Vulnerability index

Browse CVEs

2,866 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthenticationCWE-306 × clear
Blockchain HIGH 8.1
CVE-2026-3192

A security vulnerability has been detected in Chia Blockchain 2.1.0. This issue affects the function _authenticate of the file rpc_server_base.py of …

No fix yet
Fix from $1,950 2026-02-25
Unclassified MEDIUM 6.2
CVE-2026-27846

Due to missing authentication, a user with physical access to the device can misuse the mesh functionality for adding a new mesh device to the networ…

Mitigation only
Fix from $1,600 2026-02-25
Antikor Next Generation Firewall CRITICAL 9.8
CVE-2026-2624

Missing Authentication for Critical Function vulnerability in ePati Cyber ​​Security Technologies Inc. Antikor Next Generation Firewall (NGFW) allows…

Fix: 2.0.1301+
Fix from $2,300 2026-02-25
Parse Dashboard HIGH 7.5
CVE-2026-27595

Parse Dashboard is a standalone dashboard for managing Parse Server apps. In versions 7.3.0-alpha.42 through 9.0.0-alpha.7, the AI Agent API endpoint…

Mitigation only
Fix from $1,950 2026-02-25
Smart\+ Firmware HIGH 7.5
CVE-2026-26340

Tattile Smart+, Vega, and Basic device families firmware versions 1.181.5 and prior expose RTSP streams without requiring authentication. A remote at…

Fix: after 1.181.5
Fix from $1,950 2026-02-24
Actual HIGH 7.5
CVE-2026-27584

Actual is a local-first personal finance tool. Prior to version 26.2.1, missing authentication middleware in the ActualBudget server component allows…

Fix: 26.2.1+
Fix from $1,950 2026-02-24
Ncp Firmware CRITICAL 9.8
CVE-2025-14577

Slican NCP/IPL/IPM/IPU devices are vulnerable to PHP Function Injection. An unauthenticated remote attacker is able to execute arbitrary PHP commands…

Fix: 1.24.0190 / 6.61.0010+
Fix from $2,300 2026-02-24
Dinky CRITICAL 9.8
CVE-2026-3053

A vulnerability was determined in DataLinkDC dinky up to 1.2.5. This affects the function addInterceptors of the file dinky-admin/src/main/java/org/d…

Fix: after 1.2.5
Fix from $2,300 2026-02-24
Unclassified CRITICAL 10.0
CVE-2026-23693

ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for Elementor (elementskit-lite) WordPress plugin versions prior to 3.7.9 expose t…

Mitigation only
Fix from $2,300 2026-02-23
Erpnext CRITICAL 9.1
CVE-2026-27471

ERP is a free and open source Enterprise Resource Planning tool. In versions up to 15.98.0 and 16.0.0-rc.1 and through 16.6.0, certain endpoints lack…

Fix: 15.98.1 / 16.6.1+
Fix from $2,300 2026-02-21
Unclassified HIGH 7.5
CVE-2026-26048

The Wi-Fi router is vulnerable to de-authentication attacks due to the absence of management frame protection, allowing forged deauthentication and…

Mitigation only
Fix from $1,950 2026-02-20
Unclassified HIGH 8.2
CVE-2026-24790

The underlying PLC of the device can be remotely influenced, without proper safeguards or authentication.

No fix yet
Fix from $1,950 2026-02-20
Unclassified CRITICAL 9.8
CVE-2025-30410

Sensitive data disclosure and manipulation due to missing authentication. The following products are affected: Acronis Cyber Protect Cloud Agent (Lin…

Mitigation only
Fix from $2,300 2026-02-20
Openclaw HIGH 7.5
CVE-2026-26319

OpenClaw is a personal AI assistant. Versions 2026.2.13 and below allow the optional @openclaw/voice-call plugin Telnyx webhook handler to accept uns…

Fix: 2026.2.14+
Fix from $1,950 2026-02-19
Unclassified CRITICAL 9.8
CVE-2025-8350

Execution After Redirect (EAR), Missing Authentication for Critical Function vulnerability in Inrove Software and Internet Services BiEticaret CMS al…

Mitigation only
Fix from $2,300 2026-02-19
Unclassified MEDIUM 5.3
CVE-2025-14294

The Razorpay for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the getCoup…

Mitigation only
Fix from $1,600 2026-02-19
Unclassified HIGH 8.4
CVE-2026-27182

Saturn Remote Mouse Server contains a command injection vulnerability that allows unauthenticated attackers to execute arbitrary commands by sending …

Mitigation only
Fix from $1,950 2026-02-18
Unclassified HIGH 7.7
CVE-2025-1272

The Linux Kernel lockdown mode for kernel versions starting on 6.12 and above for Fedora Linux has the lockdown mode disabled without any warning. Th…

Mitigation only
Fix from $1,950 2026-02-18
Online Time Table Generator HIGH 7.5
CVE-2025-70147

Missing authentication in /admin/student.php and /admin/teacher.php in ProjectWorlds Online Time Table Generator 1.0 allows remote attackers to obtai…

No fix yet
Fix from $1,950 2026-02-18
Customer Support System CRITICAL 9.4
CVE-2025-70141

SourceCodester Customer Support System 1.0 contains an incorrect access control vulnerability in ajax.php. The AJAX dispatcher does not enforce authe…

No fix yet
Fix from $2,300 2026-02-18
Online Time Table Generator CRITICAL 9.1
CVE-2025-70146

Missing authentication in multiple administrative action scripts under /admin/ in ProjectWorlds Online Time Table Generator 1.0 allows remote attacke…

No fix yet
Fix from $2,300 2026-02-18
Unclassified CRITICAL 9.8
CVE-2026-1670

The affected products are vulnerable to an unauthenticated API endpoint exposure, which may allow an attacker to remotely change the "forgot password…

Mitigation only
Fix from $2,300 2026-02-17
Unclassified MEDIUM 6.1
CVE-2025-7706

Missing Authentication for Critical Function vulnerability in TUBITAK BILGEM Software Technologies Research Institute Liderahenk allows Remote Code I…

Mitigation only
Fix from $1,600 2026-02-17
Unclassified CRITICAL 10.0
CVE-2026-2577

The WhatsApp bridge component in Nanobot binds the WebSocket server to all network interfaces (0.0.0.0) on port 3001 by default and does not require …

Mitigation only
Fix from $2,300 2026-02-16
Unclassified MEDIUM 6.8
CVE-2025-32063

There is a misconfiguration vulnerability inside the Infotainment ECU manufactured by BOSCH. The vulnerability happens during the startup phase of a …

Mitigation only
Fix from $1,600 2026-02-15
Unclassified MEDIUM 5.3
CVE-2025-6792

The One to one user Chat by WPGuppy plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the /wp-js…

Mitigation only
Fix from $1,600 2026-02-14
Verasmart CRITICAL 9.8
CVE-2026-26333

Calero VeraSMART versions prior to 2022 R1 expose an unauthenticated .NET Remoting HTTP service on TCP port 8001. The service publishes default Objec…

Fix: 2022.0+
Fix from $2,300 2026-02-13
Milvus CRITICAL 9.8
CVE-2026-26190EPSS 37%

Milvus is an open-source vector database built for generative AI applications. Prior to 2.5.27 and 2.6.10, Milvus exposes TCP port 9091 by default, w…

Fix: 2.5.27 / 2.6.10+
Fix from $2,300 2026-02-13
Flexcity HIGH 8.8
CVE-2025-14349

Privilege Defined With Unsafe Actions, Missing Authentication for Critical Function vulnerability in Universal Software Inc. FlexCity/Kiosk allows Ac…

Fix: 1.0.36+
Fix from $1,950 2026-02-13
Yoke HIGH 7.5
CVE-2026-26055

Yoke is a Helm-inspired infrastructure-as-code (IaC) package deployer. In 0.19.0 and earlier, a vulnerability exists in the Air Traffic Controller (A…

Fix: after 0.19.0
Fix from $1,950 2026-02-12