Vulnerability index

Browse CVEs

2,866 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthenticationCWE-306 × clear
MEDIUM 5.3 CVE-2026-57475 Deloitte AI Assist for Customer accepted unauthenticated POST requests through public-facing API endpoints that allowed a remote attacker to make lim… Ai Assist For Customer 2026-03-25+ Fix from $1,6002026-07-10 HIGH 8.3 CVE-2026-56675 9Router is an AI router & token saver. Prior to 0.5.2, 9router treats loopback requests as trusted and allows /v1/* access without an API key, so a s… Patch available Fix from $1,9502026-07-10 HIGH 7.5 CVE-2026-38059 The iDirect iQ200 exposes the /api/identity and /api/ REST API endpoints without authentication. An unauthenticated attacker with network access can … Mitigation only Fix from $1,9502026-07-10 HIGH 7.5 CVE-2026-40006 Memory Allocation with Excessive Size Value, Allocation of Resources Without Limits or Throttling, Missing Authentication for Critical Function vulne… Mitigation only Fix from $1,9502026-07-10 CRITICAL 9.8 CVE-2026-58123 Hermes WebUI before 0.51.788 contains an unauthenticated remote code execution vulnerability that allows remote attackers to execute arbitrary shell … Patch available Fix from $2,3002026-07-09 MEDIUM 5.3 CVE-2026-55605 DeepSeek MCP Server is an MCP server for DeepSeek V4. Starting in version 1.4.2 and prior to version 1.8.0, the self-hosted HTTP transport of `@ariku… Mitigation only Fix from $1,6002026-07-09 HIGH 8.8 CVE-2026-59148 Mockoon provides way to design and run mock APIs. Prior to 9.7.0, Mockoon's admin API in commons-server/src/libs/server/admin-api.ts is mounted on th… Patch available Fix from $1,9502026-07-09 HIGH 7.2 CVE-2026-0283 An authentication bypass vulnerability in Large Scale VPN ( LSVPN) functionality of Palo Alto Networks PAN-OS software allows an attacker with networ… Pan Os 10.2.7 / 10.2.10+ Fix from $1,9502026-07-09 MEDIUM 5.3 CVE-2026-61344 The Superior Court of California Hearing Reminder Service at https://www.hrs.courts.ca.gov exposes an API endpoint that returns court reminder record… Mitigation only Fix from $1,6002026-07-09 CRITICAL 10.0 CVE-2026-59726 Ruflo is an agent meta-harness for Claude Code and Codex. Prior to 3.16.3, ruflo's default docker-compose deployment exposed the MCP bridge POST /mcp… Patch available Fix from $2,3002026-07-09 MEDIUM 6.5 CVE-2026-59715 Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.6.16 before 0.10.0, the Socket.IO server is configured w… Open Webui 0.10.0+ Fix from $1,6002026-07-09 MEDIUM 6.5 CVE-2026-15192 A vulnerability has been found in mettle sendportal up to 3.0.1. This issue affects the function sendgrid/postmark/postal/mailjet of the component AP… Mitigation only Fix from $1,6002026-07-09 MEDIUM 5.3 CVE-2026-31983 A Missing Authentication vulnerability was discovered in the SSH keys synchronization endpoint. An unauthenticated attacker can send a request to the… Cmc 26.2.0+ Fix from $1,6002026-07-09 HIGH 7.5 CVE-2026-44025 Fluentd collects events from various data sources and writes them to files, RDBMS, NoSQL, IaaS, SaaS, Hadoop and so on. Prior to 1.19.3, Fluentd's Mo… Fluentd 1.19.3+ Fix from $1,9502026-07-08 HIGH 8.2 CVE-2026-59822 LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.84.0, LiteLLM's MCP Streamable HTTP endpoint allowed… Litellm 1.84.0+ Fix from $1,9502026-07-08 MEDIUM 6.8 CVE-2026-59804 Midscene Bridge Server through 1.10.3, fixed in commit 86f4118, contains a missing authentication and CORS misconfiguration vulnerability that allows… Patch available Fix from $1,6002026-07-08 MEDIUM 6.3 CVE-2026-15063 A flaw was found in the gorch service template, which is part of the trustyai-service-operator. Even when authentication is enabled, the gorch servic… Mitigation only Fix from $1,6002026-07-08 CRITICAL 9.1 CVE-2026-54061 Dgraph is an open source distributed GraphQL database. Prior to version 25.3.5, Dgraph Alpha exposes the RPCs used for external snapshot import on th… Mitigation only Fix from $2,3002026-07-08 HIGH 7.5 CVE-2026-51937 An issue in Oneblog V2.3.9 allows a remote attacker to obtain sensitive information via the RestApiController.java, JsApiTicketComponent.java, and th… Mitigation only Fix from $1,9502026-07-07 CRITICAL 9.8 CVE-2026-59705 mem0's openmemory/api component contains an unauthenticated access vulnerability that allows unauthenticated attackers to read, write, and delete arb… Patch available Fix from $2,3002026-07-07 CRITICAL 9.3 CVE-2026-59706 mem0 contains unauthenticated config API endpoints that expose LLM API keys in plaintext and allow server-side request forgery via attacker-controlle… Patch available Fix from $2,3002026-07-07 CRITICAL 9.1 CVE-2026-58473 Cognee before 1.2.0 contains an improper access control vulnerability that allows unauthenticated attackers to overwrite the global LLM provider conf… Patch available Fix from $2,3002026-07-07 HIGH 8.3 CVE-2026-49471 Serena is a powerful MCP toolkit for coding that provides semantic retrieval and editing capabilities. Prior to v1.5.2, Serena's built-in web dashboa… Serena 1.5.2+ Fix from $1,9502026-07-07 MEDIUM 6.9 CVE-2026-53647 FOSSBilling is a free, open-source billing and client management system. In versions 0.5.3 through 0.7.2, the Guest `serviceapikey/get_info` API endp… Mitigation only Fix from $1,6002026-07-07 MEDIUM 6.5 CVE-2026-41899 Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.474, POST /api/feedback has n… Patch available Fix from $1,6002026-07-06 HIGH 7.7 CVE-2026-42331 FOSSBilling is a free, open-source billing and client management system. Prior to version 0.8.0, the Guest API invoice/update endpoint is missing an … Mitigation only Fix from $1,9502026-07-06 CRITICAL 9.2 CVE-2026-42341 FOSSBilling is a free, open-source billing and client management system. Versions 0.6.0 through 0.7.2 have an unauthenticated payment bypass vulnerab… Mitigation only Fix from $2,3002026-07-06 CRITICAL 9.8 CVE-2026-53913 Improper Authentication, Missing Authentication for Critical Function, Not Failing Securely ('Failing Open') vulnerability in Apache Camel Keycloak C… Camel 4.18.3 / 4.21.0+ Fix from $2,3002026-07-06 MEDIUM 6.5 CVE-2026-14714 A weakness has been identified in zhayujie chatgpt-on-wechat CowAgent 2.1.0. This issue affects the function verify_server of the file channel/wechat… Patch available Fix from $1,6002026-07-05 HIGH 7.3 CVE-2026-14622 A vulnerability was found in jairiidriss restaurant-website-php-mysql up to 521428b5b612449df0cf4a5d15ee40cba67f3d35. This vulnerability affects unkn… Mitigation only Fix from $1,9502026-07-04