Vulnerability index

Browse CVEs

2,866 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthenticationCWE-306 × clear
HIGH 8.8 CVE-2024-54013 Penetration Testing engineers at Amazon have identified a security flaw related to request handling in the web server component that could, under cer… Knb 2000 Firmware 2.23.01+ Fix from $1,9502026-04-28 MEDIUM 5.6 CVE-2026-7113 A vulnerability was found in NousResearch hermes-agent 0.8.0. Affected by this issue is some unknown functionality of the file gateway/platforms/webh… Patch available Fix from $1,6002026-04-27 HIGH 7.3 CVE-2026-7042 A flaw has been found in 666ghj MiroFish up to 0.1.2. This affects the function create_app of the file backend/app/__init__.py of the component REST … Mitigation only Fix from $1,9502026-04-26 CRITICAL 9.1 CVE-2026-41473 CyberPanel versions prior to 2.4.5 contain an authentication bypass vulnerability in the AI Scanner worker API endpoints that allows unauthenticated … Cyberpanel 2.4.4+ Fix from $2,3002026-04-24 HIGH 7.8 CVE-2026-41477 Deskflow is a keyboard and mouse sharing app. In 1.20.0, 1.26.0.134, and earlier, Deskflow daemon runs as SYSTEM and exposes an IPC named pipe with … Deskflow after 1.26.0.161 Fix from $1,9502026-04-24 HIGH 8.5 CVE-2026-6272 A client holding only a read JWT scope can still register itself as a signal provider through the production kuksa.val.v2 OpenProviderStream API by s… Mitigation only Fix from $1,9502026-04-24 CRITICAL 9.8 CVE-2026-40620 A vulnerability in SenseLive X3050’s embedded management service allows full administrative control to be established without any form of authenticat… X3500 Firmware Mitigation only Fix from $2,3002026-04-24 CRITICAL 9.1 CVE-2026-27843 A vulnerability exists in SenseLive X3050's web management interface that allows critical configuration parameters to be modified without sufficient … X3500 Firmware Mitigation only Fix from $2,3002026-04-24 HIGH 7.5 CVE-2026-35064 A vulnerability in SenseLive X3050’s management ecosystem allows unauthenticated discovery of deployed units through the vendor’s management protocol… X3500 Firmware No fix yet Fix from $1,9502026-04-24 CRITICAL 9.8 CVE-2026-25775 A vulnerability in SenseLive X3050’s remote management service allows firmware retrieval and update operations to be performed without authentication… Mitigation only Fix from $2,3002026-04-24 HIGH 8.7 CVE-2026-6376 A weakness in SpiceJet’s public booking retrieval page permits full passenger booking details to be accessed using only a PNR and last name, with no … Mitigation only Fix from $1,9502026-04-23 HIGH 8.2 CVE-2026-41273 Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, Flowise contains an authentication bypass vu… Flowise 3.1.0+ Fix from $1,9502026-04-23 CRITICAL 9.8 CVE-2026-23751 Kofax Capture, now referred to as Tungsten Capture, version 6.0.0.0 (other versions may be affected) exposes a deprecated .NET Remoting HTTP channel … Mitigation only Fix from $2,3002026-04-23 CRITICAL 9.8 CVE-2026-41176EPSS 33% Rclone is a command-line program to sync files and directories to and from different cloud storage providers. The RC endpoint `options/set` is expose… Rclone 1.73.5+ Fix from $2,3002026-04-23 CRITICAL 9.8 CVE-2026-41179EPSS 9% Rclone is a command-line program to sync files and directories to and from different cloud storage providers. Starting in version 1.48.0 and prior to… Rclone 1.73.5+ Fix from $2,3002026-04-23 HIGH 7.8 CVE-2018-25259 Terminal Services Manager 3.1 contains a stack-based buffer overflow vulnerability in the computer names field that allows local attackers to execute… Terminal Services Manager after 3.1 Fix from $1,9502026-04-22 HIGH 8.7 CVE-2026-5749 Inadequate access control in the registration process in Fullstep V5, which could allow unauthenticated users to obtain a valid JWT token with which … Mitigation only Fix from $1,9502026-04-22 HIGH 8.2 CVE-2026-40344 MinIO is a high-performance object storage system. Starting in RELEASE.2023-05-18T00-05-36Z and prior to RELEASE.2026-04-11T03-20-12Z, an authenticat… Minio 2026-04-11T03-20-12Z+ Fix from $1,9502026-04-22 CRITICAL 9.1 CVE-2026-34285 Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core). The supported version that is affecte… Identity Manager Connector Mitigation only Fix from $2,3002026-04-21 CRITICAL 9.1 CVE-2026-34286 Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core). The supported version that is affecte… Identity Manager Connector Mitigation only Fix from $2,3002026-04-21 MEDIUM 5.9 CVE-2026-34288 Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core). The supported version that is affecte… Identity Manager Connector Mitigation only Fix from $1,6002026-04-21 MEDIUM 5.9 CVE-2026-34289 Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core). The supported version that is affecte… Identity Manager Connector Mitigation only Fix from $1,6002026-04-21 CRITICAL 9.1 CVE-2026-34279 Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Event Management). Supported versions … Enterprise Manager Base Platform Mitigation only Fix from $2,3002026-04-21 MEDIUM 6.5 CVE-2026-34280 Vulnerability in the PeopleSoft Enterprise HCM Human Resources product of Oracle PeopleSoft (component: Job Profile Manager). The supported version… Peoplesoft Enterprise Hcm Human Resources Mitigation only Fix from $1,6002026-04-21 CRITICAL 9.8 CVE-2026-34275 Vulnerability in the Oracle Advanced Inbound Telephony product of Oracle E-Business Suite (component: Setup and Administration). Supported versions … Advanced Inbound Telephony after 12.2.15 Fix from $2,3002026-04-21 MEDIUM 6.5 CVE-2026-34266 Vulnerability in the PeopleSoft Enterprise HCM Absence Management product of Oracle PeopleSoft (component: Absence Management). The supported versi… Peoplesoft Enterprise Human Capital Management Absence Management Mitigation only Fix from $1,6002026-04-21 CRITICAL 9.8 CVE-2026-40884 goshs is a SimpleHTTPServer written in Go. Prior to 2.0.0-beta.6, goshs contains an SFTP authentication bypass when the documented empty-username bas… Goshs 2.0.0+ Fix from $2,3002026-04-21 CRITICAL 9.8 CVE-2026-40050 CrowdStrike has released security updates to address a critical unauthenticated path traversal vulnerability (CVE-2026-40050) in LogScale. This vulne… Mitigation only Fix from $2,3002026-04-21 HIGH 7.7 CVE-2026-24177 NVIDIA KAI Scheduler contains a vulnerability where an attacker could access API endpoints without authorization. A successful exploit of this vulner… Mitigation only Fix from $1,9502026-04-21 HIGH 7.5 CVE-2026-41039 This vulnerability exists in Quantum Networks router due to improper access control and insecure default configuration in the web-based management in… Qn I 470 Firmware Mitigation only Fix from $1,9502026-04-21