Total
518 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-42668 | 2026-06-17 | N/A | 7.5 HIGH | ||
| Unauthenticated Broken Authentication in Email Marketing for WooCommerce by Omnisend <= 1.18.0 versions. | |||||
| CVE-2026-42411 | 2026-06-17 | N/A | 8.1 HIGH | ||
| Unauthenticated Broken Authentication in CloudSecure WP Security <= 1.4.7 versions. | |||||
| CVE-2026-42378 | 2026-06-17 | N/A | 6.5 MEDIUM | ||
| Subscriber Broken Authentication in WP Full Stripe Free <= 8.4.1 versions. | |||||
| CVE-2026-42303 | 2026-06-17 | N/A | N/A | ||
| Fides is an open-source privacy engineering platform. From 2.75.0 to before 2.83.2, Fides deployments that enable both subject identity verification and duplicate privacy request detection are affected by a vulnerability in which an administrator can approve a privacy request whose identity was never verified. For erasure policies, this can result in unauthorized deletion of a data subject's records across every integration configured in the affected deployment. This vulnerability is fixed in 2.83.2. | |||||
| CVE-2026-42300 | 2026-06-17 | N/A | N/A | ||
| DevGuard provides vulnerability management for the full software supply chain. Prior to 1.2.2, the SessionMiddleware accepts a client-supplied X-Admin-Token HTTP request header and uses its raw string value as the authenticated userID when no Kratos session cookie is present. An unauthenticated attacker who knows or can guess a target user's Kratos identity UUID can issue requests as that user. Where the target user is an organisation admin or owner, this gives the attacker full control over that organisation's DevGuard resources. This vulnerability is fixed in 1.2.2. | |||||
| CVE-2026-41308 | 1 Apnotic | 1 Password Pusher | 2026-06-17 | N/A | 6.5 MEDIUM |
| Password Pusher is an open source application to communicate sensitive information over the web. Prior to versions 1.69.3 and 2.4.2, a security issue in OSS PasswordPusher allowed unauthenticated creation of file-type pushes through a generic JSON API create path under certain configurations. This could bypass the intended authentication boundary for file push creation. This issue has been patched in versions 1.69.3 and 2.4.2. | |||||
| CVE-2026-41059 | 1 Oauth2 Proxy Project | 1 Oauth2 Proxy | 2026-06-17 | N/A | 8.2 HIGH |
| OAuth2 Proxy is a reverse proxy that provides authentication using OAuth2 providers. Versions 7.5.0 through 7.15.1 have a configuration-dependent authentication bypass. Deployments are affected when all of the following are true: Use of `skip_auth_routes` or the legacy `skip_auth_regex`; use of patterns that can be widened by attacker-controlled suffixes, such as `^/foo/.*/bar$` causing potential exposure of `/foo/secret`; and protected upstream applications that interpret `#` as a fragment delimiter or otherwise route the request to the protected base path. In deployments that rely on these settings, an unauthenticated attacker can send a crafted request containing a number sign in the path, including the browser-safe encoded form `%23`, so that OAuth2 Proxy matches a public allowlist rule while the backend serves a protected resource. Deployments that do not use these skip-auth options, or that only allow exact public paths with tightly scoped method and path rules, are not affected. A fix has been implemented in version 7.15.2 to normalize request paths more conservatively before skip-auth matching so fragment content does not influence allowlist decisions. Users who cannot upgrade immediately can reduce exposure by tightening or removing `skip_auth_routes` and `skip_auth_regex` rules, especially patterns that use broad wildcards across path segments. Recommended mitigations include replacing broad rules with exact, anchored public paths and explicit HTTP methods; rejecting requests whose path contains `%23` or `#` at the ingress, load balancer, or WAF level; and/or avoiding placing sensitive application paths behind broad `skip_auth_routes` rules. | |||||
| CVE-2026-40799 | 2026-06-17 | N/A | 5.3 MEDIUM | ||
| Unauthenticated Broken Authentication in Simple Cloudflare Turnstile <= 1.38.0 versions. | |||||
| CVE-2026-40790 | 2026-06-17 | N/A | 6.5 MEDIUM | ||
| Subscriber Sensitive Data Exposure in WP SMS <= 7.2.1 versions. | |||||
| CVE-2026-40785 | 2026-06-17 | N/A | 7.1 HIGH | ||
| Subscriber Broken Authentication in AutomatorWP <= 5.6.7 versions. | |||||
| CVE-2026-40781 | 2026-06-17 | N/A | 7.5 HIGH | ||
| Unauthenticated Broken Authentication in ReviewX <= 2.3.6 versions. | |||||
| CVE-2026-40630 | 1 Senselive | 2 X3500, X3500 Firmware | 2026-06-17 | N/A | 9.8 CRITICAL |
| A vulnerability in SenseLive X3050’s web management interface allows unauthorized access to certain configuration endpoints due to improper access control enforcement. An attacker with network access to the device may be able to bypass the intended authentication mechanism and directly interact with sensitive configuration functions. | |||||
| CVE-2026-40621 | 2026-06-17 | N/A | 9.8 CRITICAL | ||
| ELECOM wireless LAN access point devices do not require authentication to access some specific URLs. The affected product may be operated without authentication. | |||||
| CVE-2026-40582 | 2026-06-17 | N/A | N/A | ||
| ChurchCRM is an open-source church management system. In versions prior to 7.2.0, the /api/public/user/login endpoint validates only the username and password before returning the user's API key, bypassing the normal authentication flow that enforces account lockout and two-factor authentication checks. An attacker with knowledge of a user's password can obtain API access even when the account is locked or has 2FA enabled, granting direct access to all protected API endpoints with that user's privileges. This issue has been fixed in version 7.2.0. Note: this issue had a duplicate, GHSA-472m-p3gf-46xp, which has been closed. | |||||
| CVE-2026-3930 | 4 Apple, Google, Linux and 1 more | 4 Macos, Chrome, Linux Kernel and 1 more | 2026-06-17 | N/A | 5.3 MEDIUM |
| Unsafe navigation in Navigation in Google Chrome on iOS prior to 146.0.7680.71 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium) | |||||
| CVE-2026-3531 | 1 Bojanz | 1 Openid Connect \/ Oauth Client | 2026-06-17 | N/A | 6.5 MEDIUM |
| Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal OpenID Connect / OAuth client allows Authentication Bypass.This issue affects OpenID Connect / OAuth client: from 0.0.0 before 1.5.0. | |||||
| CVE-2026-3461 | 2026-06-17 | N/A | 9.8 CRITICAL | ||
| The Visa Acceptance Solutions plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 2.1.0. This is due to the `express_pay_product_page_pay_for_order()` function logging users in based solely on a user-supplied billing email address during guest checkout for subscription products, without verifying email ownership, requiring a password, or validating a one-time token. This makes it possible for unauthenticated attackers to log in as any existing user, including administrators, by providing the target user's email address in the billing_details parameter, resulting in complete account takeover and site compromise. | |||||
| CVE-2026-3324 | 2026-06-17 | N/A | 8.2 HIGH | ||
| Zohocorp ManageEngine Log360 versions 13000 through 13013 are vulnerable to authentication bypass on certain actions due to improper filter configuration. | |||||
| CVE-2026-3214 | 1 Arnabdotorg | 1 Captcha | 2026-06-17 | N/A | 6.5 MEDIUM |
| Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal CAPTCHA allows Functionality Bypass.This issue affects CAPTCHA: from 0.0.0 before 1.17.0, from 2.0.0 before 2.0.10. | |||||
| CVE-2026-39450 | 2026-06-17 | N/A | 7.1 HIGH | ||
| Subscriber Broken Authentication in FunnelKit Automations <= 3.7.3 versions. | |||||
