Vulnerability index

Browse CVEs

2,866 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthenticationCWE-306 × clear
MEDIUM 6.5 CVE-2026-31846 Missing authentication in the /goform/ate endpoint in Nexxt Solutions Nebula 300+ firmware through version 12.01.01.37 allows an adjacent unauthentic… Mitigation only Fix from $1,6002026-03-23 MEDIUM 5.0 CVE-2026-4582 A security vulnerability has been detected in Shenzhen HCC Technology MPOS M6 PLUS 1V.31-N. Affected by this vulnerability is an unknown functionalit… Mitigation only Fix from $1,6002026-03-23 HIGH 7.3 CVE-2026-4562 A security flaw has been discovered in MacCMS 2025.1000.4052. This affects an unknown part of the file application/api/controller/Timming.php of the … Mitigation only Fix from $1,9502026-03-23 MEDIUM 5.0 CVE-2026-2756 A security vulnerability has been detected in OmniPEMF NeoRhythm up to 20260308. This affects an unknown function of the component BLE Interface. Suc… Mitigation only Fix from $1,6002026-03-21 HIGH 7.8 CVE-2019-25568 Memu Play 6.0.7 contains an insecure file permissions vulnerability that allows low-privilege users to escalate privileges by replacing the MemuServi… Memu after 6.0.7 Fix from $1,9502026-03-21 MEDIUM 6.5 CVE-2026-32896 The BlueBubbles webhook handler in OpenClaw versions prior to 2026.2.21 contains a passwordless fallback authentication path that allows unauthentica… Openclaw 2026.2.21+ Fix from $1,6002026-03-21 CRITICAL 9.1 CVE-2026-32064 OpenClaw versions prior to 2026.2.21 sandbox browser entrypoint launches x11vnc without authentication for noVNC observer sessions, allowing unauthen… Openclaw 2026.2.21+ Fix from $2,3002026-03-21 HIGH 7.5 CVE-2026-33231 NLTK (Natural Language Toolkit) is a suite of open source Python modules, data sets, and tutorials supporting research and development in Natural Lan… Nltk after 3.9.3 Fix from $1,9502026-03-20 HIGH 7.5 CVE-2026-33203 SiYuan is a personal knowledge management system. Prior to version 3.6.2, the SiYuan kernel WebSocket server accepts unauthenticated connections when… Siyuan 3.6.2+ Fix from $1,9502026-03-20 CRITICAL 9.8 CVE-2026-29796 WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersonation and manipulate data sent … Eparking.fi Mitigation only Fix from $2,3002026-03-20 CRITICAL 9.8 CVE-2026-25192 WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersonation and manipulate data sent … Charge Portal Mitigation only Fix from $2,3002026-03-20 CRITICAL 9.8 CVE-2026-22898 A missing authentication for critical function vulnerability has been reported to affect QVR Pro. The remote attackers can then exploit the vulnerabi… Qvr Pro 2.7.4.1485+ Fix from $2,3002026-03-20 MEDIUM 6.3 CVE-2026-4476 A vulnerability was found in Yi Technology YI Home Camera 2 2.1.1_20171024151200. The impacted element is an unknown function of the file home/web/ip… Mitigation only Fix from $1,6002026-03-20 HIGH 8.1 CVE-2026-33038 WWBN AVideo is an open source video platform. Versions 25.0 and below are vulnerable to unauthenticated application takeover through the install/chec… Avideo 26.0+ Fix from $1,9502026-03-20 CRITICAL 9.8 CVE-2026-33017 KEVEPSS 96% Langflow is a tool for building and deploying AI-powered agents and workflows. In versions prior to 1.9.0, the POST /api/v1/build_public_tmp/{flow_id… Langflow 1.8.2+ Fix from $2,3002026-03-20 CRITICAL 9.8 CVE-2026-21992 Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: REST WebServices) and Oracle Web Services Manager produc… Identity Manager Mitigation only Fix from $2,3002026-03-20 CRITICAL 9.8 CVE-2026-32985 Xerte Online Toolkits versions 3.14 and earlier contain an unauthenticated arbitrary file upload vulnerability in the template import functionality t… Xerte Online Toolkits after 3.14.0 Fix from $2,3002026-03-20 HIGH 8.1 CVE-2026-22731 Spring Boot applications with Actuator can be vulnerable to an "Authentication Bypass" vulnerability when an application endpoint that requires authe… Spring Boot 3.4.15 / 3.5.12+ Fix from $1,9502026-03-19 HIGH 7.8 CVE-2026-32041 OpenClaw versions prior to 2026.3.1 fail to properly handle authentication bootstrap errors during startup, allowing browser-control routes to remain… Openclaw 2026.3.1+ Fix from $1,9502026-03-19 CRITICAL 9.1 CVE-2025-71257EPSS 5% BMC FootPrints ITSM versions 20.20.02 through 20.24.01.001 contain an authentication bypass vulnerability due to improper enforcement of security fil… Footprints after 20.24.01.001 Fix from $2,3002026-03-19 HIGH 7.8 CVE-2026-24062 The "Privileged Helper" component of the Arturia Software Center (MacOS) does not perform sufficient client code signature validation when a client c… Mitigation only Fix from $1,9502026-03-18 HIGH 8.1 CVE-2026-2603 A flaw was found in Keycloak. A remote attacker could bypass security controls by sending a valid SAML response from an external Identity Provider (I… Build Of Keycloak 26.2.14 / 26.4.10+ Fix from $1,9502026-03-18 MEDIUM 6.8 CVE-2026-22174 OpenClaw versions prior to 2026.2.22 inject the x-OpenClaw-relay-token header into Chrome CDP probe traffic on loopback interfaces, allowing local pr… Openclaw 2026.2.22+ Fix from $1,6002026-03-18 MEDIUM 6.5 CVE-2026-1264 IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.1.0.0 through 6.1.2.7_2, 6.2.0.0 through 6.2.0.5_1, 6.2.1.0 through 6.2.1.1_1, and 6.2.2.… Sterling B2b Integrator 6.1.2.8 / 6.2.0.5_2+ Fix from $1,6002026-03-17 HIGH 7.5 CVE-2026-22727 Unprotected internal endpoints in Cloud Foundry Capi Release 1.226.0 and below, and CF Deployment v54.9.0 and below on all platforms allows any user … Mitigation only Fix from $1,9502026-03-17 CRITICAL 9.8 CVE-2026-3207 Configuration issue in Java Management Extensions (JMX) in TIBCO BPM Enterprise version 4.x allows unauthorised access. Bpm Enterprise 4.3.5+ Fix from $2,3002026-03-17 HIGH 7.5 CVE-2026-32297 The Angeet ES3 KVM allows a remote, unauthenticated attacker to write arbitrary files, including configuration files or system binaries. Modified con… Es3 Kvm Firmware Mitigation only Fix from $1,9502026-03-17 MEDIUM 6.8 CVE-2026-32291 The GL-iNet Comet (GL-RM1) KVM before 1.8.2 does not require authentication on the UART serial console. This attack requires physically opening the d… Comet Gl Rm1 Firmware 1.8.2+ Fix from $1,6002026-03-17 HIGH 8.2 CVE-2026-32296 Sipeed NanoKVM before 2.3.1 exposes a Wi-Fi configuration endpoint without proper security checks, allowing an unauthenticated attacker with network … Mitigation only Fix from $1,9502026-03-17 CRITICAL 9.8 CVE-2026-4312 GCB/FCB Audit Software developed by DrangSoft has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to directly acces… Gcb\/fcb Government Financial Cybersecurity Configuration Audit Software Mitigation only Fix from $2,3002026-03-17