Vulnerability index

Browse CVEs

2,866 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthenticationCWE-306 × clear
HIGH 8.8 CVE-2026-10054 In affected versions of Eclipse Theia (1.8.1 and later), the browser backend exposes privileged terminal RPC over WebSocket (/services/shell-terminal… Mitigation only Fix from $1,9502026-07-03 CRITICAL 9.8 CVE-2026-4767 Missing authentication for critical function vulnerability in TR7 Cyber ​​Defense Inc. WAF-ASP allows Authentication Abuse. This issue affects WAF-A… Mitigation only Fix from $2,3002026-07-02 HIGH 8.8 CVE-2026-13125 GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is an addon that can be installed with various GeoV… Mitigation only Fix from $1,9502026-07-02 CRITICAL 9.8 CVE-2026-58126 PACSgear PACS Scan 5.2.1 contains an unauthenticated remote code execution vulnerability that allows remote attackers to read and write arbitrary fil… Pacsgear after 5.2.1 Fix from $2,3002026-07-01 CRITICAL 9.8 CVE-2026-58127 PACSgear MediaWriter 5.2.1 exposes a .NET Remoting TCP service on port 9000 via PacsgearMediaServerEngine.dll, registered with ObjectURIs RemoteObj a… Pacsgear after 5.2.1 Fix from $2,3002026-07-01 HIGH 8.1 CVE-2026-56286 Capgo before 12.128.2 contains an authentication bypass vulnerability in the account deletion endpoint that allows deletion without password re-authe… Mitigation only Fix from $1,9502026-06-30 MEDIUM 6.5 CVE-2026-58446 Presenton before 0.8.8-beta bundles an MCP server that, on server/Docker deployments configured with session authentication (AUTH_USERNAME/AUTH_PASSW… Patch available Fix from $1,6002026-06-30 HIGH 7.5 CVE-2026-58375 JimuReport through 2.5.0 exposes the POST /jmreport/auto/export endpoint without authentication: the handler is annotated @JimuNoLoginRequired, so Ji… Mitigation only Fix from $1,9502026-06-30 HIGH 7.0 CVE-2026-44949 A Rancher FleetWorkspace admission path allowed side effects to occur in the Rancher webhook handler for versions 0.7.0 up to 0.7.10, 0.8.0 up to 0.… Mitigation only Fix from $1,9502026-06-30 CRITICAL 9.8 CVE-2026-14162 Hospital Queuing Management developed by Advantech has a Sensitive Data Exposure vulnerability, allowing unauthenticated remote attackers to access a… Mitigation only Fix from $2,3002026-06-30 CRITICAL 9.3 CVE-2026-12819 Delta Electronics DVP12SE PLC exposes a Modbus TCP service over a specified port without authentication or access control, permitting unauthenticated… Mitigation only Fix from $2,3002026-06-30 CRITICAL 9.8 CVE-2026-56782 Gorse before 0.5.10 contains an authentication bypass vulnerability in the /api/dump and /api/restore endpoints that allows unauthenticated attackers… Patch available Fix from $2,3002026-06-29 HIGH 7.3 CVE-2026-13546 A vulnerability was found in Feehi CMS up to 2.1.1. This vulnerability affects unknown code of the file /api/articles of the component REST API Endpo… Mitigation only Fix from $1,9502026-06-29 MEDIUM 5.3 CVE-2026-50136 Budibase is an open-source low-code platform. Prior to 3.39.3, the application server exposes an unauthenticated endpoint that generates S3 PutObject… Budibase 3.39.3+ Fix from $1,6002026-06-26 HIGH 8.5 CVE-2026-13325 A flaw was found in KubeVirt's migration proxy. When spec.configuration.migrations.disableTLS is set to true on the KubeVirt custom resource, the tar… Kubevirt after 4.22.0 Fix from $1,9502026-06-26 MEDIUM 6.9 CVE-2026-43920 FOSSBilling is a free, open-source billing and client management system. In versions 0.5.4 through 0.7.2, the /run-patcher maintenance endpoint in FO… Mitigation only Fix from $1,6002026-06-26 CRITICAL 9.4 CVE-2026-40702 WebSocket endpoints lack proper authentication mechanisms, enabling attackers to impersonate charging stations. As a result, attackers can exploit th… Mitigation only Fix from $2,3002026-06-25 CRITICAL 9.1 CVE-2025-71327 Flowise contains an authentication bypass vulnerability in the unprotected /api/v1/account/register endpoint that allows unauthenticated attackers to… Flowise No fix yet Fix from $2,3002026-06-25 CRITICAL 9.3 CVE-2026-54088 File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.6… Mitigation only Fix from $2,3002026-06-25 HIGH 7.1 CVE-2026-54040 LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. Prior to 0.8.4-rc1, the POST /api/auth/2fa/backup/regenerate endpoint reg… Librechat after 0.8.3 Fix from $1,9502026-06-25 HIGH 8.1 CVE-2026-54036 LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. Prior to 0.8.4-rc1, the GET /api/auth/2fa/enable endpoint can be called b… Librechat after 0.8.3 Fix from $1,9502026-06-25 MEDIUM 6.7 CVE-2026-4522 Missing authentication for critical function vulnerability in HYPR Passwordless on Windows allows Credentials Interception. This issue affects HYPR … Mitigation only Fix from $1,6002026-06-25 HIGH 7.5 CVE-2026-12490 When a provide-xfr is given with a tls-auth-name, a secondary requesting a transfer should provide a client certificate with that name. However, no c… Nsd 4.14.3+ Fix from $1,9502026-06-25 MEDIUM 5.9 CVE-2026-54068 SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, the /api/icon/getDynamicIcon endpoint is explicitly excluded from auth… Mitigation only Fix from $1,6002026-06-24 CRITICAL 9.3 CVE-2026-33543 FOSSBilling is a free, open-source billing and client management system. Versions 0.7.2 and prior expose a guest API endpoint, /api/guest/staff/creat… Mitigation only Fix from $2,3002026-06-24 HIGH 7.5 CVE-2026-1840 The Aclara Metrum Cellular Web Interface is vulnerable to unauthorized access due to the absence of authentication controls on critical system functi… Mitigation only Fix from $1,9502026-06-24 CRITICAL 9.8 CVE-2026-49980 Rclone is a command-line program to sync files and directories to and from different cloud storage providers. From 1.46.0 until 1.74.3, rclone rcd --… Rclone 1.74.3+ Fix from $2,3002026-06-24 HIGH 8.8 CVE-2026-13164 Missing Authentication for Critical Function (CWE-306) in the RegisterView (apps/accounts/views.py), exposed at POST /api/auth/register/, in MailerUp… Patch available Fix from $1,9502026-06-24 MEDIUM 6.5 CVE-2026-56262 Crawl4AI before 0.8.7 contains an authentication bypass vulnerability in the monitor router endpoints that allows unauthenticated attackers to access… Crawl4ai 0.8.7+ Fix from $1,6002026-06-24 HIGH 7.5 CVE-2026-56270 Flowise before 3.1.0 (versions 3.0.13 and earlier) contains a missing authentication vulnerability in the /api/v1/loginmethod endpoint that allows un… Flowise 3.1.0+ Fix from $1,9502026-06-24