Vulnerability index

Browse CVEs

2,855 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthenticationCWE-306 × clear
Unclassified CRITICAL 9.8
CVE-2026-41452

Krayin CRM 2.2.4 contains a missing authentication vulnerability in the installer middleware that allows unauthenticated remote attackers to overwrit…

No fix yet
Fix from $2,300 2026-08-03
Unclassified HIGH 7.5
CVE-2026-69091

Admidio before 5.0.11 contains an authentication bypass vulnerability in the forum module when configured in login-only mode. The access control logi…

No fix yet
Fix from $1,950 2026-08-03
Unclassified HIGH 7.5
CVE-2026-68578

ArcadeDB versions before 26.7.3 fail to bind the authenticated principal in the MCP HTTP transport, causing all engine permission checks to silently …

No fix yet
Fix from $1,950 2026-08-02
Pgadmin 4 MEDIUM 6.5
CVE-2026-17348

In SERVER mode, pgAdmin 4 enforces authentication per route via the @pga_login_required decorator; the application's before_request hook only handles…

Fix: 9.17+
Fix from $1,600 2026-07-31
Unclassified HIGH 7.5
CVE-2026-65310

ANDRITZ HIPASE-250 (formerly 250 SCALA), in the default configuration of affected versions, exposes its data and configuration endpoint without any a…

No fix yet
Fix from $1,950 2026-07-31
Unclassified MEDIUM 5.3
CVE-2026-65311

The HTTP server component of ANDRITZ HIPASE-250 (formerly 250 SCALA) in affected versions exposes an undocumented endpoint that changes the server's …

No fix yet
Fix from $1,600 2026-07-31
Unclassified HIGH 8.8
CVE-2026-12562

The RCU II+ and Multiload II+ are vulnerable to an unauthenticated service that exposes a debug interface granting full root-level access to the em…

No fix yet
Fix from $1,950 2026-07-30
Unclassified CRITICAL 9.8
CVE-2026-68502

LazyOwn RedTeam/APT Framework is an AI-powered C2 and red-team operations framework. Prior to 0.2.154, LazyOwn's lazyc2.py registers an unauthenticat…

No fix yet
Fix from $2,300 2026-07-30
Unclassified CRITICAL 9.8
CVE-2026-67594

Spikster through commit e1cdf8c contains a missing authentication vulnerability that allows unauthenticated remote attackers to access all API routes…

No fix yet
Fix from $2,300 2026-07-30
Unclassified CRITICAL 9.8
CVE-2026-67208

Juggle through 1.6.0 contains a remote code execution vulnerability that allows unauthenticated remote attackers to execute arbitrary OS commands by …

No fix yet
Fix from $2,300 2026-07-30
Sglang HIGH 7.5
CVE-2026-15978

SGLang contains a model weight exfiltration vulnerability when no API keys are configured, as SGLang will expose two endpoints that allow a remote at…

Fix: after 0.5.15
Fix from $1,950 2026-07-30
Jspwiki HIGH 7.5
CVE-2026-28814

Arbitrary Wiki Markup rendering due to lack of authentication in Apache JSPWiki up to 2.12.3 allows attacker to obtain sensitive data stored in JSPWi…

Fix: 2.12.4+
Fix from $1,950 2026-07-30
Unclassified HIGH 7.5
CVE-2026-67349

OpenCost before 1.121.0 fails to authenticate the GET /helmValues endpoint, exposing base64-decoded HELM_VALUES environment variable containing cloud…

No fix yet
Fix from $1,950 2026-07-30
Unclassified HIGH 8.2
CVE-2026-12722

Missing authentication for critical function vulnerability in FTC Software IT Services FTC E-Commerce Management Panel allows Authentication Bypass. …

No fix yet
Fix from $1,950 2026-07-30
Unclassified HIGH 7.5
CVE-2026-54365

CentreStack before 17.3 contains an unauthenticated deserialization vulnerability in GSNamespace.dll that allows unauthenticated attackers to create …

No fix yet
Fix from $1,950 2026-07-30
Unclassified HIGH 8.6
CVE-2026-54367

CentreStack before 17.2 contains an authentication bypass vulnerability that allows unauthenticated attackers to read, write, or delete arbitrary acc…

No fix yet
Fix from $1,950 2026-07-30
Unclassified CRITICAL 9.4
CVE-2026-44100

The CHARX JupiCore service allows an unauthenticated remote attacker to reconfigure charging points. This can lead to disclosure of charging point UI…

No fix yet
Fix from $2,300 2026-07-30
Unclassified CRITICAL 9.8
CVE-2026-44101

Due to missing authentication the CHARX OCPP Agent service allows an unauthenticated remote attacker to reconfigure the backend connection. This can …

No fix yet
Fix from $2,300 2026-07-30
Unclassified CRITICAL 9.8
CVE-2026-44090

Due to missing authentication, an unauthenticated remote attacker may access the MQTT broker, which is only protected from external access by a firew…

No fix yet
Fix from $2,300 2026-07-30
Unclassified HIGH 8.0
CVE-2026-47858

Starting Spring Boot applications in the Spring Tools with the live information mode enabled makes the running application vulnerable against JMX-bas…

No fix yet
Fix from $1,950 2026-07-30
Unclassified HIGH 7.3
CVE-2026-16527

An unauthenticated remote attacker can bypass access controls by sending crafted requests to the PCP pmproxy /store endpoint. This allows the attacke…

No fix yet
Fix from $1,950 2026-07-30
Unclassified HIGH 7.5
CVE-2026-5057

ATEN Unizon RpcProvider Missing Authentication Denial-of-Service Vulnerability. This vulnerability allows remote attackers to create a denial-of-serv…

No fix yet
Fix from $1,950 2026-07-29
Unclassified CRITICAL 9.3
CVE-2026-67426

Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.7, the standalone flyto-verification service in src/core/veri…

No fix yet
Fix from $2,300 2026-07-29
Websphere Application Server CRITICAL 9.8
CVE-2026-14529

IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 traditional is vulnerable to s…

Fix: 8.5.5.31 / 9.0.5.29+
Fix from $2,300 2026-07-29
Ait Gui CRITICAL 9.8
CVE-2026-60112

AMMOS Instrument Toolkit (AIT) GUI before 2.5.1 contains a missing authentication vulnerability that allows any unauthenticated network attacker to o…

No fix yet
Fix from $2,300 2026-07-29
Ait Dsn CRITICAL 9.8
CVE-2026-60113

AMMOS Instrument Toolkit (AIT) Deep Space Network (DSN) Interface before 2.2.2 contains a missing authentication vulnerability in the Space Link Exte…

No fix yet
Fix from $2,300 2026-07-29
Unclassified CRITICAL 9.1
CVE-2026-62325

goshs is a feature-rich single-binary file server for red teamers and developers. From 2.1.3 until 2.1.4, the sftpserver/sftpserver.go password handl…

No fix yet
Fix from $2,300 2026-07-28
Websphere Application Server CRITICAL 9.8
CVE-2026-14976

IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is affected by remote code execution with the collectiveController-1.0 feature e…

Fix: 26.0.0.9+
Fix from $2,300 2026-07-28
Websphere Application Server CRITICAL 9.8
CVE-2026-14446

IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to broken access control/privilege escalation in the administrative console.

Fix: 8.5.5.30 / 9.0.5.28+
Fix from $2,300 2026-07-28
Unclassified HIGH 8.8
CVE-2026-16771

In firmware versions 2.7.7 and earlier, the Arris BGW210‑700 gateway fails to enforce any server‑side authentication on its /cgi-bin/*.ha management …

No fix yet
Fix from $1,950 2026-07-28