Vulnerability index

Browse CVEs

2,866 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthenticationCWE-306 × clear
HIGH 7.6 CVE-2026-54317 Home Assistant is open source home automation software that puts local control and privacy first. Prior to 2026.6.0, the Konnected integration regist… Home Assistant 2026.6.0+ Fix from $1,9502026-06-23 CRITICAL 9.3 CVE-2026-55450EPSS 12% Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.1, unauthenticated users can upload any amount of data to… Langflow 1.9.1+ Fix from $2,3002026-06-23 HIGH 7.5 CVE-2026-13007 Tenable Identity Exposure contains multiple unauthenticated API endpoints under /w/api/* that expose sensitive application configuration data includi… Identity Exposure 3.93.5+ Fix from $1,9502026-06-23 CRITICAL 10.0 CVE-2026-54309 n8n is an open source workflow automation platform. Prior to 2.25.7 and 2.26.2, when @n8n/mcp-browser is run in HTTP transport mode, the MCP endpoint… N8n 2.25.7 / 2.26.2+ Fix from $2,3002026-06-23 CRITICAL 10.0 CVE-2026-27604 FOSSBilling is a free, open-source billing and client management system. Starting in version 0.5.4 and prior to version 0.8.0, an authorization bypas… Mitigation only Fix from $2,3002026-06-23 HIGH 8.8 CVE-2026-10711 Missing authentication for critical function vulnerability in AKIN Software Computer Import Export Industry and Trade Ltd. CafePlus allows Accessing … Mitigation only Fix from $1,9502026-06-23 MEDIUM 5.3 CVE-2026-56321 Capgo (backend Supabase edge functions) before 12.128.2 does not apply the global authentication middleware to the GET /private/role_bindings/:org_id… No fix yet Fix from $1,6002026-06-22 MEDIUM 5.5 CVE-2026-41047 Lack of authentication when using the "snapshot diff" functions in qSnapper before version 1.3.3 allowed a local attacker to see otherwise read prote… Qsnapper 1.3.3+ Fix from $1,6002026-06-22 MEDIUM 6.4 CVE-2026-6673 Mattermost versions 11.7.x <= 11.7.0, 11.6.x <= 11.6.2, 11.5.x <= 11.5.5, 10.11.x <= 10.11.17 fail to authenticate Atlassian Connect installed callba… Mattermost Server 10.11.18 / 11.5.6+ Fix from $1,6002026-06-22 MEDIUM 5.3 CVE-2026-56299 Capgo before 12.128.2 contains an authentication bypass vulnerability in the /build/upload/:jobId/* endpoint that allows unauthenticated attackers to… Mitigation only Fix from $1,6002026-06-21 HIGH 7.3 CVE-2026-12795 A vulnerability was determined in BerriAI litellm up to 1.82.2. This affects the function json.dumps of the file litellm/proxy/management_endpoints/u… Litellm after 1.82.2 Fix from $1,9502026-06-21 MEDIUM 6.5 CVE-2026-56346 AVideo through version 25.0 contains an authentication bypass vulnerability in the decryptMessage.json.php endpoint that allows unauthenticated users… Mitigation only Fix from $1,6002026-06-20 CRITICAL 9.1 CVE-2026-9142 There is an insecure default credentials vulnerability in NI grpc-device when TLS configuration is not present and the server is bound beyond loopbac… Instrumentstudio 2.18.0+ Fix from $2,3002026-06-19 HIGH 8.8 CVE-2026-49357 Line Desktop MCP is a project that, while unaffiliated with the official line-bot-mcp-server, allows users to directly operate the LINE Desktop appli… Patch available Fix from $1,9502026-06-19 CRITICAL 9.8 CVE-2026-50242 In JetBrains Hub before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 authentication bypass via direct data… Hub 2024.2.148429 / 2024.3.148430+ Fix from $2,3002026-06-19 CRITICAL 9.0 CVE-2026-12046 Two state-mutating endpoints in pgAdmin 4's SQL Editor blueprint -- DELETE /sqleditor/close/<trans_id> and POST /sqleditor/initialize/sqleditor/updat… Pgadmin 4 9.16+ Fix from $2,3002026-06-19 HIGH 7.5 CVE-2026-54130 Missing authentication for critical function in M365 Copilot allows an unauthorized attacker to disclose information over a network. 365 Copilot Mitigation only Fix from $1,9502026-06-18 CRITICAL 10.0 CVE-2026-49257 mcp-pinot is a Python-based Model Context Protocol (MCP) server for interacting with Apache Pinot. In versions 3.0.1 and below, mcp-pinot defaults to… Patch available Fix from $2,3002026-06-18 CRITICAL 9.8 CVE-2026-54103 The U.S. Government Accountability Office (GAO) Electronic Protest Docketing System (EPDS) and Civilian Board of Contract Appeals (CBCA) Electronic D… Mitigation only Fix from $2,3002026-06-18 MEDIUM 6.0 CVE-2026-12527 A broken authorization boundary in the RTSP media delivery pipeline of Shenzhen Liandian Communication Technology LTD V380 IP Camera firmware AppFHE1… Mitigation only Fix from $1,6002026-06-18 HIGH 8.9 CVE-2026-48989 Windows-MCP is an open-source project that integrates AI agents with Windows. In versions prior to 0.7.5, certain HTTP modes exposed the MCP control … Mitigation only Fix from $1,9502026-06-17 CRITICAL 9.1 CVE-2026-48814 Network-AI is a TypeScript/Node.js multi-agent orchestrator. In versions 5.7.1 and earlier, the MCP SSE server allows unauthenticated cross-origin MC… Mitigation only Fix from $2,3002026-06-17 CRITICAL 9.1 CVE-2026-55196 Hermes WebUI before 0.51.409 contains an authentication bypass vulnerability in passkey registration endpoints that allows unauthenticated remote att… Patch available Fix from $2,3002026-06-17 HIGH 7.5 CVE-2026-53869 Hermes Agent before 0.16.0 contains a DNS rebinding vulnerability in WebSocket endpoints that allows remote attackers to bypass Host and Origin valid… Patch available Fix from $1,9502026-06-17 HIGH 8.1 CVE-2026-30799 Missing Authentication for Critical Function vulnerability in RTI Connext Professional (Security Plugins) allows Identity Spoofing.This issue affects… Connext Professional 7.7.0+ Fix from $1,9502026-06-17 MEDIUM 6.5 CVE-2026-2675 Missing Authentication for Critical Function vulnerability in RTI Connext Professional (Security Plugins) allows Fake the Source of Data.This issue a… Connext Professional 7.7.0+ Fix from $1,6002026-06-17 HIGH 8.8 CVE-2026-35065 Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) a Missing Authentication for Critical Function vulnerability. An unauthenticated atta… Powerflex Manager 4.5.5.2 / 5.1.0.1+ Fix from $1,9502026-06-17 HIGH 7.5 CVE-2026-12199 A vulnerability in `nltk.app.wordnet_app` up to version 3.9.3 allows unauthenticated remote shutdown of the local WordNet Browser HTTP server when st… Mitigation only Fix from $1,9502026-06-17 HIGH 8.8 CVE-2026-46972 Vulnerability in the Oracle Outsourced Mfg for Discrete Industries product of Oracle E-Business Suite (component: Internal Operations). Supported ve… Outsourced Manufacturing For Discrete Industries after 12.2.15 Fix from $1,9502026-06-17 HIGH 8.8 CVE-2026-46973 Vulnerability in the Oracle Outsourced Mfg for Discrete Industries product of Oracle E-Business Suite (component: Internal Operations). Supported ve… Outsourced Manufacturing For Discrete Industries after 12.2.15 Fix from $1,9502026-06-17