VulnSea

CWE-287

CVEs classified under CWE-287, newest first.

462 CVEsRSS

CVE-2026-45690Medium· 5.9
3mo ago

Nextcloud is an open source content collaboration platform

Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 32.0.0 to before 32.0.9, and 33.0.0 to before 33.0.3, an authentication bypass vulnerability allowed attackers with knowledge of a user's passw…

▾ Sunlitnextcloud · nextcloud_serverEPSS 0.43%via NVD
CVE-2026-46579High· 7.4
4mo ago

A flaw was found in the OpenShift Router

A flaw was found in the OpenShift Router. When a Route has `insecureEdgeTerminationPolicy` set to Allow, the HTTP frontend does not remove `X-SSL-Client-*` headers from incoming requests. This allows an unauthenticated attacker to send p…

▾ Twilightredhat · openshift_container_platformEPSS 0.62%via NVD
CVE-2026-46817Critical· 9.8CISA KEVPoC
4mo ago

Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission)

Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with netwo…

▾ Hadaloracle · e-business_suiteEPSS 0.81%via NVD
CVE-2026-48526High· 7.4PoC
4mo ago

PyJWT is a JSON Web Token implementation in Python

PyJWT is a JSON Web Token implementation in Python. Prior to 2.13.0, when the verifier is decoding JSON Web Tokens, while supporting both asymmetric and HMAC algorithms, the library does not validate use of JSON Web Keys in HMAC algorith…

▾ Midnightpyjwt_project · pyjwtEPSS 0.43%via NVD
CVE-2026-41076High· 8.1
4mo ago

RT is an open source, enterprise-grade issue and ticket tracking system

RT is an open source, enterprise-grade issue and ticket tracking system. Versions 5.0.9 and prior in addition to 6.0.0 through 6.0.2 contain an authentication bypass vulnerability in RT installations that use LDAP/AD for user authenticat…

▾ TwilightEPSS 0.66%via NVD
CVE-2026-2812Medium· 5.3
4mo ago

ArcGIS Server contains an improper authentication vulnerability in an undocumented administrative endpoint

ArcGIS Server contains an improper authentication vulnerability in an undocumented administrative endpoint. An unauthenticated attacker could exploit this issue by sending a crafted request to the endpoint. Successful exploitation may re…

▾ Sunlitesri · arcgis_serverEPSS 0.38%via NVD
CVE-2026-9084None
4mo ago

MISP’s OIDC authentication plugin allowed automatic linking of an OIDC identity to an existing local user account based on the email claim when the local account had no stored sub value

MISP’s OIDC authentication plugin allowed automatic linking of an OIDC identity to an existing local user account based on the email claim when the local account had no stored sub value. Under insecure or untrusted IdP configurations whe…

▾ SunlitEPSS 0.22%via NVD
CVE-2026-8244Medium· 5.3
4mo ago

A vulnerability was identified in Industrial Application Software IAS Canias ERP 8.03

A vulnerability was identified in Industrial Application Software IAS Canias ERP 8.03. This impacts an unknown function of the component Login RMI Interface. The manipulation of the argument clientVersion leads to improper authentication…

▾ SunlitEPSS 0.68%via NVD
CVE-2026-42041Medium· 4.8PoC⚖ disputed
5mo ago

Axios is a promise based HTTP client for the browser and Node.js

Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, the Axios library is vulnerable to a Prototype Pollution "Gadget" attack that allows any Object.prototype pollution to silently suppress all HT…

▾ Twilightaxios · axiosEPSS 0.81%via NVD
CVE-2026-32072Medium· 6.2
5mo ago

Active Directory Spoofing Vulnerability

Improper authentication in Windows Active Directory allows an unauthorized attacker to perform spoofing locally.

▾ SunlitMicrosoft · Windows 10 Version 1607EPSS 0.40%via CVEORG
CVE-2026-5795High· 7.4
5mo ago

In Eclipse Jetty, the class JASPIAuthenticator initiates the authentication checks, which set two ThreadLocal variable. Upon returning from the initial checks, there are conditions that cause an early return from the JASPIAuthenticator…

In Eclipse Jetty, the class JASPIAuthenticator initiates the authentication checks, which set two ThreadLocal variable. Upon returning from the initial checks, there are conditions that cause an early return from the JASPIAuthenticator…

▾ Twilighteclipse · jettyEPSS 0.61%via NVD
CVE-2026-35030Critical· 9.1PoC
5mo ago

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.83.0, when JWT authentication is enabled (enable_jwt_auth: true), the OIDC userinfo cache uses token[:20] as the cache key. JWT headers prod…

▾ Abyssallitellm · litellmEPSS 0.88%via NVD
CVE-2026-5676High· 7.3
5mo ago

A vulnerability was identified in Totolink A8000R 5.9c.681_B20180413

A vulnerability was identified in Totolink A8000R 5.9c.681_B20180413. This issue affects the function setLanguageCfg of the file /cgi-bin/cstecgi.cgi. Such manipulation of the argument langType leads to missing authentication. The attack…

▾ TwilightEPSS 0.69%via NVD
CVE-2026-5632High· 7.3
5mo ago

A vulnerability was found in assafelovic gpt-researcher up to 3.4.3

A vulnerability was found in assafelovic gpt-researcher up to 3.4.3. This impacts an unknown function of the component HTTP REST API Endpoint. Performing a manipulation results in missing authentication. It is possible to initiate the at…

▾ TwilightEPSS 0.65%via NVD
CVE-2026-5616High· 7.3
5mo ago

A security vulnerability has been detected in JeecgBoot 3.9.0/3.9.1

A security vulnerability has been detected in JeecgBoot 3.9.0/3.9.1. The impacted element is an unknown function of the file jeecg-boot/jeecg-module-system/jeecg-system-biz/src/main/java/org/jeecg/modules/airag/JeecgBizToolsProvider.java…

▾ TwilightEPSS 0.69%via NVD
CVE-2026-5570High· 7.3
5mo ago

A vulnerability was determined in Technostrobe HI-LED-WR120-G2 5.5.0.1R6.03.30

A vulnerability was determined in Technostrobe HI-LED-WR120-G2 5.5.0.1R6.03.30. The affected element is the function index_config of the file /LoginCB. This manipulation causes improper authentication. It is possible to initiate the atta…

▾ Twilighttechnostrobe · hi-led-wr120-g2_firmwareEPSS 0.99%via NVD
CVE-2018-25236Critical· 9.8
5mo ago

Hirschmann HiOS and HiSecOS products RSP, RSPE, RSPS, RSPL, MSP, EES, EESX, GRS, OS, RED, EAGLE contain an authentication bypass vulnerability in the HTTP(S) management module that allows unauthenticated remote attackers to gain administ…

Hirschmann HiOS and HiSecOS products RSP, RSPE, RSPS, RSPL, MSP, EES, EESX, GRS, OS, RED, EAGLE contain an authentication bypass vulnerability in the HTTP(S) management module that allows unauthenticated remote attackers to gain administ…

▾ MidnightEPSS 0.50%via NVD
CVE-2017-20235Critical· 9.1
5mo ago

ProSoft Technology ICX35-HWC version 1.3 and prior cellular gateways contain an authentication bypass vulnerability in the web user interface that allows unauthenticated attackers to gain access to administrative functions without valid …

ProSoft Technology ICX35-HWC version 1.3 and prior cellular gateways contain an authentication bypass vulnerability in the web user interface that allows unauthenticated attackers to gain access to administrative functions without valid …

▾ Midnightprosoft-technology · icx35-hwc_firmwareEPSS 0.45%via NVD
CVE-2017-20237Critical· 9.8
5mo ago

Hirschmann Industrial HiVision versions prior to 06.0.07 and 07.0.03 contains an authentication bypass vulnerability in the master service that allows unauthenticated remote attackers to execute arbitrary commands with administrative pri…

Hirschmann Industrial HiVision versions prior to 06.0.07 and 07.0.03 contains an authentication bypass vulnerability in the master service that allows unauthenticated remote attackers to execute arbitrary commands with administrative pri…

▾ MidnightEPSS 0.96%via NVD
CVE-2026-32173High· 8.6
5mo ago

Azure SRE Agent Information Disclosure Vulnerability

Improper authentication in Azure SRE Agent allows an unauthorized attacker to disclose information over a network.

▾ TwilightMicrosoft · Azure SRE Agent Gateway - SignalR HubEPSS 1.1%via CVEORG
CVE-2026-2756Medium· 5.0
6mo ago

A security vulnerability has been detected in OmniPEMF NeoRhythm up to 20260308

A security vulnerability has been detected in OmniPEMF NeoRhythm up to 20260308. This affects an unknown function of the component BLE Interface. Such manipulation leads to missing authentication. The attack can only be initiated within …

▾ SunlitOmniPEMF · NeoRhythmEPSS 0.41%via NVD
CVE-2026-1524Critical· 9.8
6mo ago

An edgecase in SSO implementation in Neo4j Enterprise edition versions prior to version 2026.02 can lead to unauthorised access under the following conditions: If a neo4j admin configures two or more OIDC providers AND configures one o…

An edgecase in SSO implementation in Neo4j Enterprise edition versions prior to version 2026.02 can lead to unauthorised access under the following conditions: If a neo4j admin configures two or more OIDC providers AND configures one o…

▾ Midnightneo4j · neo4jEPSS 0.32%via NVD
CVE-2026-23813Critical· 9.8PoC
6mo ago

A vulnerability has been identified in the web-based management interface of AOS-CX switches that could potentially allow an unauthenticated remote actor to circumvent existing authentication controls

A vulnerability has been identified in the web-based management interface of AOS-CX switches that could potentially allow an unauthenticated remote actor to circumvent existing authentication controls. In some cases this could enable res…

▾ Abyssalhpe · arubaos-cxEPSS 0.74%via NVD
CVE-2026-24294High· 7.8PoC
6mo ago

Improper authentication in Windows SMB Server allows an authorized attacker to elevate privileges locally.

Improper authentication in Windows SMB Server allows an authorized attacker to elevate privileges locally.

▾ Midnightmicrosoft · windows_10_1607EPSS 4.7%via NVD
CVE-2026-23600Critical· 9.8
6mo ago

A remote authentication bypass vulnerability  exists in HPE AutoPass License Server (APLS).

A remote authentication bypass vulnerability  exists in HPE AutoPass License Server (APLS).

▾ Midnighthpe · autopass_license_serverEPSS 0.96%via NVD
CVE-2025-65397Medium· 6.8
8mo ago

An insecure authentication mechanism in the safe_exec.sh startup script of Blurams Flare Camera version 24.1114.151.929 and earlier allows an attacker with physical access to the device to execute arbitrary commands with root privileges,…

An insecure authentication mechanism in the safe_exec.sh startup script of Blurams Flare Camera version 24.1114.151.929 and earlier allows an attacker with physical access to the device to execute arbitrary commands with root privileges,…

▾ Sunlitblurams · dome_flare_firmwareEPSS 0.32%via NVD
CVE-2025-66698High· 8.6PoC
8mo ago

An issue in Semantic machines v5.4.8 allows attackers to bypass authentication via sending a crafted HTTP request to various API endpoints.

An issue in Semantic machines v5.4.8 allows attackers to bypass authentication via sending a crafted HTTP request to various API endpoints.

▾ Midnightsemantic-machines · vedaEPSS 0.49%via NVD
CVE-2025-15224Low· 3.1PoC
8mo ago

When doing SSH-based transfers using either SCP or SFTP, and asked to do public key authentication, curl would wrongly still ask and authenticate using a locally running SSH agent.

When doing SSH-based transfers using either SCP or SFTP, and asked to do public key authentication, curl would wrongly still ask and authenticate using a locally running SSH agent.

▾ Twilighthaxx · curlEPSS 0.49%via NVD
CVE-2025-67791Critical· 9.8
9mo ago

An issue was discovered in DriveLock 24.1 through 24.1.*, 24.2 through 24.2.*, and 25.1 through 25.1.*

An issue was discovered in DriveLock 24.1 through 24.1.*, 24.2 through 24.2.*, and 25.1 through 25.1.*. An incomplete configuration (agent authentication) in DriveLock tenant allows attackers to impersonate any DriveLock agent on the net…

▾ Midnightdrivelock · drivelockEPSS 0.37%via NVD
CVE-2025-37731Medium· 6.8
9mo ago

Elasticsearch PKI Realm Authentication Bypass Vulnerability Allows User Impersonation Through Crafted Client Certificates

Elasticsearch PKI Realm Authentication Bypass Vulnerability Allows User Impersonation Through Crafted Client Certificates

▾ Sunlitelasticsearch · org.elasticsearch.plugin:x-pack-securityEPSS 0.19%via GHSA
CWE-287 vulnerabilities (CVEs) — page 14 · VulnSea