Vulnerability index

Browse CVEs

2,855 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthenticationCWE-306 × clear
Unclassified HIGH 8.8
CVE-2026-66875

In the Mira hormone monitor device firmware v1.7.1.47 build 01070147, a remote unauthenticated attacker within BLE range (approximately 10–30 meters)…

No fix yet
Fix from $4,900 2026-08-11
Unclassified MEDIUM 6.5
CVE-2026-66098

The Mira hormone monitor device firmware accepts a 0x01 write from any BLE central without authentication, causing the device to reboot into bootload…

No fix yet
Fix from $4,000 2026-08-11
Unclassified HIGH 8.8
CVE-2026-73222

Claude Code Templates is a CLI tool for configuring and monitoring Claude Code. Prior to 1.29.4, the Claude Code Studio server launched by the --stud…

No fix yet
Fix from $4,900 2026-08-11
Sharepoint Server HIGH 8.8
CVE-2026-64921

Missing authentication for critical function in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.

Fix: 16.0.19725.20522+
Fix from $4,900 2026-08-11
Windows 10 1607 HIGH 7.8
CVE-2026-62777

Missing authentication for critical function in Windows License Manager allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.9418 / 10.0.17763.9115+
Fix from $4,900 2026-08-11
Windows 10 1607 HIGH 7.8
CVE-2026-61367

Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.9418 / 10.0.17763.9115+
Fix from $4,900 2026-08-11
Windows 10 1607 HIGH 7.8
CVE-2026-61364

Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.9418 / 10.0.17763.9115+
Fix from $4,900 2026-08-11
Windows 10 1607 HIGH 7.8
CVE-2026-61365

Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.9418 / 10.0.17763.9115+
Fix from $4,900 2026-08-11
Windows 10 1809 HIGH 7.8
CVE-2026-61356

Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.

Fix: 10.0.17763.9115 / 10.0.19044.7663+
Fix from $4,900 2026-08-11
Azure Kubernetes Service CRITICAL 9.4
CVE-2026-50516

Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a netwo…

No fix yet
Fix from $5,750 2026-08-11
Windows 10 1607 HIGH 7.8
CVE-2026-42976

Missing authentication for critical function in Windows RPC API allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.9418 / 10.0.17763.9115+
Fix from $4,900 2026-08-11
Unclassified CRITICAL 9.8
CVE-2026-72920

SeaweedFS is a distributed storage system. Prior to 4.24, the filer registers the SeaweedIdentityAccessManagement gRPC service without mandatory auth…

No fix yet
Fix from $5,750 2026-08-11
Unclassified CRITICAL 9.1
CVE-2026-72748

AVideo contains an unauthenticated arbitrary file write vulnerability in the aVideoEncoderChunk.json.php endpoint that allows remote attackers to wri…

No fix yet
Fix from $5,750 2026-08-11
Unclassified CRITICAL 10.0
CVE-2026-58115

A vulnerability has been identified in SIMATIC IoT2050 Advanced (6ES7647-0BA00-1YA2) (All versions < V4.3.4.1 running Industrial OS with Node-RED ins…

No fix yet
Fix from $5,750 2026-08-11
Unclassified HIGH 7.5
CVE-2026-72605

A missing authentication vulnerability in Swing Music 3.0.0 allows unauthenticated remote attackers to create arbitrary user accounts via the POST /a…

No fix yet
Fix from $4,900 2026-08-11
Unclassified MEDIUM 6.5
CVE-2026-72541

A missing authorization vulnerability in Windmill Labs Windmill through 1.783.0 allows any authenticated workspace member to overwrite any resource t…

No fix yet
Fix from $4,000 2026-08-11
Unclassified MEDIUM 5.4
CVE-2026-72542

A missing authorization vulnerability in Windmill Labs Windmill through 1.783.0 allows authenticated operators to write job progress and read job met…

No fix yet
Fix from $4,000 2026-08-11
Unclassified HIGH 8.6
CVE-2026-72535

A missing authentication vulnerability in Chaskiq through commit 46dfdd1 allows unauthenticated remote attackers to mint Stripe Billing Portal sessio…

No fix yet
Fix from $4,900 2026-08-11
Unclassified HIGH 8.6
CVE-2026-72536

A missing authentication vulnerability in Chaskiq through commit 46dfdd1 allows unauthenticated remote attackers to manipulate any tenant Stripe subs…

No fix yet
Fix from $4,900 2026-08-11
Unclassified HIGH 7.4
CVE-2026-15563

A flaw was found in EAP's IIOP. The listener's NameService would accept bind operations without authentication, allowing an attacker to hijack JNDI l…

No fix yet
Fix from $4,900 2026-08-11
Unclassified HIGH 7.7
CVE-2026-18941

A flaw was found in Feast and feast-operator. The default configuration for both the Feast SDK and the feast-operator is "no_auth," meaning no securi…

No fix yet
Fix from $4,900 2026-08-10
Unclassified HIGH 8.0
CVE-2026-15581

A flaw was found in the TrustyAI Service (TAS) deployment. This vulnerability allows any pod on the cluster network to bypass authentication and dire…

No fix yet
Fix from $4,900 2026-08-10
Unclassified CRITICAL 9.2
CVE-2025-15681

TBEA TLogger V2.1.0.0B0.0.0.0 contains an authentication bypass in its web server. After a user has previously authenticated to the device, an unauth…

No fix yet
Fix from $5,750 2026-08-10
Unclassified HIGH 8.8
CVE-2025-15683

TBEA TLogger V2.1.0.0B0.0.0.0 contains multiple unauthenticated denial-of-service vulnerabilities in its web server. An unauthenticated remote attack…

No fix yet
Fix from $4,900 2026-08-10
Unclassified HIGH 7.5
CVE-2026-72871

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the unauthenticated /api/providers/github/setup route in apps/dokplo…

No fix yet
Fix from $4,900 2026-08-10
Unclassified HIGH 7.5
CVE-2026-72688

A missing authentication vulnerability in OpenSignLabs opensignserver through 2.37.0 allows an unauthenticated remote attacker to read arbitrary stor…

No fix yet
Fix from $4,900 2026-08-10
Unclassified CRITICAL 9.8
CVE-2026-72593

A missing authentication vulnerability in dulldusk/phpfm through 1.8.0 allows an unauthenticated remote attacker to access the full file manager func…

No fix yet
Fix from $5,750 2026-08-10
Unclassified HIGH 7.5
CVE-2026-72586

A missing authentication vulnerability in frangoteam/FUXA through 1.3.3 allows an unauthenticated remote attacker to query all historical sensor data…

No fix yet
Fix from $4,900 2026-08-10
Unclassified CRITICAL 9.8
CVE-2026-72577

Multiple vulnerabilities in NASA fprime-gds through 3.4.3 allow an unauthenticated remote attacker to achieve arbitrary code execution on the ground …

No fix yet
Fix from $5,750 2026-08-10
Ranger HIGH 7.5
CVE-2026-55814

Missing Authentication in Apache Ranger Download APIs on versions <= 2.8.0. Users are recommended to upgrade to version 2.9.0, which fixes this issue.

No fix yet
Fix from $4,900 2026-08-10