Total
2009 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2025-7706 | 2026-02-18 | N/A | 6.1 MEDIUM | ||
|
Missing Authentication for Critical Function vulnerability in TUBITAK BILGEM Software Technologies Research Institute Liderahenk allows Remote Code Inclusion.This issue affects Liderahenk: from 3.0.0 to 3.3.1 before 3.5.0.
|
|||||
| CVE-2026-1670 | 2026-02-18 | N/A | 9.8 CRITICAL | ||
|
The affected products are vulnerable to an unauthenticated API endpoint exposure, which may allow an attacker to remotely change the "forgot password" recovery email address.
|
|||||
| CVE-2025-14038 | 1 Enterprisedb | 1 Hybrid Manager | 2026-02-18 | N/A | 7.0 HIGH |
|
EDB Hybrid Manager contains a flaw that allows an unauthenticated attacker to directly access certain gRPC endpoints. This could allow an attacker to read potentially sensitive data or possibly cause a denial-of-service by writing malformed data to certain gRPC endpoints. This flaw has been remediated in EDB Hybrid Manager 1.3.3, and customers should consider upgrading to 1.3.3 as soon as possible.
The flaw is due to a misconfiguration in the Istio Gateway, which manages authentication and autho ...
Show More |
|||||
| CVE-2026-1332 | 1 Hamastar | 1 Meetinghub Paperless Meetings | 2026-02-17 | N/A | 5.3 MEDIUM |
|
MeetingHub developed by HAMASTAR Technology has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to access specific API functions and obtain meeting-related information.
|
|||||
| CVE-2026-25895 | 1 Frangoteam | 1 Fuxa | 2026-02-13 | N/A | 9.8 CRITICAL |
|
FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. A path traversal vulnerability in FUXA allows an unauthenticated, remote attacker to write arbitrary files to arbitrary locations on the server filesystem. This affects FUXA through version 1.2.9. This issue has been patched in FUXA version 1.2.10.
|
|||||
| CVE-2026-25938 | 1 Frangoteam | 1 Fuxa | 2026-02-13 | N/A | 9.8 CRITICAL |
|
FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. From 1.2.8 through 1.2.10, an authentication bypass vulnerability in FUXA allows an unauthenticated, remote attacker to execute arbitrary code on the server when the Node-RED plugin is enabled. This has been patched in FUXA version 1.2.11.
|
|||||
| CVE-2026-25593 | 1 Openclaw | 1 Openclaw | 2026-02-13 | N/A | 8.4 HIGH |
|
OpenClaw is a personal AI assistant. Prior to 2026.1.20, an unauthenticated local client could use the Gateway WebSocket API to write config via config.apply and set unsafe cliPath values that were later used for command discovery, enabling command injection as the gateway user. This vulnerability is fixed in 2026.1.20.
|
|||||
| CVE-2026-26055 | 2026-02-13 | N/A | 7.5 HIGH | ||
|
Yoke is a Helm-inspired infrastructure-as-code (IaC) package deployer. In 0.19.0 and earlier, a vulnerability exists in the Air Traffic Controller (ATC) component of Yoke. The ATC webhook endpoints lack proper authentication mechanisms, allowing any pod within the cluster network to directly send AdmissionReview requests to the webhook, bypassing Kubernetes API Server authentication. This enables attackers to trigger WASM module execution in the ATC controller context without proper authorizatio ...
Show More |
|||||
| CVE-2026-2249 | 2026-02-12 | N/A | 9.8 CRITICAL | ||
|
METIS DFS devices (versions <= oscore 2.1.234-r18) expose a web-based shell at the /console endpoint that does not require authentication. Accessing this endpoint allows a remote attacker to execute arbitrary operating system commands with 'daemon' privileges. This results in the compromise of the software, granting unauthorized access to modify configuration, read and alter sensitive data, or disrupt services.
|
|||||
| CVE-2026-2248 | 2026-02-12 | N/A | 9.8 CRITICAL | ||
|
METIS WIC devices (versions <= oscore 2.1.234-r18) expose a web-based shell at the /console endpoint that does not require authentication. Accessing this endpoint allows a remote attacker to execute arbitrary operating system commands with root (UID 0) privileges. This results in full system compromise, allowing unauthorized access to modify system configuration, read sensitive data, or disrupt device operations
|
|||||
| CVE-2026-1729 | 2026-02-12 | N/A | 9.8 CRITICAL | ||
|
The AdForest theme for WordPress is vulnerable to authentication bypass in all versions up to, and including, 6.0.12. This is due to the plugin not properly verifying a user's identity prior to authenticating them through the 'sb_login_user_with_otp_fun' function. This makes it possible for unauthenticated attackers to log in as arbitrary users, including administrators.
|
|||||
| CVE-2025-52024 | 1 Aptsys | 1 Gemscms Backend | 2026-02-11 | N/A | 9.4 CRITICAL |
|
A vulnerability exists in the Aptsys POS Platform Web Services module thru 2025-05-28, which exposes internal API testing tools to unauthenticated users. By accessing specific URLs, an attacker is presented with a directory-style index listing all available backend services and POS web services, each with an HTML form for submitting test input. These panels are intended for developer use, but are accessible in production environments with no authentication or session validation. This grants any ...
Show More |
|||||
| CVE-2026-25084 | 2026-02-11 | N/A | 9.8 CRITICAL | ||
|
Authentication for ZLAN5143D can be bypassed by directly accessing internal URLs.
|
|||||
| CVE-2026-24789 | 2026-02-11 | N/A | 9.8 CRITICAL | ||
|
An unprotected API endpoint allows an attacker to remotely change the device password without providing authentication.
|
|||||
| CVE-2025-8025 | 2026-02-11 | N/A | 9.8 CRITICAL | ||
|
Missing Authentication for Critical Function, Improper Access Control vulnerability in Dinosoft Business Solutions Dinosoft ERP allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Dinosoft ERP: from < 3.0.1 through 11022026.
NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
|
|||||
| CVE-2026-25751 | 1 Frangoteam | 1 Fuxa | 2026-02-10 | N/A | 7.5 HIGH |
|
FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. An information disclosure vulnerability in FUXA allows an unauthenticated, remote attacker to retrieve sensitive administrative database credentials. Exploitation allows an unauthenticated, remote attacker to obtain the full system configuration, including administrative credentials for the InfluxDB database. Possession of these credentials may allow an attacker to authenticate directly to the database service, enabling th ...
Show More |
|||||
| CVE-2020-37146 | 2026-02-09 | N/A | 7.5 HIGH | ||
|
ACE Security WiP-90113 HD Camera contains a configuration disclosure vulnerability that allows unauthenticated attackers to retrieve sensitive configuration files. Attackers can access the camera's configuration backup by sending a GET request to the /config_backup.bin endpoint, exposing credentials and system settings.
|
|||||
| CVE-2020-37157 | 2026-02-09 | N/A | 7.5 HIGH | ||
|
DBPower C300 HD Camera contains a configuration disclosure vulnerability that allows unauthenticated attackers to retrieve sensitive credentials through an unprotected configuration backup endpoint. Attackers can download the configuration file and extract hardcoded username and password by accessing the /tmpfs/config_backup.bin resource.
|
|||||
| CVE-2026-2234 | 2026-02-09 | N/A | 9.1 CRITICAL | ||
|
C&Cm@il developed by HGiga has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to read and modify any user's mail content.
|
|||||
| CVE-2026-24423 | 1 Smartertools | 1 Smartermail | 2026-02-06 | N/A | 9.8 CRITICAL |
|
SmarterTools SmarterMail versions prior to build 9511 contain an unauthenticated remote code execution vulnerability in the ConnectToHub API method. The attacker could point the SmarterMail to the malicious HTTP server, which serves the malicious OS command. This command will be executed by the vulnerable application.
|
|||||
| CVE-2025-59367 | 1 Asus | 6 Dsl-ac51, Dsl-ac51 Firmware, Dsl-ac750 and 3 more | 2026-02-06 | N/A | 9.8 CRITICAL |
|
An authentication bypass vulnerability has been identified in certain DSL series routers, may allow remote attackers to gain unauthorized access into the affected system. Refer to the 'Security Update for DSL Series Router' section on the ASUS Security Advisory for more information.
|
|||||
| CVE-2026-1453 | 2026-02-04 | N/A | 9.8 CRITICAL | ||
|
A missing authentication for critical function vulnerability in KiloView Encoder Series could allow an unauthenticated attacker to create or delete administrator accounts. This vulnerability can grant the attacker full administrative control over the product.
|
|||||
| CVE-2026-24728 | 2026-02-04 | N/A | N/A | ||
|
A missing authentication for critical function vulnerability in the /servlet/baServer3 endpoint of Interinfo DreamMaker versions before 2025/10/22 allows remote attackers to access exposed administrative functionality without prior authentication.
|
|||||
| CVE-2026-1341 | 2026-02-04 | N/A | N/A | ||
|
Avation Light Engine Pro exposes its configuration and control interface without any authentication or access control.
|
|||||
| CVE-2026-1633 | 2026-02-04 | N/A | 10.0 CRITICAL | ||
|
The Synectix LAN 232 TRIO 3-Port serial to ethernet adapter exposes its web management interface without requiring authentication, allowing unauthenticated users to modify critical device settings or factory reset the device.
|
|||||
| CVE-2026-1632 | 2026-02-04 | N/A | 9.1 CRITICAL | ||
|
MOMA Seismic Station Version v2.4.2520 and prior exposes its web management interface without requiring authentication, which could allow an unauthenticated attacker to modify configuration settings, acquire device data or remotely reset the device.
|
|||||
| CVE-2025-5192 | 1 Scshr | 1 Hr Portal | 2026-02-04 | N/A | 7.5 HIGH |
|
A missing authentication for critical function vulnerability in the client application of Soar Cloud HRD Human Resource Management System through version 7.3.2025.0408 allows remote attackers to bypass authentication and access application functions.
|
|||||
| CVE-2023-54335 | 1 Extplorer | 1 Extplorer | 2026-02-03 | N/A | 9.8 CRITICAL |
|
eXtplorer 2.1.14 contains an authentication bypass vulnerability that allows attackers to login without a password by manipulating the login request. Attackers can exploit this flaw to upload malicious PHP files and execute remote commands on the vulnerable file management system.
|
|||||
| CVE-2025-3646 | 1 Petlibro | 1 Petlibro | 2026-02-03 | N/A | 7.3 HIGH |
|
Petlibro Smart Pet Feeder Platform versions up to 1.7.31 contains an authorization bypass vulnerability that allows unauthorized users to add users as shared owners to any device by exploiting missing permission checks. Attackers can send requests to the device share API to gain unauthorized access to devices and view owner information without proper authorization validation.
|
|||||
| CVE-2022-50979 | 2026-02-03 | N/A | 6.5 MEDIUM | ||
|
An unauthenticated adjacent attacker could potentially disrupt operations by switching between multiple configuration presets via Modbus (RS485).
|
|||||
| CVE-2022-50981 | 2026-02-03 | N/A | 9.8 CRITICAL | ||
|
An unauthenticated remote attacker can gain full access on the affected devices as they are shipped without a password by default and setting one is not enforced.
|
|||||
| CVE-2022-50980 | 2026-02-03 | N/A | 6.5 MEDIUM | ||
|
A unauthenticated adjacent attacker could potentially disrupt operations by switching between multiple configuration presets via CAN.
|
|||||
| CVE-2022-50977 | 2026-02-03 | N/A | 7.5 HIGH | ||
|
An unauthenticated remote attacker could potentially disrupt operations by switching between multiple configuration presets via HTTP.
|
|||||
| CVE-2022-50978 | 2026-02-03 | N/A | 7.5 HIGH | ||
|
An unauthenticated remote attacker could potentially disrupt operations by switching between multiple configuration presets via Modbus (TCP).
|
|||||
| CVE-2026-25137 | 2026-02-03 | N/A | 9.1 CRITICAL | ||
|
The NixOs Odoo package is an open source ERP and CRM system. From 21.11 to before 25.11 and 26.05, every NixOS based Odoo setup publicly exposes the database manager without any authentication. This allows unauthorized actors to delete and download the entire database, including Odoos file store. Unauthorized access is evident from http requests. If kept, searching access logs and/or Odoos log for requests to /web/database can give indicators, if this has been actively exploited. The database ma ...
Show More |
|||||
| CVE-2025-54816 | 1 Evmapa | 1 Evmapa | 2026-02-02 | N/A | 9.4 CRITICAL |
|
This vulnerability occurs when a WebSocket endpoint does not enforce
proper authentication mechanisms, allowing unauthorized users to
establish connections. As a result, attackers can exploit this weakness
to gain unauthorized access to sensitive data or perform unauthorized
actions. Given that no authentication is required, this can lead to
privilege escalation and potentially compromise the security of the
entire system.
|
|||||
| CVE-2021-47802 | 1 Tenda | 4 D151, D151 Firmware, D301 and 1 more | 2026-02-02 | N/A | 7.5 HIGH |
|
Tenda D151 and D301 routers contain an unauthenticated configuration download vulnerability that allows remote attackers to retrieve router configuration files. Attackers can send a request to /goform/getimage endpoint to download configuration data including admin credentials without authentication.
|
|||||
| CVE-2025-68716 | 1 Kaysus | 2 Ks-wr3600, Ks-wr3600 Firmware | 2026-02-02 | N/A | 8.4 HIGH |
|
KAYSUS KS-WR3600 routers with firmware 1.0.5.9.1 enable the SSH service enabled by default on the LAN interface. The root account is configured with no password, and administrators cannot disable SSH or enforce authentication via the CLI or web GUI. This allows any LAN-adjacent attacker to trivially gain root shell access and execute arbitrary commands with full privileges.
|
|||||
| CVE-2026-22238 | 1 Blusparkglobal | 1 Bluvoyix | 2026-02-02 | N/A | 9.8 CRITICAL |
|
The vulnerability exists in BLUVOYIX due to improper authentication in the BLUVOYIX admin APIs. An unauthenticated remote attacker could exploit this vulnerability by sending specially crafted HTTP requests to the vulnerable admin API to create a new user with admin privileges. Successful exploitation of this vulnerability could allow the attacker to gain full access to customers' data and completely compromise the targeted platform by logging in to the newly-created admin user.
|
|||||
| CVE-2026-23944 | 1 Arcane | 1 Arcane | 2026-02-02 | N/A | 9.8 CRITICAL |
|
Arcane is an interface for managing Docker containers, images, networks, and volumes. Prior to version 1.13.2, unauthenticated requests could be proxied to remote environment agents, allowing access to remote environment resources without authentication. The environment proxy middleware handled `/api/environments/{id}/...` requests for remote environments before authentication was enforced. When the environment ID was not local, the middleware proxied the request and attached the manager-held ag ...
Show More |
|||||