Vulnerability index

Browse CVEs

2,866 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthenticationCWE-306 × clear
Unclassified MEDIUM 5.3
CVE-2026-4187

A vulnerability was identified in Tiandy Easy7 Integrated Management Platform 7.17.0. Impacted is an unknown function of the file /WebService/UpdateL…

Mitigation only
Fix from $1,600 2026-03-16
Hue Bridge V2 Firmware HIGH 8.1
CVE-2026-3558

Philips Hue Bridge HomeKit Accessory Protocol Transient Pairing Mode Authentication Bypass Vulnerability. This vulnerability allows network-adjacent …

Fix: 1975170000+
Fix from $1,950 2026-03-16
Parse Server HIGH 7.3
CVE-2026-32594

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 8.6.40 and 9.6.0-alpha.14, the Graph…

Fix: 8.6.40 / 9.6.0+
Fix from $1,950 2026-03-16
Unclassified MEDIUM 6.3
CVE-2026-2491

Socomec DIRIS A-40 HTTP API Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to bypass authentication on aff…

Mitigation only
Fix from $1,600 2026-03-16
Smart Switch MEDIUM 5.3
CVE-2026-20995

Exposure of sensitive functionality to an unauthorized actor in Smart Switch prior to version 3.7.69.15 allows remote attackers to set a specific con…

Fix: 3.7.69.15+
Fix from $1,600 2026-03-16
Sdt Cs3b1 Firmware HIGH 7.5
CVE-2017-20222

Telesquare SKT LTE Router SDT-CS3B1 software version 1.2.0 contains an unauthenticated remote reboot vulnerability that allows attackers to trigger d…

No fix yet
Fix from $1,950 2026-03-16
Unclassified HIGH 7.5
CVE-2017-20217

Serviio PRO 1.8 contains an information disclosure vulnerability due to improper access control enforcement in the Configuration REST API that allows…

No fix yet
Fix from $1,950 2026-03-16
Unclassified HIGH 7.5
CVE-2017-20220

Serviio PRO 1.8 contains an improper access control vulnerability in the Configuration REST API that allows unauthenticated attackers to change the m…

No fix yet
Fix from $1,950 2026-03-16
Librechat HIGH 7.6
CVE-2026-31944

LibreChat is a ChatGPT clone with additional features. From 0.8.2 to 0.8.2-rc3, The MCP (Model Context Protocol) OAuth callback endpoint accepts the …

No fix yet
Fix from $1,950 2026-03-13
Dagu HIGH 7.5
CVE-2026-31882

Dagu is a workflow engine with a built-in Web user interface. Prior to 2.2.4, when Dagu is configured with HTTP Basic authentication (DAGU_AUTH_MODE=…

Fix: 2.2.4+
Fix from $1,950 2026-03-13
Wpdiscuz CRITICAL 9.9
CVE-2026-22192

Voltronic Power SNMP Web Pro version 1.1 contains an authentication bypass vulnerability that allows unauthenticated attackers to access privileged m…

Fix: 7.6.47+
Fix from $2,300 2026-03-13
Easyshare MEDIUM 5.5
CVE-2025-15515

The authentication mechanism for a specific feature in the EasyShare module contains a vulnerability. If specific conditions are met on a local netwo…

Fix: 7.0.11.5+
Fix from $1,600 2026-03-13
Unclassified MEDIUM 6.5
CVE-2025-13778

Missing authentication for critical function vulnerability in ABB AWIN GW100 rev.2, ABB AWIN GW120.This issue affects AWIN GW100 rev.2: 2.0-0, 2.0-1;…

Mitigation only
Fix from $1,600 2026-03-13
Unclassified HIGH 8.3
CVE-2025-13779

Missing authentication for critical function vulnerability in ABB AWIN GW100 rev.2, ABB AWIN GW120.This issue affects AWIN GW100 rev.2: 2.0-0, 2.0-1;…

Mitigation only
Fix from $1,950 2026-03-13
Iq4e Firmware CRITICAL 10.0
CVE-2026-3611EPSS 6%

The Honeywell IQ4x building management controller, exposes its full web-based HMI without authentication in its factory-default configuration. With n…

Fix: 3.30+
Fix from $2,300 2026-03-12
Zeptoclaw HIGH 8.2
CVE-2026-32231

ZeptoClaw is a personal AI assistant. Prior to 0.7.6, the generic webhook channel trusts caller-supplied identity fields (sender, chat_id) from the r…

Fix: after 0.7.5
Fix from $1,950 2026-03-12
Runtipi CRITICAL 9.8
CVE-2026-31881

Runtipi is a personal homeserver orchestrator. Prior to 4.8.0, an unauthenticated attacker can reset the operator (admin) password when a password-re…

Fix: 4.8.0+
Fix from $2,300 2026-03-11
Unclassified HIGH 8.4
CVE-2019-25483

Comtrend AR-5310 GE31-412SSG-C01_R10.A2pG039u.d24k contains a restricted shell escape vulnerability that allows local users to bypass command restric…

No fix yet
Fix from $1,950 2026-03-11
Vociferous HIGH 7.1
CVE-2026-27897

Vociferous provides cross-platform, offline speech-to-text with local AI refinement. Prior to 4.4.2, the vulnerability exists in src/api/system.py wi…

Fix: 4.4.2+
Fix from $1,950 2026-03-11
Argo Workflows HIGH 7.5
CVE-2026-28229

Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. Prior to 4.0.2 and 3.7.11, Workflow …

Fix: 3.7.11 / 4.0.2+
Fix from $1,950 2026-03-11
Filebrowser HIGH 7.5
CVE-2026-30933

FileBrowser Quantum is a free, self-hosted, web-based file manager. Prior to 1.3.1-beta and 1.2.2-stable, the remediation for CVE-2026-27611 is incom…

Fix: after 1.2.9
Fix from $1,950 2026-03-10
Unclassified HIGH 7.5
CVE-2026-2339

Missing Authentication for Critical Function vulnerability in TUBITAK BILGEM Software Technologies Research Institute Liderahenk allows Remote Code I…

Mitigation only
Fix from $1,950 2026-03-10
Azure Iot Explorer HIGH 7.5
CVE-2026-23662

Missing authentication for critical function in Azure IoT Explorer allows an unauthorized attacker to disclose information over a network.

Fix: 0.15.13+
Fix from $1,950 2026-03-10
Avideo MEDIUM 5.3
CVE-2026-30885

WWBN AVideo is an open source video platform. Prior to 25.0, the /objects/playlistsFromUser.json.php endpoint returns all playlists for any user with…

Fix: 25.0+
Fix from $1,600 2026-03-10
Unclassified MEDIUM 5.3
CVE-2026-1920

The Booking Calendar for Appointments and Service Businesses – Booktics plugin for WordPress is vulnerable to unauthorized modification of data due t…

Mitigation only
Fix from $1,600 2026-03-10
Unclassified MEDIUM 5.3
CVE-2026-1919

The Booking Calendar for Appointments and Service Businesses – Booktics plugin for WordPress is vulnerable to unauthorized access of data due to a mi…

Mitigation only
Fix from $1,600 2026-03-10
Flowise CRITICAL 9.8
CVE-2026-30824EPSS 36%

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.0.13, the NVIDIA NIM router (/api/v1/nvid…

Fix: 3.0.13+
Fix from $2,300 2026-03-07
Zikestor Sks8310 8x Firmware HIGH 7.5
CVE-2026-25071

XikeStor SKS8310-8X Network Switch firmware versions 1.04.B07 and prior contain a missing authentication vulnerability in the /switch_config.src endp…

Fix: after 1.04.b07
Fix from $1,950 2026-03-07
Wekan HIGH 7.5
CVE-2026-30846

Wekan is an open source kanban tool built with Meteor. In versions 8.31.0 through 8.33, the globalwebhooks publication exposes all global webhook int…

Fix: 8.33+
Fix from $1,950 2026-03-06
Api.everon.io CRITICAL 9.8
CVE-2026-26288

WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersonation and manipulate data sent …

Mitigation only
Fix from $2,300 2026-03-06