Vulnerability index

Browse CVEs

2,866 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthenticationCWE-306 × clear
CRITICAL 9.8 CVE-2021-47940 WordPress Plugin Download From Files version 1.48 and earlier contains an arbitrary file upload vulnerability that allows unauthenticated attackers t… Mitigation only Fix from $2,3002026-05-10 CRITICAL 9.8 CVE-2021-47933 WordPress MStore API 2.0.6 contains an arbitrary file upload vulnerability that allows unauthenticated attackers to upload malicious files by sending… Mitigation only Fix from $2,3002026-05-10 CRITICAL 9.8 CVE-2021-47936 OpenCATS 0.9.4 contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary commands by uploading malici… Mitigation only Fix from $2,3002026-05-10 CRITICAL 9.4 CVE-2026-42569 phpVMS is a PHP application to run and simulate an airline. Prior to version 7.0.6, a critical vulnerability in phpVMS allowed unauthenticated access… Patch available Fix from $2,3002026-05-09 MEDIUM 6.3 CVE-2026-8185 A security vulnerability has been detected in UGREEN CM933 1.1.59.4319. The impacted element is an unknown function of the component Administrative I… Mitigation only Fix from $1,6002026-05-09 CRITICAL 9.8 CVE-2026-42302 FastGPT is an AI Agent building platform. From version 4.14.10 to before version 4.14.13, the agent-sandbox component of FastGPT is vulnerable to una… Patch available Fix from $2,3002026-05-08 MEDIUM 6.7 CVE-2026-42176 Scoold is a Q&A and a knowledge sharing platform for teams. Prior to version 1.67.0, Scoold allows the admins configuration value to be modified thro… Mitigation only Fix from $1,6002026-05-08 HIGH 7.3 CVE-2026-44338EPSS 29% PraisonAI is a multi-agent teams system. From version 2.5.6 to before version 4.6.34, PraisonAI ships a legacy Flask API server with authentication d… Praisonai 4.6.34+ Fix from $1,9502026-05-08 MEDIUM 6.5 CVE-2026-6736 An authentication bypass vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to create a local user acc… Enterprise Server 3.16.18 / 3.17.15+ Fix from $1,6002026-05-07 CRITICAL 9.8 CVE-2026-7415 The MQTT broker embedded in Yarbo firmware v2.3.9 is configured to allow anonymous connections with no topic-level read or write ACLs. Any host on th… Lawn Mower Firmware Mitigation only Fix from $2,3002026-05-07 MEDIUM 5.3 CVE-2026-8031 A vulnerability was detected in PicoTronica e-Clinic Healthcare System ECHS 5.7. The affected element is an unknown function of the file /cdemos/echs… Mitigation only Fix from $1,6002026-05-06 CRITICAL 9.8 CVE-2026-41930 Vvveb before version 1.0.8.2 contains a hard-coded credentials vulnerability in its docker-compose-apache.yaml configuration that allows unauthentica… Patch available Fix from $2,3002026-05-06 MEDIUM 6.3 CVE-2026-7844 A vulnerability was detected in chatchat-space Langchain-Chatchat up to 0.3.1.3. This vulnerability affects the function files/list_files/retrieve_fi… Mitigation only Fix from $1,6002026-05-05 CRITICAL 9.1 CVE-2026-36356EPSS 14% The GoAhead web server on MeiG Smart FORGE_SLT711 devices (firmware MDM9607.LE.1.0-00110-STD.PROD-1) allows unauthenticated OS command injection via … Mitigation only Fix from $2,3002026-05-05 CRITICAL 9.8 CVE-2023-54344 Eclipse Equinox OSGi 3.7.2 and earlier contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary comm… Mitigation only Fix from $2,3002026-05-05 CRITICAL 9.8 CVE-2023-54342 Eclipse Equinox OSGi versions 3.8 through 3.18 contain a remote code execution vulnerability in the console interface that allows unauthenticated att… Mitigation only Fix from $2,3002026-05-05 CRITICAL 9.8 CVE-2026-42221 Nginx UI is a web user interface for the Nginx web server. From version 2.0.0 to before version 2.3.8, an unauthenticated network attacker can claim … Nginx Ui 2.3.8+ Fix from $2,3002026-05-04 CRITICAL 9.8 CVE-2026-42222 Nginx UI is a web user interface for the Nginx web server. In version 2.3.5, an unauthenticated bootstrap takeover exists in nginx-ui during the init… Nginx Ui Mitigation only Fix from $2,3002026-05-04 CRITICAL 9.8 CVE-2026-42796 Arelle before 2.39.10 contains an unauthenticated remote code execution vulnerability in the /rest/configure REST endpoint that accepts a plugins que… Arelle 2.39.10+ Fix from $2,3002026-05-04 HIGH 7.3 CVE-2026-7723 A flaw has been found in PrefectHQ prefect up to 3.6.13. Affected is an unknown function of the file /api/events/in of the component WebSocket Endpoi… Patch available Fix from $1,9502026-05-04 MEDIUM 6.5 CVE-2026-7714 A flaw has been found in crocodilestick Calibre-Web-Automated up to 4.0.6. Affected by this issue is some unknown functionality of the file cps/cwa_f… Patch available Fix from $1,6002026-05-04 CRITICAL 10.0 CVE-2026-39858 Traefik is an HTTP reverse proxy and load balancer. Prior to versions 2.11.43, 3.6.14, and 3.7.0-rc.2, there is a high severity authentication bypass… Traefik 2.11.43 / 3.6.14+ Fix from $2,3002026-04-30 MEDIUM 6.5 CVE-2026-35514 Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. In version 4.9.0, the … Mitigation only Fix from $1,6002026-04-30 CRITICAL 9.8 CVE-2025-13030 All versions of the package django-mdeditor are vulnerable to Missing Authentication for Critical Function in the image upload endpoint. An attacker … Django Mdeditor Patch available Fix from $2,3002026-04-30 HIGH 8.0 CVE-2026-0204 A vulnerability in the access control mechanism of SonicOS may allow certain management interface functions to be accessible under specific condition… Sonicos 6.5.5.2-28n / 7.3.2-7010+ Fix from $1,9502026-04-29 CRITICAL 9.8 CVE-2026-41940 KEVEPSS 98% cPanel and WHM versions after 11.40 contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to … Wp Squared 86.0.41 / 110.0.97+ Fix from $2,3002026-04-29 CRITICAL 9.4 CVE-2026-3893 The Carlson VASCO-B GNSS Receiver lacks an authentication mechanism, allowing an attacker with network access to directly access and modify its con… Mitigation only Fix from $2,3002026-04-28 HIGH 8.2 CVE-2026-5944 An improper access control vulnerability exists in the Cisco Intersight Device Connector for Nutanix Prism Central. The service exposes an API passth… Intersight Device Connector after 7.5.0 Fix from $1,9502026-04-28 HIGH 7.5 CVE-2026-3323 An unsecured configuration interface on affected devices allows unauthenticated remote attackers to access sensitive information, including hashed cr… Vegapuls 6x Firmware Mitigation only Fix from $1,9502026-04-28 HIGH 7.4 CVE-2026-41603 Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are re… Thrift 0.23.0+ Fix from $1,9502026-04-28