Vulnerability index

Browse CVEs

2,866 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthenticationCWE-306 × clear
Glances MEDIUM 6.5
CVE-2026-34839

Glances is an open-source system cross-platform monitoring tool. Prior to version 4.5.4, the Glances web server exposes a REST API (`/api/4/*`) that …

Fix: 4.5.4+
Fix from $1,600 2026-04-21
Powerprotect Dp Series Appliance HIGH 8.8
CVE-2026-26944

Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2025 release version 8.3.1.0 through 8.3.1.20, LTS2024 release versions 7.13.1.0 thro…

Fix: 2.7.9 / 7.13.1.70+
Fix from $1,950 2026-04-20
Vexa HIGH 7.5
CVE-2026-25058

Vexa is an open-source, self-hostable meeting bot API and meeting transcription API. Prior to 0.10.0-260419-1910, the Vexa transcription-collector se…

Fix: after 0.10
Fix from $1,950 2026-04-20
Livepatch Client MEDIUM 5.5
CVE-2026-6369

An improper access control vulnerability in the canonical-livepatch snap client prior to version 10.15.0 allows a local unprivileged user to obtain a…

Fix: 10.15.0+
Fix from $1,600 2026-04-20
Sd 330ac Firmware MEDIUM 5.3
CVE-2026-32962

SD-330AC and AMC Manager provided by silex technology, Inc. contain a missing authentication for critical function issue. The device configuration ma…

Fix: 1.50 / 5.1.0+
Fix from $1,600 2026-04-20
Sd 330ac Firmware MEDIUM 5.3
CVE-2026-32957

SD-330AC and AMC Manager provided by silex technology, Inc. contain a missing authentication for critical function issue on firmware maintenance. Arb…

Fix: 1.50 / 5.1.0+
Fix from $1,600 2026-04-20
Unclassified MEDIUM 6.5
CVE-2026-6588

A weakness has been identified in serge-chat serge up to 1.4TB. The impacted element is the function download_model/delete_model of the file api/src/…

Mitigation only
Fix from $1,600 2026-04-20
Unclassified HIGH 7.3
CVE-2026-6582

A flaw has been found in TransformerOptimus SuperAGI up to 0.0.14. Affected by this issue is the function get_vector_db_details of the file superagi/…

Mitigation only
Fix from $1,950 2026-04-19
Unclassified MEDIUM 6.5
CVE-2026-6579

A weakness has been identified in liangliangyy DjangoBlog up to 2.1.0.0. This impacts an unknown function of the file blog/views.py of the component …

Mitigation only
Fix from $1,600 2026-04-19
Unclassified HIGH 7.3
CVE-2026-6577

A vulnerability was identified in liangliangyy DjangoBlog up to 2.1.0.0. The impacted element is an unknown function of the file owntracks/views.py o…

Mitigation only
Fix from $1,950 2026-04-19
Cx7 Firmware HIGH 7.5
CVE-2026-40461

Anviz CX2 Lite and CX7 are vulnerable to unauthenticated POST requests that modify debug settings (e.g., enabling SSH), allowing unauthorized state …

Mitigation only
Fix from $1,950 2026-04-17
Cx7 Firmware CRITICAL 9.8
CVE-2026-35546

Anviz CX2 Lite and CX7 are vulnerable to unauthenticated firmware uploads. This causes crafted archives to be accepted, enabling attackers to plant …

Mitigation only
Fix from $2,300 2026-04-17
Unclassified HIGH 8.8
CVE-2026-6348

WinMatrix agent developed by Simopro Technology has a Missing Authentication vulnerability, allowing authenticated local attackers to execute arbitra…

Mitigation only
Fix from $1,950 2026-04-16
Chamilo Lms HIGH 7.2
CVE-2026-33715

Chamilo LMS is an open-source learning management system. In version 2.0-RC.2, the file public/main/inc/ajax/install.ajax.php is accessible without a…

Mitigation only
Fix from $1,950 2026-04-14
Chamilo Lms HIGH 8.6
CVE-2026-34160

Chamilo LMS is an open-source learning management system. In versions prior to 2.0.0-RC.3, the PENS (Package Exchange Notification Services) plugin e…

Fix: after 1.11.38
Fix from $1,950 2026-04-14
Windows 10 1607 HIGH 7.8
CVE-2026-26159

Missing authentication for critical function in Windows Remote Desktop Licensing Service allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.9060 / 10.0.17763.8644+
Fix from $1,950 2026-04-14
Windows 10 1607 HIGH 7.8
CVE-2026-26160

Missing authentication for critical function in Windows Remote Desktop Licensing Service allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.9060 / 10.0.17763.8644+
Fix from $1,950 2026-04-14
Fortios HIGH 8.8
CVE-2025-53847

A missing authentication for critical function vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 thro…

Fix: 7.0.18 / 7.2.12+
Fix from $1,950 2026-04-14
Praisonaiagents CRITICAL 9.1
CVE-2026-40289

PraisonAI is a multi-agent teams system. In versions below 4.5.139 of PraisonAI and 1.5.140 of praisonaiagents, the browser bridge (praisonai browser…

Fix: 1.5.140 / 4.5.139+
Fix from $2,300 2026-04-14
Unclassified CRITICAL 9.3
CVE-2026-4810

A Code Injection and Missing Authentication vulnerability in Google Agent Development Kit (ADK) versions 1.7.0 (and 2.0.0a1) through 1.28.1 (and 2.0.…

Mitigation only
Fix from $2,300 2026-04-13
Unclassified HIGH 7.3
CVE-2026-6129

A vulnerability was detected in zhayujie chatgpt-on-wechat CowAgent up to 2.0.4. This affects an unknown function of the component Agent Mode Service…

Mitigation only
Fix from $1,950 2026-04-12
Unclassified HIGH 7.3
CVE-2026-6126

A weakness has been identified in zhayujie chatgpt-on-wechat CowAgent 2.0.4. The affected element is an unknown function of the component Administrat…

Mitigation only
Fix from $1,950 2026-04-12
Unclassified MEDIUM 6.3
CVE-2026-5724

The frontend gRPC server's streaming interceptor chain did not include the authorization interceptor. When a ClaimMapper and Authorizer are configure…

Mitigation only
Fix from $1,600 2026-04-10
Trek MEDIUM 5.3
CVE-2026-40184

TREK is a collaborative travel planner. Prior to 2.7.2, TREK served uploaded photos without requiring authentication. This vulnerability is fixed in …

Fix: after 2.7.1
Fix from $1,600 2026-04-10
Unclassified HIGH 8.7
CVE-2026-5777

This vulnerability exists in the Atom 3x Projector due to improper exposure of the Android Debug Bridge (ADB) service over the local network without …

Mitigation only
Fix from $1,950 2026-04-10
Dockyard MEDIUM 5.4
CVE-2026-39848

Dockyard is a Docker container management app. Prior to 1.1.0, Docker container start and stop operations are performed through GET requests without …

Fix: 1.1.0+
Fix from $1,600 2026-04-09
Junos Os Evolved HIGH 7.8
CVE-2026-33788

A Missing Authentication for Critical Function vulnerability in the Flexible PIC Concentrators (FPCs) of Juniper Networks Junos OS Evolved on PTX Ser…

Fix: 21.2+
Fix from $1,950 2026-04-09
Unclassified HIGH 8.6
CVE-2026-4436

A low-privileged remote attacker can send Modbus packets to manipulate register values that are inputs to the odorant injection logic such that too…

Mitigation only
Fix from $1,950 2026-04-09
Marimo CRITICAL 9.8
CVE-2026-39987 KEVEPSS 97%

marimo is a reactive Python notebook. Prior to 0.23.0, Marimo has a Pre-Auth RCE vulnerability. The terminal WebSocket endpoint /terminal/ws lacks au…

Fix: 0.23.0+
Fix from $2,300 2026-04-09
Unclassified MEDIUM 6.7
CVE-2025-30650

A Missing Authentication for Critical Function vulnerability in command processing of Juniper Networks Junos OS allows a privileged local attacker to…

Mitigation only
Fix from $1,600 2026-04-08