Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-5676 |
|
Authentication Bypass in CVE-2026-5676 (CVE-2026-5676)
authentication bypass in CVE-2026-5676 (CVE-2026-5676). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-35030 |
|
Authentication Bypass in litellm (CVE-2026-35030)
authentication bypass in litellm (CVE-2026-35030). Confidential information can be exposed externally. Mitigation: upgrade to `1.83.0` or later.
|
| CVE-2026-5632 |
|
Authentication Bypass in CVE-2026-5632 (CVE-2026-5632)
authentication bypass in CVE-2026-5632 (CVE-2026-5632). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-5616 |
|
Authentication Bypass in CVE-2026-5616 (CVE-2026-5616)
authentication bypass in CVE-2026-5616 (CVE-2026-5616). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-5570 |
|
Authentication Bypass in technostrobe (CVE-2026-5570)
authentication bypass in technostrobe (CVE-2026-5570). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-5557 |
|
Authentication Bypass in CVE-2026-5557 (CVE-2026-5557)
authentication bypass in CVE-2026-5557 (CVE-2026-5557). Risk of unauthorized operations or information disclosure.
|
| CVE-2017-20235 |
|
Authentication Bypass in prosoft-technology (CVE-2017-20235)
authentication bypass in prosoft-technology (CVE-2017-20235). Confidential information can be exposed externally.
|
| CVE-2018-25236 |
|
Authentication Bypass in CVE-2018-25236 (CVE-2018-25236)
authentication bypass in CVE-2018-25236 (CVE-2018-25236). Successful exploitation can lead to full system takeover.
|
| CVE-2026-34990 |
|
Authentication Bypass in openprinting (CVE-2026-34990)
authentication bypass in openprinting (CVE-2026-34990). Successful exploitation can lead to full system takeover.
|
| CVE-2026-33175 |
|
Authentication Bypass in jupyter (CVE-2026-33175)
authentication bypass in jupyter (CVE-2026-33175). Successful exploitation can lead to full system takeover.
|
| CVE-2017-20237 |
|
Authentication Bypass in CVE-2017-20237 (CVE-2017-20237)
authentication bypass in CVE-2017-20237 (CVE-2017-20237). Successful exploitation can lead to full system takeover.
|
| CVE-2026-32173 |
|
Authentication Bypass in microsoft (CVE-2026-32173)
authentication bypass in microsoft (CVE-2026-32173). Confidential information can be exposed externally.
|
| CVE-2026-34834 |
|
Authentication Bypass in bulwarkmail (CVE-2026-34834)
authentication bypass in bulwarkmail (CVE-2026-34834). Data can be tampered with by attackers.
|
| CVE-2024-14034 |
|
Authentication Bypass in CVE-2024-14034 (CVE-2024-14034)
authentication bypass in CVE-2024-14034 (CVE-2024-14034). Successful exploitation can lead to full system takeover.
|
| CVE-2026-34736 |
|
Authentication Bypass in CVE-2026-34736 (CVE-2026-34736)
authentication bypass in CVE-2026-34736 (CVE-2026-34736). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-34121 |
|
Authentication Bypass in tp-link (CVE-2026-34121)
authentication bypass in tp-link (CVE-2026-34121). Successful exploitation can lead to full system takeover.
|
| CVE-2026-33746 |
|
Authentication Bypass in convoypanel (CVE-2026-33746)
authentication bypass in convoypanel (CVE-2026-33746). Successful exploitation can lead to full system takeover.
|
| CVE-2026-34531 |
|
Authentication Bypass in Flask-HTTPAuth (CVE-2026-34531)
authentication bypass in Flask-HTTPAuth (CVE-2026-34531). Data can be tampered with by attackers. Exploitable via ``token``. Mitigation: upgrade to `4.8.1` or later.
|
| CVE-2026-34873 |
|
Authentication Bypass in trustedfirmware (CVE-2026-34873)
authentication bypass in trustedfirmware (CVE-2026-34873). Confidential information can be exposed externally.
|
| CVE-2026-34072 |
|
Authentication Bypass in fccview (CVE-2026-34072)
authentication bypass in fccview (CVE-2026-34072). Confidential information can be exposed externally.
|
| CVE-2026-34204 |
|
Authentication Bypass in minio (CVE-2026-34204)
authentication bypass in minio (CVE-2026-34204). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-27856 |
|
Authentication Bypass in dovecot (CVE-2026-27856)
authentication bypass in dovecot (CVE-2026-27856). Confidential information can be exposed externally.
|
| CVE-2026-32305 |
|
Authentication Bypass in traefik (CVE-2026-32305)
authentication bypass in traefik (CVE-2026-32305). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-14716 |
|
Authentication Bypass in CVE-2025-14716 (CVE-2025-14716)
authentication bypass in CVE-2025-14716 (CVE-2025-14716). Confidential information can be exposed externally.
|
| CVE-2026-1524 |
|
Authentication Bypass in neo4j (CVE-2026-1524)
authentication bypass in neo4j (CVE-2026-1524). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `5.26.22, 2026.2.0` or later.
|
| CVE-2026-23813 |
|
Authentication Bypass in hpe (CVE-2026-23813)
authentication bypass in hpe (CVE-2026-23813). Successful exploitation can lead to full system takeover.
|
| CVE-2026-26128 |
|
Authentication Bypass in microsoft (CVE-2026-26128)
authentication bypass in microsoft (CVE-2026-26128). Successful exploitation can lead to full system takeover.
|
| CVE-2026-24294 |
|
Authentication Bypass in microsoft (CVE-2026-24294)
authentication bypass in microsoft (CVE-2026-24294). Successful exploitation can lead to full system takeover.
|
| CVE-2017-7921 KEV |
|
[KEV] Authentication Bypass in Hikvision multiple-products (CVE-2017-7921)
authentication bypass in Hikvision multiple-products (CVE-2017-7921). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2026-23600 |
|
A remote authentication bypass vulnerability
exists in HPE AutoPass License Server (APLS).
A remote authentication bypass vulnerability
exists in HPE AutoPass License Server (APLS).
|
| CVE-2025-71057 |
|
Authentication Bypass in CVE-2025-71057 (CVE-2025-71057)
authentication bypass in CVE-2025-71057 (CVE-2025-71057). Data can be tampered with by attackers.
|
| CVE-2026-20127 KEV |
|
[KEV] Authentication Bypass in Cisco catalyst-sd-wan-controller-and-manager (CVE-2026-20127)
authentication bypass in Cisco catalyst-sd-wan-controller-and-manager (CVE-2026-20127). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2026-27134 |
|
Authentication Bypass in apache (CVE-2026-27134)
authentication bypass in apache (CVE-2026-27134). Successful exploitation can lead to full system takeover.
|
| CVE-2025-7630 |
|
Authentication Bypass in CVE-2025-7630 (CVE-2025-7630)
authentication bypass in CVE-2025-7630 (CVE-2025-7630). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-10463 |
|
Authentication Bypass in CVE-2025-10463 (CVE-2025-10463)
authentication bypass in CVE-2025-10463 (CVE-2025-10463). Risk of unauthorized operations or information disclosure.
|
| CVE-2019-19006 KEV |
|
[KEV] Authentication Bypass in Sangoma freepbx (CVE-2019-19006)
authentication bypass in Sangoma freepbx (CVE-2019-19006). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2025-65397 |
|
Vulnerability in blurams (CVE-2025-65397)
vulnerability in blurams (CVE-2025-65397). Successful exploitation can lead to full system takeover.
|
| CVE-2025-66698 |
|
Authentication Bypass in semantic-machines (CVE-2025-66698)
authentication bypass in semantic-machines (CVE-2025-66698). Confidential information can be exposed externally.
|
| CVE-2025-60534 |
|
Authentication Bypass in blueaccesstech (CVE-2025-60534)
authentication bypass in blueaccesstech (CVE-2025-60534). Successful exploitation can lead to full system takeover.
|
| CVE-2025-67158 |
|
Authentication Bypass in revotech (CVE-2025-67158)
authentication bypass in revotech (CVE-2025-67158). Confidential information can be exposed externally.
|
| CVE-2025-64055 |
|
Authentication Bypass in fanvil (CVE-2025-64055)
authentication bypass in fanvil (CVE-2025-64055). Successful exploitation can lead to full system takeover.
|
| CVE-2025-59704 |
|
Authentication Bypass in entrust (CVE-2025-59704)
authentication bypass in entrust (CVE-2025-59704). Data can be tampered with by attackers.
|
| CVE-2025-56447 |
|
TM2 Monitoring v3.04 contains an authentication bypass and plaintext credential disclosure.
TM2 Monitoring v3.04 contains an authentication bypass and plaintext credential disclosure.
|
| CVE-2025-61884 KEV |
|
[KEV] Path Traversal in Oracle e-business-suite (CVE-2025-61884)
path traversal in Oracle e-business-suite (CVE-2025-61884). Confidential information can be exposed externally. Listed in CISA KEV — actively exploited.
|
| CVE-2016-7836 KEV |
|
[KEV] Authentication Bypass in Skysea client-view (CVE-2016-7836)
authentication bypass in Skysea client-view (CVE-2016-7836). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2025-60306 |
|
Vulnerability in code-projects (CVE-2025-60306)
vulnerability in code-projects (CVE-2025-60306). Successful exploitation can lead to full system takeover.
|
| CVE-2025-61882 KEV |
|
[KEV] Authentication Bypass in Oracle e-business-suite (CVE-2025-61882)
authentication bypass in Oracle e-business-suite (CVE-2025-61882). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2015-7755 KEV |
|
[KEV] Authentication Bypass in Juniper screenos (CVE-2015-7755)
authentication bypass in Juniper screenos (CVE-2015-7755). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2025-34186 |
|
OS Command Injection in ilevia (CVE-2025-34186)
OS command injection in ilevia (CVE-2025-34186). Successful exploitation can lead to full system takeover.
|
| CVE-2025-51451 |
|
Authentication Bypass in totolink (CVE-2025-51451)
authentication bypass in totolink (CVE-2025-51451). Successful exploitation can lead to full system takeover.
|