Vulnerability index

Browse CVEs

2,866 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthenticationCWE-306 × clear
Unclassified HIGH 8.6
CVE-2026-39310

Trilium Notes is a cross-platform, hierarchical note taking application focused on building large personal knowledge bases. In versions 0.102.1 and p…

Mitigation only
Fix from $1,950 2026-05-20
Secure Workload CRITICAL 10.0
CVE-2026-20223

A vulnerability in the access validation of internal REST APIs of Cisco Secure Workload could allow an unauthenticated, remote attacker to acces…

Fix: 3.10.8.3 / 4.0.3.17+
Fix from $2,300 2026-05-20
Scadabr CRITICAL 9.1
CVE-2026-8602

In ScadaBR version 1.2.0, a Missing Authentication for Critical Function vulnerability could allow an unauthenticated attacker to send a HTTP GET req…

Mitigation only
Fix from $2,300 2026-05-19
Firefox MEDIUM 6.5
CVE-2026-8706

Firefox for iOS hosted Reader mode on an unauthenticated local web server, allowing another application on the same device to request arbitrary URLs …

Fix: 151.0+
Fix from $1,600 2026-05-19
Unclassified CRITICAL 9.1
CVE-2026-31071

API endpoints in LalanaChami Pharmacy Management System (commit 5c3d028) lack authentication middleware. Unauthenticated remote attackers can exploit…

Mitigation only
Fix from $2,300 2026-05-19
Unclassified CRITICAL 9.8
CVE-2018-25335

WordPress Plugin Peugeot Music 1.0 contains an arbitrary file upload vulnerability that allows unauthenticated attackers to upload malicious files by…

Mitigation only
Fix from $2,300 2026-05-17
Gitbucket CRITICAL 9.8
CVE-2018-25332

GitBucket 4.23.1 contains an unauthenticated remote code execution vulnerability that allows attackers to execute arbitrary commands by exploiting we…

Fix: 4.24.0+
Fix from $2,300 2026-05-17
Unclassified MEDIUM 5.3
CVE-2026-8737

A weakness has been identified in Sanluan PublicCMS 5.202506.d. This issue affects the function execute of the file publiccms-trade/src/main/java/com…

Mitigation only
Fix from $1,600 2026-05-17
Open Webui MEDIUM 5.3
CVE-2026-45397

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.5, GET /api/v1/retrieval/ returns liv…

Fix: 0.9.5+
Fix from $1,600 2026-05-15
Guardian MEDIUM 5.3
CVE-2026-45248

Hedera Guardian through 3.5.1 contains an authentication bypass vulnerability in the GET /api/v1/demo/registered-users endpoint that allows unauthent…

Fix: after 3.5.1
Fix from $1,600 2026-05-14
Unclassified CRITICAL 9.4
CVE-2026-44592

Gradient is a nix-based continuous integration system. In 1.1.0, when GRADIENT_DISCOVERABLE=true (the default, and the NixOS module default), anyone …

Mitigation only
Fix from $2,300 2026-05-14
Devspace HIGH 7.8
CVE-2026-42283

DevSpace is a client-only developer tool for cloud-native development with Kubernetes. Prior to 6.3.21, DevSpace's UI server WebSocket accepts connec…

Mitigation only
Fix from $1,950 2026-05-14
Unclassified MEDIUM 6.3
CVE-2025-62619

Missing authentication in the KVM key download endpoint could allow an unauthenticated attacker with knowledge of the exposed URL to retrieve sensiti…

Mitigation only
Fix from $1,600 2026-05-14
Empirbus Wireless Display Unit Firmware HIGH 7.3
CVE-2025-27853

The locally served web site on the Garmin WDU (v1 1.4.6 and v2 5.0) allows its authentication to be bypassed. The WDU web site only performs authenti…

Mitigation only
Fix from $1,950 2026-05-13
Prisma Access Agent HIGH 7.8
CVE-2026-0247

Multiple authorization bypass vulnerabilities in the Endpoint DLP component of Prisma Access Agent® allow a local attacker to bypass authentication c…

Fix: 26.2.1+
Fix from $1,950 2026-05-13
Unclassified HIGH 8.8
CVE-2026-42289

ChurchCRM is an open-source church management system. Prior to 7.3.2, UserEditor.php processes user account creation and permission updates entirely …

Mitigation only
Fix from $1,950 2026-05-12
Unclassified MEDIUM 6.1
CVE-2026-42303

Fides is an open-source privacy engineering platform. From 2.75.0 to before 2.83.2, Fides deployments that enable both subject identity verification …

Patch available
Fix from $1,600 2026-05-12
Mem0 MEDIUM 5.3
CVE-2026-31245

The mem0 1.0.0 server lacks authentication and authorization controls for its memory creation API endpoint (POST /memories). The endpoint allows unau…

Mitigation only
Fix from $1,600 2026-05-12
Unclassified HIGH 7.5
CVE-2026-31240

The mem0 1.0.0 server lacks authentication and authorization controls for its memory management API endpoints. Critical functions such as updating me…

Mitigation only
Fix from $1,950 2026-05-12
Mem0 MEDIUM 6.5
CVE-2026-31241

The mem0 1.0.0 server lacks authentication and authorization controls for its memory deletion API endpoint (DELETE /memories). The endpoint allows un…

Mitigation only
Fix from $1,600 2026-05-12
Mem0 CRITICAL 9.1
CVE-2026-31242

The mem0 v1.0.0 server lacks authentication and authorization controls for its memory reset functionality accessible via the DELETE /memories endpoin…

Mitigation only
Fix from $2,300 2026-05-12
Mem0 MEDIUM 6.5
CVE-2026-31243

The mem0 1.0.0 server lacks authentication and authorization controls for its memory reset and table re-creation functionality accessible via the DEL…

Mitigation only
Fix from $1,600 2026-05-12
Mem0 MEDIUM 6.5
CVE-2026-31244

The mem0 1.0.0 server lacks authentication and authorization controls for its memory deletion API endpoint (DELETE /memories/{memory_id}). The endpoi…

Mitigation only
Fix from $1,600 2026-05-12
Unclassified HIGH 8.7
CVE-2026-5029

A remote code execution vulnerability exists in Code Runner MCP Server when run with the --transport http option, which exposes the /mcp JSON-RPC end…

Mitigation only
Fix from $1,950 2026-05-12
Simatic Cn 4100 Firmware CRITICAL 9.1
CVE-2026-22924

A vulnerability has been identified in SIMATIC CN 4100 (All versions < V5.0). The affected application does not properly restrict unauthenticated con…

Fix: 5.0+
Fix from $2,300 2026-05-12
Unclassified MEDIUM 5.3
CVE-2026-43881

WWBN AVideo is an open source video platform. In versions up to and including 29.0, objects/users.json.php exposes two unauthenticated paths that dis…

Patch available
Fix from $1,600 2026-05-11
Unclassified CRITICAL 9.9
CVE-2026-42864

FireFighter is an incident management application. Prior to 0.0.54, the POST /api/v2/firefighter/raid/jira_bot endpoint (CreateJiraBotView) is reacha…

Mitigation only
Fix from $2,300 2026-05-11
Teamcity HIGH 7.5
CVE-2026-44413

In JetBrains TeamCity before 2026.1 2025.11.5 authenticated users could expose server API to unauthorised access

Fix: 2025.11.5+
Fix from $1,950 2026-05-11
Unclassified HIGH 8.7
CVE-2026-42856

Network-AI is a TypeScript/Node.js multi-agent orchestrator. Prior to 5.1.3, the MCP HTTP transport accepts JSON-RPC tools/call requests with no auth…

Mitigation only
Fix from $1,950 2026-05-11
Pyload Ng MEDIUM 6.8
CVE-2026-42312

pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev100, the set_config_value() API method (@permission(Perms.SE…

Fix: 0.5.0b3.dev100+
Fix from $1,600 2026-05-11