Search Results (657 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-78259 2026-08-24 7.3 High
Unauthenticated Broken Authentication in WPLegalPages <= 3.7.0 versions.
CVE-2026-73381 2 Supsysticcom, Wordpress 2 Popup By Supsystic, Wordpress 2026-08-24 9.1 Critical
Unauthenticated Broken Authentication in Popup by Supsystic <= 1.13.0 versions.
CVE-2026-73379 2 Supsysticcom, Wordpress 2 Contact Form By Supsystic, Wordpress 2026-08-24 6.5 Medium
Unauthenticated Bypass Vulnerability in Contact Form by Supsystic < 1.10.0 versions.
CVE-2021-43718 2026-08-21 5.3 Medium
An Authentication Bypass vulnerability exists in EPSON EH-TW5350 EPSON 150075647YWWV110, which could let a remote malicious user cause a Denial of Service via specially crafted series of HTTP..
CVE-2026-73396 2 Makewebbetter, Wordpress 2 Hubspot For Woocommerce, Wordpress 2026-08-21 7.1 High
Subscriber Broken Authentication in MWB HubSpot for WooCommerce <= 1.6.7 versions.
CVE-2026-74001 2 Wordpress, Wpeverest 2 Wordpress, User Registration & Membership 2026-08-21 9.8 Critical
Unauthenticated Broken Authentication in User Registration & Membership Pro <= 5.4.5 versions.
CVE-2026-73399 2 Flutterwave, Wordpress 2 Flutterwave Woocommerce, Wordpress 2026-08-21 6.5 Medium
Unauthenticated Broken Authentication in Flutterwave WooCommerce <= 3.3.0 versions.
CVE-2026-71879 1 Gbif 1 Integrated Publishing Toolkit 2026-08-21 N/A
Missing authentication in initial setup functionality left exposed until first reboot in GBIF Integrated Publishing Toolkit versions before 3.3.4 allows remote authenticated attackers to gain administrative control via authentication bypass
CVE-2026-66677 2 Vaultdweller, Wordpress 2 Leyka, Wordpress 2026-08-21 7.6 High
Subscriber Broken Authentication in Leyka <= 3.32.3 versions.
CVE-2026-19490 1 Netscaler 2 Adc, Gateway 2026-08-20 N/A
Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: from 14.1 through 73.32 and from 13.1 through 63.21; Gateway: from 14.1 through 73.32 and from 13.1 through 63.21.
CVE-2026-22049 1 Netapp 2 Ontap, Ontap 9 2026-08-20 8.8 High
ONTAP versions 9.16.1 and higher with WebAuthn multi-factor authentication (MFA) configured are susceptible to a vulnerability related to the Relying Party ID which when successfully exploited could allow an attacker with valid credentials to bypass MFA.
CVE-2026-50191 1 Rargames 1 4gaboards 2026-08-19 8.8 High
4gaBoards is a boards system for realtime project management. Prior to 3.3.8, 4gaBoards is vulnerable to pre-account takeover when registrationEnabled, localRegistrationEnabled, and ssoRegistrationEnabled are enabled and Google, GitHub, Microsoft, or OIDC SSO is configured. The POST /api/register endpoint permits creation of an unverified local account with a victim's email address, and POST /api/access-tokens permits that account to authenticate while isVerified is false. During the victim's first SSO login, server/api/helpers/users/get-create-one-for-github-sso.js, server/api/helpers/users/get-create-one-for-google-sso.js, server/api/helpers/users/get-create-one-for-microsoft-sso.js, and server/api/helpers/users/get-create-one-for-oidc-sso.js find the attacker-controlled account by email and link the verified SSO identity without confirming ownership of the local account. The attacker can retain local-password access to the linked account and obtain the victim's projects, data, and permissions. This issue is fixed in version 3.3.8.
CVE-2026-73398 2 Papaki, Wordpress 2 Piraeus Bank Woocommerce Payment Gateway, Wordpress 2026-08-18 6.5 Medium
Unauthenticated Broken Authentication in Piraeus Bank WooCommerce Payment Gateway 3.2.0 versions.
CVE-2026-24185 1 Nvidia 1 Nvos 2026-08-18 7.1 High
NVIDIA NVOS for network switches contains a vulnerability in the secure shell (SSH) server configuration component while PKA-only mode is enabled, where an administrator could inadvertently enable an alternative authentication path. If best practices for replacing the default password as recommended by NVIDIA are not followed, this alternative authentication path might lead to unauthorized access. A successful exploit of this vulnerability might lead to escalation of privileges.
CVE-2026-75627 1 Bastillion-io 1 Bastillion 2026-08-18 9.8 Critical
Bastillion fails to properly validate request URI paths in its controller dispatcher, allowing unauthenticated attackers to bypass authentication filters by prefixing requests with arbitrary path segments. Attackers can access administrative controllers to read user listings, create manager accounts, and register managed systems, gaining control over SSH access to the managed fleet.
CVE-2026-32481 2 Ezoic, Wordpress 2 Ezoic, Wordpress 2026-08-18 7.5 High
Unauthenticated Broken Authentication in Ezoic <= 2.22.11 versions.
CVE-2026-75045 1 Jetbrains 1 Youtrack 2026-08-17 9.1 Critical
In JetBrains YouTrack before 2025.3.156085, 2026.1.13913, 2026.2.18112 an unauthenticated attacker could download database backups via shared draft signature
CVE-2026-68584 2 B3log, Siyuan 2 Siyuan, Siyuan 2026-08-14 8.6 High
SiYuan versions before v3.7.3 contain an authentication bypass vulnerability in publish mode where content-returning endpoints getHeadingChildrenDOM, getHeading*Transaction, and getBacklinkDoc perform no password check despite protecting the primary getDoc endpoint. Anonymous attackers can retrieve full content of password-protected documents by obtaining internal block IDs from reader-accessible endpoints and calling unprotected content endpoints to bypass the password gate.
CVE-2026-66465 2 Agnihd, Wordpress 2 Cartify, Wordpress 2026-08-14 9.8 Critical
Unauthenticated Broken Authentication in Cartify <= 1.3.0.1 versions.
CVE-2026-66453 2 Dimitri Grassi, Wordpress 2 Salon Booking System, Wordpress 2026-08-13 9.8 Critical
Unauthenticated Broken Authentication in Salon booking system <= 10.30.26 versions.