VulnSea

CWE-287

CVEs classified under CWE-287, newest first.

397 CVEsRSS

CVE-2026-61687High· 7.1
today

Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale

Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale. Prior to 0.91.1, ValidateOAuthState clears the oauth_state_ session value to an empty string after a successful OAuth callback and later…

Twilighthatchet · hatchetvia NVD
CVE-2026-61630Medium· 4.2
today

nginx ignition is a user interface for the nginx web server

nginx ignition is a user interface for the nginx web server. In versions 2.33.0 through 2.35.0, any user that has enabled the OTP 2FA can have their TOTP reused during the standard 30 second validity window. Version 2.35.1 patches the is…

Sunlitlucasdillmann · nginx-ignitionvia NVD
CVE-2026-94151Medium· 5.3PoC
today

A weakness has been identified in Omega Solution HRM OS up to 20260717

A weakness has been identified in Omega Solution HRM OS up to 20260717. This affects an unknown function of the file /role-permission/permission of the component Role Permission API. Executing a manipulation of the argument roleId can le…

TwilightOmega Solution · HRM OSEPSS 0.39%via NVD
CVE-2026-93964Medium· 5.3
yesterday

A vulnerability was detected in NginxProxyManager nginx-proxy-manager up to 2.15.1

A vulnerability was detected in NginxProxyManager nginx-proxy-manager up to 2.15.1. This impacts the function internalCertificate.validate of the file backend/internal/certificate.js of the component Validate Route. The manipulation resu…

SunlitNginxProxyManager · nginx-proxy-managerEPSS 0.27%via NVD
CVE-2026-93960Medium· 4.3
yesterday

A vulnerability was identified in Pixelfed up to 0.12.11

A vulnerability was identified in Pixelfed up to 0.12.11. Impacted is the function instancePeers of the file app/Http/Controllers/Api/ApiV1Controller.php of the component OAuth Scope Handler. Such manipulation of the argument ID leads to…

SunlitEPSS 0.37%via NVD
CVE-2026-93984Medium· 5.3
2d ago

OpenPanel tracking API through commit bad75bddc74d12d36cfb843f4531d3b830a8d994 fails to verify client secret cryptographic hash before authorizing revenue events and bot filtering

OpenPanel tracking API through commit bad75bddc74d12d36cfb843f4531d3b830a8d994 fails to verify client secret cryptographic hash before authorizing revenue events and bot filtering. Attackers with only a public client ID can supply arbitr…

SunlitOpenpanel-dev · openpanelEPSS 0.20%via NVD
CVE-2026-89093Medium· 5.3
2d ago

The Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots plugin for WordPress is vulnerable to Information Exposure by Spoofing in all versions up to, and including, 2.15.33

The Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots plugin for WordPress is vulnerable to Information Exposure by Spoofing in all versions up to, and including, 2.15.33. This is due to the `is_ai_bot_user()` fun…

Sunlitwordplus · Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat BotsEPSS 0.33%via NVD
CVE-2026-75878Critical· 9.1
3d ago

IBM Sterling File Gateway could allow a remote attacker to bypass authentication and obtain a fully authenticated session due to improper authentication via an unvalidated SSO header.

IBM Sterling File Gateway could allow a remote attacker to bypass authentication and obtain a fully authenticated session due to improper authentication via an unvalidated SSO header.

MidnightIBM · Sterling File GatewayEPSS 0.48%via NVD
CVE-2026-93559High· 7.3
3d ago

A vulnerability was identified in Forget-C Jellyfish AI Short Drama Studio 0.1.0-alpha/0.2.0/0.3.0/0.3.1/0.3.2

A vulnerability was identified in Forget-C Jellyfish AI Short Drama Studio 0.1.0-alpha/0.2.0/0.3.0/0.3.1/0.3.2. This affects an unknown function of the file backend/app/dependencies.py of the component FastAPI. The manipulation leads to …

TwilightForget-C · Jellyfish AI Short Drama StudioEPSS 0.38%via NVD
CVE-2026-93532Medium· 6.3
3d ago

A security vulnerability has been detected in gedelumbung HospitalManagement up to c2d45543789a3887067d3915f69d44cfc2cf76a8

A security vulnerability has been detected in gedelumbung HospitalManagement up to c2d45543789a3887067d3915f69d44cfc2cf76a8. This issue affects the function application/modules/global/controllers/password.php::simpan/application/modules/…

Sunlitgedelumbung · HospitalManagementEPSS 0.49%via NVD
CVE-2024-38639Medium· 4.8
3d ago

An improper authentication vulnerability has been reported to affect product

An improper authentication vulnerability has been reported to affect product. The remote attackers can then exploit the vulnerability to compromise the security of the system. QTS is not affected. We have already fixed the vulnerability…

SunlitQNAP Systems Inc. · QTSEPSS 0.25%via NVD
CVE-2026-85350Medium· 5.3
3d ago

The UpsellWP WordPress plugin before 2.2.10 does not check that products added to the cart through a Frequently Bought Together campaign belong to that campaign, allowing unauthenticated users to buy arbitrary products at the campaign's…

The UpsellWP WordPress plugin before 2.2.10 does not check that products added to the cart through a Frequently Bought Together campaign belong to that campaign, allowing unauthenticated users to buy arbitrary products at the campaign's…

SunlitEPSS 0.22%via NVD
CVE-2026-82980Medium· 6.3
3d ago

Any authenticated user can lock or unlock files they do not own by targeting absolute WebDAV paths of other users

Any authenticated user can lock or unlock files they do not own by targeting absolute WebDAV paths of other users. The DAV plugin resolves files from the absolute request URI without verifying that the path segment matches the authentica…

SunlitNextcloud · Files LockEPSS 0.21%via NVD
CVE-2026-54510High· 7.1PoC
4d ago

Speakr is a personal, self-hosted web application designed for transcribing audio recordings

Speakr is a personal, self-hosted web application designed for transcribing audio recordings. Prior to 0.8.21-alpha, the csrf_exempt_for_api_tokens() before_request hook in src/app.py calls csrf.exempt(view_func), permanently adding the …

Midnightmurtaza-nasir · speakrEPSS 0.14%via NVD
CVE-2026-85716Low· 3.7
4d ago

The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses

The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 3.0.8 until 3.0.12, processScramAuthenticationInfo and processAuthenticationInfo compute the SCRAM…

SunlitAsyncHttpClient · async-http-clientEPSS 0.32%via NVD
CVE-2026-88952Critical· 9.1
4d ago

Improper Authentication vulnerability in team-alembic AshAuthentication allows an attacker to be signed in as another user by linking an OAuth2 identity to an account that is not theirs. AshAuthentication.Strategy.OAuth2.UserResolver.re…

Improper Authentication vulnerability in team-alembic AshAuthentication allows an attacker to be signed in as another user by linking an OAuth2 identity to an account that is not theirs. AshAuthentication.Strategy.OAuth2.UserResolver.re…

Midnightteam-alembic · ash_authenticationEPSS 0.43%via NVD
CVE-2026-63472Critical· 9.1PoC
4d ago

Vendure is an open-source headless commerce platform

Vendure is an open-source headless commerce platform. Prior to 3.7.0, ExternalAuthenticationService.createCustomerAndUser in packages/core/src/service/helpers/external-authentication/external-authentication.service.ts selects an existing…

Abyssalvendurehq · vendureEPSS 0.41%via NVD
CVE-2026-80218High· 7.6
4d ago

Improper Authentication vulnerability in team-alembic AshAuthentication allows an attacker holding a sign-in token for one authenticated resource to be signed in as a user of a different resource. AshAuthentication.Strategy.Password.Sig…

Improper Authentication vulnerability in team-alembic AshAuthentication allows an attacker holding a sign-in token for one authenticated resource to be signed in as a user of a different resource. AshAuthentication.Strategy.Password.Sig…

Twilightteam-alembic · ash_authenticationEPSS 0.45%via NVD
CVE-2026-92914High· 8.1
4d ago

AVideo LoginControl contains an authentication bypass vulnerability in the PGP second factor verification that compares challenge responses using loose equality against an uninitialized session variable

AVideo LoginControl contains an authentication bypass vulnerability in the PGP second factor verification that compares challenge responses using loose equality against an uninitialized session variable. Attackers with a victim's passwor…

TwilightWWBN · AVideoEPSS 0.33%via NVD
CVE-2026-78425High· 7.6
4d ago

Authorised users of outside applications behind the same corporate identity provider (IdP), for example, a wiki, a ticketing system, an expenses tool, or anything they legitimately hold an account on can log into their system via SAML SS…

Authorised users of outside applications behind the same corporate identity provider (IdP), for example, a wiki, a ticketing system, an expenses tool, or anything they legitimately hold an account on can log into their system via SAML SS…

Twilightgo · github.com/neuvector/neuvectorEPSS 0.35%via NVD
CVE-2026-86707Critical· 9.8
4d ago

The Private Feed Key WordPress plugin through 0.1 does not verify that the key used to authenticate a feed request is one it issued, matching any stored user metadata value instead, which allows unauthenticated attackers to log in as any…

The Private Feed Key WordPress plugin through 0.1 does not verify that the key used to authenticate a feed request is one it issued, matching any stored user metadata value instead, which allows unauthenticated attackers to log in as any…

MidnightEPSS 0.28%via NVD
CVE-2026-86709Critical· 9.8
4d ago

The Pressengine WordPress plugin through 1.0 does not stop its login handler from issuing a session when authentication fails, allowing unauthenticated attackers to log in as any user, including administrators.

The Pressengine WordPress plugin through 1.0 does not stop its login handler from issuing a session when authentication fails, allowing unauthenticated attackers to log in as any user, including administrators.

MidnightEPSS 0.34%via NVD
CVE-2026-86710Critical· 9.8
4d ago

The Login with QR WordPress plugin through 1.0.0 does not verify that the code used to log a user in is one it issued, matching any stored user metadata value instead, which allows unauthenticated attackers to log in as any user, includi…

The Login with QR WordPress plugin through 1.0.0 does not verify that the code used to log a user in is one it issued, matching any stored user metadata value instead, which allows unauthenticated attackers to log in as any user, includi…

MidnightEPSS 0.28%via NVD
CVE-2026-92578High· 8.1PoC
5d ago

WWBN AVideo through 29.0 contains an authentication bypass vulnerability where the stored password hash is accepted as a valid login credential through two independent code paths in loginFromRequest() and encryptPasswordVerify()

WWBN AVideo through 29.0 contains an authentication bypass vulnerability where the stored password hash is accepted as a valid login credential through two independent code paths in loginFromRequest() and encryptPasswordVerify(). Attacke…

MidnightWWBN · AVideoEPSS 0.33%via NVD
CVE-2026-92792High· 7.5PoC
5d ago

OpenNHP through 1.0.2 selects its trusted-execution attestation verifier based on attacker-supplied evidence containing a test_purpose key, causing the FallbackVerifier to execute unconditionally

OpenNHP through 1.0.2 selects its trusted-execution attestation verifier based on attacker-supplied evidence containing a test_purpose key, causing the FallbackVerifier to execute unconditionally. Attackers can bypass attestation verific…

MidnightOpenNHP · opennhpEPSS 0.45%via NVD
CVE-2026-92401High· 7.3
5d ago

A vulnerability was identified in ChangeWeDer crm up to c07bd4c97141521af6475034bc58523beed51bbd

A vulnerability was identified in ChangeWeDer crm up to c07bd4c97141521af6475034bc58523beed51bbd. This vulnerability affects the function top.upstudy.crm.utils.LoginUserUtil.releaseUserIdFromCookie. The manipulation leads to improper aut…

TwilightChangeWeDer · crmEPSS 0.66%via NVD
CVE-2025-43936High· 8.1
5d ago

Dell ObjectScale, versions prior to ObjectScale 4.4.0.0, contains an Improper Authentication vulnerability

Dell ObjectScale, versions prior to ObjectScale 4.4.0.0, contains an Improper Authentication vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access.

Twilightdell · objectscaleEPSS 0.48%via NVD
CVE-2026-19607Medium· 5.3
5d ago

A flaw was found in the first-broker-login flow of the keycloak-services component

A flaw was found in the first-broker-login flow of the keycloak-services component. This component handles the initial authentication and account linking when a user logs in via an external identity provider. The issue allows an attacker…

SunlitRed Hat · keycloak-rhel9-containerEPSS 0.51%via NVD
CVE-2026-76187Critical· 9.8
5d ago

Apache Airflow Keycloak provider: the unauthenticated token endpoint accepts a client-credentials grant for any confidential client registered in the Keycloak realm, not only the client configured for Airflow

Apache Airflow Keycloak provider: the unauthenticated token endpoint accepts a client-credentials grant for any confidential client registered in the Keycloak realm, not only the client configured for Airflow. No allowlist restricts whic…

Midnightapache · apache-airflow-providers-keycloakEPSS 0.95%via NVD
CVE-2026-87217Critical· 9.1
6d ago

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security)

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows unauthenticated attacker with …

Midnightoracle · hyperion_financial_managementEPSS 0.38%via NVD
CWE-287 vulnerabilities (CVEs) · VulnSea