Vulnerability index

Browse CVEs

2,866 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthenticationCWE-306 × clear
Unclassified MEDIUM 6.5
CVE-2026-31846

Missing authentication in the /goform/ate endpoint in Nexxt Solutions Nebula 300+ firmware through version 12.01.01.37 allows an adjacent unauthentic…

Mitigation only
Fix from $1,600 2026-03-23
Unclassified MEDIUM 5.0
CVE-2026-4582

A security vulnerability has been detected in Shenzhen HCC Technology MPOS M6 PLUS 1V.31-N. Affected by this vulnerability is an unknown functionalit…

Mitigation only
Fix from $1,600 2026-03-23
Unclassified HIGH 7.3
CVE-2026-4562

A security flaw has been discovered in MacCMS 2025.1000.4052. This affects an unknown part of the file application/api/controller/Timming.php of the …

Mitigation only
Fix from $1,950 2026-03-23
Unclassified MEDIUM 5.0
CVE-2026-2756

A security vulnerability has been detected in OmniPEMF NeoRhythm up to 20260308. This affects an unknown function of the component BLE Interface. Suc…

Mitigation only
Fix from $1,600 2026-03-21
Memu HIGH 7.8
CVE-2019-25568

Memu Play 6.0.7 contains an insecure file permissions vulnerability that allows low-privilege users to escalate privileges by replacing the MemuServi…

Fix: after 6.0.7
Fix from $1,950 2026-03-21
Openclaw MEDIUM 6.5
CVE-2026-32896

The BlueBubbles webhook handler in OpenClaw versions prior to 2026.2.21 contains a passwordless fallback authentication path that allows unauthentica…

Fix: 2026.2.21+
Fix from $1,600 2026-03-21
Openclaw CRITICAL 9.1
CVE-2026-32064

OpenClaw versions prior to 2026.2.21 sandbox browser entrypoint launches x11vnc without authentication for noVNC observer sessions, allowing unauthen…

Fix: 2026.2.21+
Fix from $2,300 2026-03-21
Nltk HIGH 7.5
CVE-2026-33231

NLTK (Natural Language Toolkit) is a suite of open source Python modules, data sets, and tutorials supporting research and development in Natural Lan…

Fix: after 3.9.3
Fix from $1,950 2026-03-20
Siyuan HIGH 7.5
CVE-2026-33203

SiYuan is a personal knowledge management system. Prior to version 3.6.2, the SiYuan kernel WebSocket server accepts unauthenticated connections when…

Fix: 3.6.2+
Fix from $1,950 2026-03-20
Eparking.fi CRITICAL 9.8
CVE-2026-29796

WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersonation and manipulate data sent …

Mitigation only
Fix from $2,300 2026-03-20
Charge Portal CRITICAL 9.8
CVE-2026-25192

WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersonation and manipulate data sent …

Mitigation only
Fix from $2,300 2026-03-20
Qvr Pro CRITICAL 9.8
CVE-2026-22898

A missing authentication for critical function vulnerability has been reported to affect QVR Pro. The remote attackers can then exploit the vulnerabi…

Fix: 2.7.4.1485+
Fix from $2,300 2026-03-20
Unclassified MEDIUM 6.3
CVE-2026-4476

A vulnerability was found in Yi Technology YI Home Camera 2 2.1.1_20171024151200. The impacted element is an unknown function of the file home/web/ip…

Mitigation only
Fix from $1,600 2026-03-20
Avideo HIGH 8.1
CVE-2026-33038

WWBN AVideo is an open source video platform. Versions 25.0 and below are vulnerable to unauthenticated application takeover through the install/chec…

Fix: 26.0+
Fix from $1,950 2026-03-20
Langflow CRITICAL 9.8
CVE-2026-33017 KEVEPSS 96%

Langflow is a tool for building and deploying AI-powered agents and workflows. In versions prior to 1.9.0, the POST /api/v1/build_public_tmp/{flow_id…

Fix: 1.8.2+
Fix from $2,300 2026-03-20
Identity Manager CRITICAL 9.8
CVE-2026-21992

Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: REST WebServices) and Oracle Web Services Manager produc…

Mitigation only
Fix from $2,300 2026-03-20
Xerte Online Toolkits CRITICAL 9.8
CVE-2026-32985

Xerte Online Toolkits versions 3.14 and earlier contain an unauthenticated arbitrary file upload vulnerability in the template import functionality t…

Fix: after 3.14.0
Fix from $2,300 2026-03-20
Spring Boot HIGH 8.1
CVE-2026-22731

Spring Boot applications with Actuator can be vulnerable to an "Authentication Bypass" vulnerability when an application endpoint that requires authe…

Fix: 3.4.15 / 3.5.12+
Fix from $1,950 2026-03-19
Openclaw HIGH 7.8
CVE-2026-32041

OpenClaw versions prior to 2026.3.1 fail to properly handle authentication bootstrap errors during startup, allowing browser-control routes to remain…

Fix: 2026.3.1+
Fix from $1,950 2026-03-19
Footprints CRITICAL 9.1
CVE-2025-71257EPSS 5%

BMC FootPrints ITSM versions 20.20.02 through 20.24.01.001 contain an authentication bypass vulnerability due to improper enforcement of security fil…

Fix: after 20.24.01.001
Fix from $2,300 2026-03-19
Unclassified HIGH 7.8
CVE-2026-24062

The "Privileged Helper" component of the Arturia Software Center (MacOS) does not perform sufficient client code signature validation when a client c…

Mitigation only
Fix from $1,950 2026-03-18
Build Of Keycloak HIGH 8.1
CVE-2026-2603

A flaw was found in Keycloak. A remote attacker could bypass security controls by sending a valid SAML response from an external Identity Provider (I…

Fix: 26.2.14 / 26.4.10+
Fix from $1,950 2026-03-18
Openclaw MEDIUM 6.8
CVE-2026-22174

OpenClaw versions prior to 2026.2.22 inject the x-OpenClaw-relay-token header into Chrome CDP probe traffic on loopback interfaces, allowing local pr…

Fix: 2026.2.22+
Fix from $1,600 2026-03-18
Sterling B2b Integrator MEDIUM 6.5
CVE-2026-1264

IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.1.0.0 through 6.1.2.7_2, 6.2.0.0 through 6.2.0.5_1, 6.2.1.0 through 6.2.1.1_1, and 6.2.2.…

Fix: 6.1.2.8 / 6.2.0.5_2+
Fix from $1,600 2026-03-17
Unclassified HIGH 7.5
CVE-2026-22727

Unprotected internal endpoints in Cloud Foundry Capi Release 1.226.0 and below, and CF Deployment v54.9.0 and below on all platforms allows any user …

Mitigation only
Fix from $1,950 2026-03-17
Bpm Enterprise CRITICAL 9.8
CVE-2026-3207

Configuration issue in Java Management Extensions (JMX) in TIBCO BPM Enterprise version 4.x allows unauthorised access.

Fix: 4.3.5+
Fix from $2,300 2026-03-17
Es3 Kvm Firmware HIGH 7.5
CVE-2026-32297

The Angeet ES3 KVM allows a remote, unauthenticated attacker to write arbitrary files, including configuration files or system binaries. Modified con…

Mitigation only
Fix from $1,950 2026-03-17
Comet Gl Rm1 Firmware MEDIUM 6.8
CVE-2026-32291

The GL-iNet Comet (GL-RM1) KVM before 1.8.2 does not require authentication on the UART serial console. This attack requires physically opening the d…

Fix: 1.8.2+
Fix from $1,600 2026-03-17
Unclassified HIGH 8.2
CVE-2026-32296

Sipeed NanoKVM before 2.3.1 exposes a Wi-Fi configuration endpoint without proper security checks, allowing an unauthenticated attacker with network …

Mitigation only
Fix from $1,950 2026-03-17
Gcb\/fcb Government Financial Cybersecurity Configuration Audit Software CRITICAL 9.8
CVE-2026-4312

GCB/FCB Audit Software developed by DrangSoft has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to directly acces…

Mitigation only
Fix from $2,300 2026-03-17