38 CVEs — updated 2026-08-04 · vulnfeed
| CVE / ID | Title | Severity | CVSS | EPSS | Source | Date |
|---|---|---|---|---|---|---|
| CVE-2026-14446 | IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to broken access control/privilege escalation in the adminis | CRITICAL | 9.8 | 21%ile | NVD | 2026-07-28 |
| CVE-2026-68502 | LazyOwn RedTeam/APT Framework is an AI-powered C2 and red-team operations framework. Prior to 0.2.154, LazyOwn's lazyc2. | CRITICAL | 9.8 | 42%ile | NVD | 2026-07-30 |
| CVE-2026-14529 | IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 t | CRITICAL | 9.4 | 26%ile | NVD | 2026-07-29 |
| CVE-2026-60112 | AMMOS Instrument Toolkit (AIT) GUI before 2.5.1 contains a missing authentication vulnerability that allows any unauthen | CRITICAL | 9.3 | 34%ile | NVD | 2026-07-29 |
| CVE-2026-60113 | AMMOS Instrument Toolkit (AIT) Deep Space Network (DSN) Interface before 2.2.2 contains a missing authentication vulnera | CRITICAL | 9.3 | 34%ile | NVD | 2026-07-29 |
| CVE-2026-67426 | Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.7, the standalone flyto-verifica | CRITICAL | 9.3 | 21%ile | NVD | 2026-07-29 |
| CVE-2026-44090 | Due to missing authentication, an unauthenticated remote attacker may access the MQTT broker, which is only protected fr | CRITICAL | 9.3 | 33%ile | NVD | 2026-07-30 |
| CVE-2026-44101 | Due to missing authentication the CHARX OCPP Agent service allows an unauthenticated remote attacker to reconfigure the | CRITICAL | 9.3 | 33%ile | NVD | 2026-07-30 |
| CVE-2026-67208 | Juggle through 1.6.0 contains a remote code execution vulnerability that allows unauthenticated remote attackers to exec | CRITICAL | 9.3 | 62%ile | NVD | 2026-07-30 |
| CVE-2026-67594 | Spikster through commit e1cdf8c contains a missing authentication vulnerability that allows unauthenticated remote attac | CRITICAL | 9.3 | 37%ile | NVD | 2026-07-30 |
| CVE-2026-41452 | Krayin CRM 2.2.4 contains a missing authentication vulnerability in the installer middleware that allows unauthenticated | CRITICAL | 9.3 | 48%ile | NVD | 2026-08-03 |
| CVE-2026-61514 | Puwell IP Camera firmware versions 2.x through 4.x contains an authentication bypass vulnerability that allows unauthent | CRITICAL | 9.3 | — | NVD | 2026-08-04 |
| CVE-2026-69110 | OpenCode Studio before 2.4.4 contains a missing authentication vulnerability that allows unauthenticated remote attacker | CRITICAL | 9.3 | — | NVD | 2026-08-04 |
| CVE-2026-62325 | goshs is a feature-rich single-binary file server for red teamers and developers. From 2.1.3 until 2.1.4, the sftpserver | CRITICAL | 9.1 | 27%ile | NVD | 2026-07-28 |
| CVE-2026-16771 | In firmware versions 2.7.7 and earlier, the Arris BGW210‑700 gateway fails to enforce any server‑side authentication on | HIGH | 8.8 | 16%ile | NVD | 2026-07-28 |
| CVE-2026-44100 | The CHARX JupiCore service allows an unauthenticated remote attacker to reconfigure charging points. This can lead to di | HIGH | 8.8 | 20%ile | NVD | 2026-07-30 |
| CVE-2026-54367 | CentreStack before 17.2 contains an authentication bypass vulnerability that allows unauthenticated attackers to read, w | HIGH | 8.8 | 9%ile | NVD | 2026-07-30 |
| CVE-2026-16236 | The Realtyna Organic IDX plugin for WordPress is vulnerable to Arbitrary File Upload in versions up to, and including, 5 | HIGH | 8.8 | 47%ile | NVD | 2026-07-31 |
| CVE-2026-54365 | CentreStack before 17.3 contains an unauthenticated deserialization vulnerability in GSNamespace.dll that allows unauthe | HIGH | 8.7 | 12%ile | NVD | 2026-07-30 |
| CVE-2026-67349 | OpenCost before 1.121.0 fails to authenticate the GET /helmValues endpoint, exposing base64-decoded HELM_VALUES environm | HIGH | 8.7 | 21%ile | NVD | 2026-07-30 |
| CVE-2026-12562 | The RCU II+ and Multiload II+ are vulnerable to an unauthenticated service that exposes a debug interface granting full | HIGH | 8.7 | 20%ile | NVD | 2026-07-30 |
| CVE-2026-69091 | Admidio before 5.0.11 contains an authentication bypass vulnerability in the forum module when configured in login-only | HIGH | 8.7 | 28%ile | NVD | 2026-08-03 |
| CVE-2026-67610 | OpenEMR through 8.2.0 contains an improper authentication vulnerability in the OAuth2 dynamic client registration endpoi | HIGH | 8.6 | 25%ile | NVD | 2026-08-03 |
| CVE-2026-12722 | Missing authentication for critical function vulnerability in FTC Software IT Services FTC E-Commerce Management Panel a | HIGH | 8.2 | 17%ile | NVD | 2026-07-30 |
| CVE-2026-58071 | A vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to access the proxied appliance A | HIGH | 8.2 | — | NVD | 2026-08-04 |
| CVE-2026-24079 | Cryptographic Issue while processing registration requests with malformed or missing authentication parameters. | HIGH | 8.1 | — | NVD | 2026-08-04 |
| CVE-2026-47858 | Starting Spring Boot applications in the Spring Tools with the live information mode enabled makes the running applicati | HIGH | 8.0 | 10%ile | NVD | 2026-07-30 |
| CVE-2026-59913 | Dell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3.0.1005, contain a Missing Authentication for Criti | HIGH | 7.8 | 2%ile | NVD | 2026-08-03 |
| CVE-2026-68578 | ArcadeDB versions before 26.7.3 fail to bind the authenticated principal in the MCP HTTP transport, causing all engine p | HIGH | 7.7 | 12%ile | NVD | 2026-08-02 |
| CVE-2026-5057 | ATEN Unizon RpcProvider Missing Authentication Denial-of-Service Vulnerability. This vulnerability allows remote attacke | HIGH | 7.5 | 39%ile | NVD | 2026-07-29 |
| CVE-2026-28814 | Arbitrary Wiki Markup rendering due to lack of authentication in Apache JSPWiki up to 2.12.3 allows attacker to obtain s | HIGH | 7.5 | 25%ile | NVD | 2026-07-30 |
| CVE-2026-15978 | SGLang contains a model weight exfiltration vulnerability when no API keys are configured, as SGLang will expose two end | HIGH | 7.5 | 22%ile | NVD | 2026-07-30 |
| CVE-2026-65310 | ANDRITZ HIPASE-250 (formerly 250 SCALA), in the default configuration of affected versions, exposes its data and configu | HIGH | 7.5 | 24%ile | NVD | 2026-07-31 |
| CVE-2026-14976 | IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is affected by remote code execution with the colle | HIGH | 7.1 | 9%ile | NVD | 2026-07-28 |
| CVE-2026-17348 | In SERVER mode, pgAdmin 4 enforces authentication per route via the @pga_login_required decorator; the application's bef | MEDIUM | 6.9 | 16%ile | NVD | 2026-07-31 |
| CVE-2026-65311 | The HTTP server component of ANDRITZ HIPASE-250 (formerly 250 SCALA) in affected versions exposes an undocumented endpoi | MEDIUM | 5.3 | 19%ile | NVD | 2026-07-31 |
| CVE-2026-13306 | Autel MaxiCharger AC Elite Home USB Authentication Bypass Vulnerability. This vulnerability allows physically present at | MEDIUM | 4.3 | 8%ile | NVD | 2026-07-29 |
| FG-IR-26-125 | Missing Authentication for critical function in CAPWAP daemon | UNKNOWN | — | — | Fortinet | 2026-04-14 |