Export limit exceeded: 15471 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (656 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2021-43718 | 2026-08-21 | 5.3 Medium | ||
| An Authentication Bypass vulnerability exists in EPSON EH-TW5350 EPSON 150075647YWWV110, which could let a remote malicious user cause a Denial of Service via specially crafted series of HTTP.. | ||||
| CVE-2026-73396 | 2 Makewebbetter, Wordpress | 2 Hubspot For Woocommerce, Wordpress | 2026-08-21 | 7.1 High |
| Subscriber Broken Authentication in MWB HubSpot for WooCommerce <= 1.6.7 versions. | ||||
| CVE-2026-74001 | 2 Wordpress, Wpeverest | 2 Wordpress, User Registration & Membership | 2026-08-21 | 9.8 Critical |
| Unauthenticated Broken Authentication in User Registration & Membership Pro <= 5.4.5 versions. | ||||
| CVE-2026-73399 | 2 Flutterwave, Wordpress | 2 Flutterwave Woocommerce, Wordpress | 2026-08-21 | 6.5 Medium |
| Unauthenticated Broken Authentication in Flutterwave WooCommerce <= 3.3.0 versions. | ||||
| CVE-2026-71879 | 1 Gbif | 1 Integrated Publishing Toolkit | 2026-08-21 | N/A |
| Missing authentication in initial setup functionality left exposed until first reboot in GBIF Integrated Publishing Toolkit versions before 3.3.4 allows remote authenticated attackers to gain administrative control via authentication bypass | ||||
| CVE-2026-66677 | 2 Vaultdweller, Wordpress | 2 Leyka, Wordpress | 2026-08-21 | 7.6 High |
| Subscriber Broken Authentication in Leyka <= 3.32.3 versions. | ||||
| CVE-2026-19490 | 1 Netscaler | 2 Adc, Gateway | 2026-08-20 | N/A |
| Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: from 14.1 through 73.32 and from 13.1 through 63.21; Gateway: from 14.1 through 73.32 and from 13.1 through 63.21. | ||||
| CVE-2026-22049 | 1 Netapp | 2 Ontap, Ontap 9 | 2026-08-20 | 8.8 High |
| ONTAP versions 9.16.1 and higher with WebAuthn multi-factor authentication (MFA) configured are susceptible to a vulnerability related to the Relying Party ID which when successfully exploited could allow an attacker with valid credentials to bypass MFA. | ||||
| CVE-2026-50191 | 1 Rargames | 1 4gaboards | 2026-08-18 | 8.8 High |
| 4gaBoards is a boards system for realtime project management. Prior to 3.3.8, 4gaBoards is vulnerable to pre-account takeover when registrationEnabled, localRegistrationEnabled, and ssoRegistrationEnabled are enabled and Google, GitHub, Microsoft, or OIDC SSO is configured. The POST /api/register endpoint permits creation of an unverified local account with a victim's email address, and POST /api/access-tokens permits that account to authenticate while isVerified is false. During the victim's first SSO login, server/api/helpers/users/get-create-one-for-github-sso.js, server/api/helpers/users/get-create-one-for-google-sso.js, server/api/helpers/users/get-create-one-for-microsoft-sso.js, and server/api/helpers/users/get-create-one-for-oidc-sso.js find the attacker-controlled account by email and link the verified SSO identity without confirming ownership of the local account. The attacker can retain local-password access to the linked account and obtain the victim's projects, data, and permissions. This issue is fixed in version 3.3.8. | ||||
| CVE-2026-73398 | 2 Papaki, Wordpress | 2 Piraeus Bank Woocommerce Payment Gateway, Wordpress | 2026-08-18 | 6.5 Medium |
| Unauthenticated Broken Authentication in Piraeus Bank WooCommerce Payment Gateway 3.2.0 versions. | ||||
| CVE-2026-73379 | 2026-08-18 | 6.5 Medium | ||
| Unauthenticated Bypass Vulnerability in Contact Form by Supsystic < 1.10.0 versions. | ||||
| CVE-2026-24185 | 1 Nvidia | 1 Nvos | 2026-08-18 | 7.1 High |
| NVIDIA NVOS for network switches contains a vulnerability in the secure shell (SSH) server configuration component while PKA-only mode is enabled, where an administrator could inadvertently enable an alternative authentication path. If best practices for replacing the default password as recommended by NVIDIA are not followed, this alternative authentication path might lead to unauthorized access. A successful exploit of this vulnerability might lead to escalation of privileges. | ||||
| CVE-2026-75627 | 1 Bastillion-io | 1 Bastillion | 2026-08-18 | 9.8 Critical |
| Bastillion fails to properly validate request URI paths in its controller dispatcher, allowing unauthenticated attackers to bypass authentication filters by prefixing requests with arbitrary path segments. Attackers can access administrative controllers to read user listings, create manager accounts, and register managed systems, gaining control over SSH access to the managed fleet. | ||||
| CVE-2026-32481 | 2 Ezoic, Wordpress | 2 Ezoic, Wordpress | 2026-08-18 | 7.5 High |
| Unauthenticated Broken Authentication in Ezoic <= 2.22.11 versions. | ||||
| CVE-2026-73381 | 2026-08-18 | 9.1 Critical | ||
| Unauthenticated Broken Authentication in Popup by Supsystic <= 1.13.0 versions. | ||||
| CVE-2026-75045 | 1 Jetbrains | 1 Youtrack | 2026-08-17 | 9.1 Critical |
| In JetBrains YouTrack before 2025.3.156085, 2026.1.13913, 2026.2.18112 an unauthenticated attacker could download database backups via shared draft signature | ||||
| CVE-2026-66465 | 2 Agnihd, Wordpress | 2 Cartify, Wordpress | 2026-08-14 | 9.8 Critical |
| Unauthenticated Broken Authentication in Cartify <= 1.3.0.1 versions. | ||||
| CVE-2026-66453 | 2 Dimitri Grassi, Wordpress | 2 Salon Booking System, Wordpress | 2026-08-13 | 9.8 Critical |
| Unauthenticated Broken Authentication in Salon booking system <= 10.30.26 versions. | ||||
| CVE-2026-45109 | 1 Vercel | 1 Next.js | 2026-08-13 | 7.5 High |
| Next.js is a React framework for building full-stack web applications. From 15.2.0 to before 15.5.18 and 16.2.6, it was found that the fix addressing CVE-2026-44575 did not apply to middleware.ts with Turbopack. This vulnerability is fixed in 15.5.18 and 16.2.6. | ||||
| CVE-2026-44575 | 1 Vercel | 1 Next.js | 2026-08-13 | 7.5 High |
| Next.js is a React framework for building full-stack web applications. From 15.2.0 to before 15.5.16 and 16.2.5, App Router applications that rely on middleware or proxy-based checks for authorization can allow unauthorized access through transport-specific route variants used for segment prefetching. In affected configurations, specially crafted .rsc and segment-prefetch URLs can resolve to the same page without being matched by the intended middleware rule, which can allow protected content to be reached without the expected authorization check. This vulnerability is fixed in 15.5.16 and 16.2.5. | ||||