Export limit exceeded: 25311 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (707 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-93949 | 2026-10-11 | 7.1 High | ||
| Authentication Bypass Using an Alternate Path or Channel vulnerability in Omegathemes Grocery Shopping Store grocery-shopping-store allows Password Recovery Exploitation.This issue affects Grocery Shopping Store: from n/a through 1.3.3. | ||||
| CVE-2026-62038 | 2026-10-11 | 7.3 High | ||
| Unauthenticated Broken Authentication in eRoom <= 1.7.1 versions. | ||||
| CVE-2026-106602 | 2026-10-11 | 4.8 Medium | ||
| Authentication Bypass Using an Alternate Path or Channel vulnerability in Automattic Jetpack jetpack allows Password Recovery Exploitation.This issue affects Jetpack: from n/a through 16.2. | ||||
| CVE-2026-33272 | 1 Red Lion Controls | 1 700 Series | 2026-10-11 | 4.9 Medium |
| A malicious user with physical access to the device can boot the switch from factory settings without authentication, use the default administrative credentials to obtain administrative access, and save changes to the configuration file so that they persist next time the switch boots normally. | ||||
| CVE-2026-107194 | 1 Sungrowpower | 1 Isolarcloud | 2026-10-10 | N/A |
| Sungrow iSolarCloud before 2026 allows authentication bypass and account takeover via "login_type":"5" in a login request, potentially leading to "local blackouts on the whole continent" in Europe. An email address for the user_account property is required; however, a user can view the email address associated with their parent organization. | ||||
| CVE-2026-106601 | 2026-10-09 | 5.4 Medium | ||
| Authentication Bypass Using an Alternate Path or Channel vulnerability in Automattic Jetpack jetpack allows Password Recovery Exploitation.This issue affects Jetpack: from n/a through 16.2. | ||||
| CVE-2026-104075 | 1 Tvu Networks | 1 Tvu Receiver / Transceiver | 2026-10-09 | 9.8 Critical |
| TVU Networks Receiver/Transceiver devices running firmware before version 7.9 contain an authentication bypass vulnerability in the web management login endpoint POST /tvu/Login that allows remote unauthenticated attackers to obtain an administrative session by submitting an empty or absent UserName parameter. Attackers can send a crafted HTTP request directly, bypassing client-side JavaScript validation, to receive a valid session cookie regardless of the password value and gain full administrative control of the device's web management interface. | ||||
| CVE-2026-107361 | 1 Cisagov | 1 Malcolm | 2026-10-09 | 4.2 Medium |
| The Arkime live capture service (arkime-live) in Malcolm runs with network_mode: host, exposing port 8005 on all network interfaces (viewHost=0.0.0.0). Arkime trusts the X-Forwarded-User header from any IP address (userAuthIps=::,0.0.0.0/0) and auto-creates users with full access. The passwordSecret is hardcoded to the public value "Malcolm". A network-adjacent attacker bypasses nginx entirely by connecting directly to port 8005 with a forged identity header. | ||||
| CVE-2026-94585 | 1 Brocade | 1 Fabric Os | 2026-10-08 | N/A |
| An authentication bypass vulnerability exists in the web management interface of Brocade Fabric OS versions before 9.2.2d running on the MXG610 platform. An unauthenticated, network-adjacent attacker can exploit an unauthenticated endpoint within the Single Sign-On (SSO) workflow to gain administrative access to the device management interface. | ||||
| CVE-2026-19572 | 1 Flexera | 1 Flexnet Publisher | 2026-10-07 | N/A |
| A security vulnerability has been identified in FlexNet Publisher lmadmin. The vulnerability exists in a SOAP handler, where a hardcoded authentication bypass could allow an unauthenticated user to obtain a privileged administrator session without providing valid credentials. | ||||
| CVE-2026-39769 | 2 Iqonicdesign, Wordpress-extensions | 2 Graphina, Graphina | 2026-10-06 | 7.5 High |
| Unauthenticated Broken Authentication in Graphina <= 3.1.12 versions. | ||||
| CVE-2026-39793 | 2 Nicu Micle, Wordpress-extensions | 2 Simple Jwt Login, Simple Jwt Login | 2026-10-06 | 8.8 High |
| Subscriber Broken Authentication in Simple JWT Login 4.0.0 versions. | ||||
| CVE-2026-100518 | 2 Webfactoryltd, Wordpress-extensions | 2 Advanced Google Recaptcha, Advanced Google Recaptcha | 2026-10-06 | 5.3 Medium |
| Unauthenticated Broken Authentication in Advanced Google reCAPTCHA <= 5.40 versions. | ||||
| CVE-2026-100261 | 1 Jetbrains | 1 Youtrack | 2026-10-02 | 5.4 Medium |
| In JetBrains YouTrack before 2026.2.18991 changing article visibility settings was possible without update permission | ||||
| CVE-2026-63493 | 2 Grokability, Snipeitapp | 2 Snipe-it, Snipe-it | 2026-09-29 | 8.1 High |
| Snipe-IT is an IT asset/license management system. Prior to 8.7.0, a password-authenticated session for an account with self.api permission can reach the personal-access-token API flow before completing the account's second-factor challenge because CheckForTwoFactor is enforced in the web middleware group but not the API middleware group. The advisory states that the resulting persistent API token can read and modify resources with the victim's permissions and, for an administrator, can reach the users/two_factor_reset endpoint. Resetting the administrator's enrolled second factor allows the password-holding attacker to enroll an attacker-controlled factor, take over the administrator's web account, and lock out the legitimate user. The token does not create a web session, but it provides broad API access while the same browser session remains blocked at the two-factor page. This vulnerability is fixed in 8.7.0. | ||||
| CVE-2026-88828 | 1 Wordpress-extensions | 1 Blacklist Manager For Woocommerce | 2026-09-28 | 5.4 Medium |
| The Blacklist Manager for WooCommerce WordPress plugin from 1.3.0 to 2.3.1 does not enforce its user blocking on every authentication path, allowing the holder of an account the site owner has blocked to keep authenticating with that account's privileges, without the block being enforced or recorded. | ||||
| CVE-2026-90481 | 1 Portswigger | 1 Burp Suite | 2026-09-26 | N/A |
| In PortSwigger Burp Suite DAST (formerly Burp Suite Enterprise Edition) before 2026.8, an authentication bypass can occur via an alternate path or channel. | ||||
| CVE-2026-58269 | 1 Sync-in | 1 Server | 2026-09-24 | 8.1 High |
| Sync-in Server is an open-source platform for file storage, sharing, collaboration, and syncing. Prior to version 2.4.0, `POST /api/auth/token` authenticates with username and password only, then calls `getTokens()`, which returns full access and refresh JWTs without checking whether the account has TOTP 2FA enabled. An attacker with stolen or phished credentials can bypass 2FA in a single request. The parallel login endpoint (`POST /api/auth/login`) correctly enforces 2FA by calling `setCookies(user, res, true)`, which gates on `user.twoFaEnabled`. Version 2.4.0 patches the issue. | ||||
| CVE-2026-79680 | 1 Qt | 1 Qt | 2026-09-24 | 6.8 Medium |
| Authentication bypass vulnerability in the password authentication mechanism of the Qt VNC Server module. An attacker using a specially modified VNC client that violates the RFB protocol can bypass Qt VNC Server's password authentication and gain unauthorized remote access to the shared application, compromising the confidentiality and integrity of the session. | ||||
| CVE-2026-1603 | 1 Ivanti | 1 Endpoint Manager | 2026-09-24 | 8.6 High |
| An authentication bypass in Ivanti Endpoint Manager before version 2024 SU5 allows a remote unauthenticated attacker to leak specific stored credential data. | ||||