Export limit exceeded: 389339 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (4368 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-86207 | 1 N-able | 1 N-central | 2026-09-08 | N/A |
| An authentication bypass in N-central < 2026.3 HF 3 leads to authentication bypass in internal only APIs | ||||
| CVE-2026-67277 | 1 Mikrotik | 1 Routeros | 2026-09-08 | N/A |
| RouterOS accepts a "related" btest connection before the corresponding primary session has completed authentication. An unauthenticated client can use this state to start an IPv4 UDP test. With "random-data=false", the sender transmits an uninitialized tail from a kernel packet buffer. A separate unchecked, inverted packet-size interval causes unsigned integer underflow, anomalously large fragmented output, and can restart the RouterOS kernel. This issue was fixed in versions: 6.49.21 (Long-term), 7.23.4 (Long-term) and 7.24.2 (Stable) | ||||
| CVE-2026-16876 | 1 Nec | 1 Univerge Ix | 2026-09-08 | N/A |
| An authentication bypass vulnerability exists in the WebGUI of Series UNIVERGE IX-R/IX-V. A user could bypass authentication and execute arbitrary CLI commands by tampering with WebGUI messages and sending them to the device via internet. | ||||
| CVE-2026-86729 | 1 Wwbn | 1 Avideo | 2026-09-08 | 7.4 High |
| WWBN AVideo through commit e01e41ecc (no patched version available) exposes get_api_preauthorize in plugin/API/API.php as a second, undocumented login path. Unlike get_api_signIn, which enforces a rate limit of 10 attempts per 5 minutes via checkRateLimit(), get_api_preauthorize performs the same credential check with no throttling for any client, allowing unlimited remote password guessing against arbitrary accounts, including admin. The endpoint also acts as a credential oracle: it returns the message "Invalid credentials" for both correct and incorrect passwords, while the users_id field in the response body discloses the authenticated identity (users_id:1 on success, users_id:0 on failure), and a correct password establishes a session cookie that remains usable for authenticated API requests. Together these issues permit unauthenticated brute-force account takeover. | ||||
| CVE-2026-86727 | 1 Wwbn | 1 Avideo | 2026-09-08 | 7.5 High |
| AVideo through 29.0 contains an information disclosure vulnerability in plugin/Live/stats.json.php that allows unauthenticated attackers to retrieve stream keys and m3u8 URLs by accessing the endpoint without authentication. Attackers can enumerate private, unlisted, and group-restricted live streams by parsing the hidden_applications array in the JSON response to obtain sensitive streaming credentials. | ||||
| CVE-2026-86293 | 1 Sourcecodester | 1 Simple Traffic Offense System | 2026-09-08 | 6.5 Medium |
| A flaw has been found in SourceCodester Simple Traffic Offense System 1.0. Affected by this vulnerability is an unknown functionality of the file delete-user.php of the component Deletion Endpoint. Executing a manipulation of the argument ID can lead to missing authentication. The attack may be launched remotely. The exploit has been published and may be used. | ||||
| CVE-2026-86259 | 1 Thu-maic | 1 Openmaic | 2026-09-08 | 7.5 High |
| OpenMAIC before 1.0.1 skips server-side request forgery validation in non-production builds, allowing unauthenticated attackers to reach cloud instance metadata services. Attackers can supply arbitrary provider URLs via the x-base-url header or baseUrl parameter to access sensitive cloud credentials and metadata. | ||||
| CVE-2026-85702 | 1 Ramon-victor | 1 Freegpt-webui | 2026-09-08 | 7.3 High |
| A security vulnerability has been detected in ramon-victor freegpt-webui up to 098db3dfeb41555c2ca9269df0f13e10ec1c35dc. Affected is the function _conversation of the file server/backend.py of the component Backend Conversation API. Such manipulation of the argument model leads to missing authentication. The attack may be launched remotely. The exploit has been disclosed publicly and may be used. This product operates on a rolling release basis, ensuring continuous delivery. Consequently, there are no version details for either affected or updated releases. This vulnerability only affects products that are no longer supported by the maintainer. | ||||
| CVE-2026-19397 | 1 Asus | 1 Control Center Express Agent | 2026-09-08 | N/A |
| Missing authentication for a critical function in ASUS Control Center Express Agent allows an unauthenticated nearby user to control the host via a direct connection to the agent when the host has an active login session. Refer to the ' Security Update for ASUS Control Center Express Agent ' section on the ASUS Security Advisory for more information. | ||||
| CVE-2026-86506 | 1 Jetbrains | 1 Goland | 2026-09-08 | 5.9 Medium |
| In JetBrains GoLand before 2026.2.2.1 missing authentication on the GoLand profiler's injected pprof server exposed profiling data | ||||
| CVE-2026-86502 | 1 Jetbrains | 1 Intellij Idea | 2026-09-08 | 8.4 High |
| In JetBrains IntelliJ IDEA before 2026.2.2 missing TLS and authentication on the IJent gRPC server allowed local code execution on Remote Development hosts | ||||
| CVE-2026-86486 | 1 Jetbrains | 1 Youtrack | 2026-09-08 | 3.7 Low |
| In JetBrains YouTrack before 2026.2.18634 the generic VCS webhook handler failed open when its secret was blank | ||||
| CVE-2026-86480 | 1 Jetbrains | 1 Hub | 2026-09-08 | 9.8 Critical |
| In JetBrains Hub before 2026.2.52442 an unauthenticated attacker could register a trusted service and gain superuser privileges | ||||
| CVE-2026-86543 | 1 Knowns-dev | 1 Knowns | 2026-09-08 | 9.8 Critical |
| knowns versions before 0.30.0 serve the management API without authentication on all network interfaces by default, with no password required on fresh installations. Attackers can access the unauthenticated /api/tunnel/start endpoint to provision a public tunnel and republish the API at a publicly accessible address. | ||||
| CVE-2026-20514 | 1 Mediatek, Inc. | 1 Mediatek Chipset | 2026-09-07 | 4.4 Medium |
| In Audio HAL, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11087632; Issue ID: MSV-8244. | ||||
| CVE-2026-86292 | 1 Sourcecodester | 1 Simple Traffic Offense System | 2026-09-07 | 7.3 High |
| A vulnerability was detected in SourceCodester Simple Traffic Offense System 1.0. Affected is an unknown function of the file saveuser.php of the component User Creation. Performing a manipulation of the argument position results in missing authentication. The attack may be initiated remotely. The exploit is now public and may be used. | ||||
| CVE-2026-75430 | 1 Powerjob | 1 Powerjob | 2026-09-07 | 9.8 Critical |
| PowerJob Worker version 5.1.2 (and likely earlier versions) exposes the /worker/deployContainer HTTP endpoint without authentication on the default transport port. This allows a remote attacker to execute arbitrary code. | ||||
| CVE-2026-71625 | 1 Slimkit | 1 Thinksns+ | 2026-09-07 | N/A |
| An issue in slimkit plus ThinkSNS+ v.2.4 allows a remote attacker to escalate privileges via the ResetPasswordController.php component | ||||
| CVE-2026-85688 | 1 Ten-framework | 1 Ten-framework | 2026-09-07 | 9.8 Critical |
| TEN Framework 0.11.71 contains unauthenticated arbitrary file read and write vulnerabilities in the TMAN Designer file-content API endpoints. Attackers can submit POST and PUT requests to the /api/designer/v1/file-content endpoints to read arbitrary files or write malicious content to system paths, enabling code execution through authorized_keys, cron files, or executable graph files. | ||||
| CVE-2026-86124 | 1 Hkuds | 1 Autoagent | 2026-09-07 | 9.8 Critical |
| AutoAgent contains an unauthenticated remote code execution vulnerability in the TCP server that binds to all interfaces and executes attacker-supplied commands as root. Attackers can connect to the exposed communication port and execute arbitrary bash commands within the container, gaining access to bind-mounted host workspace directories. | ||||