Vulnerability index

Browse CVEs

2,866 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthenticationCWE-306 × clear
HIGH 7.5 CVE-2025-67805 A non-default configuration in Sage DPW 2025_06_004 allows unauthenticated access to diagnostic endpoints within the Database Monitor feature, exposi… Sage Dpw Mitigation only Fix from $1,9502026-04-01 MEDIUM 5.3 CVE-2026-34999 OpenViking versions 0.2.5 prior to 0.2.14 contain a missing authentication vulnerability in the bot proxy router that allows remote unauthenticated a… Openviking 0.2.14+ Fix from $1,6002026-04-01 CRITICAL 10.0 CVE-2026-4370 A vulnerability was identified in Juju from version 3.2.0 until 3.6.19 and from version 4.0 until 4.0.4, where the internal Dqlite database cluster f… Juju 3.6.20 / 4.0.5+ Fix from $2,3002026-04-01 HIGH 7.5 CVE-2026-34731 WWBN AVideo is an open source video platform. In versions 26.0 and prior, the AVideo on_publish_done.php endpoint in the Live plugin allows unauthent… Avideo after 26.0 Fix from $1,9502026-03-31 HIGH 7.5 CVE-2026-34732 WWBN AVideo is an open source video platform. In versions 26.0 and prior, the AVideo CreatePlugin template for list.json.php does not include any aut… Avideo after 26.0 Fix from $1,9502026-03-31 CRITICAL 9.8 CVE-2026-1579 The MAVLink communication protocol does not require cryptographic authentication by default. When MAVLink 2.0 message signing is not enabled, any m… Autopilot No fix yet Fix from $2,3002026-03-31 CRITICAL 9.3 CVE-2026-3356 The MS27102A Remote Spectrum Monitor is vulnerable to an authentication bypass that allows unauthorized users to access and manipulate its management… Mitigation only Fix from $2,3002026-03-31 HIGH 8.8 CVE-2026-34227 Sliver is a command and control framework that uses a custom Wireguard netstack. Prior to version 1.7.4, a single click on a malicious link gives an … Sliver 1.7.4+ Fix from $1,9502026-03-31 HIGH 7.5 CVE-2026-34200 Nhost is an open source Firebase alternative with GraphQL. Prior to version 1.41.0, The Nhost CLI MCP server, when explicitly configured to listen on… Cli 1.41.0+ Fix from $1,9502026-03-31 CRITICAL 10.0 CVE-2026-34162 FastGPT is an AI Agent building platform. Prior to version 4.14.9.5, the FastGPT HTTP tools testing endpoint (/api/core/app/httpTools/runTool) is exp… Fastgpt 4.14.9.5+ Fix from $2,3002026-03-31 CRITICAL 9.8 CVE-2026-33032EPSS 38% Nginx UI is a web user interface for the Nginx web server. In versions 2.3.5 and prior, the nginx-ui MCP (Model Context Protocol) integration exposes… Nginx Ui after 2.3.5 Fix from $2,3002026-03-30 HIGH 7.1 CVE-2026-34472EPSS 9% Unauthenticated credential disclosure in the wizard interface in ZTE ZXHN H188A V6.0.10P2_TE and V6.0.10P3N3_TE allows unauthenticated attackers on t… Zxhn H188a Firmware Mitigation only Fix from $1,9502026-03-30 HIGH 7.3 CVE-2026-5000 A vulnerability was detected in PromtEngineer localGPT up to 4d41c7d1713b16b216d8e062e51a5dd88b20b054. Impacted is the function LocalGPTHandler of th… Mitigation only Fix from $1,9502026-03-28 HIGH 7.8 CVE-2018-25224 PMS 0.42 contains a stack-based buffer overflow vulnerability that allows local unauthenticated attackers to execute arbitrary code by supplying mali… Practical Music Search after 0.42 Fix from $1,9502026-03-28 HIGH 7.8 CVE-2018-25225 SIPP 3.3 contains a stack-based buffer overflow vulnerability that allows local unauthenticated attackers to execute arbitrary code by supplying mali… Sipp No fix yet Fix from $1,9502026-03-28 MEDIUM 5.3 CVE-2026-34411 Appsmith versions prior to 1.98 expose sensitive instance management API endpoints without authentication. Unauthenticated attackers can query endpoi… Appsmith 1.98+ Fix from $1,6002026-03-27 HIGH 7.5 CVE-2026-4959 A vulnerability was found in OpenBMB XAgent 1.0.0. This impacts the function check_user of the file XAgentServer/application/websockets/share.py of t… Xagent No fix yet Fix from $1,9502026-03-27 MEDIUM 5.3 CVE-2026-33366 Missing authentication for critical function vulnerability in BUFFALO Wi-Fi router products may allow an attacker to forcibly reboot the product with… Wcr 1166dhpl Firmware 1.01 / 2.53+ Fix from $1,6002026-03-27 MEDIUM 6.5 CVE-2026-3527 Missing Authentication for Critical Function vulnerability in Drupal AJAX Dashboard allows Exploiting Incorrectly Configured Access Control Security … Ajax Dashboard 3.1.0+ Fix from $1,6002026-03-26 HIGH 8.8 CVE-2026-24068 The VSL privileged helper does utilize NSXPC for IPC. The implementation of the "shouldAcceptNewConnection" function, which is used by the NSXPC fram… Mitigation only Fix from $1,9502026-03-26 HIGH 7.5 CVE-2026-1724 GitLab has remediated an issue in GitLab EE affecting all versions from 18.5 before 18.8.7, 18.9 before 18.9.3, and 18.10 before 18.10.1 that could h… GitLab 18.8.7 / 18.9.3+ Fix from $1,9502026-03-25 MEDIUM 5.7 CVE-2026-32326 SHARP routers do not perform authentication for some web APIs. The device information may be retrieved without authentication. If the administrative … Mitigation only Fix from $1,6002026-03-25 CRITICAL 9.3 CVE-2026-2417 A Missing Authentication for Critical Function vulnerability in Pharos Controls Mosaic Show Controller firmware version 2.15.3 could allow an unauthe… Mitigation only Fix from $2,3002026-03-24 MEDIUM 6.5 CVE-2026-33159 Craft CMS is a content management system (CMS). From version 4.0.0-RC1 to before version 4.17.8 and from version 5.0.0-RC1 to before version 5.9.14, … Craft Cms 4.17.8 / 5.9.14+ Fix from $1,6002026-03-24 CRITICAL 9.1 CVE-2026-33340EPSS 22% LoLLMs WEBUI provides the Web user interface for Lord of Large Language and Multi modal Systems. A critical Server-Side Request Forgery (SSRF) vulner… Lollms Web Ui No fix yet Fix from $2,3002026-03-24 MEDIUM 5.5 CVE-2019-25632 phpFileManager 1.7.8 contains a local file inclusion vulnerability that allows unauthenticated attackers to read arbitrary files by manipulating the … Phpfilemanager No fix yet Fix from $1,6002026-03-24 MEDIUM 5.3 CVE-2026-4649 Apache Artemis before version 2.52.0 is affected by an authentication bypass flaw which allows reading all messages exchanged via the broker and inje… Mitigation only Fix from $1,6002026-03-24 HIGH 7.5 CVE-2026-4640 Vitals ESP developed by Galaxy Software Services has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to execute cer… Vitalsesp after 6.3 Fix from $1,9502026-03-24 HIGH 8.6 CVE-2026-33719 WWBN AVideo is an open source video platform. In versions up to and including 26.0, the CDN plugin endpoints `plugin/CDN/status.json.php` and `plugin… Avideo after 26.0 Fix from $1,9502026-03-23 HIGH 8.1 CVE-2025-15517 A missing authentication check in the HTTP server on TP-Link Archer NX200, NX210, NX500 and NX600 to certain cgi endpoints allows unauthenticated acc… Archer Nx600 Firmware 1.3.0 / 1.4.0+ Fix from $1,9502026-03-23