Vulnerability index

Browse CVEs

2,855 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthenticationCWE-306 × clear
HIGH 8.8 CVE-2026-66875 In the Mira hormone monitor device firmware v1.7.1.47 build 01070147, a remote unauthenticated attacker within BLE range (approximately 10–30 meters)… No fix yet Fix from $4,9002026-08-11 MEDIUM 6.5 CVE-2026-66098 The Mira hormone monitor device firmware accepts a 0x01 write from any BLE central without authentication, causing the device to reboot into bootload… No fix yet Fix from $4,0002026-08-11 HIGH 8.8 CVE-2026-73222 Claude Code Templates is a CLI tool for configuring and monitoring Claude Code. Prior to 1.29.4, the Claude Code Studio server launched by the --stud… No fix yet Fix from $4,9002026-08-11 HIGH 8.8 CVE-2026-64921 Missing authentication for critical function in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network. Sharepoint Server 16.0.19725.20522+ Fix from $4,9002026-08-11 HIGH 7.8 CVE-2026-62777 Missing authentication for critical function in Windows License Manager allows an authorized attacker to elevate privileges locally. Windows 10 1607 10.0.14393.9418 / 10.0.17763.9115+ Fix from $4,9002026-08-11 HIGH 7.8 CVE-2026-61367 Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally. Windows 10 1607 10.0.14393.9418 / 10.0.17763.9115+ Fix from $4,9002026-08-11 HIGH 7.8 CVE-2026-61364 Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally. Windows 10 1607 10.0.14393.9418 / 10.0.17763.9115+ Fix from $4,9002026-08-11 HIGH 7.8 CVE-2026-61365 Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally. Windows 10 1607 10.0.14393.9418 / 10.0.17763.9115+ Fix from $4,9002026-08-11 HIGH 7.8 CVE-2026-61356 Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally. Windows 10 1809 10.0.17763.9115 / 10.0.19044.7663+ Fix from $4,9002026-08-11 CRITICAL 9.4 CVE-2026-50516 Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a netwo… Azure Kubernetes Service No fix yet Fix from $5,7502026-08-11 HIGH 7.8 CVE-2026-42976 Missing authentication for critical function in Windows RPC API allows an authorized attacker to elevate privileges locally. Windows 10 1607 10.0.14393.9418 / 10.0.17763.9115+ Fix from $4,9002026-08-11 CRITICAL 9.8 CVE-2026-72920 SeaweedFS is a distributed storage system. Prior to 4.24, the filer registers the SeaweedIdentityAccessManagement gRPC service without mandatory auth… No fix yet Fix from $5,7502026-08-11 CRITICAL 9.1 CVE-2026-72748 AVideo contains an unauthenticated arbitrary file write vulnerability in the aVideoEncoderChunk.json.php endpoint that allows remote attackers to wri… No fix yet Fix from $5,7502026-08-11 CRITICAL 10.0 CVE-2026-58115 A vulnerability has been identified in SIMATIC IoT2050 Advanced (6ES7647-0BA00-1YA2) (All versions < V4.3.4.1 running Industrial OS with Node-RED ins… No fix yet Fix from $5,7502026-08-11 HIGH 7.5 CVE-2026-72605 A missing authentication vulnerability in Swing Music 3.0.0 allows unauthenticated remote attackers to create arbitrary user accounts via the POST /a… No fix yet Fix from $4,9002026-08-11 MEDIUM 6.5 CVE-2026-72541 A missing authorization vulnerability in Windmill Labs Windmill through 1.783.0 allows any authenticated workspace member to overwrite any resource t… No fix yet Fix from $4,0002026-08-11 MEDIUM 5.4 CVE-2026-72542 A missing authorization vulnerability in Windmill Labs Windmill through 1.783.0 allows authenticated operators to write job progress and read job met… No fix yet Fix from $4,0002026-08-11 HIGH 8.6 CVE-2026-72535 A missing authentication vulnerability in Chaskiq through commit 46dfdd1 allows unauthenticated remote attackers to mint Stripe Billing Portal sessio… No fix yet Fix from $4,9002026-08-11 HIGH 8.6 CVE-2026-72536 A missing authentication vulnerability in Chaskiq through commit 46dfdd1 allows unauthenticated remote attackers to manipulate any tenant Stripe subs… No fix yet Fix from $4,9002026-08-11 HIGH 7.4 CVE-2026-15563 A flaw was found in EAP's IIOP. The listener's NameService would accept bind operations without authentication, allowing an attacker to hijack JNDI l… No fix yet Fix from $4,9002026-08-11 HIGH 7.7 CVE-2026-18941 A flaw was found in Feast and feast-operator. The default configuration for both the Feast SDK and the feast-operator is "no_auth," meaning no securi… No fix yet Fix from $4,9002026-08-10 HIGH 8.0 CVE-2026-15581 A flaw was found in the TrustyAI Service (TAS) deployment. This vulnerability allows any pod on the cluster network to bypass authentication and dire… No fix yet Fix from $4,9002026-08-10 CRITICAL 9.2 CVE-2025-15681 TBEA TLogger V2.1.0.0B0.0.0.0 contains an authentication bypass in its web server. After a user has previously authenticated to the device, an unauth… No fix yet Fix from $5,7502026-08-10 HIGH 8.8 CVE-2025-15683 TBEA TLogger V2.1.0.0B0.0.0.0 contains multiple unauthenticated denial-of-service vulnerabilities in its web server. An unauthenticated remote attack… No fix yet Fix from $4,9002026-08-10 HIGH 7.5 CVE-2026-72871 Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the unauthenticated /api/providers/github/setup route in apps/dokplo… No fix yet Fix from $4,9002026-08-10 HIGH 7.5 CVE-2026-72688 A missing authentication vulnerability in OpenSignLabs opensignserver through 2.37.0 allows an unauthenticated remote attacker to read arbitrary stor… No fix yet Fix from $4,9002026-08-10 CRITICAL 9.8 CVE-2026-72593 A missing authentication vulnerability in dulldusk/phpfm through 1.8.0 allows an unauthenticated remote attacker to access the full file manager func… No fix yet Fix from $5,7502026-08-10 HIGH 7.5 CVE-2026-72586 A missing authentication vulnerability in frangoteam/FUXA through 1.3.3 allows an unauthenticated remote attacker to query all historical sensor data… No fix yet Fix from $4,9002026-08-10 CRITICAL 9.8 CVE-2026-72577 Multiple vulnerabilities in NASA fprime-gds through 3.4.3 allow an unauthenticated remote attacker to achieve arbitrary code execution on the ground … No fix yet Fix from $5,7502026-08-10 HIGH 7.5 CVE-2026-55814 Missing Authentication in Apache Ranger Download APIs on versions <= 2.8.0. Users are recommended to upgrade to version 2.9.0, which fixes this issue. Ranger No fix yet Fix from $4,9002026-08-10