Vulnerability index

Browse CVEs

2,866 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthenticationCWE-306 × clear
Knb 2000 Firmware HIGH 8.8
CVE-2024-54013

Penetration Testing engineers at Amazon have identified a security flaw related to request handling in the web server component that could, under cer…

Fix: 2.23.01+
Fix from $1,950 2026-04-28
Unclassified MEDIUM 5.6
CVE-2026-7113

A vulnerability was found in NousResearch hermes-agent 0.8.0. Affected by this issue is some unknown functionality of the file gateway/platforms/webh…

Patch available
Fix from $1,600 2026-04-27
Unclassified HIGH 7.3
CVE-2026-7042

A flaw has been found in 666ghj MiroFish up to 0.1.2. This affects the function create_app of the file backend/app/__init__.py of the component REST …

Mitigation only
Fix from $1,950 2026-04-26
Cyberpanel CRITICAL 9.1
CVE-2026-41473

CyberPanel versions prior to 2.4.5 contain an authentication bypass vulnerability in the AI Scanner worker API endpoints that allows unauthenticated …

Fix: 2.4.4+
Fix from $2,300 2026-04-24
Deskflow HIGH 7.8
CVE-2026-41477

Deskflow is a keyboard and mouse sharing app. In 1.20.0, 1.26.0.134, and earlier, Deskflow daemon runs as SYSTEM and exposes an IPC named pipe with …

Fix: after 1.26.0.161
Fix from $1,950 2026-04-24
Unclassified HIGH 8.5
CVE-2026-6272

A client holding only a read JWT scope can still register itself as a signal provider through the production kuksa.val.v2 OpenProviderStream API by s…

Mitigation only
Fix from $1,950 2026-04-24
X3500 Firmware CRITICAL 9.8
CVE-2026-40620

A vulnerability in SenseLive X3050’s embedded management service allows full administrative control to be established without any form of authenticat…

Mitigation only
Fix from $2,300 2026-04-24
X3500 Firmware CRITICAL 9.1
CVE-2026-27843

A vulnerability exists in SenseLive X3050's web management interface that allows critical configuration parameters to be modified without sufficient …

Mitigation only
Fix from $2,300 2026-04-24
X3500 Firmware HIGH 7.5
CVE-2026-35064

A vulnerability in SenseLive X3050’s management ecosystem allows unauthenticated discovery of deployed units through the vendor’s management protocol…

No fix yet
Fix from $1,950 2026-04-24
Unclassified CRITICAL 9.8
CVE-2026-25775

A vulnerability in SenseLive X3050’s remote management service allows firmware retrieval and update operations to be performed without authentication…

Mitigation only
Fix from $2,300 2026-04-24
Unclassified HIGH 8.7
CVE-2026-6376

A weakness in SpiceJet’s public booking retrieval page permits full passenger booking details to be accessed using only a PNR and last name, with no …

Mitigation only
Fix from $1,950 2026-04-23
Flowise HIGH 8.2
CVE-2026-41273

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, Flowise contains an authentication bypass vu…

Fix: 3.1.0+
Fix from $1,950 2026-04-23
Unclassified CRITICAL 9.8
CVE-2026-23751

Kofax Capture, now referred to as Tungsten Capture, version 6.0.0.0 (other versions may be affected) exposes a deprecated .NET Remoting HTTP channel …

Mitigation only
Fix from $2,300 2026-04-23
Rclone CRITICAL 9.8
CVE-2026-41176EPSS 33%

Rclone is a command-line program to sync files and directories to and from different cloud storage providers. The RC endpoint `options/set` is expose…

Fix: 1.73.5+
Fix from $2,300 2026-04-23
Rclone CRITICAL 9.8
CVE-2026-41179EPSS 9%

Rclone is a command-line program to sync files and directories to and from different cloud storage providers. Starting in version 1.48.0 and prior to…

Fix: 1.73.5+
Fix from $2,300 2026-04-23
Terminal Services Manager HIGH 7.8
CVE-2018-25259

Terminal Services Manager 3.1 contains a stack-based buffer overflow vulnerability in the computer names field that allows local attackers to execute…

Fix: after 3.1
Fix from $1,950 2026-04-22
Unclassified HIGH 8.7
CVE-2026-5749

Inadequate access control in the registration process in Fullstep V5, which could allow unauthenticated users to obtain a valid JWT token with which …

Mitigation only
Fix from $1,950 2026-04-22
Minio HIGH 8.2
CVE-2026-40344

MinIO is a high-performance object storage system. Starting in RELEASE.2023-05-18T00-05-36Z and prior to RELEASE.2026-04-11T03-20-12Z, an authenticat…

Fix: 2026-04-11T03-20-12Z+
Fix from $1,950 2026-04-22
Identity Manager Connector CRITICAL 9.1
CVE-2026-34285

Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core). The supported version that is affecte…

Mitigation only
Fix from $2,300 2026-04-21
Identity Manager Connector CRITICAL 9.1
CVE-2026-34286

Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core). The supported version that is affecte…

Mitigation only
Fix from $2,300 2026-04-21
Identity Manager Connector MEDIUM 5.9
CVE-2026-34288

Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core). The supported version that is affecte…

Mitigation only
Fix from $1,600 2026-04-21
Identity Manager Connector MEDIUM 5.9
CVE-2026-34289

Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core). The supported version that is affecte…

Mitigation only
Fix from $1,600 2026-04-21
Enterprise Manager Base Platform CRITICAL 9.1
CVE-2026-34279

Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Event Management). Supported versions …

Mitigation only
Fix from $2,300 2026-04-21
Peoplesoft Enterprise Hcm Human Resources MEDIUM 6.5
CVE-2026-34280

Vulnerability in the PeopleSoft Enterprise HCM Human Resources product of Oracle PeopleSoft (component: Job Profile Manager). The supported version…

Mitigation only
Fix from $1,600 2026-04-21
Advanced Inbound Telephony CRITICAL 9.8
CVE-2026-34275

Vulnerability in the Oracle Advanced Inbound Telephony product of Oracle E-Business Suite (component: Setup and Administration). Supported versions …

Fix: after 12.2.15
Fix from $2,300 2026-04-21
Peoplesoft Enterprise Human Capital Management Absence Management MEDIUM 6.5
CVE-2026-34266

Vulnerability in the PeopleSoft Enterprise HCM Absence Management product of Oracle PeopleSoft (component: Absence Management). The supported versi…

Mitigation only
Fix from $1,600 2026-04-21
Goshs CRITICAL 9.8
CVE-2026-40884

goshs is a SimpleHTTPServer written in Go. Prior to 2.0.0-beta.6, goshs contains an SFTP authentication bypass when the documented empty-username bas…

Fix: 2.0.0+
Fix from $2,300 2026-04-21
Unclassified CRITICAL 9.8
CVE-2026-40050

CrowdStrike has released security updates to address a critical unauthenticated path traversal vulnerability (CVE-2026-40050) in LogScale. This vulne…

Mitigation only
Fix from $2,300 2026-04-21
Unclassified HIGH 7.7
CVE-2026-24177

NVIDIA KAI Scheduler contains a vulnerability where an attacker could access API endpoints without authorization. A successful exploit of this vulner…

Mitigation only
Fix from $1,950 2026-04-21
Qn I 470 Firmware HIGH 7.5
CVE-2026-41039

This vulnerability exists in Quantum Networks router due to improper access control and insecure default configuration in the web-based management in…

Mitigation only
Fix from $1,950 2026-04-21