Vulnerability index

Browse CVEs

2,855 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthenticationCWE-306 × clear
CRITICAL 9.2 CVE-2026-71878 Missing authentication in initial setup functionality left exposed after initial setup is completed in GBIF Integrated Publishing Toolkit versions be… Fix unknown Fix from $5,7502026-08-18 CRITICAL 9.8 CVE-2026-75852 ArcadeDB versions before 26.8.1 fail to enforce SASL authentication on data commands in the MongoDB wire-protocol plugin. Unauthenticated attackers c… Fix unknown Fix from $5,7502026-08-18 CRITICAL 9.8 CVE-2026-75854 ArcadeDB versions before 26.8.1 contain a missing authentication vulnerability in the Redis wire-protocol plugin that allows unauthenticated attacker… Fix unknown Fix from $5,7502026-08-18 HIGH 8.6 CVE-2026-56677 9Router is an AI router & token saver. In 0.5.4 and earlier, the POST /api/auth/oidc/test endpoint in src/app/api/auth/oidc/test/route.js passes the … Fix unknown Fix from $4,9002026-08-17 HIGH 7.5 CVE-2026-75479 JimuReport contains an authentication bypass vulnerability in the report folder template listing endpoint that allows unauthenticated attackers to en… Fix unknown Fix from $4,9002026-08-17 CRITICAL 9.8 CVE-2026-67966 Tenda W20E V16.01.0.6(2782) /goform/telnet endpoint allows unauthenticated remote attackers to activate the Telnet daemon and obtain root shell acces… Fix unknown Fix from $5,7502026-08-17 HIGH 8.4 CVE-2026-75060 In JetBrains PyCharm before 2026.2.1 code execution was possible via unauthenticated Jupyter MCP tools Fix unknown Fix from $4,9002026-08-17 CRITICAL 9.3 CVE-2026-71566 FakeFish handles incoming credentials by passing them down to scripts. This works for real hardware because in the end it's up to the BMC to valida… Fix unknown Fix from $5,7502026-08-17 MEDIUM 6.5 CVE-2026-74243 A flaw was found in Red Hat Quay. When the SECURITY_SCANNER_V4_PSK (pre-shared key) is not set, a remote unauthenticated attacker can send POST reque… No fix yet Fix from $4,0002026-08-14 MEDIUM 5.9 CVE-2026-74245 A flaw was found in Red Hat Quay's exported logs feature. An unauthenticated attacker with a valid file ID could download exported action logs withou… No fix yet Fix from $4,0002026-08-14 HIGH 7.1 CVE-2026-19908 PAX Technology Q80 XCB Daemon Missing Authentication Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive inform… No fix yet Fix from $4,9002026-08-14 CRITICAL 9.8 CVE-2026-50027 mcp-memory-service is a semantic memory layer for AI applications. Prior to 10.67.1, all HTTP routes under /api/documents/* in mcp-memory-service are… No fix yet Fix from $5,7502026-08-14 CRITICAL 9.8 CVE-2026-73849 Emlog is an open source website building system. In 2.6.26 and earlier, install.php accepts action=reinstall without authentication and deliberately … No fix yet Fix from $5,7502026-08-14 HIGH 8.8 CVE-2026-73673 Netis NC63 router firmware V3.0.0.3327 contains an unauthenticated firmware update vulnerability that allows unauthenticated attackers to submit unsi… No fix yet Fix from $4,9002026-08-14 CRITICAL 9.8 CVE-2026-72822 The getgrav/grav-plugin-api Composer package before 1.0.13 (affected <= 1.0.12) fails to enforce API key scope caps on the disable2fa endpoint. Unlik… No fix yet Fix from $5,7502026-08-14 CRITICAL 9.0 CVE-2026-73842 OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.0.3, 1.1.3, and 1.2.0-rc.2, internal/cluster-gateway/server.go ex… No fix yet Fix from $5,7502026-08-13 CRITICAL 9.6 CVE-2026-73843 OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.0.2 and 1.1.2, internal/cluster-gateway/server.go served caller-f… No fix yet Fix from $5,7502026-08-13 HIGH 8.2 CVE-2026-73666 OpenChoreo is a developer platform for Kubernetes. Prior to 1.0.4, 1.1.4, and 1.2.1, the OpenChoreo Backstage backend hardcoded backend.auth.dangerou… No fix yet Fix from $4,9002026-08-13 CRITICAL 9.8 CVE-2026-72776 AgenticSeek (commit fc242c7) contains an unauthenticated remote code execution vulnerability that allows any network-adjacent attacker to execute arb… No fix yet Fix from $5,7502026-08-13 HIGH 7.3 CVE-2026-73669 The Signify Philips Hue Bridge Pro firmware embeds a Mosquitto MQTT broker service that listens on all network interfaces without authentication. An … No fix yet Fix from $4,9002026-08-13 CRITICAL 9.4 CVE-2026-14525 IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 IBM WebSphere Application Server Liberty is vulnerable to an authentication bypa… Websphere Application Server No fix yet Fix from $5,7502026-08-13 CRITICAL 9.8 CVE-2026-49827 WebErpMesv2 is a Resource Management and Manufacturing execution system Web for industry. Versions 1.19 and prior allow any self-registered user to u… No fix yet Fix from $5,7502026-08-13 CRITICAL 9.3 CVE-2026-59506 CWE-306: Missing Authentication for Critical Function No fix yet Fix from $5,7502026-08-13 CRITICAL 9.8 CVE-2026-49819 UpSnap is a wake on lan web app. Versions 4.4.1 through 5.3.5 are vulnerable to a missing-authentication / privilege-escalation chain in `pb.HandlerI… No fix yet Fix from $5,7502026-08-13 MEDIUM 5.3 CVE-2026-18673 When kuma-dp is configured with the Envoy admin API on a Unix domain socket, which is the default, its readiness service on TCP port 9902 - bound to … No fix yet Fix from $4,0002026-08-12 CRITICAL 9.4 CVE-2026-73296 Microsoft UFO open-source framework for intelligent automation across devices and platforms. Prior to 3.0.8, create_mobile_data_collection_server and… No fix yet Fix from $5,7502026-08-12 HIGH 8.8 CVE-2026-65941 In WhatsUp Gold versions released before 2026.0.2, an unauthenticated remote attacker with network access to the affected service can execute arbitra… No fix yet Fix from $4,9002026-08-12 HIGH 8.2 CVE-2026-19426 POS System developed by FitSoft has a Missing Authentication vulnerability. Unauthenticated remote attackers can directly access and operate the syst… No fix yet Fix from $4,9002026-08-12 MEDIUM 6.5 CVE-2026-73245 Kestra is an open-source, event-driven orchestration platform. Prior to 2.0.0-rc6, Kestra's cli/src/main/resources/application.yml serves Micronaut m… No fix yet Fix from $4,0002026-08-11 HIGH 7.5 CVE-2026-73246 Kestra is an open-source, event-driven orchestration platform. Prior to 2.0.0-rc6, Kestra's worker/src/main/java/io/kestra/worker/endpoint/WorkerEndp… No fix yet Fix from $4,9002026-08-11