Vulnerability index

Browse CVEs

2,866 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthenticationCWE-306 × clear
CRITICAL 9.8 CVE-2026-11420 Two path traversal vulnerabilities in the Network Installation Service (NIS) of Altium Enterprise Server allow an unauthenticated network attacker to… On Prem Enterprise Server 8.1.1+ Fix from $2,3002026-06-05 HIGH 8.2 CVE-2026-45327 TinyIce is a streaming server for audio and video. In versions 0.8.95 through 2.4.1, missing authentication on WebRTC ingest endpoint allows unauthen… Patch available Fix from $1,9502026-06-05 CRITICAL 9.8 CVE-2025-71318 NetMan 204 fails to enforce authentication on its administrative pages and command endpoints. A remote, unauthenticated attacker can directly request… Mitigation only Fix from $2,3002026-06-05 CRITICAL 9.8 CVE-2026-6274 Improper Authentication, Missing authentication for critical function, Weak Authentication vulnerability in DTS Electronics Industry and Trade Ltd. C… Mitigation only Fix from $2,3002026-06-05 MEDIUM 5.9 CVE-2026-11238 Inappropriate implementation in DevTools in Google Chrome prior to 149.0.7827.53 allowed an attacker who convinced a user to install a malicious exte… Chrome 149.0.7827.53+ Fix from $1,6002026-06-05 CRITICAL 9.6 CVE-2024-27892 Affected platforms running Arista EOS with OpenConfig configured, a gNMI Set request can be run when it should have been rejected. This can result in… No fix yet Fix from $2,3002026-06-04 CRITICAL 9.6 CVE-2024-27890 Affected platforms running Arista EOS with OpenConfig configured, a gNMI Set request can be run when it should have been rejected. This can result in… No fix yet Fix from $2,3002026-06-04 CRITICAL 9.8 CVE-2026-25550 Seagull Software BarTender 2010, 2016, and 2019 contain an unauthenticated remote code execution vulnerability in the .NET Remoting service exposed o… Mitigation only Fix from $2,3002026-06-04 CRITICAL 9.8 CVE-2019-25738 WordPress Hybrid Composer 1.4.6 contains an unauthenticated settings change vulnerability that allows unauthenticated attackers to modify WordPress o… Mitigation only Fix from $2,3002026-06-04 CRITICAL 9.1 CVE-2026-50225 The registration path /v1/account/register provides no bot mitigation mechanisms, allowing malicious automated systems to flood the database. Connect M6e 5g Firmware Mitigation only Fix from $2,3002026-06-04 HIGH 8.1 CVE-2026-36603 Mercusys AC12G (EU) V1 router with firmware AC12G(EU)_V1_200909 exposes 15 of 18 UPnP IGD actions without authentication on port 1900, including AddP… Mitigation only Fix from $1,9502026-06-03 HIGH 7.3 CVE-2026-10617 A security vulnerability has been detected in nextlevelbuilder GoClaw up to 3.11.3. This affects the function resolveAuth of the file internal/http/a… Mitigation only Fix from $1,9502026-06-02 CRITICAL 9.8 CVE-2026-42074 OpenClaude is an open-source coding-agent command line interface for cloud and local model providers. Prior to version 0.5.1, the dangerouslyDisableS… Openclaude 0.5.1+ Fix from $2,3002026-06-02 CRITICAL 9.8 CVE-2026-0611 Spacelabs Healthcare Sentinel versions 10.5.x and higher and 11.x.x before 11.6.0 contain an unauthenticated remote code execution vulnerability thro… Mitigation only Fix from $2,3002026-06-02 HIGH 8.2 CVE-2026-24088 Cryptographic Issue while processing a specific partition which allows unauthorized write access to load a customized bootloader. Ar9380 Firmware Patch available Fix from $1,9502026-06-01 HIGH 7.1 CVE-2026-24090 Cryptographic issue while processing partition table entries allows unauthorized modification of boot flow. Snapdragon 460 Mobile Platform Firmware Patch available Fix from $1,9502026-06-01 HIGH 7.3 CVE-2026-10281 A weakness has been identified in Enderfga claw-orchestrator up to 3.5.5. This affects the function EmbeddedServer of the file src/embedded-server.ts… Patch available Fix from $1,9502026-06-01 MEDIUM 6.3 CVE-2026-10283 A vulnerability was detected in Bottelet DaybydayCRM up to 2.2.1. Affected is an unknown function of the component Setting Handler. Performing a mani… Patch available Fix from $1,6002026-06-01 CRITICAL 9.6 CVE-2026-44211 Cline is an autonomous coding agent as an SDK, IDE extension, or CLI assistant. In versions 2.13.0 and prior, there is a cross-origin WebSocket hijac… Cline after 2.13.0 Fix from $2,3002026-06-01 MEDIUM 6.3 CVE-2026-25599 Missing authentication and clear‑text transmission of data from the heat pumps to the control server, combined with the absence of input validation o… Mitigation only Fix from $1,6002026-06-01 HIGH 7.3 CVE-2026-10243 A security vulnerability has been detected in code-projects Smart Parking System 1.0. Affected is an unknown function of the component Admin Endpoint… Mitigation only Fix from $1,9502026-06-01 CRITICAL 9.8 CVE-2018-25412 Delta Sql 1.8.2 contains an arbitrary file upload vulnerability that allows unauthenticated attackers to upload malicious files by sending POST reque… Deltasql Mitigation only Fix from $2,3002026-05-30 CRITICAL 9.1 CVE-2026-9051 There is an authentication bypass vulnerability in the NI SystemLink Enterprise Dashboard application that may allow an unauthenticated remote attack… Mitigation only Fix from $2,3002026-05-29 CRITICAL 9.8 CVE-2026-44649 SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines,… Mitigation only Fix from $2,3002026-05-29 HIGH 8.8 CVE-2026-5768 The Frontier X2 device allows unauthenticated BLE read/write access to critical GATT characteristics without enforcing pairing authentication or auth… Mitigation only Fix from $1,9502026-05-29 MEDIUM 6.9 CVE-2026-45577 Neotoma provides versioned records that persist across agent runs. From 0.6.0 to before 0.11.1, Neotoma can treat public reverse-proxied requests as … Mitigation only Fix from $1,6002026-05-29 MEDIUM 6.5 CVE-2026-45610 WWBN AVideo is an open source video platform. In 29.0 and earlier, there is a cross-site request forgery vulnerability on the 2FA toggle. plugin/Logi… Avideo after 29.0 Fix from $1,6002026-05-29 HIGH 8.8 CVE-2026-49195 Unauthenticated Debug Service. The /sbin/mtk_dut binary is exposed on TCP port 9000 without authentication, allowing any LAN-based attacker to execut… Predator Connect W6x Firmware Mitigation only Fix from $1,9502026-05-29 CRITICAL 9.8 CVE-2026-8732EPSS 19% The WP Maps Pro plugin for WordPress is vulnerable to Privilege Escalation via Administrator Account Creation in all versions up to, and including, 6… Mitigation only Fix from $2,3002026-05-29 CRITICAL 10.0 CVE-2026-46840 Vulnerability in Oracle REST Data Services (component: Backend-as-a-Service). Supported versions that are affected are 24.2.0-26.1.0. Easily exploit… Rest Data Services after 26.1.0 Fix from $2,3002026-05-28