Vulnerability index

Browse CVEs

2,855 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthenticationCWE-306 × clear
CRITICAL 9.8 CVE-2026-41452 Krayin CRM 2.2.4 contains a missing authentication vulnerability in the installer middleware that allows unauthenticated remote attackers to overwrit… No fix yet Fix from $2,3002026-08-03 HIGH 7.5 CVE-2026-69091 Admidio before 5.0.11 contains an authentication bypass vulnerability in the forum module when configured in login-only mode. The access control logi… No fix yet Fix from $1,9502026-08-03 HIGH 7.5 CVE-2026-68578 ArcadeDB versions before 26.7.3 fail to bind the authenticated principal in the MCP HTTP transport, causing all engine permission checks to silently … No fix yet Fix from $1,9502026-08-02 MEDIUM 6.5 CVE-2026-17348 In SERVER mode, pgAdmin 4 enforces authentication per route via the @pga_login_required decorator; the application's before_request hook only handles… Pgadmin 4 9.17+ Fix from $1,6002026-07-31 HIGH 7.5 CVE-2026-65310 ANDRITZ HIPASE-250 (formerly 250 SCALA), in the default configuration of affected versions, exposes its data and configuration endpoint without any a… No fix yet Fix from $1,9502026-07-31 MEDIUM 5.3 CVE-2026-65311 The HTTP server component of ANDRITZ HIPASE-250 (formerly 250 SCALA) in affected versions exposes an undocumented endpoint that changes the server's … No fix yet Fix from $1,6002026-07-31 HIGH 8.8 CVE-2026-12562 The RCU II+ and Multiload II+ are vulnerable to an unauthenticated service that exposes a debug interface granting full root-level access to the em… No fix yet Fix from $1,9502026-07-30 CRITICAL 9.8 CVE-2026-68502 LazyOwn RedTeam/APT Framework is an AI-powered C2 and red-team operations framework. Prior to 0.2.154, LazyOwn's lazyc2.py registers an unauthenticat… No fix yet Fix from $2,3002026-07-30 CRITICAL 9.8 CVE-2026-67594 Spikster through commit e1cdf8c contains a missing authentication vulnerability that allows unauthenticated remote attackers to access all API routes… No fix yet Fix from $2,3002026-07-30 CRITICAL 9.8 CVE-2026-67208 Juggle through 1.6.0 contains a remote code execution vulnerability that allows unauthenticated remote attackers to execute arbitrary OS commands by … No fix yet Fix from $2,3002026-07-30 HIGH 7.5 CVE-2026-15978 SGLang contains a model weight exfiltration vulnerability when no API keys are configured, as SGLang will expose two endpoints that allow a remote at… Sglang after 0.5.15 Fix from $1,9502026-07-30 HIGH 7.5 CVE-2026-28814 Arbitrary Wiki Markup rendering due to lack of authentication in Apache JSPWiki up to 2.12.3 allows attacker to obtain sensitive data stored in JSPWi… Jspwiki 2.12.4+ Fix from $1,9502026-07-30 HIGH 7.5 CVE-2026-67349 OpenCost before 1.121.0 fails to authenticate the GET /helmValues endpoint, exposing base64-decoded HELM_VALUES environment variable containing cloud… No fix yet Fix from $1,9502026-07-30 HIGH 8.2 CVE-2026-12722 Missing authentication for critical function vulnerability in FTC Software IT Services FTC E-Commerce Management Panel allows Authentication Bypass. … No fix yet Fix from $1,9502026-07-30 HIGH 7.5 CVE-2026-54365 CentreStack before 17.3 contains an unauthenticated deserialization vulnerability in GSNamespace.dll that allows unauthenticated attackers to create … No fix yet Fix from $1,9502026-07-30 HIGH 8.6 CVE-2026-54367 CentreStack before 17.2 contains an authentication bypass vulnerability that allows unauthenticated attackers to read, write, or delete arbitrary acc… No fix yet Fix from $1,9502026-07-30 CRITICAL 9.4 CVE-2026-44100 The CHARX JupiCore service allows an unauthenticated remote attacker to reconfigure charging points. This can lead to disclosure of charging point UI… No fix yet Fix from $2,3002026-07-30 CRITICAL 9.8 CVE-2026-44101 Due to missing authentication the CHARX OCPP Agent service allows an unauthenticated remote attacker to reconfigure the backend connection. This can … No fix yet Fix from $2,3002026-07-30 CRITICAL 9.8 CVE-2026-44090 Due to missing authentication, an unauthenticated remote attacker may access the MQTT broker, which is only protected from external access by a firew… No fix yet Fix from $2,3002026-07-30 HIGH 8.0 CVE-2026-47858 Starting Spring Boot applications in the Spring Tools with the live information mode enabled makes the running application vulnerable against JMX-bas… No fix yet Fix from $1,9502026-07-30 HIGH 7.3 CVE-2026-16527 An unauthenticated remote attacker can bypass access controls by sending crafted requests to the PCP pmproxy /store endpoint. This allows the attacke… No fix yet Fix from $1,9502026-07-30 HIGH 7.5 CVE-2026-5057 ATEN Unizon RpcProvider Missing Authentication Denial-of-Service Vulnerability. This vulnerability allows remote attackers to create a denial-of-serv… No fix yet Fix from $1,9502026-07-29 CRITICAL 9.3 CVE-2026-67426 Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.7, the standalone flyto-verification service in src/core/veri… No fix yet Fix from $2,3002026-07-29 CRITICAL 9.8 CVE-2026-14529 IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 traditional is vulnerable to s… Websphere Application Server 8.5.5.31 / 9.0.5.29+ Fix from $2,3002026-07-29 CRITICAL 9.8 CVE-2026-60112 AMMOS Instrument Toolkit (AIT) GUI before 2.5.1 contains a missing authentication vulnerability that allows any unauthenticated network attacker to o… Ait Gui No fix yet Fix from $2,3002026-07-29 CRITICAL 9.8 CVE-2026-60113 AMMOS Instrument Toolkit (AIT) Deep Space Network (DSN) Interface before 2.2.2 contains a missing authentication vulnerability in the Space Link Exte… Ait Dsn No fix yet Fix from $2,3002026-07-29 CRITICAL 9.1 CVE-2026-62325 goshs is a feature-rich single-binary file server for red teamers and developers. From 2.1.3 until 2.1.4, the sftpserver/sftpserver.go password handl… No fix yet Fix from $2,3002026-07-28 CRITICAL 9.8 CVE-2026-14976 IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is affected by remote code execution with the collectiveController-1.0 feature e… Websphere Application Server 26.0.0.9+ Fix from $2,3002026-07-28 CRITICAL 9.8 CVE-2026-14446 IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to broken access control/privilege escalation in the administrative console. Websphere Application Server 8.5.5.30 / 9.0.5.28+ Fix from $2,3002026-07-28 HIGH 8.8 CVE-2026-16771 In firmware versions 2.7.7 and earlier, the Arris BGW210‑700 gateway fails to enforce any server‑side authentication on its /cgi-bin/*.ha management … No fix yet Fix from $1,9502026-07-28