[ advisories ]

the public advisory dataset

CC-BY 4.0 · stable ids · forkable

ADVISORIES

The KEV for AI exposure

32 exposure-class advisories (unclaimed setup pages, no-auth-by-design APIs, agent-memory stores): the deployment exposures no CNA or bounty program will ever record. Plus 28 curated CVE mappings with verification provenance.

Every record has a stable UNAUTH-2026-NNNN id and a canonical citation line. The dataset is CC-BY 4.0: attribute "unauth.dev / Raúl Acedo". Records with honeypot telemetry carry an in_the_wild block only unauth.dev can publish; records without telemetry say so (null). Numbers are never invented.

Raw JSON Fork the dataset Census Honeypot

[ ledger ]

All records

exposure-class first · they're the point

60 records.

ID Product Advisory Severity In the wild
UNAUTH-2026-0001 Ollama Ollama API open to the internet
no-auth-by-design
CRITICAL 367 probes/30d Record →
UNAUTH-2026-0002 n8n n8n instance open — settings or owner-setup reachable without login
unclaimed-setup
CRITICAL 431 probes/30d Record →
UNAUTH-2026-0003 Open WebUI Open WebUI reachable from the internet
no-auth-by-design
HIGH Record →
UNAUTH-2026-0004 vLLM vLLM API open to the internet
no-auth-by-design
HIGH Record →
UNAUTH-2026-0005 Langfuse Langfuse reachable from the internet
agent-trace-store
MEDIUM 2,399 probes/30d Record →
UNAUTH-2026-0006 ComfyUI ComfyUI open to the internet
no-auth-by-design
CRITICAL Record →
UNAUTH-2026-0007 Ray Ray dashboard open to the internet
no-auth-by-design
CRITICAL Record →
UNAUTH-2026-0008 Qdrant Qdrant vector database open without authentication
agent-memory-store
CRITICAL 22 probes/30d Record →
UNAUTH-2026-0009 Qdrant Qdrant gRPC data plane (:6334) accepts connections
data-plane
HIGH Record →
UNAUTH-2026-0010 Milvus Milvus vector database exposed to the internet
agent-memory-store
HIGH Record →
UNAUTH-2026-0011 Milvus Milvus gRPC data plane (:19530) accepts connections
data-plane
HIGH Record →
UNAUTH-2026-0012 Dify Dify console exposed to the internet
unclaimed-setup
CRITICAL Record →
UNAUTH-2026-0013 AnythingLLM AnythingLLM open without authentication
no-auth-by-design
CRITICAL Record →
UNAUTH-2026-0014 Jupyter Jupyter notebook server exposed
no-auth-by-design
CRITICAL Record →
UNAUTH-2026-0015 Gradio Gradio app exposed to the internet
no-auth-by-design
HIGH 3 probes/30d Record →
UNAUTH-2026-0016 Langflow Langflow instance exposed to the internet
no-auth-by-design
HIGH Record →
UNAUTH-2026-0017 Flowise Flowise agent builder / public chatflows exposed
no-auth-by-design
CRITICAL Record →
UNAUTH-2026-0018 Chroma Chroma vector database open without authentication
agent-memory-store
CRITICAL 245 probes/30d Record →
UNAUTH-2026-0019 Weaviate Weaviate vector database open without authentication
agent-memory-store
CRITICAL Record →
UNAUTH-2026-0020 Weaviate Weaviate gRPC data plane (:50051) accepts connections
data-plane
HIGH Record →
UNAUTH-2026-0021 Redis Redis management console exposed to the internet
agent-memory-store
CRITICAL Record →
UNAUTH-2026-0022 LangServe LangServe chain API exposed without authentication
no-auth-by-design
CRITICAL Record →
UNAUTH-2026-0023 OpenClaw OpenClaw control plane exposed to the internet
no-auth-by-design
CRITICAL Record →
UNAUTH-2026-0024 OpenHands OpenHands agent server exposed to the internet
no-auth-by-design
CRITICAL Record →
UNAUTH-2026-0025 OpenAI-compatible API OpenAI-compatible API exposed without authentication
no-auth-by-design
HIGH Record →
UNAUTH-2026-0026 AutoGen Studio AutoGen Studio agent API exposed without authentication
no-auth-by-design
CRITICAL Record →
UNAUTH-2026-0027 CrewAI Studio CrewAI Studio exposed to the internet
no-auth-by-design
HIGH Record →
UNAUTH-2026-0028 MCP MCP server exposed without authentication
tool-transport
CRITICAL 304 probes/30d Record →
UNAUTH-2026-0029 MLflow MLflow tracking UI/API reachable without authentication
no-auth-by-design
HIGH Record →
UNAUTH-2026-0030 LiteLLM LiteLLM proxy reachable without a master key
no-auth-by-design
HIGH Record →
UNAUTH-2026-0031 Kubeflow Kubeflow dashboard reachable without authentication
no-auth-by-design
HIGH Record →
UNAUTH-2026-0032 LM Studio LM Studio local API reachable without authentication
no-auth-by-design
HIGH Record →
UNAUTH-2026-0033 n8n n8n CVE-2026-21858 (Ni8mare)
cve
CRITICAL Record →
UNAUTH-2026-0034 Ollama Ollama CVE-2024-37032 (Probllama)
cve
CRITICAL Record →
UNAUTH-2026-0035 ComfyUI-Manager ComfyUI-Manager CVE-2025-67303
cve
CRITICAL Record →
UNAUTH-2026-0036 Open WebUI Open WebUI CVE-2026-44551
cve
CRITICAL Record →
UNAUTH-2026-0037 Langfuse Langfuse CVE-2025-64504
cve
MEDIUM Record →
UNAUTH-2026-0038 Langfuse Langfuse CVE-2026-41487
cve
MEDIUM Record →
UNAUTH-2026-0039 vLLM vLLM CVE-2026-22778
cve
CRITICAL Record →
UNAUTH-2026-0040 vLLM vLLM CVE-2026-54236
cve
MEDIUM Record →
UNAUTH-2026-0041 Langflow Langflow CVE-2026-33017
cve
CRITICAL Record →
UNAUTH-2026-0042 n8n n8n CVE-2025-68613
cve CISA KEV
CRITICAL Record →
UNAUTH-2026-0043 Langflow Langflow CVE-2025-3248
cve CISA KEV
CRITICAL Record →
UNAUTH-2026-0044 Langflow Langflow CVE-2026-0770
cve CISA KEV
CRITICAL Record →
UNAUTH-2026-0045 Langflow Langflow CVE-2026-55255
cve CISA KEV
CRITICAL Record →
UNAUTH-2026-0046 Langflow Langflow CVE-2025-34291
cve CISA KEV
CRITICAL Record →
UNAUTH-2026-0047 n8n n8n CVE-2026-65014
cve
MEDIUM Record →
UNAUTH-2026-0048 n8n n8n CVE-2026-65015
cve
HIGH Record →
UNAUTH-2026-0049 n8n n8n CVE-2026-65016
cve
HIGH Record →
UNAUTH-2026-0050 n8n n8n CVE-2026-65589
cve
MEDIUM Record →
UNAUTH-2026-0051 n8n n8n CVE-2026-65590
cve
MEDIUM Record →
UNAUTH-2026-0052 n8n n8n CVE-2026-65591
cve
HIGH Record →
UNAUTH-2026-0053 n8n n8n CVE-2026-65592
cve
HIGH Record →
UNAUTH-2026-0054 n8n n8n CVE-2026-65593
cve
MEDIUM Record →
UNAUTH-2026-0055 n8n n8n CVE-2026-65594
cve
MEDIUM Record →
UNAUTH-2026-0056 n8n n8n CVE-2026-65595
cve
HIGH Record →
UNAUTH-2026-0057 n8n n8n CVE-2026-65596
cve
MEDIUM Record →
UNAUTH-2026-0058 n8n n8n CVE-2026-65597
cve
HIGH Record →
UNAUTH-2026-0059 n8n n8n CVE-2026-65598
cve
HIGH Record →
UNAUTH-2026-0060 n8n n8n CVE-2026-65599
cve
MEDIUM Record →
[ license ]

Use it

CC-BY 4.0

The dataset (this ledger, every record page, and /advisories.json) is CC-BY 4.0: copy, redistribute, and build on it with attribution "unauth.dev / Raúl Acedo" and a link to this page. Site copy and brand stay proprietary; the scanner engine stays MIT as published. Schema and stability promise: additive-only within v1; ids are never renumbered.

unauth.dev advisory dataset — https://unauth.dev/advisories · CC-BY 4.0