Total
518 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-59524 | 2026-07-23 | N/A | 6.5 MEDIUM | ||
| Unauthenticated Broken Authentication in Easy Digital Downloads <= 3.6.7 versions. | |||||
| CVE-2026-59545 | 2026-07-23 | N/A | 8.1 HIGH | ||
| Unauthenticated Broken Authentication in miniOrange Discord Integration <= 2.2.4 versions. | |||||
| CVE-2026-33843 | 1 Microsoft | 1 Entra Id | 2026-07-23 | N/A | 9.1 CRITICAL |
| Authentication bypass using an alternate path or channel in Microsoft Azure Active Directory B2C allows an unauthorized attacker to elevate privileges over a network. | |||||
| CVE-2025-68711 | 2026-07-23 | N/A | 2.4 LOW | ||
| AppLockZ App Lock and Fingerprint Lock (applock.passwordfingerprint.applockz) 4.2.11 for Android allows a local attacker with physical access to bypass the PIN lock. The lock is implemented as an overlay rather than by using Android's secure authentication APIs. By navigating cascading interface flows - insecure navigation through exposed routes facilitates app control evasion {I.N.T.E.R.F.A.C.E] via advertisement or browser intents, an attacker can evade lockscreen verification and access protected apps (e.g., Chrome). This results in information disclosure and privilege escalation. | |||||
| CVE-2026-10523 | 1 Ivanti | 1 Standalone Sentry | 2026-07-23 | N/A | 9.9 CRITICAL |
| An Authentication Bypass vulnerability (CWE-288) in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated attacker to create arbitrary administrative accounts and obtain full administrative access | |||||
| CVE-2026-39385 | 2026-07-22 | N/A | N/A | ||
| Frappe LMS is an open source learning management system. In version 2.51.0 and earlier, a user could bypass payment validation for courses by using unrelated batch. This has been patched in 2.52.0 with enrollment now validating that the batch is linked to course. | |||||
| CVE-2026-36175 | 2026-07-22 | N/A | 6.8 MEDIUM | ||
| An issue in the U-Boot component of GNCC GP5 v7.1.76 allows physically-proximate attackers to bypass authentication and gain root access via interrupting the boot sequence and injecting a crafted string into the kernel boot arguments. | |||||
| CVE-2026-42654 | 2026-07-22 | N/A | 7.1 HIGH | ||
| Authentication Bypass Using an Alternate Path or Channel vulnerability in WP Swings Wallet System for WooCommerce allows Password Recovery Exploitation. This issue affects Wallet System for WooCommerce: from n/a through 2.7.5. | |||||
| CVE-2026-40780 | 2026-07-22 | N/A | 7.5 HIGH | ||
| Authentication Bypass Using an Alternate Path or Channel vulnerability in Liquid Web / StellarWP BookIt allows Password Recovery Exploitation. This issue affects BookIt: from n/a before 2.5.4.1. | |||||
| CVE-2026-57980 | 1 Microsoft | 1 Edge Chromium | 2026-07-21 | N/A | 5.4 MEDIUM |
| Authentication bypass using an alternate path or channel in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform tampering over a network. | |||||
| CVE-2026-57807 | 2026-07-21 | N/A | 9.8 CRITICAL | ||
| Authentication Bypass Using an Alternate Path or Channel vulnerability in miniOrange Security Software Pvt Ltd. OAuth Single Sign On - SSO (OAuth Client) allows Password Recovery Exploitation. This issue affects OAuth Single Sign On - SSO (OAuth Client): from n/a through 38.5.8. | |||||
| CVE-2026-16198 | 2026-07-21 | 5.1 MEDIUM | 5.6 MEDIUM | ||
| A vulnerability was detected in Sipeed PicoClaw up to 0.2.9. The impacted element is an unknown function of the file web/backend/middleware/access_control.go of the component First Run Setup. Performing a manipulation of the argument allowed_cidrs results in authentication bypass using alternate channel. The attack may be initiated remotely. The attack's complexity is rated as high. The exploitability is regarded as difficult. The exploit is now public and may be used. The patch is named 017601354be38cb027ff3ffb01aed79bd5d12610. Applying a patch is the recommended action to fix this issue. | |||||
| CVE-2026-45577 | 2026-07-21 | N/A | N/A | ||
| Neotoma provides versioned records that persist across agent runs. From 0.6.0 to before 0.11.1, Neotoma can treat public reverse-proxied requests as local when the app receives them over a loopback socket and no Bearer token is present. In affected deployments, the REST auth middleware can resolve unauthenticated requests as the local development user, making the hosted Inspector and related API surface reachable without credentials. This vulnerability is fixed in 0.11.1. | |||||
| CVE-2025-41273 | 1 Waterfall-security | 2 Wf-500, Wf-500 Firmware | 2026-07-21 | N/A | 9.8 CRITICAL |
| Nozomi Networks Labs identified a CWE-288: Authentication Bypass Using an Alternate Path or Channel in the Console WebUI in Waterfall WF-500 TX and RX Hosts in version 7.9.1.0 R2502171040 that allows remote unauthenticated attackers to bypass authentication of the Console web application and perform actions as an authenticated user. | |||||
| CVE-2025-3652 | 1 Petlibro | 1 Petlibro | 2026-07-20 | N/A | 5.3 MEDIUM |
| Petlibro Smart Pet Feeder Platform versions up to 1.7.31 contains an information disclosure vulnerability that allows unauthorized access to private audio recordings by exploiting sequential audio IDs and insecure assignment endpoints. Attackers can send requests to /device/deviceAudio/use with arbitrary audio IDs to assign recordings to any device, then retrieve audio URLs to access other users' private recordings. | |||||
| CVE-2026-8598 | 2026-07-20 | N/A | 9.1 CRITICAL | ||
| An undocumented configuration export port is accessible on some models of ZKTeco CCTV cameras. This port does not require authentication and exposes critical information about the camera such as open services and camera account credentials. | |||||
| CVE-2026-45109 | 1 Vercel | 1 Next.js | 2026-07-16 | N/A | 7.5 HIGH |
| Next.js is a React framework for building full-stack web applications. From 15.2.0 to before 15.5.18 and 16.2.6, it was found that the fix addressing CVE-2026-44575 did not apply to middleware.ts with Turbopack. This vulnerability is fixed in 15.5.18 and 16.2.6. | |||||
| CVE-2026-44574 | 1 Vercel | 1 Next.js | 2026-07-16 | N/A | 8.1 HIGH |
| Next.js is a React framework for building full-stack web applications. From 15.4.0 to before 15.5.16 and 16.2.5, applications that rely on middleware to protect dynamic routes can be vulnerable to authorization bypass. In affected deployments, specially crafted query parameters can alter the dynamic route value seen by the page while leaving the visible path unchanged, which can allow protected content to be rendered without passing the expected middleware check. This vulnerability is fixed in 15.5.16 and 16.2.5. | |||||
| CVE-2026-47481 | 2026-07-15 | N/A | 6.5 MEDIUM | ||
| NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause an authentication bypass through an alternative path or channel. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure, and data tampering. | |||||
| CVE-2026-4700 | 1 Mozilla | 1 Firefox | 2026-07-15 | N/A | 9.8 CRITICAL |
| Mitigation bypass in the Networking: HTTP component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9. | |||||
