Vulnerability index

Browse CVEs

2,855 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthenticationCWE-306 × clear
CRITICAL 9.8 CVE-2026-47391 PraisonAI is a multi-agent teams system. Prior to version 4.6.40, PraisonAI's first-party A2A server example exposes an unauthenticated A2A JSON-RPC … Patch available Fix from $2,3002026-07-21 HIGH 8.2 CVE-2026-57495 AgenticMail gives AI agents real email addresses and phone numbers. In @agenticmail/claudecode prior to version 0.2.39, @agenticmail/codex prior to v… Mitigation only Fix from $1,9502026-07-20 HIGH 7.3 CVE-2026-55626 xrdp is an open source RDP server. In versions 0.10.6 and prior, when an authenticated user session is initialized using the Xvnc backend over UNIX d… Xrdp 0.10.6.1+ Fix from $1,9502026-07-20 HIGH 7.1 CVE-2026-46555 WhatsApp MCP Server is a Model Context Protocol (MCP) server for WhatsApp, enabling Claude to read and send WhatsApp messages. Prior to version 0.2.1… Whatsapp Mcp Server Fix available Fix from $1,9502026-07-20 HIGH 8.6 CVE-2026-63429 HeyForm is an open-source form builder. Prior to version 3.0.0-rc.9, `POST /api/upload` has no authentication guard, no global guard, no form-context… Patch available Fix from $1,9502026-07-20 HIGH 8.8 CVE-2026-63757 SurrealDB versions before 3.1.0 contain a session hijacking vulnerability where the HTTP /rpc sessions method returns attached session UUIDs without … Surrealdb 3.1.0+ Fix from $1,9502026-07-20 CRITICAL 9.4 CVE-2026-16242 A flaw was found in the Konnectivity proxy-server configuration for hosted control planes. The agent-facing listener was started without --cluster-ca… Patch available Fix from $2,3002026-07-20 HIGH 7.3 CVE-2026-16210 A vulnerability was found in newpanjing simpleui 2026.01.13. This affects the function self.get_action of the file simpleui/admin.py of the component… No fix yet Fix from $1,9502026-07-19 HIGH 7.3 CVE-2026-16209 A vulnerability has been found in Gerapy up to 0.9.13. The impacted element is an unknown function of the file gerapy/server/core/views.py of the com… Patch available Fix from $1,9502026-07-19 CRITICAL 9.8 CVE-2026-8505 IBM Langflow OSS 1.0.0 through 1.10.0 has a vulnerability in Langflow's webhook authentication logic allows unauthenticated users to trigger the exec… Langflow 1.10.1+ Fix from $2,3002026-07-17 CRITICAL 9.8 CVE-2026-9103 IBM Langflow OSS 1.0.0 through 1.10.0 could allow a remote attacker to gain unauthorized access due to improper authentication in the /api/v1/login/a… Langflow 1.10.1+ Fix from $2,3002026-07-17 CRITICAL 9.8 CVE-2026-9202 IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to create unlimited user accounts on any Langflow instance; when NEW_USER_IS_A… Langflow 1.10.1+ Fix from $2,3002026-07-17 HIGH 7.5 CVE-2026-63101 Open Event Server through 1.19.1 contains a missing authentication vulnerability that allows unauthenticated attackers to export the complete member … No fix yet Fix from $1,9502026-07-17 HIGH 7.5 CVE-2026-12691 Missing authentication for critical function vulnerability in Vimesoft Inc. Enterprise Video Platform allows Authentication Bypass. This issue affec… No fix yet Fix from $1,9502026-07-17 MEDIUM 5.3 CVE-2026-63098 TheHive through 4.1.24 contains an unauthenticated information disclosure vulnerability that allows unauthenticated attackers to retrieve sensitive c… Thehive after 4.1.24 Fix from $1,6002026-07-17 MEDIUM 6.3 CVE-2026-16015 A vulnerability was determined in poco-ai poco-claw up to 0.5.4. This vulnerability affects the function create_task of the file executor_manager/app… Patch available Fix from $1,6002026-07-17 CRITICAL 9.1 CVE-2026-62241EPSS 7% clawvet self-hosted API server (apps/api) before 0.7.5 hard-codes a fallback JWT secret ('clawvet-dev-secret-change-me') in auth.ts and ships it as t… Clawvet 0.7.5+ Fix from $2,3002026-07-17 HIGH 7.1 CVE-2024-34268 EQ-3 Eqiva CC-RT-BLE Bluetooth Smart Radiator Thermostat Firmware up to the latest version 1.46 was discovered to allow unsecured bluetooth connectio… No fix yet Fix from $1,9502026-07-16 CRITICAL 9.8 CVE-2026-63087 Grafana OnCall through 1.16.11 contains an unauthenticated access vulnerability that allows remote attackers to obtain a valid PluginAuthToken by sen… No fix yet Fix from $2,3002026-07-16 MEDIUM 5.5 CVE-2026-6511 During an internal security assessment, a potential improper access control vulnerability was discovered in Lenovo Smart Connect for Windows that cou… No fix yet Fix from $1,6002026-07-16 HIGH 8.6 CVE-2026-57206 SimpleChat is a secure AI conversation application with personal and group workspaces for document-grounded interactions. Prior to 0.241.206, several… No fix yet Fix from $1,9502026-07-16 CRITICAL 9.8 CVE-2026-45695 Kopia is a cross-platform backup tool for Windows, macOS, and Linux with fast incremental backups, client-side end-to-end encryption, compression, an… Patch available Fix from $2,3002026-07-16 CRITICAL 10.0 CVE-2026-46339 9Router is an AI router & token saver. From 0.4.30 until 0.4.37, 9Router's src/proxy.js middleware did not protect /api/cli-tools/* and /api/mcp/*, a… Patch available Fix from $2,3002026-07-15 HIGH 8.2 CVE-2026-58658 GPUStack through 2.2.1, fixed in commit 4e20551, contains an unauthenticated information disclosure vulnerability that allows unauthenticated attacke… Patch available Fix from $1,9502026-07-15 CRITICAL 9.1 CVE-2026-53512 Better Auth is an authentication and authorization library for TypeScript. Prior to 1.6.11, the legacy oidcProvider and mcp plugins expose OAuth toke… Better Auth 1.6.11+ Fix from $2,3002026-07-15 HIGH 7.7 CVE-2026-61613 Cursor is a code editor built for programming with AI. Prior to the Cloud Agent fix on 03/31/2026, browser-enabled Cursor Cloud Agent sessions allowe… Mitigation only Fix from $1,9502026-07-15 CRITICAL 9.3 CVE-2026-48325 ColdFusion is affected by a Missing Authentication for Critical Function vulnerability that could result in arbitrary code execution in the context o… Coldfusion Mitigation only Fix from $2,3002026-07-14 HIGH 7.3 CVE-2026-24229 NVIDIA TensorRT-LLM for Linux contains a vulnerability in the disaggregated orchestrator component, where an attacker could read, write, or delete in… Mitigation only Fix from $1,9502026-07-14 MEDIUM 6.4 CVE-2026-24259 NVIDIA TensorRT-LLM for Linux contains a vulnerability where an attacker could cause missing authentication for a critical function. A successful exp… Mitigation only Fix from $1,6002026-07-14 HIGH 8.6 CVE-2026-48252 Adobe Experience Manager is affected by a Missing Authentication for Critical Function vulnerability that could result in a Security feature bypass. … Experience Manager after 2020.5.0 Fix from $1,9502026-07-14