Search Results (4383 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-85701 1 Ramon-victor 1 Freegpt-webui 2026-09-08 5.3 Medium
A vulnerability has been found in ramon-victor freegpt-webui up to 098db3dfeb41555c2ca9269df0f13e10ec1c35dc. This issue affects the function ChatCompletion.create of the file g4f/__init__.py of the component Authentication Check. Such manipulation leads to missing authentication. The attack may be performed from remote. The exploit has been disclosed to the public and may be used. This product utilizes a rolling release system for continuous delivery, and as such, version information for affected or updated releases is not disclosed. This vulnerability only affects products that are no longer supported by the maintainer.
CVE-2026-85636 1 Jofpin 1 Trape 2026-09-08 5.3 Medium
A vulnerability was identified in jofpin trape 1.0.0. Affected by this vulnerability is an unknown functionality of the file core/stats.py of the component Login Endpoint. The manipulation leads to missing authentication. The attack may be initiated remotely. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet.
CVE-2026-17057 1 Ibm 1 I 2026-09-08 6.5 Medium
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service and affect data integrity due to missing authentication for critical functions.
CVE-2026-86728 1 Wwbn 1 Avideo 2026-09-08 7.5 High
AVideo through 29.0 contains an authentication bypass vulnerability in plugin/PlayLists/epg.json.php that exposes live-stream keys and private EPG schedules to unauthenticated users. Attackers can request the endpoint with sequential user or playlist IDs to retrieve sensitive credentials, server identifiers, and complete programme schedules without authentication.
CVE-2026-86207 1 N-able 1 N-central 2026-09-08 N/A
An authentication bypass in N-central < 2026.3 HF 3 leads to authentication bypass in internal only APIs
CVE-2026-16876 1 Nec 1 Univerge Ix 2026-09-08 N/A
An authentication bypass vulnerability exists in the WebGUI of Series UNIVERGE IX-R/IX-V. A user could bypass authentication and execute arbitrary CLI commands by tampering with WebGUI messages and sending them to the device via internet.
CVE-2026-86293 1 Sourcecodester 1 Simple Traffic Offense System 2026-09-08 6.5 Medium
A flaw has been found in SourceCodester Simple Traffic Offense System 1.0. Affected by this vulnerability is an unknown functionality of the file delete-user.php of the component Deletion Endpoint. Executing a manipulation of the argument ID can lead to missing authentication. The attack may be launched remotely. The exploit has been published and may be used.
CVE-2026-86259 1 Thu-maic 1 Openmaic 2026-09-08 7.5 High
OpenMAIC before 1.0.1 skips server-side request forgery validation in non-production builds, allowing unauthenticated attackers to reach cloud instance metadata services. Attackers can supply arbitrary provider URLs via the x-base-url header or baseUrl parameter to access sensitive cloud credentials and metadata.
CVE-2026-85702 1 Ramon-victor 1 Freegpt-webui 2026-09-08 7.3 High
A security vulnerability has been detected in ramon-victor freegpt-webui up to 098db3dfeb41555c2ca9269df0f13e10ec1c35dc. Affected is the function _conversation of the file server/backend.py of the component Backend Conversation API. Such manipulation of the argument model leads to missing authentication. The attack may be launched remotely. The exploit has been disclosed publicly and may be used. This product operates on a rolling release basis, ensuring continuous delivery. Consequently, there are no version details for either affected or updated releases. This vulnerability only affects products that are no longer supported by the maintainer.
CVE-2026-19397 1 Asus 1 Control Center Express Agent 2026-09-08 N/A
Missing authentication for a critical function in ASUS Control Center Express Agent allows an unauthenticated nearby user to control the host via a direct connection to the agent when the host has an active login session. Refer to the '  Security Update for ASUS Control Center Express Agent ' section on the ASUS Security Advisory for more information.
CVE-2026-86506 1 Jetbrains 1 Goland 2026-09-08 5.9 Medium
In JetBrains GoLand before 2026.2.2.1 missing authentication on the GoLand profiler's injected pprof server exposed profiling data
CVE-2026-86502 1 Jetbrains 1 Intellij Idea 2026-09-08 8.4 High
In JetBrains IntelliJ IDEA before 2026.2.2 missing TLS and authentication on the IJent gRPC server allowed local code execution on Remote Development hosts
CVE-2026-86486 1 Jetbrains 1 Youtrack 2026-09-08 3.7 Low
In JetBrains YouTrack before 2026.2.18634 the generic VCS webhook handler failed open when its secret was blank
CVE-2026-86480 1 Jetbrains 1 Hub 2026-09-08 9.8 Critical
In JetBrains Hub before 2026.2.52442 an unauthenticated attacker could register a trusted service and gain superuser privileges
CVE-2026-86543 1 Knowns-dev 1 Knowns 2026-09-08 9.8 Critical
knowns versions before 0.30.0 serve the management API without authentication on all network interfaces by default, with no password required on fresh installations. Attackers can access the unauthenticated /api/tunnel/start endpoint to provision a public tunnel and republish the API at a publicly accessible address.
CVE-2026-20514 1 Mediatek, Inc. 1 Mediatek Chipset 2026-09-07 4.4 Medium
In Audio HAL, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11087632; Issue ID: MSV-8244.
CVE-2026-75430 1 Powerjob 1 Powerjob 2026-09-07 9.8 Critical
PowerJob Worker version 5.1.2 (and likely earlier versions) exposes the /worker/deployContainer HTTP endpoint without authentication on the default transport port. This allows a remote attacker to execute arbitrary code.
CVE-2026-85688 1 Ten-framework 1 Ten-framework 2026-09-07 9.8 Critical
TEN Framework 0.11.71 contains unauthenticated arbitrary file read and write vulnerabilities in the TMAN Designer file-content API endpoints. Attackers can submit POST and PUT requests to the /api/designer/v1/file-content endpoints to read arbitrary files or write malicious content to system paths, enabling code execution through authorized_keys, cron files, or executable graph files.
CVE-2026-86124 1 Hkuds 1 Autoagent 2026-09-07 9.8 Critical
AutoAgent contains an unauthenticated remote code execution vulnerability in the TCP server that binds to all interfaces and executes attacker-supplied commands as root. Attackers can connect to the exposed communication port and execute arbitrary bash commands within the container, gaining access to bind-mounted host workspace directories.
CVE-2026-85671 2 Netease, Youdao 2 Qanything, Qanything 2026-09-07 7.5 High
QAnything 2.0.0 contains an authentication bypass vulnerability in the /api/local_doc_qa/get_file_base64 and /api/local_doc_qa/get_doc endpoints that allows unauthenticated attackers to access any uploaded file or document. Attackers can enumerate file identifiers through unauthenticated endpoints and retrieve base64-encoded files or parsed document chunks without ownership verification to disclose cross-tenant knowledge base content.