Vulnerability index

Browse CVEs

2,866 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthenticationCWE-306 × clear
HIGH 8.1 CVE-2026-35276 Vulnerability in the PeopleSoft Enterprise PT PeopleTools product of Oracle PeopleSoft (component: Application Server). Supported versions that are … Peoplesoft Enterprise Pt Peopletools Mitigation only Fix from $1,9502026-06-17 HIGH 8.8 CVE-2026-35265 Vulnerability in the Identity Manager product of Oracle Fusion Middleware (component: Security). Supported versions that are affected are 12.2.1.4.0… Identity Manager Mitigation only Fix from $1,9502026-06-17 HIGH 8.8 CVE-2026-35267 Vulnerability in the Identity Manager product of Oracle Fusion Middleware (component: REST WebServices). Supported versions that are affected are 12… Identity Manager Mitigation only Fix from $1,9502026-06-17 HIGH 8.8 CVE-2026-0647 An improper authentication security issue exists within the 1794-AENTR adapter's embedded web server. The vulnerability allows an unauthenticated att… Mitigation only Fix from $1,9502026-06-16 HIGH 7.5 CVE-2018-25437 WordPress CherryFramework Themes 3.1.4 contains an information disclosure vulnerability that allows unauthenticated attackers to download sensitive b… No fix yet Fix from $1,9502026-06-15 CRITICAL 9.8 CVE-2026-12183 Nefteprodukttekhnika BUK TS-G Gas Station Automation System 2.9.1 through 2.10.2 on Linux contains an Improper Authentication vulnerability (CWE-287)… Mitigation only Fix from $2,3002026-06-13 HIGH 7.5 CVE-2026-53868 Capgo before 12.128.2 contains a denial of service vulnerability allowing attackers to register accounts using arbitrary email addresses without veri… Mitigation only Fix from $1,9502026-06-12 HIGH 8.7 CVE-2026-50287 AgenticMail gives AI agents real email addresses and phone numbers. Prior to version 0.9.27, @agenticmail/mcp exposes a Streamable HTTP transport whe… Mitigation only Fix from $1,9502026-06-12 HIGH 7.6 CVE-2026-53981 Cap-go prior to 12.128.2 contains an account takeover vulnerability in its email change mechanism that allows an attacker with temporary authenticate… Patch available Fix from $1,9502026-06-12 CRITICAL 9.8 CVE-2026-50085 The Aqara Board service (op-test.aqara.com) accepts arbitrary MQTT command payloads, and forwards them to the platfom's HiveMQ broker without authent… Board Service Mitigation only Fix from $2,3002026-06-12 MEDIUM 5.3 CVE-2026-50082 The Aqara Cloud Developer Portal (developer.aqara.com) issued a developer token to any email address supplied by the attacker. This is an instance of… Cloud Developer Portal No fix yet Fix from $1,6002026-06-12 MEDIUM 5.3 CVE-2026-8694 Improper access control in Devolutions PowerShell Universal 2026.1.7 and earlier allows an unauthenticated remote attacker to obtain the OpenAPI spec… Powershell Universal 2026.1.7+ Fix from $1,6002026-06-12 MEDIUM 5.3 CVE-2026-11848 The iRM-IEI Remote Management developed by IEI Integration Corp has a Missing Authentication vulnerability, allowing unauthenticated remote attackers… Mitigation only Fix from $1,6002026-06-12 CRITICAL 9.4 CVE-2026-11535 An unauthorized access vulnerability exists in the PcSuite APP. The vulnerability can be exploited by attackers to Unauthorized access to the victim’… No fix yet Fix from $2,3002026-06-12 HIGH 7.7 CVE-2026-50245 Brickcom cameras allow unauthenticated access to live snapshot images via the /ONVIF endpoint and no authentication is required to retrieve still ima… Mitigation only Fix from $1,9502026-06-11 CRITICAL 9.4 CVE-2026-49973 Hermes WebUI before version 0.51.358 contains an improper access control vulnerability that allows unauthenticated remote attackers to hijack initial… Patch available Fix from $2,3002026-06-11 CRITICAL 9.8 CVE-2026-35273 KEVEPSS 95% Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Updates Environment Management). Supported versions t… Peoplesoft Enterprise Peopletools Mitigation only Fix from $2,3002026-06-11 HIGH 8.8 CVE-2026-46612 Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior t… Patch available Fix from $1,9502026-06-10 CRITICAL 9.8 CVE-2026-20253 KEVEPSS 97% In Splunk Enterprise 10.2 versions below 10.2.4 and 10 versions below 10.0.7, an unauthenticated user could create or truncate arbitrary files throug… Splunk 10.0.7 / 10.2.4+ Fix from $2,3002026-06-10 HIGH 8.3 CVE-2026-45567 Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, there is an authentication bypa… Mitigation only Fix from $1,9502026-06-10 HIGH 7.8 CVE-2026-9045 During an internal security assessment, a potential vulnerability was discovered in Lenovo Accessories and Display Manager for Enterprise for Windows… Mitigation only Fix from $1,9502026-06-10 HIGH 7.1 CVE-2026-8335 A missing authentication check on the Aix‑DB "/llm/process_llm_out" endpoint allows unauthenticated clients to execute arbitrary "SELECT" SQL queries… Mitigation only Fix from $1,9502026-06-10 HIGH 8.1 CVE-2026-53469 A flaw was found in migration-planner. An authenticated user can exploit this vulnerability by sending a DELETE request to the /api/v1/sources route,… Migration Assessment 0.13.5+ Fix from $1,9502026-06-10 HIGH 7.8 CVE-2026-50512 Missing authentication for critical function in Microsoft PC Manager allows an authorized attacker to elevate privileges locally. Pc Manager 3.21.6.0+ Fix from $1,9502026-06-09 HIGH 8.0 CVE-2026-9212 Insufficient authentication and input validation in the listed NETGEAR models allow users connected to the local network to execute commands impactin… Lbr1020 Firmware 1.0.4.96 / 1.0.5.50+ Fix from $1,9502026-06-09 MEDIUM 6.8 CVE-2026-50507EPSS 5% Missing authentication for critical function in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack. Windows 10 1607 10.0.14393.9234 / 10.0.17763.8880+ Fix from $1,6002026-06-09 CRITICAL 9.6 CVE-2026-47281 Missing authorization in Visual Studio Code allows an unauthorized attacker to elevate privileges over a network. Visual Studio Code 1.123.1+ Fix from $2,3002026-06-09 CRITICAL 9.8 CVE-2023-54352 WordPress Seotheme contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary PHP code by uploading ma… Mitigation only Fix from $2,3002026-06-08 HIGH 7.5 CVE-2023-54350 WordPress Augmented-Reality plugin contains a remote code execution vulnerability in the elFinder connector that allows unauthenticated attackers to … No fix yet Fix from $1,9502026-06-08 CRITICAL 10.0 CVE-2026-11429 Two endpoints in the Vault Service ScriptsController, shared by Altium Enterprise Server and Altium 365, accept file uploads where a user-supplied fi… Mitigation only Fix from $2,3002026-06-05