Vulnerability index

Browse CVEs

2,866 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthenticationCWE-306 × clear
HIGH 8.1 CVE-2026-3192 A security vulnerability has been detected in Chia Blockchain 2.1.0. This issue affects the function _authenticate of the file rpc_server_base.py of … Blockchain No fix yet Fix from $1,9502026-02-25 MEDIUM 6.2 CVE-2026-27846 Due to missing authentication, a user with physical access to the device can misuse the mesh functionality for adding a new mesh device to the networ… Mitigation only Fix from $1,6002026-02-25 CRITICAL 9.8 CVE-2026-2624 Missing Authentication for Critical Function vulnerability in ePati Cyber ​​Security Technologies Inc. Antikor Next Generation Firewall (NGFW) allows… Antikor Next Generation Firewall 2.0.1301+ Fix from $2,3002026-02-25 HIGH 7.5 CVE-2026-27595 Parse Dashboard is a standalone dashboard for managing Parse Server apps. In versions 7.3.0-alpha.42 through 9.0.0-alpha.7, the AI Agent API endpoint… Parse Dashboard Mitigation only Fix from $1,9502026-02-25 HIGH 7.5 CVE-2026-26340 Tattile Smart+, Vega, and Basic device families firmware versions 1.181.5 and prior expose RTSP streams without requiring authentication. A remote at… Smart\+ Firmware after 1.181.5 Fix from $1,9502026-02-24 HIGH 7.5 CVE-2026-27584 Actual is a local-first personal finance tool. Prior to version 26.2.1, missing authentication middleware in the ActualBudget server component allows… Actual 26.2.1+ Fix from $1,9502026-02-24 CRITICAL 9.8 CVE-2025-14577 Slican NCP/IPL/IPM/IPU devices are vulnerable to PHP Function Injection. An unauthenticated remote attacker is able to execute arbitrary PHP commands… Ncp Firmware 1.24.0190 / 6.61.0010+ Fix from $2,3002026-02-24 CRITICAL 9.8 CVE-2026-3053 A vulnerability was determined in DataLinkDC dinky up to 1.2.5. This affects the function addInterceptors of the file dinky-admin/src/main/java/org/d… Dinky after 1.2.5 Fix from $2,3002026-02-24 CRITICAL 10.0 CVE-2026-23693 ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for Elementor (elementskit-lite) WordPress plugin versions prior to 3.7.9 expose t… Mitigation only Fix from $2,3002026-02-23 CRITICAL 9.1 CVE-2026-27471 ERP is a free and open source Enterprise Resource Planning tool. In versions up to 15.98.0 and 16.0.0-rc.1 and through 16.6.0, certain endpoints lack… Erpnext 15.98.1 / 16.6.1+ Fix from $2,3002026-02-21 HIGH 7.5 CVE-2026-26048 The Wi-Fi router is vulnerable to de-authentication attacks due to the absence of management frame protection, allowing forged deauthentication and… Mitigation only Fix from $1,9502026-02-20 HIGH 8.2 CVE-2026-24790 The underlying PLC of the device can be remotely influenced, without proper safeguards or authentication. No fix yet Fix from $1,9502026-02-20 CRITICAL 9.8 CVE-2025-30410 Sensitive data disclosure and manipulation due to missing authentication. The following products are affected: Acronis Cyber Protect Cloud Agent (Lin… Mitigation only Fix from $2,3002026-02-20 HIGH 7.5 CVE-2026-26319 OpenClaw is a personal AI assistant. Versions 2026.2.13 and below allow the optional @openclaw/voice-call plugin Telnyx webhook handler to accept uns… Openclaw 2026.2.14+ Fix from $1,9502026-02-19 CRITICAL 9.8 CVE-2025-8350 Execution After Redirect (EAR), Missing Authentication for Critical Function vulnerability in Inrove Software and Internet Services BiEticaret CMS al… Mitigation only Fix from $2,3002026-02-19 MEDIUM 5.3 CVE-2025-14294 The Razorpay for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the getCoup… Mitigation only Fix from $1,6002026-02-19 HIGH 8.4 CVE-2026-27182 Saturn Remote Mouse Server contains a command injection vulnerability that allows unauthenticated attackers to execute arbitrary commands by sending … Mitigation only Fix from $1,9502026-02-18 HIGH 7.7 CVE-2025-1272 The Linux Kernel lockdown mode for kernel versions starting on 6.12 and above for Fedora Linux has the lockdown mode disabled without any warning. Th… Mitigation only Fix from $1,9502026-02-18 HIGH 7.5 CVE-2025-70147 Missing authentication in /admin/student.php and /admin/teacher.php in ProjectWorlds Online Time Table Generator 1.0 allows remote attackers to obtai… Online Time Table Generator No fix yet Fix from $1,9502026-02-18 CRITICAL 9.4 CVE-2025-70141 SourceCodester Customer Support System 1.0 contains an incorrect access control vulnerability in ajax.php. The AJAX dispatcher does not enforce authe… Customer Support System No fix yet Fix from $2,3002026-02-18 CRITICAL 9.1 CVE-2025-70146 Missing authentication in multiple administrative action scripts under /admin/ in ProjectWorlds Online Time Table Generator 1.0 allows remote attacke… Online Time Table Generator No fix yet Fix from $2,3002026-02-18 CRITICAL 9.8 CVE-2026-1670 The affected products are vulnerable to an unauthenticated API endpoint exposure, which may allow an attacker to remotely change the "forgot password… Mitigation only Fix from $2,3002026-02-17 MEDIUM 6.1 CVE-2025-7706 Missing Authentication for Critical Function vulnerability in TUBITAK BILGEM Software Technologies Research Institute Liderahenk allows Remote Code I… Mitigation only Fix from $1,6002026-02-17 CRITICAL 10.0 CVE-2026-2577 The WhatsApp bridge component in Nanobot binds the WebSocket server to all network interfaces (0.0.0.0) on port 3001 by default and does not require … Mitigation only Fix from $2,3002026-02-16 MEDIUM 6.8 CVE-2025-32063 There is a misconfiguration vulnerability inside the Infotainment ECU manufactured by BOSCH. The vulnerability happens during the startup phase of a … Mitigation only Fix from $1,6002026-02-15 MEDIUM 5.3 CVE-2025-6792 The One to one user Chat by WPGuppy plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the /wp-js… Mitigation only Fix from $1,6002026-02-14 CRITICAL 9.8 CVE-2026-26333 Calero VeraSMART versions prior to 2022 R1 expose an unauthenticated .NET Remoting HTTP service on TCP port 8001. The service publishes default Objec… Verasmart 2022.0+ Fix from $2,3002026-02-13 CRITICAL 9.8 CVE-2026-26190EPSS 37% Milvus is an open-source vector database built for generative AI applications. Prior to 2.5.27 and 2.6.10, Milvus exposes TCP port 9091 by default, w… Milvus 2.5.27 / 2.6.10+ Fix from $2,3002026-02-13 HIGH 8.8 CVE-2025-14349 Privilege Defined With Unsafe Actions, Missing Authentication for Critical Function vulnerability in Universal Software Inc. FlexCity/Kiosk allows Ac… Flexcity 1.0.36+ Fix from $1,9502026-02-13 HIGH 7.5 CVE-2026-26055 Yoke is a Helm-inspired infrastructure-as-code (IaC) package deployer. In 0.19.0 and earlier, a vulnerability exists in the Air Traffic Controller (A… Yoke after 0.19.0 Fix from $1,9502026-02-12