CVE & CISA-KEV Catalog

384,908 CVEs1,688 actively exploited (KEV)
Active:
  • CVSS 8.1 v3·EPSS 0.3%·No fix yet

    Gophish through 0.12.1 fails to enforce account lockout and password change requirements in the API authentication middleware. Attackers with valid API keys can bypass these security controls and retain full API access even when their account is locked or password change is required.

    Published 2026-08-28

  • CVSS 9.8 v3·EPSS 0.7%·No fix yet

    Xiiaozet LK100Wt contains an authentication weakness within an administrative service that may allow an attacker to bypass intended access controls and obtain command execution capabilities. Successful exploitation could allow unauthorized interaction with privileged functionality and may lead to complete device compromise.

    Published 2026-08-28

  • CVSS 9.3 v4·EPSS 0.5%·No fix yet

    A vulnerability allowing an unauthenticated network attacker to coerce SMB authentication from the service account.

    Published 2026-08-26

  • CVSS 5.5 v3·EPSS 0.2%·Fix available

    GitLab has remediated an issue in GitLab EE affecting all versions from 11.3 before 19.1.7, 19.2 before 19.2.5, and 19.3 before 19.3.1 that, under certain conditions, an authenticated user with project Maintainer permissions could have accessed the terminal of a protected environment they were not authorized to use due to improper authorization checks.

    Published 2026-08-26

  • CVSS 8.1 v3·EPSS 0.2%·No fix yet

    In FreeBSD 15.0, the kernel structure used to represent user credentials changed: previously the primary group ID was stored in the first element of the array containing the list of supplementary group IDs, whereas now the primary group ID is stored in a dedicated field. This change was largely internal to the kernel and not user-visible. One function, group_is_primary(), was not properly updated as a part of this transition. This function is used by mac_do to determine the primary group ID of the credential after applying a transition rule, used when the rule target does not explicitly specify a group. As a result, with certain mac_do rules, it is possible for a credential switch to incorrectly set the primary group ID to the ID stored in the first element of the original credential's

    Published 2026-08-26

  • CVSS 9.8 v3·EPSS 0.3%·No fix yet

    Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Internationalization Single Sign-On allows Authentication Bypass. This issue affects Internationalization Single Sign-On versions: from 0.0.0 to 1.8.0.

    Published 2026-08-25

  • CVSS 8.6 v3·EPSS 0.3%·No fix yet

    The SMS control function of IE-SR-2TX-WL-4G devices can require a password for SMS commands via the 'Enable Password Authorization' setting. The device increments a retry counter on each failed SMS password attempt; after 5 consecutive failed attempts, SMS password authorization is automatically disabled. An unauthenticated remote attacker who is able to send SMS messages to the device can deliberately trigger this by submitting 5 or more invalid passwords, after which subsequent SMS commands are executed without requiring a password, resulting in potential limited configuration tampering, limited information leakage and potentially full loss of availability.

    Published 2026-08-25

  • CVSS 7.3 v3·EPSS 0.2%·No fix yet

    Unauthenticated Broken Authentication in WPLegalPages <= 3.7.0 versions.

    Published 2026-08-24

  • CVSS 9.8 v3·EPSS 0.4%·No fix yet

    Unauthenticated Broken Authentication in User Registration & Membership Pro <= 5.4.5 versions.

    Published 2026-08-20

  • CVSS 7.6 v3·EPSS 0.4%·No fix yet

    Subscriber Broken Authentication in Leyka <= 3.32.3 versions.

    Published 2026-08-20

  • CVSS 9.3 v4·EPSS 3.4%·No fix yet

    Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: from 14.1 through 73.32 and from 13.1 through 63.21; Gateway: from 14.1 through 73.32 and from 13.1 through 63.21.

    Published 2026-08-19

  • CVSS 8.8 v3·EPSS 0.3%·No fix yet

    4gaBoards is a boards system for realtime project management. Prior to 3.3.8, 4gaBoards is vulnerable to pre-account takeover when registrationEnabled, localRegistrationEnabled, and ssoRegistrationEnabled are enabled and Google, GitHub, Microsoft, or OIDC SSO is configured. The POST /api/register endpoint permits creation of an unverified local account with a victim's email address, and POST /api/access-tokens permits that account to authenticate while isVerified is false. During the victim's first SSO login, server/api/helpers/users/get-create-one-for-github-sso.js, server/api/helpers/users/get-create-one-for-google-sso.js, server/api/helpers/users/get-create-one-for-microsoft-sso.js, and server/api/helpers/users/get-create-one-for-oidc-sso.js find the attacker-controlled account by email

    Published 2026-08-18

  • CVSS 7.1 v3·EPSS 0.2%·No fix yet

    NVIDIA NVOS for network switches contains a vulnerability in the secure shell (SSH) server configuration component while PKA-only mode is enabled, where an administrator could inadvertently enable an alternative authentication path. If best practices for replacing the default password as recommended by NVIDIA are not followed, this alternative authentication path might lead to unauthorized access. A successful exploit of this vulnerability might lead to escalation of privileges.

    Published 2026-08-18

  • CVSS 5.3 v3·EPSS 0.4%·No fix yet

    An Authentication Bypass vulnerability exists in EPSON EH-TW5350 EPSON 150075647YWWV110, which could let a remote malicious user cause a Denial of Service via specially crafted series of HTTP..

    Published 2026-08-18

  • CVSS 9.1 v4·EPSS 0.5%·No fix yet

    Missing authentication in initial setup functionality left exposed until first reboot in GBIF Integrated Publishing Toolkit versions before 3.3.4 allows remote authenticated attackers to gain administrative control via authentication bypass

    Published 2026-08-18

  • CVSS 6.5 v3·EPSS 0.4%·No fix yet

    Unauthenticated Broken Authentication in Flutterwave WooCommerce <= 3.3.0 versions.

    Published 2026-08-18

  • CVSS 6.5 v3·EPSS 0.3%·No fix yet

    Unauthenticated Broken Authentication in Piraeus Bank WooCommerce Payment Gateway 3.2.0 versions.

    Published 2026-08-18

  • CVSS 7.1 v3·EPSS 0.4%·No fix yet

    Subscriber Broken Authentication in MWB HubSpot for WooCommerce <= 1.6.7 versions.

    Published 2026-08-18

  • CVSS 9.1 v3·EPSS 0.5%·No fix yet

    Unauthenticated Broken Authentication in Popup by Supsystic <= 1.13.0 versions.

    Published 2026-08-18

  • CVSS 6.5 v3·EPSS 0.2%·No fix yet

    Unauthenticated Bypass Vulnerability in Contact Form by Supsystic < 1.10.0 versions.

    Published 2026-08-18

  • CVSS 7.5 v3·EPSS 0.3%·No fix yet

    Unauthenticated Broken Authentication in Ezoic <= 2.22.11 versions.

    Published 2026-08-18

  • CVSS 9.8 v3·EPSS 0.4%·No fix yet

    Bastillion fails to properly validate request URI paths in its controller dispatcher, allowing unauthenticated attackers to bypass authentication filters by prefixing requests with arbitrary path segments. Attackers can access administrative controllers to read user listings, create manager accounts, and register managed systems, gaining control over SSH access to the managed fleet.

    Published 2026-08-18

  • CVSS 9.1 v3·EPSS 0.3%·No fix yet

    In JetBrains YouTrack before 2025.3.156085, 2026.1.13913, 2026.2.18112 an unauthenticated attacker could download database backups via shared draft signature

    Published 2026-08-17

  • CVSS 9.8 v3·EPSS 0.4%·No fix yet

    Unauthenticated Broken Authentication in Cartify <= 1.3.0.1 versions.

    Published 2026-08-13

  • CVSS 9.8 v3·EPSS 0.4%·No fix yet

    Unauthenticated Broken Authentication in Salon booking system <= 10.30.26 versions.

    Published 2026-08-13

  • CVSS 8.1 v3·EPSS 0.8%·No fix yet

    A authentication bypass using an alternate path or channel vulnerability in Fortinet FortiManager 7.6.1, FortiManager 7.4.3 through 7.4.5, FortiManager 7.2.5 through 7.2.9, FortiManager Cloud 7.6.1, FortiManager Cloud 7.4.3 through 7.4.5, FortiManager Cloud 7.2.5 through 7.2.9 may allow attacker to improper access control via <insert attack vector here>

    Published 2026-08-12

  • CVSS 6.8 v3·EPSS 0.2%·No fix yet

    The Velociraptor gRPC API has a VFSGetBuffer endpoint which allows reading files from the datastore. To prevent users from reading sensitive files or accessing other orgs, the requested path is prefix checked against a list of denied prefixes. This prefix check can be bypassed allowing a user to access usually denied files. If the user has read permission in the ROOT org, this allows access to other orgs, in which the user may not have permission.

    Published 2026-08-11

  • CVSS 7.5 v3·EPSS 0.4%·No fix yet

    An authentication bypass vulnerability in OpenSignLabs opensignserver through 2.37.0 allows an unauthenticated remote attacker to mint MASTER_KEY-signed file access tokens for arbitrary stored files via the getsignedurl Parse cloud function. The function skips its isAuthenticated check whenever any docId parameter is supplied, even one corresponding to no real document, allowing the authentication gate to be bypassed by supplying an arbitrary string as docId.

    Published 2026-08-10

  • CVSS 6.5 v3·EPSS 0.2%·No fix yet

    Unauthenticated Broken Authentication in WP Event SOlution <= 4.1.9 versions.

    Published 2026-08-06

  • CVSS 6.5 v3·EPSS 0.3%·No fix yet

    Unauthenticated Broken Authentication in Gutena Forms – Contact Form, Survey Form, Feedback Form, Booking Form, and Custom Form Builder <= 1.9.0 versions.

    Published 2026-08-06

  • CVSS 8.8 v3·EPSS 0.3%·No fix yet

    Unauthenticated Broken Authentication in Super Socializer <= 7.14.5 versions.

    Published 2026-08-06

  • CVSS 9.8 v3·EPSS 0.5%·No fix yet

    NVIDIA Dynamo for Linux contains a vulnerability in the multimodal serving topology, where an attacker could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, denial of service, and information disclosure.

    Published 2026-08-04

  • CVSS 9.5 v4·EPSS 0.3%·No fix yet

    A vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to impersonate a managed agent andobtain that agent's credentials.

    Published 2026-08-04

  • CVSS 8.6 v3·EPSS 0.3%·No fix yet

    SiYuan versions before v3.7.3 contain an authentication bypass vulnerability in publish mode where content-returning endpoints getHeadingChildrenDOM, getHeading*Transaction, and getBacklinkDoc perform no password check despite protecting the primary getDoc endpoint. Anonymous attackers can retrieve full content of password-protected documents by obtaining internal block IDs from reader-accessible endpoints and calling unprotected content endpoints to bypass the password gate.

    Published 2026-08-03

  • CVSS 9.3 v4·EPSS 1.0%·No fix yet

    An authentication bypass vulnerability in Check Point Security Management Server and Multi-Domain Security Management Server (MDS) could allow an unauthenticated remote attacker with network access to Management services to execute arbitrary commands on the Security Management Server. Successful exploitation could result in full compromise of the Security Management system. Check Point discovered this issue internally and has no indication of active exploitation.

    Published 2026-08-03

  • CVSS 10.0 v4·EPSS 0.5%·No fix yet

    A vulnerability in Wapt Server before version 2.6.1.17813 allows a remote unauthenticated attacker to bypass security restriction using a specially crafted packet and retrieve a valid session token for the targeted account.

    Published 2026-08-03

  • CVSS 8.1 v3·EPSS 54%·Fix available

    An incomplete patch for CVE-2026-18556 allows for authentication bypass and account takeover in N-central Versions through 2026.3.1

    Published 2026-08-02

  • CVSS 7.4 v3·EPSS 40%·No fix yet

    Authentication bypass using an alternate path or channel vulnerability in N-able N-central allows Authentication Bypass. This issue affects N-central: through 2026.1.

    Published 2026-08-01

  • CVSS 6.5 v3·EPSS 0.3%·No fix yet

    better-auth versions before 1.4.9 contain a two-factor authentication bypass vulnerability when session.cookieCache is enabled. Attackers with valid primary credentials can access authenticated routes without completing second-factor verification by exploiting premature session caching.

    Published 2026-08-01

  • CVSS 9.2 v4·EPSS 0.3%·No fix yet

    A Spring Security authentication and authorization bypass exists in Coverity Connect versions between 2023.6.0 and 2026.3.0. An unauthenticated malicious threat actor that can send a specially crafted HTTP request is able to bypass authentication and authorization controls on certain API endpoints to access data within Coverity.

    Published 2026-07-29

  • CVSS 8.0 v3·EPSS 0.2%·No fix yet

    TeamViewer Full Client and Host for macOS before version 15.80 contain a business logic error that can allow an authenticated attacker to bypass a configured 2FA for Connections approval flow via Unattended Access and establish a remote connection to an affected macOS host.

    Published 2026-07-29

  • CVSS 6.5 v3·EPSS 0.3%·No fix yet

    A flaw was found in Dogtag PKI's ACME responder where the web.xml security constraints use exact URL pattern matching for admin-only enable/disable endpoints. By appending a trailing slash to the URL, an unauthenticated attacker can bypass the Tomcat authentication constraint while RESTEasy still routes the request to the handler, allowing unauthorized toggling of the ACME service state including persistent denial of service.

    Published 2026-07-28

  • CVSS 9.8 v3·EPSS 0.5%·No fix yet

    The SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery plugin for WordPress is vulnerable to Authentication Bypass leading to Account Takeover in all versions up to, and including, 3.9.7 via the `billing_phone` parameter. This is due to the `processRegistration()` function using a phone-unbound `$_SESSION['sa_mobile_verified']` boolean flag as the sole gate before issuing an authentication cookie — the flag is set to `true` after any successful OTP validation without being bound to the specific phone number that was verified. This makes it possible for unauthenticated attackers to complete OTP verification for a phone number they control, then resubmit the registration request with a victim's `billing_phone` value to have `wp_set_auth_cookie()` called for

    Published 2026-07-28

  • CVSS 9.8 v3·EPSS 0.7%·No fix yet

    The web management interface of Tycon Systems TPDIN-Monitor-WEB2 does not perform server-side validation of credentials during the login process. By submitting empty values for both credential fields, an unauthenticated remote attacker can bypass the authentication check and establish a valid administrative session. This grants full access to device controls including power relay management, device reboot, remote access service configuration, and network settings, which could allow an attacker to disrupt connected infrastructure or cause physical damage to equipment.

    Published 2026-07-24

  • CVSS 8.1 v3·EPSS 0.5%·No fix yet

    Unauthenticated Broken Authentication in miniOrange Discord Integration <= 2.2.4 versions.

    Published 2026-07-23

  • CVSS 6.5 v3·EPSS 0.4%·No fix yet

    Unauthenticated Broken Authentication in Easy Digital Downloads <= 3.6.7 versions.

    Published 2026-07-23

  • CVSS 8.8 v3·EPSS 0.3%·Fix available

    ONTAP versions 9.16.1 and higher with WebAuthn multi-factor authentication (MFA) configured are susceptible to a vulnerability related to the Relying Party ID which when successfully exploited could allow an attacker with valid credentials to bypass MFA.

    Published 2026-07-22

  • CVSS 8.9 v4·EPSS 0.8%·No fix yet

    FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Versions 1.2.11 until 1.3.1 allow an unauthenticated remote attacker to achieve Full Remote Code Execution (RCE) as root. The exploit succeeds even when the platform is configured in its most secure state (Secure Mode Enabled and Node-RED Secure Auth Enabled). Version 1.3.1 fixes the issue.

    Published 2026-07-21

  • CVSS 9.4 v4·EPSS 0.6%·No fix yet

    Joomla Extension - balbooa.com - Authentication bypass in Gridbox < 1.6.0 - The Joomla extension Gridbox is vulnerable an authenticated bypass, potentially leading to full admin access.

    Published 2026-07-20

  • CVSS 7.1 v4·EPSS 0.4%·No fix yet

    Frappe LMS is an open source learning management system. In version 2.51.0 and earlier, a user could bypass payment validation for courses by using unrelated batch. This has been patched in 2.52.0 with enrollment now validating that the batch is linked to course.

    Published 2026-07-20

Free CVE lookup by TridentStack Control, automated patching for Windows, macOS, and Linux fleets. Learn more·Uses NVD data but is not endorsed or certified by the NVD. EPSS scores courtesy of FIRST.org (https://www.first.org/epss). Source: CISA KEV Catalog.