Vulnerability index

Browse CVEs

2,866 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthenticationCWE-306 × clear
Ci4ms HIGH 8.1
CVE-2026-39393

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior t…

Fix: 0.31.4.0+
Fix from $1,950 2026-04-08
Coolercontrold CRITICAL 9.1
CVE-2026-5300

Unauthenticated functionality in CoolerControl/coolercontrold <4.0.0 allows unauthenticated attackers to view and modify potentially sensitive data …

Fix: 4.0.0+
Fix from $2,300 2026-04-08
Vite HIGH 7.5
CVE-2026-39363

Vite is a frontend tooling framework for JavaScript. From 6.0.0 to before 6.4.2, 7.3.2, and 8.0.5, if it is possible to connect to the Vite dev serve…

Fix: after 8.0.4
Fix from $1,950 2026-04-07
Freescout MEDIUM 6.5
CVE-2026-35584

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to 1.8.212, the endpoint GET /thread/read/{conversation_id}/…

Fix: 1.8.212+
Fix from $1,600 2026-04-07
Strawberry Graphql HIGH 7.5
CVE-2026-35523

Strawberry GraphQL is a library for creating GraphQL APIs. Strawberry up until version 0.312.3 is vulnerable to an authentication bypass on WebSocket…

Fix: 0.312.3+
Fix from $1,950 2026-04-07
E Cology CRITICAL 9.8
CVE-2026-22679EPSS 21%

Weaver (Fanwei) E-cology 10.0 versions prior to 20260312 contain an unauthenticated remote code execution vulnerability in the /papi/esearch/data/dev…

Fix: 20260312+
Fix from $2,300 2026-04-07
Link Whisper MEDIUM 6.5
CVE-2026-1900

The Link Whisper Free WordPress plugin before 0.9.1 has a publicly accessible REST endpoint that allows unauthenticated settings updates.

Fix: 0.9.1+
Fix from $1,600 2026-04-07
Avideo MEDIUM 5.3
CVE-2026-35450

WWBN AVideo is an open source video platform. In versions 26.0 and prior, the plugin/API/check.ffmpeg.json.php endpoint probes the FFmpeg remote serv…

Fix: after 26.0
Fix from $1,600 2026-04-06
Unclassified HIGH 7.3
CVE-2026-5676

A vulnerability was identified in Totolink A8000R 5.9c.681_B20180413. This issue affects the function setLanguageCfg of the file /cgi-bin/cstecgi.cgi…

Mitigation only
Fix from $1,950 2026-04-06
Glpi MEDIUM 6.1
CVE-2026-26027

GLPI is a free asset and IT management software package. From 11.0.0 to before 11.0.6, an unauthenticated user can store an XSS payload through the i…

Fix: 11.0.6+
Fix from $1,600 2026-04-06
Unclassified HIGH 7.3
CVE-2026-5632

A vulnerability was found in assafelovic gpt-researcher up to 3.4.3. This impacts an unknown function of the component HTTP REST API Endpoint. Perfor…

Mitigation only
Fix from $1,950 2026-04-06
Unclassified HIGH 7.3
CVE-2026-5616

A security vulnerability has been detected in JeecgBoot 3.9.0/3.9.1. The impacted element is an unknown function of the file jeecg-boot/jeecg-module-…

Patch available
Fix from $1,950 2026-04-06
Unclassified HIGH 8.1
CVE-2026-4272

Missing Authentication for Critical Function vulnerability in Honeywell Handheld Scanners allows Authentication Abuse.This issue affects Handheld Sca…

Mitigation only
Fix from $1,950 2026-04-05
Core Ftp HIGH 7.5
CVE-2019-25686

Core FTP 2.0 build 653 contains a denial of service vulnerability in the PBSZ command that allows unauthenticated attackers to crash the service by s…

No fix yet
Fix from $1,950 2026-04-05
Computing For Good\'s Basic Laboratory Information System HIGH 7.5
CVE-2019-25678

C4G Basic Laboratory Information System 3.4 contains multiple SQL injection vulnerabilities that allow unauthenticated attackers to execute arbitrary…

Fix: after 3.4
Fix from $1,950 2026-04-05
Unclassified HIGH 7.5
CVE-2018-25246

Wikipedia 12.0 contains a denial of service vulnerability that allows unauthenticated attackers to crash the application by submitting oversized inpu…

No fix yet
Fix from $1,950 2026-04-04
Unclassified HIGH 7.5
CVE-2018-25241

VPN Browser+ 1.1.0.0 contains a denial of service vulnerability that allows unauthenticated attackers to crash the application by submitting oversize…

No fix yet
Fix from $1,950 2026-04-04
Praisonai CRITICAL 9.1
CVE-2026-34952

PraisonAI is a multi-agent teams system. Prior to version 4.5.97, the PraisonAI Gateway server accepts WebSocket connections at /ws and serves agent …

Fix: 4.5.97+
Fix from $2,300 2026-04-03
Cloud Api HIGH 7.5
CVE-2026-32646

A specific administrative endpoint is accessible without proper authentication, exposing device management functions.

Fix: 2.12.2026+
Fix from $1,950 2026-04-03
Cloud Api HIGH 7.5
CVE-2026-28766

A specific endpoint exposes all user account information for registered Gardyn users without requiring authentication.

Fix: 2.12.2026+
Fix from $1,950 2026-04-03
Cloud Api MEDIUM 5.3
CVE-2026-28767

A specific administrative endpoint notifications is accessible without proper authentication.

Fix: 2.12.2026+
Fix from $1,600 2026-04-03
Mlflow CRITICAL 9.8
CVE-2026-0545

In mlflow/mlflow, the FastAPI job endpoints under `/ajax-api/3.0/jobs/*` are not protected by authentication or authorization when the `basic-auth` a…

Mitigation only
Fix from $2,300 2026-04-03
Azure Web Apps HIGH 7.5
CVE-2026-32211

Missing authentication for critical function in Azure MCP Server allows an unauthorized attacker to disclose information over a network.

Mitigation only
Fix from $1,950 2026-04-03
Hios Switch HIGH 8.6
CVE-2025-15620

HiOS Switch Platform versions 09.1.00 through 09.4.04 and 10.0.00 through 10.3.00 contain a denial-of-service vulnerability in the web interface that…

Fix: 09.4.05 / 10.3.01+
Fix from $1,950 2026-04-02
Oneuptime CRITICAL 9.8
CVE-2026-35053

OneUptime is an open-source monitoring and observability platform. Prior to version 10.0.42, the Worker service's ManualAPI exposes workflow executio…

Fix: 10.0.42+
Fix from $2,300 2026-04-02
Oneuptime CRITICAL 9.1
CVE-2026-34758

OneUptime is an open-source monitoring and observability platform. Prior to version 10.0.42, unauthenticated access to Notification test and Phone Nu…

Fix: 10.0.40+
Fix from $2,300 2026-04-02
Signal K Server HIGH 7.5
CVE-2026-33951

Signal K Server is a server application that runs on a central hub in a boat. Prior to version 2.24.0-beta.1, the SignalK Server exposes an unauthent…

Fix: 2.24.0+
Fix from $1,950 2026-04-02
Secure Email Gateway HIGH 7.5
CVE-2026-29132

SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker with access to a victim's GINA account to bypass a second-password check and r…

Fix: 15.0.3+
Fix from $1,950 2026-04-02
Unclassified HIGH 7.3
CVE-2026-5320

A vulnerability was detected in vanna-ai vanna up to 2.0.2. Affected by this vulnerability is an unknown functionality of the file /api/vanna/v2/ of …

Mitigation only
Fix from $1,950 2026-04-02
Cronmaster CRITICAL 9.8
CVE-2026-34072

Cr*nMaster (cronmaster) is a Cronjob management UI with human readable syntax, live logging and log history for cronjobs. Prior to version 2.2.0, an …

Fix: 2.2.0+
Fix from $2,300 2026-04-01