Vulnerability index

Browse CVEs

2,866 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthenticationCWE-306 × clear
MEDIUM 5.3 CVE-2026-4187 A vulnerability was identified in Tiandy Easy7 Integrated Management Platform 7.17.0. Impacted is an unknown function of the file /WebService/UpdateL… Mitigation only Fix from $1,6002026-03-16 HIGH 8.1 CVE-2026-3558 Philips Hue Bridge HomeKit Accessory Protocol Transient Pairing Mode Authentication Bypass Vulnerability. This vulnerability allows network-adjacent … Hue Bridge V2 Firmware 1975170000+ Fix from $1,9502026-03-16 HIGH 7.3 CVE-2026-32594 Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 8.6.40 and 9.6.0-alpha.14, the Graph… Parse Server 8.6.40 / 9.6.0+ Fix from $1,9502026-03-16 MEDIUM 6.3 CVE-2026-2491 Socomec DIRIS A-40 HTTP API Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to bypass authentication on aff… Mitigation only Fix from $1,6002026-03-16 MEDIUM 5.3 CVE-2026-20995 Exposure of sensitive functionality to an unauthorized actor in Smart Switch prior to version 3.7.69.15 allows remote attackers to set a specific con… Smart Switch 3.7.69.15+ Fix from $1,6002026-03-16 HIGH 7.5 CVE-2017-20222 Telesquare SKT LTE Router SDT-CS3B1 software version 1.2.0 contains an unauthenticated remote reboot vulnerability that allows attackers to trigger d… Sdt Cs3b1 Firmware No fix yet Fix from $1,9502026-03-16 HIGH 7.5 CVE-2017-20217 Serviio PRO 1.8 contains an information disclosure vulnerability due to improper access control enforcement in the Configuration REST API that allows… No fix yet Fix from $1,9502026-03-16 HIGH 7.5 CVE-2017-20220 Serviio PRO 1.8 contains an improper access control vulnerability in the Configuration REST API that allows unauthenticated attackers to change the m… No fix yet Fix from $1,9502026-03-16 HIGH 7.6 CVE-2026-31944 LibreChat is a ChatGPT clone with additional features. From 0.8.2 to 0.8.2-rc3, The MCP (Model Context Protocol) OAuth callback endpoint accepts the … Librechat No fix yet Fix from $1,9502026-03-13 HIGH 7.5 CVE-2026-31882 Dagu is a workflow engine with a built-in Web user interface. Prior to 2.2.4, when Dagu is configured with HTTP Basic authentication (DAGU_AUTH_MODE=… Dagu 2.2.4+ Fix from $1,9502026-03-13 CRITICAL 9.9 CVE-2026-22192 Voltronic Power SNMP Web Pro version 1.1 contains an authentication bypass vulnerability that allows unauthenticated attackers to access privileged m… Wpdiscuz 7.6.47+ Fix from $2,3002026-03-13 MEDIUM 5.5 CVE-2025-15515 The authentication mechanism for a specific feature in the EasyShare module contains a vulnerability. If specific conditions are met on a local netwo… Easyshare 7.0.11.5+ Fix from $1,6002026-03-13 MEDIUM 6.5 CVE-2025-13778 Missing authentication for critical function vulnerability in ABB AWIN GW100 rev.2, ABB AWIN GW120.This issue affects AWIN GW100 rev.2: 2.0-0, 2.0-1;… Mitigation only Fix from $1,6002026-03-13 HIGH 8.3 CVE-2025-13779 Missing authentication for critical function vulnerability in ABB AWIN GW100 rev.2, ABB AWIN GW120.This issue affects AWIN GW100 rev.2: 2.0-0, 2.0-1;… Mitigation only Fix from $1,9502026-03-13 CRITICAL 10.0 CVE-2026-3611EPSS 6% The Honeywell IQ4x building management controller, exposes its full web-based HMI without authentication in its factory-default configuration. With n… Iq4e Firmware 3.30+ Fix from $2,3002026-03-12 HIGH 8.2 CVE-2026-32231 ZeptoClaw is a personal AI assistant. Prior to 0.7.6, the generic webhook channel trusts caller-supplied identity fields (sender, chat_id) from the r… Zeptoclaw after 0.7.5 Fix from $1,9502026-03-12 CRITICAL 9.8 CVE-2026-31881 Runtipi is a personal homeserver orchestrator. Prior to 4.8.0, an unauthenticated attacker can reset the operator (admin) password when a password-re… Runtipi 4.8.0+ Fix from $2,3002026-03-11 HIGH 8.4 CVE-2019-25483 Comtrend AR-5310 GE31-412SSG-C01_R10.A2pG039u.d24k contains a restricted shell escape vulnerability that allows local users to bypass command restric… No fix yet Fix from $1,9502026-03-11 HIGH 7.1 CVE-2026-27897 Vociferous provides cross-platform, offline speech-to-text with local AI refinement. Prior to 4.4.2, the vulnerability exists in src/api/system.py wi… Vociferous 4.4.2+ Fix from $1,9502026-03-11 HIGH 7.5 CVE-2026-28229 Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. Prior to 4.0.2 and 3.7.11, Workflow … Argo Workflows 3.7.11 / 4.0.2+ Fix from $1,9502026-03-11 HIGH 7.5 CVE-2026-30933 FileBrowser Quantum is a free, self-hosted, web-based file manager. Prior to 1.3.1-beta and 1.2.2-stable, the remediation for CVE-2026-27611 is incom… Filebrowser after 1.2.9 Fix from $1,9502026-03-10 HIGH 7.5 CVE-2026-2339 Missing Authentication for Critical Function vulnerability in TUBITAK BILGEM Software Technologies Research Institute Liderahenk allows Remote Code I… Mitigation only Fix from $1,9502026-03-10 HIGH 7.5 CVE-2026-23662 Missing authentication for critical function in Azure IoT Explorer allows an unauthorized attacker to disclose information over a network. Azure Iot Explorer 0.15.13+ Fix from $1,9502026-03-10 MEDIUM 5.3 CVE-2026-30885 WWBN AVideo is an open source video platform. Prior to 25.0, the /objects/playlistsFromUser.json.php endpoint returns all playlists for any user with… Avideo 25.0+ Fix from $1,6002026-03-10 MEDIUM 5.3 CVE-2026-1920 The Booking Calendar for Appointments and Service Businesses – Booktics plugin for WordPress is vulnerable to unauthorized modification of data due t… Mitigation only Fix from $1,6002026-03-10 MEDIUM 5.3 CVE-2026-1919 The Booking Calendar for Appointments and Service Businesses – Booktics plugin for WordPress is vulnerable to unauthorized access of data due to a mi… Mitigation only Fix from $1,6002026-03-10 CRITICAL 9.8 CVE-2026-30824EPSS 36% Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.0.13, the NVIDIA NIM router (/api/v1/nvid… Flowise 3.0.13+ Fix from $2,3002026-03-07 HIGH 7.5 CVE-2026-25071 XikeStor SKS8310-8X Network Switch firmware versions 1.04.B07 and prior contain a missing authentication vulnerability in the /switch_config.src endp… Zikestor Sks8310 8x Firmware after 1.04.b07 Fix from $1,9502026-03-07 HIGH 7.5 CVE-2026-30846 Wekan is an open source kanban tool built with Meteor. In versions 8.31.0 through 8.33, the globalwebhooks publication exposes all global webhook int… Wekan 8.33+ Fix from $1,9502026-03-06 CRITICAL 9.8 CVE-2026-26288 WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersonation and manipulate data sent … Api.everon.io Mitigation only Fix from $2,3002026-03-06