ADVISORIES
The KEV for AI exposure
32 exposure-class advisories (unclaimed setup pages, no-auth-by-design APIs, agent-memory stores): the deployment exposures no CNA or bounty program will ever record. Plus 28 curated CVE mappings with verification provenance.
Every record has a stable UNAUTH-2026-NNNN id and a canonical citation line. The dataset is CC-BY 4.0: attribute "unauth.dev / Raúl Acedo". Records with honeypot telemetry carry an in_the_wild block only unauth.dev can publish; records without telemetry say so (null). Numbers are never invented.
60 records.
| ID | Product | Advisory | Severity | In the wild | |
|---|---|---|---|---|---|
| UNAUTH-2026-0001 | Ollama |
Ollama API open to the internet
no-auth-by-design
|
CRITICAL | 367 probes/30d | Record → |
| UNAUTH-2026-0002 | n8n |
n8n instance open — settings or owner-setup reachable without login
unclaimed-setup
|
CRITICAL | 431 probes/30d | Record → |
| UNAUTH-2026-0003 | Open WebUI |
Open WebUI reachable from the internet
no-auth-by-design
|
HIGH | — | Record → |
| UNAUTH-2026-0004 | vLLM |
vLLM API open to the internet
no-auth-by-design
|
HIGH | — | Record → |
| UNAUTH-2026-0005 | Langfuse |
Langfuse reachable from the internet
agent-trace-store
|
MEDIUM | 2,399 probes/30d | Record → |
| UNAUTH-2026-0006 | ComfyUI |
ComfyUI open to the internet
no-auth-by-design
|
CRITICAL | — | Record → |
| UNAUTH-2026-0007 | Ray |
Ray dashboard open to the internet
no-auth-by-design
|
CRITICAL | — | Record → |
| UNAUTH-2026-0008 | Qdrant |
Qdrant vector database open without authentication
agent-memory-store
|
CRITICAL | 22 probes/30d | Record → |
| UNAUTH-2026-0009 | Qdrant |
Qdrant gRPC data plane (:6334) accepts connections
data-plane
|
HIGH | — | Record → |
| UNAUTH-2026-0010 | Milvus |
Milvus vector database exposed to the internet
agent-memory-store
|
HIGH | — | Record → |
| UNAUTH-2026-0011 | Milvus |
Milvus gRPC data plane (:19530) accepts connections
data-plane
|
HIGH | — | Record → |
| UNAUTH-2026-0012 | Dify |
Dify console exposed to the internet
unclaimed-setup
|
CRITICAL | — | Record → |
| UNAUTH-2026-0013 | AnythingLLM |
AnythingLLM open without authentication
no-auth-by-design
|
CRITICAL | — | Record → |
| UNAUTH-2026-0014 | Jupyter |
Jupyter notebook server exposed
no-auth-by-design
|
CRITICAL | — | Record → |
| UNAUTH-2026-0015 | Gradio |
Gradio app exposed to the internet
no-auth-by-design
|
HIGH | 3 probes/30d | Record → |
| UNAUTH-2026-0016 | Langflow |
Langflow instance exposed to the internet
no-auth-by-design
|
HIGH | — | Record → |
| UNAUTH-2026-0017 | Flowise |
Flowise agent builder / public chatflows exposed
no-auth-by-design
|
CRITICAL | — | Record → |
| UNAUTH-2026-0018 | Chroma |
Chroma vector database open without authentication
agent-memory-store
|
CRITICAL | 245 probes/30d | Record → |
| UNAUTH-2026-0019 | Weaviate |
Weaviate vector database open without authentication
agent-memory-store
|
CRITICAL | — | Record → |
| UNAUTH-2026-0020 | Weaviate |
Weaviate gRPC data plane (:50051) accepts connections
data-plane
|
HIGH | — | Record → |
| UNAUTH-2026-0021 | Redis |
Redis management console exposed to the internet
agent-memory-store
|
CRITICAL | — | Record → |
| UNAUTH-2026-0022 | LangServe |
LangServe chain API exposed without authentication
no-auth-by-design
|
CRITICAL | — | Record → |
| UNAUTH-2026-0023 | OpenClaw |
OpenClaw control plane exposed to the internet
no-auth-by-design
|
CRITICAL | — | Record → |
| UNAUTH-2026-0024 | OpenHands |
OpenHands agent server exposed to the internet
no-auth-by-design
|
CRITICAL | — | Record → |
| UNAUTH-2026-0025 | OpenAI-compatible API |
OpenAI-compatible API exposed without authentication
no-auth-by-design
|
HIGH | — | Record → |
| UNAUTH-2026-0026 | AutoGen Studio |
AutoGen Studio agent API exposed without authentication
no-auth-by-design
|
CRITICAL | — | Record → |
| UNAUTH-2026-0027 | CrewAI Studio |
CrewAI Studio exposed to the internet
no-auth-by-design
|
HIGH | — | Record → |
| UNAUTH-2026-0028 | MCP |
MCP server exposed without authentication
tool-transport
|
CRITICAL | 304 probes/30d | Record → |
| UNAUTH-2026-0029 | MLflow |
MLflow tracking UI/API reachable without authentication
no-auth-by-design
|
HIGH | — | Record → |
| UNAUTH-2026-0030 | LiteLLM |
LiteLLM proxy reachable without a master key
no-auth-by-design
|
HIGH | — | Record → |
| UNAUTH-2026-0031 | Kubeflow |
Kubeflow dashboard reachable without authentication
no-auth-by-design
|
HIGH | — | Record → |
| UNAUTH-2026-0032 | LM Studio |
LM Studio local API reachable without authentication
no-auth-by-design
|
HIGH | — | Record → |
| UNAUTH-2026-0033 | n8n |
n8n CVE-2026-21858 (Ni8mare)
cve
|
CRITICAL | — | Record → |
| UNAUTH-2026-0034 | Ollama |
Ollama CVE-2024-37032 (Probllama)
cve
|
CRITICAL | — | Record → |
| UNAUTH-2026-0035 | ComfyUI-Manager |
ComfyUI-Manager CVE-2025-67303
cve
|
CRITICAL | — | Record → |
| UNAUTH-2026-0036 | Open WebUI |
Open WebUI CVE-2026-44551
cve
|
CRITICAL | — | Record → |
| UNAUTH-2026-0037 | Langfuse |
Langfuse CVE-2025-64504
cve
|
MEDIUM | — | Record → |
| UNAUTH-2026-0038 | Langfuse |
Langfuse CVE-2026-41487
cve
|
MEDIUM | — | Record → |
| UNAUTH-2026-0039 | vLLM |
vLLM CVE-2026-22778
cve
|
CRITICAL | — | Record → |
| UNAUTH-2026-0040 | vLLM |
vLLM CVE-2026-54236
cve
|
MEDIUM | — | Record → |
| UNAUTH-2026-0041 | Langflow |
Langflow CVE-2026-33017
cve
|
CRITICAL | — | Record → |
| UNAUTH-2026-0042 | n8n |
n8n CVE-2025-68613
cve
CISA KEV
|
CRITICAL | — | Record → |
| UNAUTH-2026-0043 | Langflow |
Langflow CVE-2025-3248
cve
CISA KEV
|
CRITICAL | — | Record → |
| UNAUTH-2026-0044 | Langflow |
Langflow CVE-2026-0770
cve
CISA KEV
|
CRITICAL | — | Record → |
| UNAUTH-2026-0045 | Langflow |
Langflow CVE-2026-55255
cve
CISA KEV
|
CRITICAL | — | Record → |
| UNAUTH-2026-0046 | Langflow |
Langflow CVE-2025-34291
cve
CISA KEV
|
CRITICAL | — | Record → |
| UNAUTH-2026-0047 | n8n |
n8n CVE-2026-65014
cve
|
MEDIUM | — | Record → |
| UNAUTH-2026-0048 | n8n |
n8n CVE-2026-65015
cve
|
HIGH | — | Record → |
| UNAUTH-2026-0049 | n8n |
n8n CVE-2026-65016
cve
|
HIGH | — | Record → |
| UNAUTH-2026-0050 | n8n |
n8n CVE-2026-65589
cve
|
MEDIUM | — | Record → |
| UNAUTH-2026-0051 | n8n |
n8n CVE-2026-65590
cve
|
MEDIUM | — | Record → |
| UNAUTH-2026-0052 | n8n |
n8n CVE-2026-65591
cve
|
HIGH | — | Record → |
| UNAUTH-2026-0053 | n8n |
n8n CVE-2026-65592
cve
|
HIGH | — | Record → |
| UNAUTH-2026-0054 | n8n |
n8n CVE-2026-65593
cve
|
MEDIUM | — | Record → |
| UNAUTH-2026-0055 | n8n |
n8n CVE-2026-65594
cve
|
MEDIUM | — | Record → |
| UNAUTH-2026-0056 | n8n |
n8n CVE-2026-65595
cve
|
HIGH | — | Record → |
| UNAUTH-2026-0057 | n8n |
n8n CVE-2026-65596
cve
|
MEDIUM | — | Record → |
| UNAUTH-2026-0058 | n8n |
n8n CVE-2026-65597
cve
|
HIGH | — | Record → |
| UNAUTH-2026-0059 | n8n |
n8n CVE-2026-65598
cve
|
HIGH | — | Record → |
| UNAUTH-2026-0060 | n8n |
n8n CVE-2026-65599
cve
|
MEDIUM | — | Record → |
The dataset (this ledger, every record page, and /advisories.json) is CC-BY 4.0: copy, redistribute, and build on it with attribution "unauth.dev / Raúl Acedo" and a link to this page. Site copy and brand stay proprietary; the scanner engine stays MIT as published. Schema and stability promise: additive-only within v1; ids are never renumbered.
unauth.dev advisory dataset — https://unauth.dev/advisories · CC-BY 4.0