Vulnerability index

Browse CVEs

2,866 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthenticationCWE-306 × clear
HIGH 8.6 CVE-2026-39310 Trilium Notes is a cross-platform, hierarchical note taking application focused on building large personal knowledge bases. In versions 0.102.1 and p… Mitigation only Fix from $1,9502026-05-20 CRITICAL 10.0 CVE-2026-20223 A vulnerability in the&nbsp;access validation of internal REST APIs of Cisco Secure Workload could allow an unauthenticated, remote attacker to acces… Secure Workload 3.10.8.3 / 4.0.3.17+ Fix from $2,3002026-05-20 CRITICAL 9.1 CVE-2026-8602 In ScadaBR version 1.2.0, a Missing Authentication for Critical Function vulnerability could allow an unauthenticated attacker to send a HTTP GET req… Scadabr Mitigation only Fix from $2,3002026-05-19 MEDIUM 6.5 CVE-2026-8706 Firefox for iOS hosted Reader mode on an unauthenticated local web server, allowing another application on the same device to request arbitrary URLs … Firefox 151.0+ Fix from $1,6002026-05-19 CRITICAL 9.1 CVE-2026-31071 API endpoints in LalanaChami Pharmacy Management System (commit 5c3d028) lack authentication middleware. Unauthenticated remote attackers can exploit… Mitigation only Fix from $2,3002026-05-19 CRITICAL 9.8 CVE-2018-25335 WordPress Plugin Peugeot Music 1.0 contains an arbitrary file upload vulnerability that allows unauthenticated attackers to upload malicious files by… Mitigation only Fix from $2,3002026-05-17 CRITICAL 9.8 CVE-2018-25332 GitBucket 4.23.1 contains an unauthenticated remote code execution vulnerability that allows attackers to execute arbitrary commands by exploiting we… Gitbucket 4.24.0+ Fix from $2,3002026-05-17 MEDIUM 5.3 CVE-2026-8737 A weakness has been identified in Sanluan PublicCMS 5.202506.d. This issue affects the function execute of the file publiccms-trade/src/main/java/com… Mitigation only Fix from $1,6002026-05-17 MEDIUM 5.3 CVE-2026-45397 Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.5, GET /api/v1/retrieval/ returns liv… Open Webui 0.9.5+ Fix from $1,6002026-05-15 MEDIUM 5.3 CVE-2026-45248 Hedera Guardian through 3.5.1 contains an authentication bypass vulnerability in the GET /api/v1/demo/registered-users endpoint that allows unauthent… Guardian after 3.5.1 Fix from $1,6002026-05-14 CRITICAL 9.4 CVE-2026-44592 Gradient is a nix-based continuous integration system. In 1.1.0, when GRADIENT_DISCOVERABLE=true (the default, and the NixOS module default), anyone … Mitigation only Fix from $2,3002026-05-14 HIGH 7.8 CVE-2026-42283 DevSpace is a client-only developer tool for cloud-native development with Kubernetes. Prior to 6.3.21, DevSpace's UI server WebSocket accepts connec… Devspace Mitigation only Fix from $1,9502026-05-14 MEDIUM 6.3 CVE-2025-62619 Missing authentication in the KVM key download endpoint could allow an unauthenticated attacker with knowledge of the exposed URL to retrieve sensiti… Mitigation only Fix from $1,6002026-05-14 HIGH 7.3 CVE-2025-27853 The locally served web site on the Garmin WDU (v1 1.4.6 and v2 5.0) allows its authentication to be bypassed. The WDU web site only performs authenti… Empirbus Wireless Display Unit Firmware Mitigation only Fix from $1,9502026-05-13 HIGH 7.8 CVE-2026-0247 Multiple authorization bypass vulnerabilities in the Endpoint DLP component of Prisma Access Agent® allow a local attacker to bypass authentication c… Prisma Access Agent 26.2.1+ Fix from $1,9502026-05-13 HIGH 8.8 CVE-2026-42289 ChurchCRM is an open-source church management system. Prior to 7.3.2, UserEditor.php processes user account creation and permission updates entirely … Mitigation only Fix from $1,9502026-05-12 MEDIUM 6.1 CVE-2026-42303 Fides is an open-source privacy engineering platform. From 2.75.0 to before 2.83.2, Fides deployments that enable both subject identity verification … Patch available Fix from $1,6002026-05-12 MEDIUM 5.3 CVE-2026-31245 The mem0 1.0.0 server lacks authentication and authorization controls for its memory creation API endpoint (POST /memories). The endpoint allows unau… Mem0 Mitigation only Fix from $1,6002026-05-12 HIGH 7.5 CVE-2026-31240 The mem0 1.0.0 server lacks authentication and authorization controls for its memory management API endpoints. Critical functions such as updating me… Mitigation only Fix from $1,9502026-05-12 MEDIUM 6.5 CVE-2026-31241 The mem0 1.0.0 server lacks authentication and authorization controls for its memory deletion API endpoint (DELETE /memories). The endpoint allows un… Mem0 Mitigation only Fix from $1,6002026-05-12 CRITICAL 9.1 CVE-2026-31242 The mem0 v1.0.0 server lacks authentication and authorization controls for its memory reset functionality accessible via the DELETE /memories endpoin… Mem0 Mitigation only Fix from $2,3002026-05-12 MEDIUM 6.5 CVE-2026-31243 The mem0 1.0.0 server lacks authentication and authorization controls for its memory reset and table re-creation functionality accessible via the DEL… Mem0 Mitigation only Fix from $1,6002026-05-12 MEDIUM 6.5 CVE-2026-31244 The mem0 1.0.0 server lacks authentication and authorization controls for its memory deletion API endpoint (DELETE /memories/{memory_id}). The endpoi… Mem0 Mitigation only Fix from $1,6002026-05-12 HIGH 8.7 CVE-2026-5029 A remote code execution vulnerability exists in Code Runner MCP Server when run with the --transport http option, which exposes the /mcp JSON-RPC end… Mitigation only Fix from $1,9502026-05-12 CRITICAL 9.1 CVE-2026-22924 A vulnerability has been identified in SIMATIC CN 4100 (All versions < V5.0). The affected application does not properly restrict unauthenticated con… Simatic Cn 4100 Firmware 5.0+ Fix from $2,3002026-05-12 MEDIUM 5.3 CVE-2026-43881 WWBN AVideo is an open source video platform. In versions up to and including 29.0, objects/users.json.php exposes two unauthenticated paths that dis… Patch available Fix from $1,6002026-05-11 CRITICAL 9.9 CVE-2026-42864 FireFighter is an incident management application. Prior to 0.0.54, the POST /api/v2/firefighter/raid/jira_bot endpoint (CreateJiraBotView) is reacha… Mitigation only Fix from $2,3002026-05-11 HIGH 7.5 CVE-2026-44413 In JetBrains TeamCity before 2026.1 2025.11.5 authenticated users could expose server API to unauthorised access Teamcity 2025.11.5+ Fix from $1,9502026-05-11 HIGH 8.7 CVE-2026-42856 Network-AI is a TypeScript/Node.js multi-agent orchestrator. Prior to 5.1.3, the MCP HTTP transport accepts JSON-RPC tools/call requests with no auth… Mitigation only Fix from $1,9502026-05-11 MEDIUM 6.8 CVE-2026-42312 pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev100, the set_config_value() API method (@permission(Perms.SE… Pyload Ng 0.5.0b3.dev100+ Fix from $1,6002026-05-11