Vulnerability index

Browse CVEs

2,866 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthenticationCWE-306 × clear
HIGH 8.1 CVE-2026-39393 CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior t… Ci4ms 0.31.4.0+ Fix from $1,9502026-04-08 CRITICAL 9.1 CVE-2026-5300 Unauthenticated functionality in CoolerControl/coolercontrold <4.0.0 allows unauthenticated attackers to view and modify potentially sensitive data … Coolercontrold 4.0.0+ Fix from $2,3002026-04-08 HIGH 7.5 CVE-2026-39363 Vite is a frontend tooling framework for JavaScript. From 6.0.0 to before 6.4.2, 7.3.2, and 8.0.5, if it is possible to connect to the Vite dev serve… Vite after 8.0.4 Fix from $1,9502026-04-07 MEDIUM 6.5 CVE-2026-35584 FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to 1.8.212, the endpoint GET /thread/read/{conversation_id}/… Freescout 1.8.212+ Fix from $1,6002026-04-07 HIGH 7.5 CVE-2026-35523 Strawberry GraphQL is a library for creating GraphQL APIs. Strawberry up until version 0.312.3 is vulnerable to an authentication bypass on WebSocket… Strawberry Graphql 0.312.3+ Fix from $1,9502026-04-07 CRITICAL 9.8 CVE-2026-22679EPSS 21% Weaver (Fanwei) E-cology 10.0 versions prior to 20260312 contain an unauthenticated remote code execution vulnerability in the /papi/esearch/data/dev… E Cology 20260312+ Fix from $2,3002026-04-07 MEDIUM 6.5 CVE-2026-1900 The Link Whisper Free WordPress plugin before 0.9.1 has a publicly accessible REST endpoint that allows unauthenticated settings updates. Link Whisper 0.9.1+ Fix from $1,6002026-04-07 MEDIUM 5.3 CVE-2026-35450 WWBN AVideo is an open source video platform. In versions 26.0 and prior, the plugin/API/check.ffmpeg.json.php endpoint probes the FFmpeg remote serv… Avideo after 26.0 Fix from $1,6002026-04-06 HIGH 7.3 CVE-2026-5676 A vulnerability was identified in Totolink A8000R 5.9c.681_B20180413. This issue affects the function setLanguageCfg of the file /cgi-bin/cstecgi.cgi… Mitigation only Fix from $1,9502026-04-06 MEDIUM 6.1 CVE-2026-26027 GLPI is a free asset and IT management software package. From 11.0.0 to before 11.0.6, an unauthenticated user can store an XSS payload through the i… Glpi 11.0.6+ Fix from $1,6002026-04-06 HIGH 7.3 CVE-2026-5632 A vulnerability was found in assafelovic gpt-researcher up to 3.4.3. This impacts an unknown function of the component HTTP REST API Endpoint. Perfor… Mitigation only Fix from $1,9502026-04-06 HIGH 7.3 CVE-2026-5616 A security vulnerability has been detected in JeecgBoot 3.9.0/3.9.1. The impacted element is an unknown function of the file jeecg-boot/jeecg-module-… Patch available Fix from $1,9502026-04-06 HIGH 8.1 CVE-2026-4272 Missing Authentication for Critical Function vulnerability in Honeywell Handheld Scanners allows Authentication Abuse.This issue affects Handheld Sca… Mitigation only Fix from $1,9502026-04-05 HIGH 7.5 CVE-2019-25686 Core FTP 2.0 build 653 contains a denial of service vulnerability in the PBSZ command that allows unauthenticated attackers to crash the service by s… Core Ftp No fix yet Fix from $1,9502026-04-05 HIGH 7.5 CVE-2019-25678 C4G Basic Laboratory Information System 3.4 contains multiple SQL injection vulnerabilities that allow unauthenticated attackers to execute arbitrary… Computing For Good\'s Basic Laboratory Information System after 3.4 Fix from $1,9502026-04-05 HIGH 7.5 CVE-2018-25246 Wikipedia 12.0 contains a denial of service vulnerability that allows unauthenticated attackers to crash the application by submitting oversized inpu… No fix yet Fix from $1,9502026-04-04 HIGH 7.5 CVE-2018-25241 VPN Browser+ 1.1.0.0 contains a denial of service vulnerability that allows unauthenticated attackers to crash the application by submitting oversize… No fix yet Fix from $1,9502026-04-04 CRITICAL 9.1 CVE-2026-34952 PraisonAI is a multi-agent teams system. Prior to version 4.5.97, the PraisonAI Gateway server accepts WebSocket connections at /ws and serves agent … Praisonai 4.5.97+ Fix from $2,3002026-04-03 HIGH 7.5 CVE-2026-32646 A specific administrative endpoint is accessible without proper authentication, exposing device management functions. Cloud Api 2.12.2026+ Fix from $1,9502026-04-03 HIGH 7.5 CVE-2026-28766 A specific endpoint exposes all user account information for registered Gardyn users without requiring authentication. Cloud Api 2.12.2026+ Fix from $1,9502026-04-03 MEDIUM 5.3 CVE-2026-28767 A specific administrative endpoint notifications is accessible without proper authentication. Cloud Api 2.12.2026+ Fix from $1,6002026-04-03 CRITICAL 9.8 CVE-2026-0545 In mlflow/mlflow, the FastAPI job endpoints under `/ajax-api/3.0/jobs/*` are not protected by authentication or authorization when the `basic-auth` a… Mlflow Mitigation only Fix from $2,3002026-04-03 HIGH 7.5 CVE-2026-32211 Missing authentication for critical function in Azure MCP Server allows an unauthorized attacker to disclose information over a network. Azure Web Apps Mitigation only Fix from $1,9502026-04-03 HIGH 8.6 CVE-2025-15620 HiOS Switch Platform versions 09.1.00 through 09.4.04 and 10.0.00 through 10.3.00 contain a denial-of-service vulnerability in the web interface that… Hios Switch 09.4.05 / 10.3.01+ Fix from $1,9502026-04-02 CRITICAL 9.8 CVE-2026-35053 OneUptime is an open-source monitoring and observability platform. Prior to version 10.0.42, the Worker service's ManualAPI exposes workflow executio… Oneuptime 10.0.42+ Fix from $2,3002026-04-02 CRITICAL 9.1 CVE-2026-34758 OneUptime is an open-source monitoring and observability platform. Prior to version 10.0.42, unauthenticated access to Notification test and Phone Nu… Oneuptime 10.0.40+ Fix from $2,3002026-04-02 HIGH 7.5 CVE-2026-33951 Signal K Server is a server application that runs on a central hub in a boat. Prior to version 2.24.0-beta.1, the SignalK Server exposes an unauthent… Signal K Server 2.24.0+ Fix from $1,9502026-04-02 HIGH 7.5 CVE-2026-29132 SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker with access to a victim's GINA account to bypass a second-password check and r… Secure Email Gateway 15.0.3+ Fix from $1,9502026-04-02 HIGH 7.3 CVE-2026-5320 A vulnerability was detected in vanna-ai vanna up to 2.0.2. Affected by this vulnerability is an unknown functionality of the file /api/vanna/v2/ of … Mitigation only Fix from $1,9502026-04-02 CRITICAL 9.8 CVE-2026-34072 Cr*nMaster (cronmaster) is a Cronjob management UI with human readable syntax, live logging and log history for cronjobs. Prior to version 2.2.0, an … Cronmaster 2.2.0+ Fix from $2,3002026-04-01