Vulnerability index

Browse CVEs

2,866 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthenticationCWE-306 × clear
Universal Work Queue CRITICAL 9.9
CVE-2026-46824

Vulnerability in the Oracle Universal Work Queue product of Oracle E-Business Suite (component: Work Provider Site Level Administration). Supported …

Fix: after 12.2.15
Fix from $2,300 2026-05-28
E Business Suite HIGH 8.8
CVE-2026-46826

Vulnerability in the Oracle Payroll product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12…

Fix: after 12.2.15
Fix from $1,950 2026-05-28
E Business Suite HIGH 8.8
CVE-2026-46827

Vulnerability in the Oracle Payroll product of Oracle E-Business Suite (component: Self Service Manager). Supported versions that are affected are 1…

Fix: after 12.2.15
Fix from $1,950 2026-05-28
E Business Suite CRITICAL 9.8
CVE-2026-46817 KEVEPSS 13%

Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affected are 12.…

Fix: after 12.2.15
Fix from $2,300 2026-05-28
Unclassified HIGH 7.5
CVE-2026-45332

Automad is a flat-file content management system and template engine. From 2.0.0-alpha.1 to 2.0.0-beta.27, a Broken Access Control vulnerability allo…

Mitigation only
Fix from $1,950 2026-05-28
Unclassified MEDIUM 6.0
CVE-2026-46685

RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.2, when RUSTFS_CORS_ALLOWED_ORIGINS is unset, the RustFS S3 listener…

Mitigation only
Fix from $1,600 2026-05-28
Unclassified MEDIUM 6.9
CVE-2026-47136

RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.2, the RustFS console endpoint GET /rustfs/console/license returns p…

Mitigation only
Fix from $1,600 2026-05-28
Unclassified HIGH 8.8
CVE-2026-45044

RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.2, the admin router explicitly whitelists /profile/cpu and /profile/…

Mitigation only
Fix from $1,950 2026-05-28
Archer C64 Firmware HIGH 8.8
CVE-2026-8697

Due to improper enforcement of authentication rate-limiting on a debug SSH service in Archer C64 v1, the SSH service allows unlimited authentication …

Mitigation only
Fix from $1,950 2026-05-28
Unclassified CRITICAL 9.8
CVE-2026-45083

The Goobi viewer is a web application that allows digitised material to be displayed in a web browser. From 4.8.0 to before 26.04.1, the Goobi viewer…

Patch available
Fix from $2,300 2026-05-27
Unclassified CRITICAL 9.8
CVE-2026-8364

Gladinet Triofox Cloud Server Agent Access Service (GladServerAgentService.exe) listens on TCP port 7878 and processes remote HTTP messages with URL …

Mitigation only
Fix from $2,300 2026-05-27
Unclassified CRITICAL 10.0
CVE-2026-45087

Dalfox is a powerful open-source XSS scanner and utility focused on automation. Prior to 2.13.0, when dalfox is started in REST API server mode (dalf…

Mitigation only
Fix from $2,300 2026-05-27
Unclassified HIGH 7.5
CVE-2026-45088

Dalfox is a powerful open-source XSS scanner and utility focused on automation. Prior to 2.13.0, when dalfox is run in REST API server mode, the cust…

Mitigation only
Fix from $1,950 2026-05-27
Unclassified HIGH 8.2
CVE-2026-45089

Dalfox is a powerful open-source XSS scanner and utility focused on automation. Prior to 2.13.0, when dalfox is run in REST API server mode, the outp…

Mitigation only
Fix from $1,950 2026-05-27
Unclassified HIGH 7.4
CVE-2026-44460

FileRise is a self-hosted web-based file manager with multi-file upload, editing, and batch operations. Prior to 3.12.0, /api/totp_setup.php is calla…

Mitigation only
Fix from $1,950 2026-05-27
Free5gc CRITICAL 10.0
CVE-2026-44327

free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's NEF mounts the nnef-oam route group without inbound OAuth2…

Fix: 4.2.2+
Fix from $2,300 2026-05-27
Free5gc HIGH 8.2
CVE-2026-44328

free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's SMF mounts the UPI management route group without inbound …

Fix: 4.2.2+
Fix from $1,950 2026-05-27
Free5gc CRITICAL 10.0
CVE-2026-44329

free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's SMF mounts the UPI management route group without OAuth2/b…

Fix: 4.2.2+
Fix from $2,300 2026-05-27
Free5gc HIGH 7.3
CVE-2026-44320

free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's NEF mounts the nnef-callback route group without inbound O…

Fix: 4.2.2+
Fix from $1,950 2026-05-27
Free5gc HIGH 7.5
CVE-2026-44321

free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's SMF mounts the UPI management route group without inbound …

Fix: 4.2.2+
Fix from $1,950 2026-05-27
Unclassified HIGH 8.7
CVE-2026-44830

Nocturne Memory is a lightweight, rollbackable, and visual Long-Term Memory Server for MCP Agents. Prior to 2.4.1, when API_TOKEN is unset or empty, …

Mitigation only
Fix from $1,950 2026-05-27
Unclassified CRITICAL 9.2
CVE-2026-44895

GitLab MCP Server lets an AI agent talk directly to GitLab. Prior to 0.6.0, the HTTP transport in src/transport.ts ships with no authentication layer…

Mitigation only
Fix from $2,300 2026-05-26
Unclassified MEDIUM 6.5
CVE-2026-47672

epa4all-client is the Java Client for epa4all / ePA 3.0 in the Telematik Infrastruktur. In 1.2.4 and earlier, any network-reachable caller can write …

Patch available
Fix from $1,600 2026-05-26
Unclassified HIGH 7.5
CVE-2026-44847

MaxKB is an open-source AI assistant for enterprise. Prior to 2.9.0, MaxKB's webhook trigger endpoint (/api/trigger/v1/webhook/{trigger_id}) is acces…

Mitigation only
Fix from $1,950 2026-05-26
Unclassified MEDIUM 6.9
CVE-2026-44775

Kavita is a cross platform reading server. Prior to 0.9.0, the ReaderController.GetImage endpoint is decorated with [AllowAnonymous], allowing comple…

Mitigation only
Fix from $1,600 2026-05-26
Unclassified CRITICAL 9.8
CVE-2026-44668

FACTION is a PenTesting Report Generation and Collaboration Framework. Prior to 1.8.3, AccessControlInterceptor, the authentication gate for all Stru…

Mitigation only
Fix from $2,300 2026-05-26
Fastnetmon HIGH 8.1
CVE-2026-48692

FastNetMon Community Edition through 1.2.9 exposes a gRPC API server on port 50052 with no authentication mechanism. The server is initialized with g…

Fix: after 1.2.9
Fix from $1,950 2026-05-26
Unclassified MEDIUM 5.6
CVE-2026-9371

A security vulnerability has been detected in ItzCrazyKns Vane up to 1.12.1. Affected by this issue is some unknown functionality of the file route.t…

Mitigation only
Fix from $1,600 2026-05-24
Unclassified CRITICAL 10.0
CVE-2026-9152

A missing authentication vulnerability exists in the Altium 365 SearchService. A legacy SOAP endpoint exposes search index operations without requiri…

Mitigation only
Fix from $2,300 2026-05-21
Unclassified CRITICAL 9.8
CVE-2026-9141

Taiko AG1000-01A SMS Alert Gateway Rev 7.3 and Rev 8 contains an authentication bypass vulnerability in the embedded web configuration interface that…

Mitigation only
Fix from $2,300 2026-05-20