Vulnerability index

Browse CVEs

2,855 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthenticationCWE-306 × clear
MEDIUM 5.3 CVE-2026-47212 Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 6.4.40, 7.4.12, and 8.0.12, TwilioRequestP… Symfony 6.4.40 / 7.4.12+ Fix from $1,6002026-07-14 MEDIUM 5.3 CVE-2026-45754 Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 6.4.40, 7.4.12, and 8.0.12, the Mailjet ma… Symfony 6.4.40 / 7.4.12+ Fix from $1,6002026-07-14 MEDIUM 5.3 CVE-2026-45755 Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 7.4.12 and 8.0.12, MailtrapRequestParser::… Symfony 7.4.12 / 8.0.12+ Fix from $1,6002026-07-14 HIGH 7.8 CVE-2026-50451 Missing authentication for critical function in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges … Windows 10 1607 10.0.14393.9339 / 10.0.17763.9020+ Fix from $1,9502026-07-14 HIGH 8.8 CVE-2026-50444 Missing authentication for critical function in Windows Server Update Service allows an authorized attacker to elevate privileges over a network. Windows 10 1607 10.0.14393.9339 / 10.0.17763.9020+ Fix from $1,9502026-07-14 HIGH 8.8 CVE-2026-57969 Missing authentication for critical function in Azure CycleCloud allows an authorized attacker to elevate privileges over a network. Azure Cyclecloud 8.9.1+ Fix from $1,9502026-07-14 CRITICAL 9.8 CVE-2026-56164 KEVEPSS 22% Missing authentication for critical function in Microsoft Office SharePoint allows an unauthorized attacker to elevate privileges over a network. Sharepoint Server 16.0.19725.20434+ Fix from $2,3002026-07-14 HIGH 7.8 CVE-2026-50333 Missing authentication for critical function in Windows Spaceport.sys allows an authorized attacker to elevate privileges locally. Windows 10 1607 10.0.14393.9339 / 10.0.17763.9020+ Fix from $1,9502026-07-14 MEDIUM 6.1 CVE-2026-49174 Missing authentication for critical function in Microsoft Windows DNS allows an authorized attacker to perform tampering locally. Windows 10 1809 10.0.17763.9020 / 10.0.19044.7548+ Fix from $1,6002026-07-14 CRITICAL 10.0 CVE-2026-10577 A security issue exists within the 1715-AENTR EtherNet/IP Adapter. The affected product exposes a network-accessible debug port that does not enforce… Mitigation only Fix from $2,3002026-07-14 CRITICAL 9.8 CVE-2026-62422 In JetBrains YouTrack before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 authentication bypass via direct… Youtrack 2024.2.148429 / 2024.3.148430+ Fix from $2,3002026-07-14 CRITICAL 9.1 CVE-2026-58319 Certain Apache Doris FE HTTP REST administrative APIs were accessible without proper authentication. An unauthenticated attacker with network access … Doris 3.1.0+ Fix from $2,3002026-07-14 HIGH 8.9 CVE-2026-15416 A flaw was identified in Argo CD, the GitOps engine used by Red Hat OpenShift GitOps, that could allow an unauthenticated attacker with network acces… Patch available Fix from $1,9502026-07-14 CRITICAL 9.1 CVE-2026-62327 9Router through version 0.4.41 contains an unauthenticated information disclosure vulnerability that allows remote attackers to retrieve plaintext AP… Mitigation only Fix from $2,3002026-07-13 CRITICAL 9.8 CVE-2026-59801 9Router through version 0.4.41 contains an unauthenticated access vulnerability that allows remote attackers to interact with provider management API… Mitigation only Fix from $2,3002026-07-13 CRITICAL 9.3 CVE-2026-6847 Remote Code Execution vulnerability exists in ThemisNETPanel due to missing authentication for a critical file upload function. The application expos… Mitigation only Fix from $2,3002026-07-13 CRITICAL 9.3 CVE-2026-22096 The webserver running on port 8090 does not require authentication. This allows for sensitive information leakage such as configured passwords, or up… Mitigation only Fix from $2,3002026-07-13 HIGH 7.3 CVE-2026-15491 A weakness has been identified in RafyMrX TOKO-ONLINE-ROTI up to ddfe1cd587be0a0b5135d8b6e85cce2ec3aece99. This affects an unknown part. This manipul… No fix yet Fix from $1,9502026-07-12 CRITICAL 9.2 CVE-2026-55884 Tilt defines dev environments as code for microservice apps on Kubernetes. From 0.20.8 through 0.37.3, the Tilt HUD HTTP server registers handlers on… Patch available Fix from $2,3002026-07-10 MEDIUM 5.3 CVE-2026-57475 Deloitte AI Assist for Customer accepted unauthenticated POST requests through public-facing API endpoints that allowed a remote attacker to make lim… Ai Assist For Customer 2026-03-25+ Fix from $1,6002026-07-10 HIGH 8.3 CVE-2026-56675 9Router is an AI router & token saver. Prior to 0.5.2, 9router treats loopback requests as trusted and allows /v1/* access without an API key, so a s… Patch available Fix from $1,9502026-07-10 HIGH 7.5 CVE-2026-38059 The iDirect iQ200 exposes the /api/identity and /api/ REST API endpoints without authentication. An unauthenticated attacker with network access can … Mitigation only Fix from $1,9502026-07-10 HIGH 7.5 CVE-2026-40006 Memory Allocation with Excessive Size Value, Allocation of Resources Without Limits or Throttling, Missing Authentication for Critical Function vulne… Mitigation only Fix from $1,9502026-07-10 CRITICAL 9.8 CVE-2026-58123 Hermes WebUI before 0.51.788 contains an unauthenticated remote code execution vulnerability that allows remote attackers to execute arbitrary shell … Patch available Fix from $2,3002026-07-09 MEDIUM 5.3 CVE-2026-55605 DeepSeek MCP Server is an MCP server for DeepSeek V4. Starting in version 1.4.2 and prior to version 1.8.0, the self-hosted HTTP transport of `@ariku… Mitigation only Fix from $1,6002026-07-09 HIGH 8.8 CVE-2026-59148 Mockoon provides way to design and run mock APIs. Prior to 9.7.0, Mockoon's admin API in commons-server/src/libs/server/admin-api.ts is mounted on th… Patch available Fix from $1,9502026-07-09 HIGH 7.2 CVE-2026-0283 An authentication bypass vulnerability in Large Scale VPN ( LSVPN) functionality of Palo Alto Networks PAN-OS software allows an attacker with networ… Pan Os 10.2.7 / 10.2.10+ Fix from $1,9502026-07-09 MEDIUM 5.3 CVE-2026-61344 The Superior Court of California Hearing Reminder Service at https://www.hrs.courts.ca.gov exposes an API endpoint that returns court reminder record… Mitigation only Fix from $1,6002026-07-09 CRITICAL 10.0 CVE-2026-59726 Ruflo is an agent meta-harness for Claude Code and Codex. Prior to 3.16.3, ruflo's default docker-compose deployment exposed the MCP bridge POST /mcp… Patch available Fix from $2,3002026-07-09 MEDIUM 6.5 CVE-2026-59715 Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.6.16 before 0.10.0, the Socket.IO server is configured w… Open Webui 0.10.0+ Fix from $1,6002026-07-09