Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

Filtering: Tag: auth-bypass Clear
ID Title
CVE-2026-67611 Vulnerability in CVE-2026-67611 (CVE-2026-67611)
vulnerability in CVE-2026-67611 (CVE-2026-67611). Confidential information can be exposed externally.
CVE-2026-69091 Vulnerability in CVE-2026-69091 (CVE-2026-69091)
vulnerability in CVE-2026-69091 (CVE-2026-69091). Confidential information can be exposed externally.
CVE-2026-68584 Vulnerability in CVE-2026-68584 (CVE-2026-68584)
vulnerability in CVE-2026-68584 (CVE-2026-68584). Confidential information can be exposed externally.
CVE-2026-64827 Vulnerability in CVE-2026-64827 (CVE-2026-64827)
vulnerability in CVE-2026-64827 (CVE-2026-64827). Successful exploitation can lead to full system takeover.
CVE-2026-18089 Vulnerability in timlegge (CVE-2026-18089)
vulnerability in timlegge (CVE-2026-18089). Data can be tampered with by attackers.
CVE-2026-18092 Vulnerability in timlegge (CVE-2026-18092)
vulnerability in timlegge (CVE-2026-18092). Data can be tampered with by attackers.
CVE-2026-18108 Vulnerability in timlegge (CVE-2026-18108)
vulnerability in timlegge (CVE-2026-18108). Successful exploitation can lead to full system takeover.
CVE-2026-18574 Vulnerability in CVE-2026-18574 (CVE-2026-18574)
vulnerability in CVE-2026-18574 (CVE-2026-18574). Risk of unauthorized operations or information disclosure.
CVE-2026-18577 KEV [KEV] Vulnerability in N-able n-central (CVE-2026-18577)
vulnerability in N-able n-central (CVE-2026-18577). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
CVE-2026-8457 Vulnerability in wordpress (CVE-2026-8457)
vulnerability in wordpress (CVE-2026-8457). Successful exploitation can lead to full system takeover.
CVE-2026-18556 KEV [KEV] Vulnerability in N-able n-central (CVE-2026-18556)
vulnerability in N-able n-central (CVE-2026-18556). Confidential information can be exposed externally. Listed in CISA KEV — actively exploited.
CVE-2026-67337 Vulnerability in CVE-2026-67337 (CVE-2026-67337)
vulnerability in CVE-2026-67337 (CVE-2026-67337). Confidential information can be exposed externally.
CVE-2026-67328 Cross-Site Scripting (XSS) in CVE-2026-67328 (CVE-2026-67328)
cross-site scripting in CVE-2026-67328 (CVE-2026-67328). Confidential information can be exposed externally.
CVE-2026-67309 Path Traversal in github.com/traefik/traefik/v3 (CVE-2026-67309)
path traversal in github.com/traefik/traefik/v3 (CVE-2026-67309). Risk of unauthorized operations or information disclosure. Exploitable via ``RewriteTarget``. Mitigation: upgrade to `3.7.8` or later.
CVE-2026-15964 Vulnerability in wordpress (CVE-2026-15964)
vulnerability in wordpress (CVE-2026-15964). Successful exploitation can lead to full system takeover. Exploitable via ``wp_ajax_nopriv_ssoprocess_ajax``.
CVE-2026-15988 Cross-Site Request Forgery (CSRF) in wordpress (CVE-2026-15988)
vulnerability in wordpress (CVE-2026-15988). Successful exploitation can lead to full system takeover.
CVE-2026-18141 A flaw was found in aap-gateway, a component of Ansible Automation Platform's Event-Driven...
A flaw was found in aap-gateway, a component of Ansible Automation Platform's Event-Driven...
CVE-2026-14541 Authentication Bypass in google (CVE-2026-14541)
authentication bypass in google (CVE-2026-14541). Confidential information can be exposed externally.
CVE-2026-28323 Authentication Bypass in solarwinds (CVE-2026-28323)
authentication bypass in solarwinds (CVE-2026-28323). Successful exploitation can lead to full system takeover.
CVE-2026-59309 Vulnerability in vmware (CVE-2026-59309)
vulnerability in vmware (CVE-2026-59309). Successful exploitation can lead to full system takeover.
CVE-2026-54367 Vulnerability in CVE-2026-54367 (CVE-2026-54367)
vulnerability in CVE-2026-54367 (CVE-2026-54367). Data can be tampered with by attackers.
CVE-2026-12722 Vulnerability in CVE-2026-12722 (CVE-2026-12722)
vulnerability in CVE-2026-12722 (CVE-2026-12722). Confidential information can be exposed externally.
CVE-2026-53431 Vulnerability in CVE-2026-53431 (CVE-2026-53431)
vulnerability in CVE-2026-53431 (CVE-2026-53431). Risk of unauthorized operations or information disclosure.
CVE-2026-44094 An unauthenticated remote attacker can enforce the system to fall back to a firmware partition...
An unauthenticated remote attacker can enforce the system to fall back to a firmware partition...
CVE-2026-13306 Vulnerability in CVE-2026-13306 (CVE-2026-13306)
vulnerability in CVE-2026-13306 (CVE-2026-13306). Risk of unauthorized operations or information disclosure.
CVE-2026-6267 GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.1.0 before 19.0.5,...
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.1.0 before 19.0.5,...
CVE-2026-12436 GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.0 before 19.0.5, 19...
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.0 before 19.0.5, 19...
CVE-2026-67425 Flyto2 Core: LLM/API keys leak to an attacker-controlled base_url
Flyto2 Core: LLM/API keys leak to an attacker-controlled base_url
CVE-2026-14354 Vulnerability in CVE-2026-14354 (CVE-2026-14354)
vulnerability in CVE-2026-14354 (CVE-2026-14354). Risk of unauthorized operations or information disclosure.
CVE-2026-63238 Authentication Bypass in CVE-2026-63238 (CVE-2026-63238)
authentication bypass in CVE-2026-63238 (CVE-2026-63238). Confidential information can be exposed externally.
CVE-2026-63237 Vulnerability in CVE-2026-63237 (CVE-2026-63237)
vulnerability in CVE-2026-63237 (CVE-2026-63237). Risk of unauthorized operations or information disclosure.
CVE-2026-18072 Vulnerability in wordpress (CVE-2026-18072)
vulnerability in wordpress (CVE-2026-18072). Successful exploitation can lead to full system takeover. Exploitable via ``init``.
CVE-2026-15014 Vulnerability in wordpress (CVE-2026-15014)
vulnerability in wordpress (CVE-2026-15014). Successful exploitation can lead to full system takeover. Exploitable via ``billing_phone``.
CVE-2026-66473 Unauthenticated Broken Access Control in Xendit Payment <= 7.1.0 versions.
Unauthenticated Broken Access Control in Xendit Payment <= 7.1.0 versions.
CVE-2026-66013 Vulnerability in CVE-2026-66013 (CVE-2026-66013)
vulnerability in CVE-2026-66013 (CVE-2026-66013). Risk of unauthorized operations or information disclosure.
CVE-2026-66006 Vulnerability in lakefs (CVE-2026-66006)
vulnerability in lakefs (CVE-2026-66006). Risk of unauthorized operations or information disclosure.
CVE-2026-66139 Vulnerability in CVE-2026-66139 (CVE-2026-66139)
vulnerability in CVE-2026-66139 (CVE-2026-66139). Risk of unauthorized operations or information disclosure.
CVE-2026-15981 Authentication Bypass in wordpress (CVE-2026-15981)
authentication bypass in wordpress (CVE-2026-15981). Successful exploitation can lead to full system takeover.
CVE-2026-63765 Vulnerability in CVE-2026-63765 (CVE-2026-63765)
vulnerability in CVE-2026-63765 (CVE-2026-63765). Data can be tampered with by attackers.
CVE-2026-15348 Authentication Bypass in wordpress (CVE-2026-15348)
authentication bypass in wordpress (CVE-2026-15348). Risk of unauthorized operations or information disclosure. Exploitable via ``wpdmppdl``.
CVE-2025-50325 Vulnerability in CVE-2025-50325 (CVE-2025-50325)
vulnerability in CVE-2025-50325 (CVE-2025-50325). Risk of unauthorized operations or information disclosure.
CVE-2026-62144 Authentication Bypass in CVE-2026-62144 (CVE-2026-62144)
authentication bypass in CVE-2026-62144 (CVE-2026-62144). Confidential information can be exposed externally.
CVE-2026-16232 KEV [KEV] Authentication Bypass in Check point checkpoint (CVE-2026-16232)
authentication bypass in Check point checkpoint (CVE-2026-16232). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
CVE-2026-65600 Path Traversal in github.com/traefik/traefik/v2 (CVE-2026-65600)
path traversal in github.com/traefik/traefik/v2 (CVE-2026-65600). Risk of unauthorized operations or information disclosure. Exploitable via `GET /api../admin`. Mitigation: upgrade to `2.11.52` or later.
CVE-2026-4773 Vulnerability in CVE-2026-4773 (CVE-2026-4773)
vulnerability in CVE-2026-4773 (CVE-2026-4773). Confidential information can be exposed externally.
CVE-2026-16454 Vulnerability in privilege-escalation (CVE-2026-16454)
vulnerability in privilege-escalation (CVE-2026-16454). Risk of unauthorized operations or information disclosure.
CVE-2026-3183 Vulnerability in CVE-2026-3183 (CVE-2026-3183)
vulnerability in CVE-2026-3183 (CVE-2026-3183). Data can be tampered with by attackers.
CVE-2026-57852 Vulnerability in CVE-2026-57852 (CVE-2026-57852)
vulnerability in CVE-2026-57852 (CVE-2026-57852). Risk of unauthorized operations or information disclosure.
CVE-2026-61425 Vulnerability in CVE-2026-61425 (CVE-2026-61425)
vulnerability in CVE-2026-61425 (CVE-2026-61425). Risk of unauthorized operations or information disclosure.
CVE-2026-63749 Authorization Flaw in surrealdb (CVE-2026-63749)
vulnerability in surrealdb (CVE-2026-63749). Risk of unauthorized operations or information disclosure.

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →