CVE & CISA-KEV Catalog

395,283 CVEs1,715 actively exploited (KEV)
Active:
  • CVSS 6.5 v3·EPSS -·No fix yet

    Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applications. Prior to 4.3.0, Steeltoe.Security.Authorization.Certificate deployments using AddOrgAndSpacePolicies() and UseCertificateAuthorization() trust the public certificate supplied in the X-Client-Cert request header without proving possession of the corresponding private key. Common Cloud Foundry routers do not remove this header from inbound requests. When inbound requests are not restricted to a known trusted proxy source IP, an attacker who obtains the public certificate of an application instance in the target organization or space and can reach the application can spoof X-Client-Cert to bypass the SameOrg and SameSpace policies for the certificate validity period. Th

    Published 2026-09-17

  • CVSS 9.8 v3·EPSS -·No fix yet

    Unauthenticated Broken Authentication in EduAdmin Booking <= 5.4.2 versions.

    Published 2026-09-17

  • CVSS 7.7 v4·EPSS -·No fix yet

    A SAML authentication bypass vulnerability affects the Kong SAML plugin when the validate_assertion_signature option is explicitly set to false. This option is enabled by default. When disabled, the plugin may extract the SAML identity from an unsigned assertion and authenticate the user without verifying a valid cryptographic signature. As a result, an unauthenticated remote attacker may be able to submit a crafted SAML response and impersonate arbitrary users, including administrators

    Published 2026-09-16

  • CVSS 9.8 v3·EPSS -·No fix yet

    An unauthenticated remote attacker can exploit an authentication bypass in the _account_log function to log in as an admin, even when accounts are properly configured.

    Published 2026-09-16

  • CVSS 8.2 v3·EPSS 0.4%·No fix yet

    PraisonAI is a multi-agent teams system. From 1.5.1 until 1.7.2, MCPSecurity.evaluatePolicy() in src/praisonai-ts/src/mcp/security.ts invokes the configured credential validator only when AuthMethod is api-key or bearer. Basic and OAuth policies accept any non-empty Authorization header without calling auth.validate(), then return an authenticated result, allowing callers with invalid credentials to access MCP tools and resources protected by those policies. This issue is fixed in version 1.7.2.

    Published 2026-09-15

  • CVSS 7.2 v3·EPSS 0.3%·No fix yet

    goproxy through 15.3 fails to apply HTTP proxy basic authentication to CONNECT tunnel requests, allowing unauthenticated clients to bypass credential requirements. Attackers can issue CONNECT requests to establish tunnels through the authenticated proxy without providing credentials, enabling arbitrary TCP traffic relay and access to restricted destinations.

    Published 2026-09-14

  • CVSS 8.7 v4·EPSS 0.2%·No fix yet

    Authentication bypass using an alternate path or channel and Improper validation of syntactic correctness of input vulnerability in Brainzcompany Zenius EMS 8.0 allows Remote Code Inclusion. This issue affects Zenius EMS 8.0: through OAM (Build 109).

    Published 2026-09-11

  • CVSS 6.3 v4·EPSS 0.3%·No fix yet

    Concrete CMS OAuth callback login path prior to version 9.5.3 did not check whether an account was active or email-validated before establishing a session. A deactivated or unvalidated user with an existing OAuth binding could complete authentication and receive a session that was fully authenticated for the callback response, with the login recorded and login events dispatched. The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 6.3 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N. Thanks Yonatan Drori from Tenzai for reporting.

    Published 2026-09-11

  • CVSS 7.3 v3·EPSS 0.2%·No fix yet

    Unauthenticated Broken Authentication in WP Travel <= 12.0.3 versions.

    Published 2026-09-10

  • CVSS 6.5 v3·EPSS 0.2%·No fix yet

    Unauthenticated Broken Authentication in IMPress for IDX Broker <= 3.3.0 versions.

    Published 2026-09-10

  • CVSS 7.1 v3·EPSS 0.2%·No fix yet

    Subscriber Broken Authentication in MailMunch – Grow your Email List <= 3.2.5 versions.

    Published 2026-09-10

  • CVSS 8.3 v3·EPSS 0.3%·No fix yet

    Capgo (Cap-go/capgo.app) contains an authentication bypass affecting all versions (no patched version available at time of publication). The Edge authorization path allows a password-only Supabase aal1 session to exercise privileged RBAC permissions even when the account has a verified MFA factor that has not been used for the session: the Edge JWT middleware (foundJWT() in supabase/functions/_backend/utils/hono_middleware.ts) accepts the JWT without validating its assurance level, and the direct RBAC path (checkPermission()/checkPermissionPg() in supabase/functions/_backend/utils/rbac.ts calling public.rbac_check_permission_direct()) authorizes by user ID without passing or checking the session aal, unlike the public.verify_mfa() control which correctly requires aal2. An attacker who know

    Published 2026-09-10

  • CVSS 5.5 v3·EPSS 0.3%·Fix available

    n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the public OIDC login and callback endpoints completed authentication even when OIDC was not the enabled active authentication method. An Enterprise administrator who had configured and later disabled an identity provider still exposed a working route that could issue valid sessions. The affected logic is packages/cli/src/modules/sso-oidc/oidc.service.ee.ts, including generateLoginUrl and the callback flow that lacked assertOidcLoginEnabled. This issue is fixed in versions 1.123.76, 2.37.7 and 2.38.2.

    Published 2026-09-08

  • CVSS 7.8 v3·EPSS 0.1%·No fix yet

    In maybeRemoveInvalidInstallerPackageName of InstallRepository.kt, there is a possible unauthorized app update due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published 2026-09-08

  • CVSS 8.1 v3·EPSS 1.5%·No fix yet

    An Authentication Bypass vulnerability in Sentry before R10.8.2, R10.7.3 and R10.6.4 allows a remote unauthenticated attacker to gain administrative level access.

    Published 2026-09-08

  • CVSS 7.5 v3·EPSS 0.3%·Fix available

    CommServe contained an authentication bypass issue affecting access authorization and information disclosure. Software customers upgrade to resolved maintenance release. Update CommServe.

    Published 2026-09-08

  • CVSS 8.8 v3·EPSS 0.3%·No fix yet

    A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). Server-side authorization checks in the web-based management interface are not properly enforced, allowing role-based access control (RBAC) restrictions to be bypassed through manipulation of request data. This could allow an authenticated, low-privileged remote attacker to escalate privileges to an administrative level.

    Published 2026-09-08

  • CVSS 9.1 v3·EPSS 0.6%·No fix yet

    Authentication bypass using an alternate path or channel in Microsoft Entra ID allows an unauthorized attacker to elevate privileges over a network.

    Published 2026-09-08

  • CVSS 7.5 v3·EPSS 0.5%·Fix available

    fastify versions >= 4.0.0 and before 5.12.2 can route a malformed URL sent under one plugin prefix to the custom not-found handler of a different sibling plugin, and invoke it without the preHandler hook declared for that handler. The internal not-found router for encapsulated handlers dispatches malformed paths through a single shared handler pointer before URL decoding, ignoring the prefix and skipping the selected handler's normal lifecycle. An unauthenticated attacker can therefore reach an authentication-protected private fallback through an unrelated public prefix and read its full response, bypassing the authentication hook and breaking prefix encapsulation. Users should upgrade to fastify 5.12.2 or later.

    Published 2026-09-04

  • CVSS 7.4 v3·EPSS 0.2%·No fix yet

    Unauthenticated Broken Authentication in Really Simple SSL <= 9.8.0 versions.

    Published 2026-09-03

  • CVSS 3.7 v3·EPSS 0.3%·Fix available

    Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal CAPTCHA Protected Page allows Functionality Bypass. This issue affects CAPTCHA Protected Page versions: from 0.0.0 to 1.0.2.

    Published 2026-09-02

  • CVSS 4.1 v3·EPSS 0.3%·Fix available

    Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Disable Login Page allows Functionality Bypass. This issue affects Disable Login Page versions: from 0.0.0 to 1.1.4.

    Published 2026-09-02

  • CVSS 7.4 v3·EPSS 0.2%·No fix yet

    Unauthenticated Broken Authentication in RegistrationMagic <= 6.0.9.8 versions.

    Published 2026-08-31

  • CVSS 8.1 v3·EPSS 0.3%·No fix yet

    Gophish through 0.12.1 fails to enforce account lockout and password change requirements in the API authentication middleware. Attackers with valid API keys can bypass these security controls and retain full API access even when their account is locked or password change is required.

    Published 2026-08-28

  • CVSS 9.8 v3·EPSS 0.7%·No fix yet

    Xiiaozet LK100Wt contains an authentication weakness within an administrative service that may allow an attacker to bypass intended access controls and obtain command execution capabilities. Successful exploitation could allow unauthorized interaction with privileged functionality and may lead to complete device compromise.

    Published 2026-08-28

  • CVSS 9.3 v4·EPSS 0.5%·No fix yet

    A vulnerability allowing an unauthenticated network attacker to coerce SMB authentication from the service account.

    Published 2026-08-26

  • CVSS 5.5 v3·EPSS 0.2%·Fix available

    GitLab has remediated an issue in GitLab EE affecting all versions from 11.3 before 19.1.7, 19.2 before 19.2.5, and 19.3 before 19.3.1 that, under certain conditions, an authenticated user with project Maintainer permissions could have accessed the terminal of a protected environment they were not authorized to use due to improper authorization checks.

    Published 2026-08-26

  • CVSS 8.1 v3·EPSS 0.2%·No fix yet

    In FreeBSD 15.0, the kernel structure used to represent user credentials changed: previously the primary group ID was stored in the first element of the array containing the list of supplementary group IDs, whereas now the primary group ID is stored in a dedicated field. This change was largely internal to the kernel and not user-visible. One function, group_is_primary(), was not properly updated as a part of this transition. This function is used by mac_do to determine the primary group ID of the credential after applying a transition rule, used when the rule target does not explicitly specify a group. As a result, with certain mac_do rules, it is possible for a credential switch to incorrectly set the primary group ID to the ID stored in the first element of the original credential's

    Published 2026-08-26

  • CVSS 9.8 v3·EPSS 0.3%·No fix yet

    Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Internationalization Single Sign-On allows Authentication Bypass. This issue affects Internationalization Single Sign-On versions: from 0.0.0 to 1.8.0.

    Published 2026-08-25

  • CVSS 8.6 v3·EPSS 0.3%·No fix yet

    The SMS control function of IE-SR-2TX-WL-4G devices can require a password for SMS commands via the 'Enable Password Authorization' setting. The device increments a retry counter on each failed SMS password attempt; after 5 consecutive failed attempts, SMS password authorization is automatically disabled. An unauthenticated remote attacker who is able to send SMS messages to the device can deliberately trigger this by submitting 5 or more invalid passwords, after which subsequent SMS commands are executed without requiring a password, resulting in potential limited configuration tampering, limited information leakage and potentially full loss of availability.

    Published 2026-08-25

  • CVSS 7.3 v3·EPSS 0.2%·No fix yet

    Unauthenticated Broken Authentication in WPLegalPages <= 3.7.0 versions.

    Published 2026-08-24

  • CVSS 9.8 v3·EPSS 0.4%·No fix yet

    Unauthenticated Broken Authentication in User Registration & Membership Pro <= 5.4.5 versions.

    Published 2026-08-20

  • CVSS 7.6 v3·EPSS 0.4%·No fix yet

    Subscriber Broken Authentication in Leyka <= 3.32.3 versions.

    Published 2026-08-20

  • CriticalKEV
    CVSS 9.8 v3·EPSS 5.6%·Fix available

    Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: from 14.1 through 73.32 and from 13.1 through 63.21; Gateway: from 14.1 through 73.32 and from 13.1 through 63.21.

    Published 2026-08-19

  • CVSS 8.8 v3·EPSS 0.3%·No fix yet

    4gaBoards is a boards system for realtime project management. Prior to 3.3.8, 4gaBoards is vulnerable to pre-account takeover when registrationEnabled, localRegistrationEnabled, and ssoRegistrationEnabled are enabled and Google, GitHub, Microsoft, or OIDC SSO is configured. The POST /api/register endpoint permits creation of an unverified local account with a victim's email address, and POST /api/access-tokens permits that account to authenticate while isVerified is false. During the victim's first SSO login, server/api/helpers/users/get-create-one-for-github-sso.js, server/api/helpers/users/get-create-one-for-google-sso.js, server/api/helpers/users/get-create-one-for-microsoft-sso.js, and server/api/helpers/users/get-create-one-for-oidc-sso.js find the attacker-controlled account by email

    Published 2026-08-18

  • CVSS 7.1 v3·EPSS 0.2%·No fix yet

    NVIDIA NVOS for network switches contains a vulnerability in the secure shell (SSH) server configuration component while PKA-only mode is enabled, where an administrator could inadvertently enable an alternative authentication path. If best practices for replacing the default password as recommended by NVIDIA are not followed, this alternative authentication path might lead to unauthorized access. A successful exploit of this vulnerability might lead to escalation of privileges.

    Published 2026-08-18

  • CVSS 5.3 v3·EPSS 0.4%·No fix yet

    An Authentication Bypass vulnerability exists in EPSON EH-TW5350 EPSON 150075647YWWV110, which could let a remote malicious user cause a Denial of Service via specially crafted series of HTTP..

    Published 2026-08-18

  • CVSS 9.1 v4·EPSS 0.5%·No fix yet

    Missing authentication in initial setup functionality left exposed until first reboot in GBIF Integrated Publishing Toolkit versions before 3.3.4 allows remote authenticated attackers to gain administrative control via authentication bypass

    Published 2026-08-18

  • CVSS 6.5 v3·EPSS 0.4%·No fix yet

    Unauthenticated Broken Authentication in Flutterwave WooCommerce <= 3.3.0 versions.

    Published 2026-08-18

  • CVSS 6.5 v3·EPSS 0.3%·No fix yet

    Unauthenticated Broken Authentication in Piraeus Bank WooCommerce Payment Gateway 3.2.0 versions.

    Published 2026-08-18

  • CVSS 7.1 v3·EPSS 0.4%·No fix yet

    Subscriber Broken Authentication in MWB HubSpot for WooCommerce <= 1.6.7 versions.

    Published 2026-08-18

  • CVSS 9.1 v3·EPSS 0.5%·No fix yet

    Unauthenticated Broken Authentication in Popup by Supsystic <= 1.13.0 versions.

    Published 2026-08-18

  • CVSS 6.5 v3·EPSS 0.2%·No fix yet

    Unauthenticated Bypass Vulnerability in Contact Form by Supsystic < 1.10.0 versions.

    Published 2026-08-18

  • CVSS 7.5 v3·EPSS 0.3%·No fix yet

    Unauthenticated Broken Authentication in Ezoic <= 2.22.11 versions.

    Published 2026-08-18

  • CVSS 9.8 v3·EPSS 0.4%·No fix yet

    Bastillion fails to properly validate request URI paths in its controller dispatcher, allowing unauthenticated attackers to bypass authentication filters by prefixing requests with arbitrary path segments. Attackers can access administrative controllers to read user listings, create manager accounts, and register managed systems, gaining control over SSH access to the managed fleet.

    Published 2026-08-18

  • CVSS 9.1 v3·EPSS 0.3%·Fix available

    In JetBrains YouTrack before 2025.3.156085, 2026.1.13913, 2026.2.18112 an unauthenticated attacker could download database backups via shared draft signature

    Published 2026-08-17

  • CVSS 9.8 v3·EPSS 0.4%·No fix yet

    Unauthenticated Broken Authentication in Cartify <= 1.3.0.1 versions.

    Published 2026-08-13

  • CVSS 9.8 v3·EPSS 0.4%·No fix yet

    Unauthenticated Broken Authentication in Salon booking system <= 10.30.26 versions.

    Published 2026-08-13

  • CVSS 8.1 v3·EPSS 0.7%·Fix available

    A authentication bypass using an alternate path or channel vulnerability in Fortinet FortiManager 7.6.1, FortiManager 7.4.3 through 7.4.5, FortiManager 7.2.5 through 7.2.9, FortiManager Cloud 7.6.1, FortiManager Cloud 7.4.3 through 7.4.5, FortiManager Cloud 7.2.5 through 7.2.9 may allow attacker to improper access control via <insert attack vector here>

    Published 2026-08-12

  • CVSS 6.8 v3·EPSS 0.2%·No fix yet

    The Velociraptor gRPC API has a VFSGetBuffer endpoint which allows reading files from the datastore. To prevent users from reading sensitive files or accessing other orgs, the requested path is prefix checked against a list of denied prefixes. This prefix check can be bypassed allowing a user to access usually denied files. If the user has read permission in the ROOT org, this allows access to other orgs, in which the user may not have permission.

    Published 2026-08-11

Free CVE lookup by TridentStack Control, automated patching for Windows, macOS, and Linux fleets. Learn more·Uses NVD data but is not endorsed or certified by the NVD. EPSS scores courtesy of FIRST.org (https://www.first.org/epss). Source: CISA KEV Catalog.