VulnSea

CWE-287

CVEs classified under CWE-287, newest first.

462 CVEsRSS

CVE-2026-56169High· 8.1
2mo ago

Windows Admin Center Elevation of Privilege Vulnerability

Improper authentication in Windows Admin Center allows an authorized attacker to elevate privileges over a network.

▾ TwilightMicrosoft · Windows Admin CenterEPSS 0.75%via CVEORG
CVE-2026-50365High· 8.0
2mo ago

Remote Access Management service/API (RPC server) Elevation of Privilege Vulnerability

Improper authentication in Windows RPC API allows an unauthorized attacker to elevate privileges over an adjacent network.

▾ TwilightMicrosoft · Windows 10 Version 1607EPSS 0.54%via CVEORG
CVE-2026-47677Critical
2mo ago

FacturaScripts: Account takeover of any 2FA-enabled user

FacturaScripts: Account takeover of any 2FA-enabled user

▾ Midnightfacturascripts · facturascripts/facturascriptsvia GHSA
CVE-2026-59955High· 7.5
2mo ago

Apollo ConfigService access key authentication bypass via raw config file appId parsing

Apollo ConfigService access key authentication bypass via raw config file appId parsing

▾ Twilightctrip · com.ctrip.framework.apollo:apolloEPSS 0.57%via GHSA
CVE-2026-59954High· 7.5
2mo ago

Apollo ConfigService access key authentication bypass via appId parsing and non-canonical matching

Apollo ConfigService access key authentication bypass via appId parsing and non-canonical matching

▾ Twilightctrip · com.ctrip.framework.apollo:apolloEPSS 0.57%via GHSA
CVE-2026-15542High· 7.3
2mo ago

A vulnerability has been found in will-moss Isaiah up to 1.36.9

A vulnerability has been found in will-moss Isaiah up to 1.36.9. This affects an unknown function of the file app/main.go of the component Websocket Connection Authentication. The manipulation leads to improper authentication. The attack…

▾ TwilightEPSS 0.70%via NVD
CVE-2026-15491High· 7.3
2mo ago

A weakness has been identified in RafyMrX TOKO-ONLINE-ROTI up to ddfe1cd587be0a0b5135d8b6e85cce2ec3aece99

A weakness has been identified in RafyMrX TOKO-ONLINE-ROTI up to ddfe1cd587be0a0b5135d8b6e85cce2ec3aece99. This affects an unknown part. This manipulation causes missing authentication. The attack is possible to be carried out remotely. …

▾ TwilightEPSS 0.65%via NVD
CVE-2026-56666Medium· 4.8
2mo ago

ZITADEL is an open source identity management platform

ZITADEL is an open source identity management platform. Prior to 4.15.3, ZITADEL's external identity provider handler checks that the local user's email is verified but does not verify that the external IdP confirmed ownership of the sam…

▾ Sunlitzitadel · zitadelEPSS 0.29%via NVD
CVE-2026-57216Medium· 6.8
2mo ago

RabbitMQ is a messaging and streaming broker

RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.20, 4.1.11, and 4.2.6, AMQP 0-9-1, AMQP 1.0, and Stream Protocol authentication can allow a loopback-restricted user such as guest to connect remotely when traffic is ac…

▾ SunlitEPSS 0.50%via NVD
CVE-2026-12761Critical· 9.8
2mo ago

The miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) plugin for WordPress is vulnerable to authentication bypass leading to account takeover in versions up to and including 7.7.0

The miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) plugin for WordPress is vulnerable to authentication bypass leading to account takeover in versions up to and including 7.7.0. This is due to the Profile Compl…

▾ MidnightEPSS 0.89%via NVD
CVE-2026-55377High· 8.1
2mo ago

Logto is the modern, open-source auth infrastructure for SaaS and AI apps

Logto is the modern, open-source auth infrastructure for SaaS and AI apps. Prior to 1.41.0, Logto's Account Center step-up check accepted any active verification record that belonged to the current user and had isVerified === true. A Web…

▾ TwilightEPSS 0.46%via NVD
GHSA-g936-7jqj-mwv8Critical· 9.0
2mo ago

TSDProxy: Internal proxy auth token forwarded to backend services enables management API escalation

TSDProxy: Internal proxy auth token forwarded to backend services enables management API escalation

▾ Midnightalmeidapaulopt · github.com/almeidapaulopt/tsdproxyvia GHSA
CVE-2026-54089Critical· 9.1
2mo ago

File Browser: Authentication Bypass via Proxy Auth Header Forgery

File Browser: Authentication Bypass via Proxy Auth Header Forgery

▾ Midnightfilebrowser · github.com/filebrowser/filebrowser/v2EPSS 0.61%via GHSA
CVE-2026-15192Medium· 6.5
2mo ago

A vulnerability has been found in mettle sendportal up to 3.0.1

A vulnerability has been found in mettle sendportal up to 3.0.1. This issue affects the function sendgrid/postmark/postal/mailjet of the component APIv1 Webhooks. The manipulation leads to missing authentication. The attack is possible t…

▾ SunlitEPSS 0.76%via NVD
CVE-2026-58253High· 8.8
2mo ago

NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system

NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.0, 2.12.7, and 2.11.16, when no_auth_user was configured, a parser fast path intended for ordinary client connections could a…

▾ Twilightlinuxfoundation · nats-serverEPSS 0.37%via NVD
CVE-2026-59822High· 8.2CISA KEVPoC
2mo ago

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.84.0, LiteLLM's MCP Streamable HTTP endpoint allowed an unauthenticated attacker to use a fabricated Authorization header to trigger an OAut…

▾ Abyssallitellm · litellmEPSS 0.84%via NVD
GHSA-f66q-9rf6-8795Medium
2mo ago

Flask-Security-Too: WebAuthn reauthentication freshness bypass via cross-user assertion

Flask-Security-Too: WebAuthn reauthentication freshness bypass via cross-user assertion

▾ Sunlitflask-security-too · flask-security-toovia OSV
CVE-2026-53514High· 7.7
2mo ago

Better Auth vulnerable to unauthorized invitation acceptance via unverified email match in organization plugin

Better Auth vulnerable to unauthorized invitation acceptance via unverified email match in organization plugin

▾ Twilightbetter-auth · better-authEPSS 0.20%via GHSA
CVE-2026-53516High· 8.3
2mo ago

Better Auth has an account takeover issue via OAuth auto-link to unverified pre-registered email

Better Auth has an account takeover issue via OAuth auto-link to unverified pre-registered email

▾ Twilightbetter-auth · better-authEPSS 0.29%via GHSA
CVE-2026-53512Critical· 9.1
2mo ago

Better Auth: OAuth refresh-token replay via missing client authentication on oidc-provider and mcp plugins

Better Auth: OAuth refresh-token replay via missing client authentication on oidc-provider and mcp plugins

▾ Midnightbetter-auth · better-authEPSS 0.27%via GHSA
CVE-2026-55076High· 7.4
2mo ago

Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking

Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking

▾ Twilightcoder · github.com/coder/coder/v2EPSS 0.61%via GHSA
CVE-2026-55075High· 7.4
2mo ago

Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass

Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass

▾ Twilightcoder · github.com/coder/coder/v2EPSS 0.48%via GHSA
CVE-2026-14627Medium· 5.6
2mo ago

A security vulnerability has been detected in NousResearch hermes-agent up to 0.15.2

A security vulnerability has been detected in NousResearch hermes-agent up to 0.15.2. This affects the function DiscordAdapter._is_allowed_user of the file gateway/platforms/discord.py of the component Discord Platform Integration. Such …

▾ SunlitEPSS 0.55%via NVD
CVE-2026-12196None
2mo ago

HestiaCP panel cronjob feature is affected by a broken access control vulnerability

HestiaCP panel cronjob feature is affected by a broken access control vulnerability. Low privilege users can modify the panel cronjob to execute scripts HestiaCP management scripts with passwordless sudo. This could result in the takeove…

▾ SunlitEPSS 0.40%via NVD
CVE-2026-14622High· 7.3
2mo ago

A vulnerability was found in jairiidriss restaurant-website-php-mysql up to 521428b5b612449df0cf4a5d15ee40cba67f3d35

A vulnerability was found in jairiidriss restaurant-website-php-mysql up to 521428b5b612449df0cf4a5d15ee40cba67f3d35. This vulnerability affects unknown code of the file /admin/ajax_files of the component AJAX Endpoint. Performing a mani…

▾ TwilightEPSS 0.69%via NVD
CVE-2026-52830Critical· 9.4
2mo ago

fast-mcp-telegram: Bearer token path traversal bypasses reserved Telegram session protection

fast-mcp-telegram: Bearer token path traversal bypasses reserved Telegram session protection

▾ Midnightfast-mcp-telegram · fast-mcp-telegramEPSS 0.65%via GHSA
CVE-2026-49852High
2mo ago

joserfc: HS256/HS384/HS512 verify accepts empty/nil HMAC key (cross-language sibling of CVE-2026-45363)

joserfc: HS256/HS384/HS512 verify accepts empty/nil HMAC key (cross-language sibling of CVE-2026-45363)

▾ Twilightjoserfc · joserfcEPSS 0.19%via OSV
GHSA-rggc-m335-3wvjHigh
2mo ago

OpenClaw: Same-host trusted-proxy deployments could accept local forged identity headers

OpenClaw: Same-host trusted-proxy deployments could accept local forged identity headers

▾ Twilightopenclaw · openclawvia GHSA
CVE-2026-53817High· 8.0
2mo ago

OpenClaw: Control UI locality spoofing could mint a durable admin device token

OpenClaw: Control UI locality spoofing could mint a durable admin device token

▾ Twilightopenclaw · openclawEPSS 0.45%via GHSA
CVE-2026-55955Medium· 6.5⚖ disputed
3mo ago

Improper Authentication vulnerability in Apache Tomcat allowed a replay attack against the EncryptionInterceptor in the cluster component. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, from 10.1.0-M1 through 10.1.55,…

Improper Authentication vulnerability in Apache Tomcat allowed a replay attack against the EncryptionInterceptor in the cluster component. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, from 10.1.0-M1 through 10.1.55,…

▾ Sunlitapache · tomcatEPSS 0.44%via NVD
CWE-287 vulnerabilities (CVEs) — page 12 · VulnSea