Vulnerability index

Browse CVEs

2,866 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthenticationCWE-306 × clear
Peoplesoft Enterprise Pt Peopletools HIGH 8.1
CVE-2026-35276

Vulnerability in the PeopleSoft Enterprise PT PeopleTools product of Oracle PeopleSoft (component: Application Server). Supported versions that are …

Mitigation only
Fix from $1,950 2026-06-17
Identity Manager HIGH 8.8
CVE-2026-35265

Vulnerability in the Identity Manager product of Oracle Fusion Middleware (component: Security). Supported versions that are affected are 12.2.1.4.0…

Mitigation only
Fix from $1,950 2026-06-17
Identity Manager HIGH 8.8
CVE-2026-35267

Vulnerability in the Identity Manager product of Oracle Fusion Middleware (component: REST WebServices). Supported versions that are affected are 12…

Mitigation only
Fix from $1,950 2026-06-17
Unclassified HIGH 8.8
CVE-2026-0647

An improper authentication security issue exists within the 1794-AENTR adapter's embedded web server. The vulnerability allows an unauthenticated att…

Mitigation only
Fix from $1,950 2026-06-16
Unclassified HIGH 7.5
CVE-2018-25437

WordPress CherryFramework Themes 3.1.4 contains an information disclosure vulnerability that allows unauthenticated attackers to download sensitive b…

No fix yet
Fix from $1,950 2026-06-15
Unclassified CRITICAL 9.8
CVE-2026-12183

Nefteprodukttekhnika BUK TS-G Gas Station Automation System 2.9.1 through 2.10.2 on Linux contains an Improper Authentication vulnerability (CWE-287)…

Mitigation only
Fix from $2,300 2026-06-13
Unclassified HIGH 7.5
CVE-2026-53868

Capgo before 12.128.2 contains a denial of service vulnerability allowing attackers to register accounts using arbitrary email addresses without veri…

Mitigation only
Fix from $1,950 2026-06-12
Unclassified HIGH 8.7
CVE-2026-50287

AgenticMail gives AI agents real email addresses and phone numbers. Prior to version 0.9.27, @agenticmail/mcp exposes a Streamable HTTP transport whe…

Mitigation only
Fix from $1,950 2026-06-12
Unclassified HIGH 7.6
CVE-2026-53981

Cap-go prior to 12.128.2 contains an account takeover vulnerability in its email change mechanism that allows an attacker with temporary authenticate…

Patch available
Fix from $1,950 2026-06-12
Board Service CRITICAL 9.8
CVE-2026-50085

The Aqara Board service (op-test.aqara.com) accepts arbitrary MQTT command payloads, and forwards them to the platfom's HiveMQ broker without authent…

Mitigation only
Fix from $2,300 2026-06-12
Cloud Developer Portal MEDIUM 5.3
CVE-2026-50082

The Aqara Cloud Developer Portal (developer.aqara.com) issued a developer token to any email address supplied by the attacker. This is an instance of…

No fix yet
Fix from $1,600 2026-06-12
Powershell Universal MEDIUM 5.3
CVE-2026-8694

Improper access control in Devolutions PowerShell Universal 2026.1.7 and earlier allows an unauthenticated remote attacker to obtain the OpenAPI spec…

Fix: 2026.1.7+
Fix from $1,600 2026-06-12
Unclassified MEDIUM 5.3
CVE-2026-11848

The iRM-IEI Remote Management developed by IEI Integration Corp has a Missing Authentication vulnerability, allowing unauthenticated remote attackers…

Mitigation only
Fix from $1,600 2026-06-12
Unclassified CRITICAL 9.4
CVE-2026-11535

An unauthorized access vulnerability exists in the PcSuite APP. The vulnerability can be exploited by attackers to Unauthorized access to the victim’…

No fix yet
Fix from $2,300 2026-06-12
Unclassified HIGH 7.7
CVE-2026-50245

Brickcom cameras allow unauthenticated access to live snapshot images via the /ONVIF endpoint and no authentication is required to retrieve still ima…

Mitigation only
Fix from $1,950 2026-06-11
Unclassified CRITICAL 9.4
CVE-2026-49973

Hermes WebUI before version 0.51.358 contains an improper access control vulnerability that allows unauthenticated remote attackers to hijack initial…

Patch available
Fix from $2,300 2026-06-11
Peoplesoft Enterprise Peopletools CRITICAL 9.8
CVE-2026-35273 KEVEPSS 95%

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Updates Environment Management). Supported versions t…

Mitigation only
Fix from $2,300 2026-06-11
Unclassified HIGH 8.8
CVE-2026-46612

Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior t…

Patch available
Fix from $1,950 2026-06-10
Splunk CRITICAL 9.8
CVE-2026-20253 KEVEPSS 97%

In Splunk Enterprise 10.2 versions below 10.2.4 and 10 versions below 10.0.7, an unauthenticated user could create or truncate arbitrary files throug…

Fix: 10.0.7 / 10.2.4+
Fix from $2,300 2026-06-10
Unclassified HIGH 8.3
CVE-2026-45567

Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, there is an authentication bypa…

Mitigation only
Fix from $1,950 2026-06-10
Unclassified HIGH 7.8
CVE-2026-9045

During an internal security assessment, a potential vulnerability was discovered in Lenovo Accessories and Display Manager for Enterprise for Windows…

Mitigation only
Fix from $1,950 2026-06-10
Unclassified HIGH 7.1
CVE-2026-8335

A missing authentication check on the Aix‑DB "/llm/process_llm_out" endpoint allows unauthenticated clients to execute arbitrary "SELECT" SQL queries…

Mitigation only
Fix from $1,950 2026-06-10
Migration Assessment HIGH 8.1
CVE-2026-53469

A flaw was found in migration-planner. An authenticated user can exploit this vulnerability by sending a DELETE request to the /api/v1/sources route,…

Fix: 0.13.5+
Fix from $1,950 2026-06-10
Pc Manager HIGH 7.8
CVE-2026-50512

Missing authentication for critical function in Microsoft PC Manager allows an authorized attacker to elevate privileges locally.

Fix: 3.21.6.0+
Fix from $1,950 2026-06-09
Lbr1020 Firmware HIGH 8.0
CVE-2026-9212

Insufficient authentication and input validation in the listed NETGEAR models allow users connected to the local network to execute commands impactin…

Fix: 1.0.4.96 / 1.0.5.50+
Fix from $1,950 2026-06-09
Windows 10 1607 MEDIUM 6.8
CVE-2026-50507EPSS 5%

Missing authentication for critical function in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.

Fix: 10.0.14393.9234 / 10.0.17763.8880+
Fix from $1,600 2026-06-09
Visual Studio Code CRITICAL 9.6
CVE-2026-47281

Missing authorization in Visual Studio Code allows an unauthorized attacker to elevate privileges over a network.

Fix: 1.123.1+
Fix from $2,300 2026-06-09
Unclassified CRITICAL 9.8
CVE-2023-54352

WordPress Seotheme contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary PHP code by uploading ma…

Mitigation only
Fix from $2,300 2026-06-08
Unclassified HIGH 7.5
CVE-2023-54350

WordPress Augmented-Reality plugin contains a remote code execution vulnerability in the elFinder connector that allows unauthenticated attackers to …

No fix yet
Fix from $1,950 2026-06-08
Unclassified CRITICAL 10.0
CVE-2026-11429

Two endpoints in the Vault Service ScriptsController, shared by Altium Enterprise Server and Altium 365, accept file uploads where a user-supplied fi…

Mitigation only
Fix from $2,300 2026-06-05