Vulnerability index

Browse CVEs

2,866 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthenticationCWE-306 × clear
Sage Dpw HIGH 7.5
CVE-2025-67805

A non-default configuration in Sage DPW 2025_06_004 allows unauthenticated access to diagnostic endpoints within the Database Monitor feature, exposi…

Mitigation only
Fix from $1,950 2026-04-01
Openviking MEDIUM 5.3
CVE-2026-34999

OpenViking versions 0.2.5 prior to 0.2.14 contain a missing authentication vulnerability in the bot proxy router that allows remote unauthenticated a…

Fix: 0.2.14+
Fix from $1,600 2026-04-01
Juju CRITICAL 10.0
CVE-2026-4370

A vulnerability was identified in Juju from version 3.2.0 until 3.6.19 and from version 4.0 until 4.0.4, where the internal Dqlite database cluster f…

Fix: 3.6.20 / 4.0.5+
Fix from $2,300 2026-04-01
Avideo HIGH 7.5
CVE-2026-34731

WWBN AVideo is an open source video platform. In versions 26.0 and prior, the AVideo on_publish_done.php endpoint in the Live plugin allows unauthent…

Fix: after 26.0
Fix from $1,950 2026-03-31
Avideo HIGH 7.5
CVE-2026-34732

WWBN AVideo is an open source video platform. In versions 26.0 and prior, the AVideo CreatePlugin template for list.json.php does not include any aut…

Fix: after 26.0
Fix from $1,950 2026-03-31
Autopilot CRITICAL 9.8
CVE-2026-1579

The MAVLink communication protocol does not require cryptographic authentication by default. When MAVLink 2.0 message signing is not enabled, any m…

No fix yet
Fix from $2,300 2026-03-31
Unclassified CRITICAL 9.3
CVE-2026-3356

The MS27102A Remote Spectrum Monitor is vulnerable to an authentication bypass that allows unauthorized users to access and manipulate its management…

Mitigation only
Fix from $2,300 2026-03-31
Sliver HIGH 8.8
CVE-2026-34227

Sliver is a command and control framework that uses a custom Wireguard netstack. Prior to version 1.7.4, a single click on a malicious link gives an …

Fix: 1.7.4+
Fix from $1,950 2026-03-31
Cli HIGH 7.5
CVE-2026-34200

Nhost is an open source Firebase alternative with GraphQL. Prior to version 1.41.0, The Nhost CLI MCP server, when explicitly configured to listen on…

Fix: 1.41.0+
Fix from $1,950 2026-03-31
Fastgpt CRITICAL 10.0
CVE-2026-34162

FastGPT is an AI Agent building platform. Prior to version 4.14.9.5, the FastGPT HTTP tools testing endpoint (/api/core/app/httpTools/runTool) is exp…

Fix: 4.14.9.5+
Fix from $2,300 2026-03-31
Nginx Ui CRITICAL 9.8
CVE-2026-33032EPSS 38%

Nginx UI is a web user interface for the Nginx web server. In versions 2.3.5 and prior, the nginx-ui MCP (Model Context Protocol) integration exposes…

Fix: after 2.3.5
Fix from $2,300 2026-03-30
Zxhn H188a Firmware HIGH 7.1
CVE-2026-34472EPSS 9%

Unauthenticated credential disclosure in the wizard interface in ZTE ZXHN H188A V6.0.10P2_TE and V6.0.10P3N3_TE allows unauthenticated attackers on t…

Mitigation only
Fix from $1,950 2026-03-30
Unclassified HIGH 7.3
CVE-2026-5000

A vulnerability was detected in PromtEngineer localGPT up to 4d41c7d1713b16b216d8e062e51a5dd88b20b054. Impacted is the function LocalGPTHandler of th…

Mitigation only
Fix from $1,950 2026-03-28
Practical Music Search HIGH 7.8
CVE-2018-25224

PMS 0.42 contains a stack-based buffer overflow vulnerability that allows local unauthenticated attackers to execute arbitrary code by supplying mali…

Fix: after 0.42
Fix from $1,950 2026-03-28
Sipp HIGH 7.8
CVE-2018-25225

SIPP 3.3 contains a stack-based buffer overflow vulnerability that allows local unauthenticated attackers to execute arbitrary code by supplying mali…

No fix yet
Fix from $1,950 2026-03-28
Appsmith MEDIUM 5.3
CVE-2026-34411

Appsmith versions prior to 1.98 expose sensitive instance management API endpoints without authentication. Unauthenticated attackers can query endpoi…

Fix: 1.98+
Fix from $1,600 2026-03-27
Xagent HIGH 7.5
CVE-2026-4959

A vulnerability was found in OpenBMB XAgent 1.0.0. This impacts the function check_user of the file XAgentServer/application/websockets/share.py of t…

No fix yet
Fix from $1,950 2026-03-27
Wcr 1166dhpl Firmware MEDIUM 5.3
CVE-2026-33366

Missing authentication for critical function vulnerability in BUFFALO Wi-Fi router products may allow an attacker to forcibly reboot the product with…

Fix: 1.01 / 2.53+
Fix from $1,600 2026-03-27
Ajax Dashboard MEDIUM 6.5
CVE-2026-3527

Missing Authentication for Critical Function vulnerability in Drupal AJAX Dashboard allows Exploiting Incorrectly Configured Access Control Security …

Fix: 3.1.0+
Fix from $1,600 2026-03-26
Unclassified HIGH 8.8
CVE-2026-24068

The VSL privileged helper does utilize NSXPC for IPC. The implementation of the "shouldAcceptNewConnection" function, which is used by the NSXPC fram…

Mitigation only
Fix from $1,950 2026-03-26
GitLab HIGH 7.5
CVE-2026-1724

GitLab has remediated an issue in GitLab EE affecting all versions from 18.5 before 18.8.7, 18.9 before 18.9.3, and 18.10 before 18.10.1 that could h…

Fix: 18.8.7 / 18.9.3+
Fix from $1,950 2026-03-25
Unclassified MEDIUM 5.7
CVE-2026-32326

SHARP routers do not perform authentication for some web APIs. The device information may be retrieved without authentication. If the administrative …

Mitigation only
Fix from $1,600 2026-03-25
Unclassified CRITICAL 9.3
CVE-2026-2417

A Missing Authentication for Critical Function vulnerability in Pharos Controls Mosaic Show Controller firmware version 2.15.3 could allow an unauthe…

Mitigation only
Fix from $2,300 2026-03-24
Craft Cms MEDIUM 6.5
CVE-2026-33159

Craft CMS is a content management system (CMS). From version 4.0.0-RC1 to before version 4.17.8 and from version 5.0.0-RC1 to before version 5.9.14, …

Fix: 4.17.8 / 5.9.14+
Fix from $1,600 2026-03-24
Lollms Web Ui CRITICAL 9.1
CVE-2026-33340EPSS 22%

LoLLMs WEBUI provides the Web user interface for Lord of Large Language and Multi modal Systems. A critical Server-Side Request Forgery (SSRF) vulner…

No fix yet
Fix from $2,300 2026-03-24
Phpfilemanager MEDIUM 5.5
CVE-2019-25632

phpFileManager 1.7.8 contains a local file inclusion vulnerability that allows unauthenticated attackers to read arbitrary files by manipulating the …

No fix yet
Fix from $1,600 2026-03-24
Unclassified MEDIUM 5.3
CVE-2026-4649

Apache Artemis before version 2.52.0 is affected by an authentication bypass flaw which allows reading all messages exchanged via the broker and inje…

Mitigation only
Fix from $1,600 2026-03-24
Vitalsesp HIGH 7.5
CVE-2026-4640

Vitals ESP developed by Galaxy Software Services has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to execute cer…

Fix: after 6.3
Fix from $1,950 2026-03-24
Avideo HIGH 8.6
CVE-2026-33719

WWBN AVideo is an open source video platform. In versions up to and including 26.0, the CDN plugin endpoints `plugin/CDN/status.json.php` and `plugin…

Fix: after 26.0
Fix from $1,950 2026-03-23
Archer Nx600 Firmware HIGH 8.1
CVE-2025-15517

A missing authentication check in the HTTP server on TP-Link Archer NX200, NX210, NX500 and NX600 to certain cgi endpoints allows unauthenticated acc…

Fix: 1.3.0 / 1.4.0+
Fix from $1,950 2026-03-23