Vulnerability index

Browse CVEs

2,866 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthenticationCWE-306 × clear
Unclassified CRITICAL 9.8
CVE-2021-47940

WordPress Plugin Download From Files version 1.48 and earlier contains an arbitrary file upload vulnerability that allows unauthenticated attackers t…

Mitigation only
Fix from $2,300 2026-05-10
Unclassified CRITICAL 9.8
CVE-2021-47933

WordPress MStore API 2.0.6 contains an arbitrary file upload vulnerability that allows unauthenticated attackers to upload malicious files by sending…

Mitigation only
Fix from $2,300 2026-05-10
Unclassified CRITICAL 9.8
CVE-2021-47936

OpenCATS 0.9.4 contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary commands by uploading malici…

Mitigation only
Fix from $2,300 2026-05-10
Unclassified CRITICAL 9.4
CVE-2026-42569

phpVMS is a PHP application to run and simulate an airline. Prior to version 7.0.6, a critical vulnerability in phpVMS allowed unauthenticated access…

Patch available
Fix from $2,300 2026-05-09
Unclassified MEDIUM 6.3
CVE-2026-8185

A security vulnerability has been detected in UGREEN CM933 1.1.59.4319. The impacted element is an unknown function of the component Administrative I…

Mitigation only
Fix from $1,600 2026-05-09
Unclassified CRITICAL 9.8
CVE-2026-42302

FastGPT is an AI Agent building platform. From version 4.14.10 to before version 4.14.13, the agent-sandbox component of FastGPT is vulnerable to una…

Patch available
Fix from $2,300 2026-05-08
Unclassified MEDIUM 6.7
CVE-2026-42176

Scoold is a Q&A and a knowledge sharing platform for teams. Prior to version 1.67.0, Scoold allows the admins configuration value to be modified thro…

Mitigation only
Fix from $1,600 2026-05-08
Praisonai HIGH 7.3
CVE-2026-44338EPSS 29%

PraisonAI is a multi-agent teams system. From version 2.5.6 to before version 4.6.34, PraisonAI ships a legacy Flask API server with authentication d…

Fix: 4.6.34+
Fix from $1,950 2026-05-08
Enterprise Server MEDIUM 6.5
CVE-2026-6736

An authentication bypass vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to create a local user acc…

Fix: 3.16.18 / 3.17.15+
Fix from $1,600 2026-05-07
Lawn Mower Firmware CRITICAL 9.8
CVE-2026-7415

The MQTT broker embedded in Yarbo firmware v2.3.9 is configured to allow anonymous connections with no topic-level read or write ACLs. Any host on th…

Mitigation only
Fix from $2,300 2026-05-07
Unclassified MEDIUM 5.3
CVE-2026-8031

A vulnerability was detected in PicoTronica e-Clinic Healthcare System ECHS 5.7. The affected element is an unknown function of the file /cdemos/echs…

Mitigation only
Fix from $1,600 2026-05-06
Unclassified CRITICAL 9.8
CVE-2026-41930

Vvveb before version 1.0.8.2 contains a hard-coded credentials vulnerability in its docker-compose-apache.yaml configuration that allows unauthentica…

Patch available
Fix from $2,300 2026-05-06
Unclassified MEDIUM 6.3
CVE-2026-7844

A vulnerability was detected in chatchat-space Langchain-Chatchat up to 0.3.1.3. This vulnerability affects the function files/list_files/retrieve_fi…

Mitigation only
Fix from $1,600 2026-05-05
Unclassified CRITICAL 9.1
CVE-2026-36356EPSS 14%

The GoAhead web server on MeiG Smart FORGE_SLT711 devices (firmware MDM9607.LE.1.0-00110-STD.PROD-1) allows unauthenticated OS command injection via …

Mitigation only
Fix from $2,300 2026-05-05
Unclassified CRITICAL 9.8
CVE-2023-54344

Eclipse Equinox OSGi 3.7.2 and earlier contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary comm…

Mitigation only
Fix from $2,300 2026-05-05
Unclassified CRITICAL 9.8
CVE-2023-54342

Eclipse Equinox OSGi versions 3.8 through 3.18 contain a remote code execution vulnerability in the console interface that allows unauthenticated att…

Mitigation only
Fix from $2,300 2026-05-05
Nginx Ui CRITICAL 9.8
CVE-2026-42221

Nginx UI is a web user interface for the Nginx web server. From version 2.0.0 to before version 2.3.8, an unauthenticated network attacker can claim …

Fix: 2.3.8+
Fix from $2,300 2026-05-04
Nginx Ui CRITICAL 9.8
CVE-2026-42222

Nginx UI is a web user interface for the Nginx web server. In version 2.3.5, an unauthenticated bootstrap takeover exists in nginx-ui during the init…

Mitigation only
Fix from $2,300 2026-05-04
Arelle CRITICAL 9.8
CVE-2026-42796

Arelle before 2.39.10 contains an unauthenticated remote code execution vulnerability in the /rest/configure REST endpoint that accepts a plugins que…

Fix: 2.39.10+
Fix from $2,300 2026-05-04
Unclassified HIGH 7.3
CVE-2026-7723

A flaw has been found in PrefectHQ prefect up to 3.6.13. Affected is an unknown function of the file /api/events/in of the component WebSocket Endpoi…

Patch available
Fix from $1,950 2026-05-04
Unclassified MEDIUM 6.5
CVE-2026-7714

A flaw has been found in crocodilestick Calibre-Web-Automated up to 4.0.6. Affected by this issue is some unknown functionality of the file cps/cwa_f…

Patch available
Fix from $1,600 2026-05-04
Traefik CRITICAL 10.0
CVE-2026-39858

Traefik is an HTTP reverse proxy and load balancer. Prior to versions 2.11.43, 3.6.14, and 3.7.0-rc.2, there is a high severity authentication bypass…

Fix: 2.11.43 / 3.6.14+
Fix from $2,300 2026-04-30
Unclassified MEDIUM 6.5
CVE-2026-35514

Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. In version 4.9.0, the …

Mitigation only
Fix from $1,600 2026-04-30
Django Mdeditor CRITICAL 9.8
CVE-2025-13030

All versions of the package django-mdeditor are vulnerable to Missing Authentication for Critical Function in the image upload endpoint. An attacker …

Patch available
Fix from $2,300 2026-04-30
Sonicos HIGH 8.0
CVE-2026-0204

A vulnerability in the access control mechanism of SonicOS may allow certain management interface functions to be accessible under specific condition…

Fix: 6.5.5.2-28n / 7.3.2-7010+
Fix from $1,950 2026-04-29
Wp Squared CRITICAL 9.8
CVE-2026-41940 KEVEPSS 98%

cPanel and WHM versions after 11.40 contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to …

Fix: 86.0.41 / 110.0.97+
Fix from $2,300 2026-04-29
Unclassified CRITICAL 9.4
CVE-2026-3893

The Carlson VASCO-B GNSS Receiver lacks an authentication mechanism, allowing an attacker with network access to directly access and modify its con…

Mitigation only
Fix from $2,300 2026-04-28
Intersight Device Connector HIGH 8.2
CVE-2026-5944

An improper access control vulnerability exists in the Cisco Intersight Device Connector for Nutanix Prism Central. The service exposes an API passth…

Fix: after 7.5.0
Fix from $1,950 2026-04-28
Vegapuls 6x Firmware HIGH 7.5
CVE-2026-3323

An unsecured configuration interface on affected devices allows unauthenticated remote attackers to access sensitive information, including hashed cr…

Mitigation only
Fix from $1,950 2026-04-28
Thrift HIGH 7.4
CVE-2026-41603

Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are re…

Fix: 0.23.0+
Fix from $1,950 2026-04-28