Total
671 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-71879 | 2026-08-31 | N/A | N/A | ||
| Missing authentication in initial setup functionality left exposed until first reboot in GBIF Integrated Publishing Toolkit versions before 3.3.4 allows remote authenticated attackers to gain administrative control via authentication bypass | |||||
| CVE-2026-3035 | 1 Gitlab | 1 Gitlab | 2026-08-31 | N/A | 5.5 MEDIUM |
| GitLab has remediated an issue in GitLab EE affecting all versions from 11.3 before 19.1.7, 19.2 before 19.2.5, and 19.3 before 19.3.1 that, under certain conditions, an authenticated user with project Maintainer permissions could have accessed the terminal of a protected environment they were not authorized to use due to improper authorization checks. | |||||
| CVE-2026-82269 | 2026-08-28 | N/A | 8.1 HIGH | ||
| Gophish through 0.12.1 fails to enforce account lockout and password change requirements in the API authentication middleware. Attackers with valid API keys can bypass these security controls and retain full API access even when their account is locked or password change is required. | |||||
| CVE-2026-18636 | 2026-08-28 | N/A | 6.8 MEDIUM | ||
| The Velociraptor gRPC API has a VFSGetBuffer endpoint which allows reading files from the datastore. To prevent users from reading sensitive files or accessing other orgs, the requested path is prefix checked against a list of denied prefixes. This prefix check can be bypassed allowing a user to access usually denied files. If the user has read permission in the ROOT org, this allows access to other orgs, in which the user may not have permission. | |||||
| CVE-2026-16639 | 2026-08-28 | N/A | 9.8 CRITICAL | ||
| Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Internationalization Single Sign-On allows Authentication Bypass. This issue affects Internationalization Single Sign-On versions: from 0.0.0 to 1.8.0. | |||||
| CVE-2026-58092 | 2026-08-27 | N/A | 8.1 HIGH | ||
| In FreeBSD 15.0, the kernel structure used to represent user credentials changed: previously the primary group ID was stored in the first element of the array containing the list of supplementary group IDs, whereas now the primary group ID is stored in a dedicated field. This change was largely internal to the kernel and not user-visible. One function, group_is_primary(), was not properly updated as a part of this transition. This function is used by mac_do to determine the primary group ID of the credential after applying a transition rule, used when the rule target does not explicitly specify a group. As a result, with certain mac_do rules, it is possible for a credential switch to incorrectly set the primary group ID to the ID stored in the first element of the original credential's supplementary group array. If the list of supplementary groups is empty, this value will be 0, corresponding to the "wheel" group. For example, a rule such as "uid=1001>uid=1002" can be abused to set the primary group ID to 0 even if the process did not originally belong to group 0. Certain mac_do rules can be abused to set a process' group ID to 0. Note however, that the rule must apply to the caller in order for the bug to be triggered, e.g., given the ruleset "uid=1001>uid=1002", the user must have user ID 1001 in order to trigger the bug. Further, logged-in users will in general have a non-empty supplementary group list, in which case the bug can at worst be used to set the credential's first supplementary group ID as its primary group ID. Processes must explicitly remove themselves from all supplementary groups, using the privileged setgroups(2) system call, in order to exploit the bug to set 0 as the primary group ID. Since membership in group 0 is often used to enable controlled privilege escalation, the bug might be further exploitable to obtain root privileges, depending on the system configuration. For instance, a ruleset such as the following could be exploited by a process running as user 1001 and with an empty supplementary group list: "uid=1001>uid=1002;gid=0>uid=0". | |||||
| CVE-2026-72691 | 2026-08-26 | N/A | 7.5 HIGH | ||
| An authentication bypass vulnerability in OpenSignLabs opensignserver through 2.37.0 allows an unauthenticated remote attacker to mint MASTER_KEY-signed file access tokens for arbitrary stored files via the getsignedurl Parse cloud function. The function skips its isAuthenticated check whenever any docId parameter is supplied, even one corresponding to no real document, allowing the authentication gate to be bypassed by supplying an arbitrary string as docId. | |||||
| CVE-2026-68584 | 2026-08-26 | N/A | 8.6 HIGH | ||
| SiYuan versions before v3.7.3 contain an authentication bypass vulnerability in publish mode where content-returning endpoints getHeadingChildrenDOM, getHeading*Transaction, and getBacklinkDoc perform no password check despite protecting the primary getDoc endpoint. Anonymous attackers can retrieve full content of password-protected documents by obtaining internal block IDs from reader-accessible endpoints and calling unprotected content endpoints to bypass the password gate. | |||||
| CVE-2026-78259 | 2026-08-26 | N/A | 7.3 HIGH | ||
| Unauthenticated Broken Authentication in WPLegalPages <= 3.7.0 versions. | |||||
| CVE-2026-74001 | 2026-08-20 | N/A | 9.8 CRITICAL | ||
| Unauthenticated Broken Authentication in User Registration & Membership Pro <= 5.4.5 versions. | |||||
| CVE-2026-66677 | 2026-08-20 | N/A | 7.6 HIGH | ||
| Subscriber Broken Authentication in Leyka <= 3.32.3 versions. | |||||
| CVE-2026-24185 | 2026-08-20 | N/A | 7.1 HIGH | ||
| NVIDIA NVOS for network switches contains a vulnerability in the secure shell (SSH) server configuration component while PKA-only mode is enabled, where an administrator could inadvertently enable an alternative authentication path. If best practices for replacing the default password as recommended by NVIDIA are not followed, this alternative authentication path might lead to unauthorized access. A successful exploit of this vulnerability might lead to escalation of privileges. | |||||
| CVE-2026-32481 | 2026-08-20 | N/A | 7.5 HIGH | ||
| Unauthenticated Broken Authentication in Ezoic <= 2.22.11 versions. | |||||
| CVE-2026-73399 | 2026-08-20 | N/A | 6.5 MEDIUM | ||
| Unauthenticated Broken Authentication in Flutterwave WooCommerce <= 3.3.0 versions. | |||||
| CVE-2026-73396 | 2026-08-20 | N/A | 7.1 HIGH | ||
| Subscriber Broken Authentication in MWB HubSpot for WooCommerce <= 1.6.7 versions. | |||||
| CVE-2026-73379 | 2026-08-20 | N/A | 6.5 MEDIUM | ||
| Unauthenticated Bypass Vulnerability in Contact Form by Supsystic < 1.10.0 versions. | |||||
| CVE-2026-73381 | 2026-08-20 | N/A | 9.1 CRITICAL | ||
| Unauthenticated Broken Authentication in Popup by Supsystic <= 1.13.0 versions. | |||||
| CVE-2026-73398 | 2026-08-20 | N/A | 6.5 MEDIUM | ||
| Unauthenticated Broken Authentication in Piraeus Bank WooCommerce Payment Gateway 3.2.0 versions. | |||||
| CVE-2026-22049 | 1 Netapp | 1 Ontap | 2026-08-20 | N/A | 8.8 HIGH |
| ONTAP versions 9.16.1 and higher with WebAuthn multi-factor authentication (MFA) configured are susceptible to a vulnerability related to the Relying Party ID which when successfully exploited could allow an attacker with valid credentials to bypass MFA. | |||||
| CVE-2026-75627 | 2026-08-18 | N/A | 9.8 CRITICAL | ||
| Bastillion fails to properly validate request URI paths in its controller dispatcher, allowing unauthenticated attackers to bypass authentication filters by prefixing requests with arbitrary path segments. Attackers can access administrative controllers to read user listings, create manager accounts, and register managed systems, gaining control over SSH access to the managed fleet. | |||||
