an unauthorized attacker to disclose information over a network.

Mitigation only
Fix from $1,950 2026-06-18
Unclassified CRITICAL 10.0
CVE-2026-49257

mcp-pinot is a Python-based Model Context Protocol (MCP) server for interacting with Apache Pinot. In versions 3.0.1 and below, mcp-pinot defaults to…

Patch available
Fix from $2,300 2026-06-18
Unclassified CRITICAL 9.8
CVE-2026-54103

The U.S. Government Accountability Office (GAO) Electronic Protest Docketing System (EPDS) and Civilian Board of Contract Appeals (CBCA) Electronic D…

Mitigation only
Fix from $2,300 2026-06-18
Unclassified MEDIUM 6.0
CVE-2026-12527

A broken authorization boundary in the RTSP media delivery pipeline of Shenzhen Liandian Communication Technology LTD V380 IP Camera firmware AppFHE1…

Mitigation only
Fix from $1,600 2026-06-18
Unclassified HIGH 8.9
CVE-2026-48989

Windows-MCP is an open-source project that integrates AI agents with Windows. In versions prior to 0.7.5, certain HTTP modes exposed the MCP control …

Mitigation only
Fix from $1,950 2026-06-17
Unclassified CRITICAL 9.1
CVE-2026-48814

Network-AI is a TypeScript/Node.js multi-agent orchestrator. In versions 5.7.1 and earlier, the MCP SSE server allows unauthenticated cross-origin MC…

Mitigation only
Fix from $2,300 2026-06-17
Unclassified CRITICAL 9.1
CVE-2026-55196

Hermes WebUI before 0.51.409 contains an authentication bypass vulnerability in passkey registration endpoints that allows unauthenticated remote att…

Patch available
Fix from $2,300 2026-06-17
Unclassified HIGH 7.5
CVE-2026-53869

Hermes Agent before 0.16.0 contains a DNS rebinding vulnerability in WebSocket endpoints that allows remote attackers to bypass Host and Origin valid…

Patch available
Fix from $1,950 2026-06-17
Connext Professional HIGH 8.1
CVE-2026-30799

Missing Authentication for Critical Function vulnerability in RTI Connext Professional (Security Plugins) allows Identity Spoofing.This issue affects…

Fix: 7.7.0+
Fix from $1,950 2026-06-17
Connext Professional MEDIUM 6.5
CVE-2026-2675

Missing Authentication for Critical Function vulnerability in RTI Connext Professional (Security Plugins) allows Fake the Source of Data.This issue a…

Fix: 7.7.0+
Fix from $1,600 2026-06-17
Powerflex Manager HIGH 8.8
CVE-2026-35065

Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) a Missing Authentication for Critical Function vulnerability. An unauthenticated atta…

Fix: 4.5.5.2 / 5.1.0.1+
Fix from $1,950 2026-06-17
Unclassified HIGH 7.5
CVE-2026-12199

A vulnerability in `nltk.app.wordnet_app` up to version 3.9.3 allows unauthenticated remote shutdown of the local WordNet Browser HTTP server when st…

Mitigation only
Fix from $1,950 2026-06-17
Outsourced Manufacturing For Discrete Industries HIGH 8.8
CVE-2026-46972

Vulnerability in the Oracle Outsourced Mfg for Discrete Industries product of Oracle E-Business Suite (component: Internal Operations). Supported ve…

Fix: after 12.2.15
Fix from $1,950 2026-06-17
Outsourced Manufacturing For Discrete Industries HIGH 8.8
CVE-2026-46973

Vulnerability in the Oracle Outsourced Mfg for Discrete Industries product of Oracle E-Business Suite (component: Internal Operations). Supported ve…

Fix: after 12.2.15
Fix from $1,950 2026-06-17