Vulnerability index

Browse CVEs

2,866 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthenticationCWE-306 × clear
Navbox Firmware HIGH 7.5
CVE-2026-2754

Navtor NavBox exposes sensitive configuration and operational data due to missing authentication on HTTP API endpoints. An unauthenticated remote att…

Fix: 4.16.2.4+
Fix from $1,950 2026-03-06
Mobiliti E Mobi.hu CRITICAL 9.8
CVE-2026-26051

WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersonation and manipulate data sent …

Mitigation only
Fix from $2,300 2026-03-06
Chartbrew HIGH 7.5
CVE-2026-27603

Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. Prior to version 4.8.4…

Fix: 4.8.4+
Fix from $1,950 2026-03-06
Epower.ie CRITICAL 9.8
CVE-2026-22552

WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersonation and manipulate data sent …

Mitigation only
Fix from $2,300 2026-03-06
Payment Orchestrator Service CRITICAL 9.8
CVE-2026-26125

Payment Orchestrator Service Elevation of Privilege Vulnerability

No fix yet
Fix from $2,300 2026-03-05
Openclaw MEDIUM 5.9
CVE-2026-29613

OpenClaw versions prior to 2026.2.12 contain a vulnerability in the BlueBubbles (optional plugin) webhook handler in which it authenticates requests …

Fix: 2026.2.12+
Fix from $1,600 2026-03-05
Openclaw HIGH 7.8
CVE-2026-28485

OpenClaw versions 2026.1.5 prior to 2026.2.12 fail to enforce mandatory authentication on the /agent/act browser-control HTTP route, allowing unautho…

Fix: 2026.2.12+
Fix from $1,950 2026-03-05
Openclaw MEDIUM 6.5
CVE-2026-29606

OpenClaw versions prior to 2026.2.14 contain a webhook signature-verification bypass in the voice-call extension that allows unauthenticated requests…

Fix: 2026.2.14+
Fix from $1,600 2026-03-05
Openclaw CRITICAL 9.8
CVE-2026-28472

OpenClaw versions prior to 2026.2.2 contain a vulnerability in the gateway WebSocket connect handshake in which it allows skipping device identity ch…

Fix: 2026.2.2+
Fix from $2,300 2026-03-05
Openclaw HIGH 7.7
CVE-2026-28468

OpenClaw versions 2026.1.29-beta.1 prior to 2026.2.14 contain a vulnerability in the sandbox browser bridge server in which it accepts requests witho…

Fix: 2026.2.14+
Fix from $1,950 2026-03-05
Openclaw MEDIUM 5.4
CVE-2026-28458

OpenClaw version 2026.1.20 prior to 2026.2.1 contains a vulnerability in the Browser Relay (extension must be installed and enabled) /cdp WebSocket e…

Fix: 2026.2.1+
Fix from $1,600 2026-03-05
Openclaw HIGH 8.2
CVE-2026-28450

OpenClaw versions prior to 2026.2.12 with the optional Nostr plugin enabled expose unauthenticated HTTP endpoints at /api/channels/nostr/:accountId/p…

Fix: 2026.2.12+
Fix from $1,950 2026-03-05
Nginx Ui CRITICAL 9.8
CVE-2026-27944EPSS 22%

Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.3, the /api/backup endpoint is accessible without authentication and …

Fix: 2.3.3+
Fix from $2,300 2026-03-05
Sb H50 Firmware CRITICAL 9.8
CVE-2026-23767

ESC/POS, a printer control language designed by Seiko Epson Corporation, lacks mechanisms for user authentication and command authorization, does not…

Mitigation only
Fix from $2,300 2026-03-05
Artemis CRITICAL 9.8
CVE-2026-27446EPSS 10%

Missing Authentication for Critical Function (CWE-306) vulnerability in Apache Artemis, Apache ActiveMQ Artemis. An unauthenticated remote attacker c…

Fix: after 2.44.0
Fix from $2,300 2026-03-04
Openstamanager CRITICAL 9.8
CVE-2026-27012

OpenSTAManager is an open source management software for technical assistance and invoicing. In 2.9.8 and earlier, a privilege escalation and authent…

Fix: after 2.9.8
Fix from $2,300 2026-03-03
Unclassified HIGH 8.8
CVE-2026-1775

The Labkotec LID-3300IP has an existing vulnerability in the ice detector software that enables an unauthenticated attacker to alter device parameter…

Mitigation only
Fix from $1,950 2026-03-03
Unclassified CRITICAL 9.0
CVE-2025-30035

The vulnerability enables an attacker to fully bypass authentication in CGM CLININET and gain access to any active user account by supplying only the…

Mitigation only
Fix from $2,300 2026-03-02
Timepictra HIGH 7.5
CVE-2026-2844

Missing Authentication for Critical Function vulnerability in Microchip TimePictra allows Configuration/Environment Manipulation.This issue affects T…

Fix: after 11.3
Fix from $1,950 2026-02-28
Indico MEDIUM 6.5
CVE-2026-28352

Indico is an event management system that uses Flask-Multipass, a multi-backend authentication system for Flask. In versions prior to 3.3.11, the API…

Fix: 3.3.11+
Fix from $1,600 2026-02-27
Mobility46.se CRITICAL 9.8
CVE-2026-27028

WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersonation and manipulate data sen…

Mitigation only
Fix from $2,300 2026-02-27
Swtchenergy.com CRITICAL 9.8
CVE-2026-27767

WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersonation and manipulate data sen…

Mitigation only
Fix from $2,300 2026-02-27
Ev.energy CRITICAL 9.8
CVE-2026-27772

WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersonation and manipulate data sen…

Mitigation only
Fix from $2,300 2026-02-27
Chargemap.com CRITICAL 9.8
CVE-2026-25851

WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersonation and manipulate data sen…

Mitigation only
Fix from $2,300 2026-02-27
Ev2go.io CRITICAL 9.8
CVE-2026-24731

WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersonation and manipulate data sen…

Mitigation only
Fix from $2,300 2026-02-27
Cloudcharge.se CRITICAL 9.8
CVE-2026-20781

WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersonation and manipulate data sen…

Mitigation only
Fix from $2,300 2026-02-27
Unclassified HIGH 7.5
CVE-2026-27449

Umbraco Engage is a business intelligence platform. A vulnerability has been identified in Umbraco Engage prior to versions 16.2.1 and 17.1.1 where c…

Mitigation only
Fix from $1,950 2026-02-26
Unclassified CRITICAL 9.8
CVE-2026-22207

OpenViking through version 0.1.18, prior to commit 0251c70, contains a broken access control vulnerability that allows unauthenticated attackers to g…

Patch available
Fix from $2,300 2026-02-26
Go2 Firmware HIGH 8.0
CVE-2026-27509

Unitree Go2 firmware versions V1.1.7 through V1.1.9, and V1.1.11 (EDU) do not implement DDS authentication or authorization for the Eclipse CycloneDD…

Fix: after 1.1.9
Fix from $1,950 2026-02-26
Blockchain HIGH 7.0
CVE-2026-3194

A flaw has been found in Chia Blockchain 2.1.0. The affected element is the function send_transaction/get_private_key of the component RPC Server Mas…

No fix yet
Fix from $1,950 2026-02-25