Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 7.5
CVE-2025-67805
A non-default configuration in Sage DPW 2025_06_004 allows unauthenticated access to diagnostic endpoints within the Database Monitor feature, exposi…
Sage Dpw
Mitigation only
MEDIUM 5.3
CVE-2026-34999
OpenViking versions 0.2.5 prior to 0.2.14 contain a missing authentication vulnerability in the bot proxy router that allows remote unauthenticated a…
Openviking
0.2.14+
CRITICAL 10.0
CVE-2026-4370
A vulnerability was identified in Juju from version 3.2.0 until 3.6.19 and from version 4.0 until 4.0.4, where the internal Dqlite database cluster f…
Juju
3.6.20 / 4.0.5+
HIGH 7.5
CVE-2026-34731
WWBN AVideo is an open source video platform. In versions 26.0 and prior, the AVideo on_publish_done.php endpoint in the Live plugin allows unauthent…
Avideo
after 26.0
HIGH 7.5
CVE-2026-34732
WWBN AVideo is an open source video platform. In versions 26.0 and prior, the AVideo CreatePlugin template for list.json.php does not include any aut…
Avideo
after 26.0
CRITICAL 9.8
CVE-2026-1579
The MAVLink communication protocol does not require cryptographic
authentication by default. When MAVLink 2.0 message signing is not
enabled, any m…
Autopilot
No fix yet
CRITICAL 9.3
CVE-2026-3356
The MS27102A Remote Spectrum Monitor is vulnerable to an authentication bypass that allows unauthorized users to access and manipulate its management…
Mitigation only
HIGH 8.8
CVE-2026-34227
Sliver is a command and control framework that uses a custom Wireguard netstack. Prior to version 1.7.4, a single click on a malicious link gives an …
Sliver
1.7.4+
HIGH 7.5
CVE-2026-34200
Nhost is an open source Firebase alternative with GraphQL. Prior to version 1.41.0, The Nhost CLI MCP server, when explicitly configured to listen on…
Cli
1.41.0+
CRITICAL 10.0
CVE-2026-34162
FastGPT is an AI Agent building platform. Prior to version 4.14.9.5, the FastGPT HTTP tools testing endpoint (/api/core/app/httpTools/runTool) is exp…
Fastgpt
4.14.9.5+
CRITICAL 9.8
CVE-2026-33032EPSS 38%
Nginx UI is a web user interface for the Nginx web server. In versions 2.3.5 and prior, the nginx-ui MCP (Model Context Protocol) integration exposes…
Nginx Ui
after 2.3.5
HIGH 7.1
CVE-2026-34472EPSS 9%
Unauthenticated credential disclosure in the wizard interface in ZTE ZXHN H188A V6.0.10P2_TE and V6.0.10P3N3_TE allows unauthenticated attackers on t…
Zxhn H188a Firmware
Mitigation only
HIGH 7.3
CVE-2026-5000
A vulnerability was detected in PromtEngineer localGPT up to 4d41c7d1713b16b216d8e062e51a5dd88b20b054. Impacted is the function LocalGPTHandler of th…
Mitigation only
HIGH 7.8
CVE-2018-25224
PMS 0.42 contains a stack-based buffer overflow vulnerability that allows local unauthenticated attackers to execute arbitrary code by supplying mali…
Practical Music Search
after 0.42
HIGH 7.8
CVE-2018-25225
SIPP 3.3 contains a stack-based buffer overflow vulnerability that allows local unauthenticated attackers to execute arbitrary code by supplying mali…
Sipp
No fix yet
MEDIUM 5.3
CVE-2026-34411
Appsmith versions prior to 1.98 expose sensitive instance management API endpoints without authentication. Unauthenticated attackers can query endpoi…
Appsmith
1.98+
HIGH 7.5
CVE-2026-4959
A vulnerability was found in OpenBMB XAgent 1.0.0. This impacts the function check_user of the file XAgentServer/application/websockets/share.py of t…
Xagent
No fix yet
MEDIUM 5.3
CVE-2026-33366
Missing authentication for critical function vulnerability in BUFFALO Wi-Fi router products may allow an attacker to forcibly reboot the product with…
Wcr 1166dhpl Firmware
1.01 / 2.53+
MEDIUM 6.5
CVE-2026-3527
Missing Authentication for Critical Function vulnerability in Drupal AJAX Dashboard allows Exploiting Incorrectly Configured Access Control Security …
Ajax Dashboard
3.1.0+
HIGH 8.8
CVE-2026-24068
The VSL privileged helper does utilize NSXPC for IPC. The implementation of the "shouldAcceptNewConnection" function, which is used by the NSXPC fram…
Mitigation only
HIGH 7.5
CVE-2026-1724
GitLab has remediated an issue in GitLab EE affecting all versions from 18.5 before 18.8.7, 18.9 before 18.9.3, and 18.10 before 18.10.1 that could h…
GitLab
18.8.7 / 18.9.3+
MEDIUM 5.7
CVE-2026-32326
SHARP routers do not perform authentication for some web APIs. The device information may be retrieved without authentication. If the administrative …
Mitigation only
CRITICAL 9.3
CVE-2026-2417
A Missing Authentication for Critical Function vulnerability in Pharos Controls Mosaic Show Controller firmware version 2.15.3 could allow an unauthe…
Mitigation only
MEDIUM 6.5
CVE-2026-33159
Craft CMS is a content management system (CMS). From version 4.0.0-RC1 to before version 4.17.8 and from version 5.0.0-RC1 to before version 5.9.14, …
Craft Cms
4.17.8 / 5.9.14+
CRITICAL 9.1
CVE-2026-33340EPSS 22%
LoLLMs WEBUI provides the Web user interface for Lord of Large Language and Multi modal Systems. A critical Server-Side Request Forgery (SSRF) vulner…
Lollms Web Ui
No fix yet
MEDIUM 5.5
CVE-2019-25632
phpFileManager 1.7.8 contains a local file inclusion vulnerability that allows unauthenticated attackers to read arbitrary files by manipulating the …
Phpfilemanager
No fix yet
MEDIUM 5.3
CVE-2026-4649
Apache Artemis before version 2.52.0 is affected by an authentication bypass flaw which allows reading all messages exchanged via the broker and inje…
Mitigation only
HIGH 7.5
CVE-2026-4640
Vitals ESP developed by Galaxy Software Services has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to execute cer…
Vitalsesp
after 6.3
HIGH 8.6
CVE-2026-33719
WWBN AVideo is an open source video platform. In versions up to and including 26.0, the CDN plugin endpoints `plugin/CDN/status.json.php` and `plugin…
Avideo
after 26.0
HIGH 8.1
CVE-2025-15517
A missing authentication check in the HTTP server on TP-Link Archer NX200, NX210, NX500 and NX600 to certain cgi endpoints allows unauthenticated acc…
Archer Nx600 Firmware
1.3.0 / 1.4.0+