Vulnerability index

Browse CVEs

2,866 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthenticationCWE-306 × clear
CRITICAL 9.9 CVE-2026-46824 Vulnerability in the Oracle Universal Work Queue product of Oracle E-Business Suite (component: Work Provider Site Level Administration). Supported … Universal Work Queue after 12.2.15 Fix from $2,3002026-05-28 HIGH 8.8 CVE-2026-46826 Vulnerability in the Oracle Payroll product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12… E Business Suite after 12.2.15 Fix from $1,9502026-05-28 HIGH 8.8 CVE-2026-46827 Vulnerability in the Oracle Payroll product of Oracle E-Business Suite (component: Self Service Manager). Supported versions that are affected are 1… E Business Suite after 12.2.15 Fix from $1,9502026-05-28 CRITICAL 9.8 CVE-2026-46817 KEVEPSS 13% Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affected are 12.… E Business Suite after 12.2.15 Fix from $2,3002026-05-28 HIGH 7.5 CVE-2026-45332 Automad is a flat-file content management system and template engine. From 2.0.0-alpha.1 to 2.0.0-beta.27, a Broken Access Control vulnerability allo… Mitigation only Fix from $1,9502026-05-28 MEDIUM 6.0 CVE-2026-46685 RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.2, when RUSTFS_CORS_ALLOWED_ORIGINS is unset, the RustFS S3 listener… Mitigation only Fix from $1,6002026-05-28 MEDIUM 6.9 CVE-2026-47136 RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.2, the RustFS console endpoint GET /rustfs/console/license returns p… Mitigation only Fix from $1,6002026-05-28 HIGH 8.8 CVE-2026-45044 RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.2, the admin router explicitly whitelists /profile/cpu and /profile/… Mitigation only Fix from $1,9502026-05-28 HIGH 8.8 CVE-2026-8697 Due to improper enforcement of authentication rate-limiting on a debug SSH service in Archer C64 v1, the SSH service allows unlimited authentication … Archer C64 Firmware Mitigation only Fix from $1,9502026-05-28 CRITICAL 9.8 CVE-2026-45083 The Goobi viewer is a web application that allows digitised material to be displayed in a web browser. From 4.8.0 to before 26.04.1, the Goobi viewer… Patch available Fix from $2,3002026-05-27 CRITICAL 9.8 CVE-2026-8364 Gladinet Triofox Cloud Server Agent Access Service (GladServerAgentService.exe) listens on TCP port 7878 and processes remote HTTP messages with URL … Mitigation only Fix from $2,3002026-05-27 CRITICAL 10.0 CVE-2026-45087 Dalfox is a powerful open-source XSS scanner and utility focused on automation. Prior to 2.13.0, when dalfox is started in REST API server mode (dalf… Mitigation only Fix from $2,3002026-05-27 HIGH 7.5 CVE-2026-45088 Dalfox is a powerful open-source XSS scanner and utility focused on automation. Prior to 2.13.0, when dalfox is run in REST API server mode, the cust… Mitigation only Fix from $1,9502026-05-27 HIGH 8.2 CVE-2026-45089 Dalfox is a powerful open-source XSS scanner and utility focused on automation. Prior to 2.13.0, when dalfox is run in REST API server mode, the outp… Mitigation only Fix from $1,9502026-05-27 HIGH 7.4 CVE-2026-44460 FileRise is a self-hosted web-based file manager with multi-file upload, editing, and batch operations. Prior to 3.12.0, /api/totp_setup.php is calla… Mitigation only Fix from $1,9502026-05-27 CRITICAL 10.0 CVE-2026-44327 free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's NEF mounts the nnef-oam route group without inbound OAuth2… Free5gc 4.2.2+ Fix from $2,3002026-05-27 HIGH 8.2 CVE-2026-44328 free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's SMF mounts the UPI management route group without inbound … Free5gc 4.2.2+ Fix from $1,9502026-05-27 CRITICAL 10.0 CVE-2026-44329 free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's SMF mounts the UPI management route group without OAuth2/b… Free5gc 4.2.2+ Fix from $2,3002026-05-27 HIGH 7.3 CVE-2026-44320 free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's NEF mounts the nnef-callback route group without inbound O… Free5gc 4.2.2+ Fix from $1,9502026-05-27 HIGH 7.5 CVE-2026-44321 free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's SMF mounts the UPI management route group without inbound … Free5gc 4.2.2+ Fix from $1,9502026-05-27 HIGH 8.7 CVE-2026-44830 Nocturne Memory is a lightweight, rollbackable, and visual Long-Term Memory Server for MCP Agents. Prior to 2.4.1, when API_TOKEN is unset or empty, … Mitigation only Fix from $1,9502026-05-27 CRITICAL 9.2 CVE-2026-44895 GitLab MCP Server lets an AI agent talk directly to GitLab. Prior to 0.6.0, the HTTP transport in src/transport.ts ships with no authentication layer… Mitigation only Fix from $2,3002026-05-26 MEDIUM 6.5 CVE-2026-47672 epa4all-client is the Java Client for epa4all / ePA 3.0 in the Telematik Infrastruktur. In 1.2.4 and earlier, any network-reachable caller can write … Patch available Fix from $1,6002026-05-26 HIGH 7.5 CVE-2026-44847 MaxKB is an open-source AI assistant for enterprise. Prior to 2.9.0, MaxKB's webhook trigger endpoint (/api/trigger/v1/webhook/{trigger_id}) is acces… Mitigation only Fix from $1,9502026-05-26 MEDIUM 6.9 CVE-2026-44775 Kavita is a cross platform reading server. Prior to 0.9.0, the ReaderController.GetImage endpoint is decorated with [AllowAnonymous], allowing comple… Mitigation only Fix from $1,6002026-05-26 CRITICAL 9.8 CVE-2026-44668 FACTION is a PenTesting Report Generation and Collaboration Framework. Prior to 1.8.3, AccessControlInterceptor, the authentication gate for all Stru… Mitigation only Fix from $2,3002026-05-26 HIGH 8.1 CVE-2026-48692 FastNetMon Community Edition through 1.2.9 exposes a gRPC API server on port 50052 with no authentication mechanism. The server is initialized with g… Fastnetmon after 1.2.9 Fix from $1,9502026-05-26 MEDIUM 5.6 CVE-2026-9371 A security vulnerability has been detected in ItzCrazyKns Vane up to 1.12.1. Affected by this issue is some unknown functionality of the file route.t… Mitigation only Fix from $1,6002026-05-24 CRITICAL 10.0 CVE-2026-9152 A missing authentication vulnerability exists in the Altium 365 SearchService. A legacy SOAP endpoint exposes search index operations without requiri… Mitigation only Fix from $2,3002026-05-21 CRITICAL 9.8 CVE-2026-9141 Taiko AG1000-01A SMS Alert Gateway Rev 7.3 and Rev 8 contains an authentication bypass vulnerability in the embedded web configuration interface that… Mitigation only Fix from $2,3002026-05-20