CVE-2026-89177High· 8.8▾ TwilightWeenyGenius, a computer lab management system by Howyar Technologies, has a Use of Insecure Protocol vulnerability. Due to the reliance on ZMTP Null mode, unauthenticated attackers on the same network can capture packets to leak transmit…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 48.4 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Exploit-prediction probability, daily snapshots since Sep 11.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
0.2%
WeenyGenius, a computer lab management system by Howyar Technologies, has a Use of Insecure Protocol vulnerability. Due to the reliance on ZMTP Null mode, unauthenticated attackers on the same network can capture packets to leak transmitted data, or perform replay attacks with forged commands to disrupt classroom operations.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-89176High· 8.8WeenyGenius, a computer lab management system developed by Howyar Technologies, has a Missing Authentication vulnerability
CVE-2026-89178High· 8.8WeenyGenius, a computer lab management system by Howyar Technologies, has an Origin Validation Error vulnerability
CVE-2026-89179Medium· 4.3WeenyGenius, a computer lab management system by Howyar Technologies, has a Missing Support for Integrity Check vulnerability
CVE-2026-55953High· 7.4The Erlang/OTP ssl TLS 1.2 (and earlier) and DTLS client does not verify that the cipher suite selected by the server in ServerHello was among the suites offered by the client in ClientHello
CVE-2026-18691High· 8.8An issue in MongoDB Server's intra-cluster connection setup could allow a party with suitable network access to influence which authentication mechanism is used when one replica set member connects to another
CVE-2026-54291HighPostgreSQL JDBC Driver: Silent channel-binding authentication downgrade via unsupported certificate algorithms