Vulnerability index

Browse CVEs

2,866 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthenticationCWE-306 × clear
HIGH 7.5 CVE-2026-2754 Navtor NavBox exposes sensitive configuration and operational data due to missing authentication on HTTP API endpoints. An unauthenticated remote att… Navbox Firmware 4.16.2.4+ Fix from $1,9502026-03-06 CRITICAL 9.8 CVE-2026-26051 WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersonation and manipulate data sent … Mobiliti E Mobi.hu Mitigation only Fix from $2,3002026-03-06 HIGH 7.5 CVE-2026-27603 Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. Prior to version 4.8.4… Chartbrew 4.8.4+ Fix from $1,9502026-03-06 CRITICAL 9.8 CVE-2026-22552 WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersonation and manipulate data sent … Epower.ie Mitigation only Fix from $2,3002026-03-06 CRITICAL 9.8 CVE-2026-26125 Payment Orchestrator Service Elevation of Privilege Vulnerability Payment Orchestrator Service No fix yet Fix from $2,3002026-03-05 MEDIUM 5.9 CVE-2026-29613 OpenClaw versions prior to 2026.2.12 contain a vulnerability in the BlueBubbles (optional plugin) webhook handler in which it authenticates requests … Openclaw 2026.2.12+ Fix from $1,6002026-03-05 HIGH 7.8 CVE-2026-28485 OpenClaw versions 2026.1.5 prior to 2026.2.12 fail to enforce mandatory authentication on the /agent/act browser-control HTTP route, allowing unautho… Openclaw 2026.2.12+ Fix from $1,9502026-03-05 MEDIUM 6.5 CVE-2026-29606 OpenClaw versions prior to 2026.2.14 contain a webhook signature-verification bypass in the voice-call extension that allows unauthenticated requests… Openclaw 2026.2.14+ Fix from $1,6002026-03-05 CRITICAL 9.8 CVE-2026-28472 OpenClaw versions prior to 2026.2.2 contain a vulnerability in the gateway WebSocket connect handshake in which it allows skipping device identity ch… Openclaw 2026.2.2+ Fix from $2,3002026-03-05 HIGH 7.7 CVE-2026-28468 OpenClaw versions 2026.1.29-beta.1 prior to 2026.2.14 contain a vulnerability in the sandbox browser bridge server in which it accepts requests witho… Openclaw 2026.2.14+ Fix from $1,9502026-03-05 MEDIUM 5.4 CVE-2026-28458 OpenClaw version 2026.1.20 prior to 2026.2.1 contains a vulnerability in the Browser Relay (extension must be installed and enabled) /cdp WebSocket e… Openclaw 2026.2.1+ Fix from $1,6002026-03-05 HIGH 8.2 CVE-2026-28450 OpenClaw versions prior to 2026.2.12 with the optional Nostr plugin enabled expose unauthenticated HTTP endpoints at /api/channels/nostr/:accountId/p… Openclaw 2026.2.12+ Fix from $1,9502026-03-05 CRITICAL 9.8 CVE-2026-27944EPSS 22% Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.3, the /api/backup endpoint is accessible without authentication and … Nginx Ui 2.3.3+ Fix from $2,3002026-03-05 CRITICAL 9.8 CVE-2026-23767 ESC/POS, a printer control language designed by Seiko Epson Corporation, lacks mechanisms for user authentication and command authorization, does not… Sb H50 Firmware Mitigation only Fix from $2,3002026-03-05 CRITICAL 9.8 CVE-2026-27446EPSS 10% Missing Authentication for Critical Function (CWE-306) vulnerability in Apache Artemis, Apache ActiveMQ Artemis. An unauthenticated remote attacker c… Artemis after 2.44.0 Fix from $2,3002026-03-04 CRITICAL 9.8 CVE-2026-27012 OpenSTAManager is an open source management software for technical assistance and invoicing. In 2.9.8 and earlier, a privilege escalation and authent… Openstamanager after 2.9.8 Fix from $2,3002026-03-03 HIGH 8.8 CVE-2026-1775 The Labkotec LID-3300IP has an existing vulnerability in the ice detector software that enables an unauthenticated attacker to alter device parameter… Mitigation only Fix from $1,9502026-03-03 CRITICAL 9.0 CVE-2025-30035 The vulnerability enables an attacker to fully bypass authentication in CGM CLININET and gain access to any active user account by supplying only the… Mitigation only Fix from $2,3002026-03-02 HIGH 7.5 CVE-2026-2844 Missing Authentication for Critical Function vulnerability in Microchip TimePictra allows Configuration/Environment Manipulation.This issue affects T… Timepictra after 11.3 Fix from $1,9502026-02-28 MEDIUM 6.5 CVE-2026-28352 Indico is an event management system that uses Flask-Multipass, a multi-backend authentication system for Flask. In versions prior to 3.3.11, the API… Indico 3.3.11+ Fix from $1,6002026-02-27 CRITICAL 9.8 CVE-2026-27028 WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersonation and manipulate data sen… Mobility46.se Mitigation only Fix from $2,3002026-02-27 CRITICAL 9.8 CVE-2026-27767 WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersonation and manipulate data sen… Swtchenergy.com Mitigation only Fix from $2,3002026-02-27 CRITICAL 9.8 CVE-2026-27772 WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersonation and manipulate data sen… Ev.energy Mitigation only Fix from $2,3002026-02-27 CRITICAL 9.8 CVE-2026-25851 WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersonation and manipulate data sen… Chargemap.com Mitigation only Fix from $2,3002026-02-27 CRITICAL 9.8 CVE-2026-24731 WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersonation and manipulate data sen… Ev2go.io Mitigation only Fix from $2,3002026-02-27 CRITICAL 9.8 CVE-2026-20781 WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersonation and manipulate data sen… Cloudcharge.se Mitigation only Fix from $2,3002026-02-27 HIGH 7.5 CVE-2026-27449 Umbraco Engage is a business intelligence platform. A vulnerability has been identified in Umbraco Engage prior to versions 16.2.1 and 17.1.1 where c… Mitigation only Fix from $1,9502026-02-26 CRITICAL 9.8 CVE-2026-22207 OpenViking through version 0.1.18, prior to commit 0251c70, contains a broken access control vulnerability that allows unauthenticated attackers to g… Patch available Fix from $2,3002026-02-26 HIGH 8.0 CVE-2026-27509 Unitree Go2 firmware versions V1.1.7 through V1.1.9, and V1.1.11 (EDU) do not implement DDS authentication or authorization for the Eclipse CycloneDD… Go2 Firmware after 1.1.9 Fix from $1,9502026-02-26 HIGH 7.0 CVE-2026-3194 A flaw has been found in Chia Blockchain 2.1.0. The affected element is the function send_transaction/get_private_key of the component RPC Server Mas… Blockchain No fix yet Fix from $1,9502026-02-25