VulnSea

CWE-287

CVEs classified under CWE-287, newest first.

461 CVEsRSS

CVE-2026-73956Critical· 9.8
1w ago

Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Composer)

Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Composer). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacke…

▾ Midnightoracle · webcenter_portalEPSS 0.51%via NVD
CVE-2026-73953Critical· 9.8
1w ago

Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Portlet Services)

Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Portlet Services). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated…

▾ Midnightoracle · webcenter_portalEPSS 0.51%via NVD
CVE-2026-73952Critical· 9.1
1w ago

Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Portlet Services)

Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Portlet Services). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated…

▾ Midnightoracle · webcenter_portalEPSS 0.43%via NVD
CVE-2026-73950Critical· 9.8
1w ago

Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine)

Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthentica…

▾ Midnightoracle · access_managerEPSS 0.51%via NVD
CVE-2026-73947Critical· 9.8
1w ago

Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine)

Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthentica…

▾ Midnightoracle · access_managerEPSS 0.51%via NVD
CVE-2026-73944Critical· 9.1
1w ago

Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine)

Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthentica…

▾ Midnightoracle · access_managerEPSS 0.43%via NVD
CVE-2026-73940Critical· 9.8
1w ago

Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine)

Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthentica…

▾ Midnightoracle · access_managerEPSS 0.51%via NVD
CVE-2026-71133Critical· 10.0
1w ago

Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine)

Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthentica…

▾ Midnightoracle · access_managerEPSS 0.51%via NVD
CVE-2026-70913Critical· 9.8
1w ago

Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: Core)

Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker wi…

▾ Midnightoracle · identity_managerEPSS 0.51%via NVD
CVE-2026-70757Critical· 9.8
1w ago

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core)

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unau…

▾ MidnightOracle Corporation · Oracle WebLogic ServerEPSS 0.48%via NVD
CVE-2026-70756Critical· 9.8
1w ago

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core)

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unau…

▾ MidnightOracle Corporation · Oracle WebLogic ServerEPSS 0.48%via NVD
CVE-2026-70748Critical· 9.8
1w ago

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core)

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unau…

▾ MidnightOracle Corporation · Oracle WebLogic ServerEPSS 0.48%via NVD
CVE-2026-76673Critical· 9.8
1w ago

Vulnerabilities have been identified in the API of EdgeConnect SD-WAN Orchestrator that could potentially allow an unauthenticated remote actor to circumvent existing authentication controls

Vulnerabilities have been identified in the API of EdgeConnect SD-WAN Orchestrator that could potentially allow an unauthenticated remote actor to circumvent existing authentication controls. Successful exploitation could allow an attack…

▾ Midnightarubanetworks · edgeconnect_sd-wan_orchestratorEPSS 0.61%via NVD
CVE-2026-76684High· 8.1
1w ago

Vulnerabilities have been identified in the API of HPE Networking EdgeConnect SD-WAN Orchestrator that could potentially allow an unauthenticated remote actor to circumvent existing authentication controls

Vulnerabilities have been identified in the API of HPE Networking EdgeConnect SD-WAN Orchestrator that could potentially allow an unauthenticated remote actor to circumvent existing authentication controls. Successful exploitation could …

▾ Twilightarubanetworks · edgeconnect_sd-wan_orchestratorEPSS 0.46%via NVD
CVE-2026-76688High· 7.5
1w ago

Vulnerabilities have been identified in the web-based management interface of EdgeConnect SD-WAN Orchestrator that could potentially allow an unauthenticated remote actor to circumvent existing authentication controls

Vulnerabilities have been identified in the web-based management interface of EdgeConnect SD-WAN Orchestrator that could potentially allow an unauthenticated remote actor to circumvent existing authentication controls. Successful exploit…

▾ Twilightarubanetworks · edgeconnect_sd-wan_orchestratorEPSS 0.38%via NVD
CVE-2026-81237Medium· 6.5
1w ago

Dell Wyse Management Suite, versions prior to 2605.0.3.683, contain an Improper Authentication vulnerability

Dell Wyse Management Suite, versions prior to 2605.0.3.683, contain an Improper Authentication vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access.

▾ Sunlitdell · wyse_management_suiteEPSS 0.34%via NVD
CVE-2026-57134High· 8.2PoC
1w ago

PraisonAI is a multi-agent teams system

PraisonAI is a multi-agent teams system. From 1.5.1 until 1.7.2, MCPSecurity.evaluatePolicy() in src/praisonai-ts/src/mcp/security.ts invokes the configured credential validator only when AuthMethod is api-key or bearer. Basic and OAuth …

▾ MidnightMervinPraison · PraisonAIEPSS 0.41%via NVD
CVE-2026-91002Medium· 5.3PoC
1w ago

A weakness has been identified in stamparm maltrail up to 3.0.1

A weakness has been identified in stamparm maltrail up to 3.0.1. This vulnerability affects the function _blacklist of the file core/httpd.py of the component Blacklist Endpoint. Executing a manipulation can lead to missing authenticatio…

▾ Twilightstamparm · maltrailEPSS 0.77%via NVD
CVE-2026-90840High· 7.3PoC
1w ago

A vulnerability was identified in PHPGurukul Blood Donor Management System 1.0

A vulnerability was identified in PHPGurukul Blood Donor Management System 1.0. Affected is the function __construct of the file /application/controllers/admin/Dashboard.php of the component Admin Controllers. The manipulation leads to i…

▾ MidnightPHPGurukul · Blood Donor Management SystemEPSS 0.69%via NVD
CVE-2026-57148Critical· 9.8PoC
1w ago

PraisonAI is a multi-agent teams system

PraisonAI is a multi-agent teams system. Prior to 0.1.6, praisonai_platform/services/auth_service.py falls back to the public dev-secret-change-me HS256 signing key when PLATFORM_JWT_SECRET is unset, while the startup and token-issuance …

▾ AbyssalMervinPraison · PraisonAIEPSS 0.64%via NVD
CVE-2026-54547High· 7.4PoC
1w ago

Meta Ads MCP is a Model Context Protocol (MCP) server that lets AI assistants run Meta Ads

Meta Ads MCP is a Model Context Protocol (MCP) server that lets AI assistants run Meta Ads. Prior to version 1.0.115, AuthInjectionMiddleware in meta_ads_mcp/core/http_auth_integration.py rejects HTTP MCP requests only when both auth_tok…

▾ Midnightpipeboard-co · meta-ads-mcpEPSS 0.52%via NVD
CVE-2026-52827High· 7.1
1w ago

Kimai is an open-source time tracking application

Kimai is an open-source time tracking application. Prior to 2.59.0, the KIMAI_SESSION cookie issued after password verification but before TOTP completion is accepted by every /api route because config/packages/security.yaml protects the…

▾ Twilightkimai · kimaiEPSS 0.58%via NVD
CVE-2026-47426High· 7.6
1w ago

Open Access Management (OpenAM) is an access management solution

Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the private_key_jwt client authentication path uses ClientJwksResolverCache without reliably binding a cached jwks_uri resolver and verified assertion to …

▾ TwilightOpenIdentityPlatform · OpenAMEPSS 0.55%via NVD
CVE-2026-46488Critical· 9.1PoC
1w ago

motionEye (mEye) is an online interface for a piece of software called "motion," which is a video surveillance program with motion detection

motionEye (mEye) is an online interface for a piece of software called "motion," which is a video surveillance program with motion detection. Prior to 0.44.0, motionEye accepts the client-controlled meye_username and meye_password_hash c…

▾ Abyssalmotioneye-project · motioneyeEPSS 0.46%via NVD
CVE-2026-86890Medium· 4.6
1w ago

A logic issue was addressed with improved checks

A logic issue was addressed with improved checks. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27. An attacker with physical access to a locked device may be able to view sensitive user information.

▾ Sunlitapple · ipadosEPSS 0.21%via NVD
CVE-2026-65375High· 7.5
1w ago

The issue was addressed with improved authentication

The issue was addressed with improved authentication. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.6. An app may be able to cause unexpected system termination.

▾ Twilightapple · macosEPSS 0.66%via NVD
CVE-2026-84623High· 7.5
1w ago

An authorization issue was addressed with improved state management

An authorization issue was addressed with improved state management. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27. An app may be able to fingerprint the device.

▾ Twilightapple · ipadosEPSS 0.34%via NVD
CVE-2026-20683High· 7.1
1w ago

An authentication issue was addressed with improved state management

An authentication issue was addressed with improved state management. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, visionOS 27. An app may be able to use the Sign In With Apple …

▾ Twilightapple · ipadosEPSS 0.19%via NVD
CVE-2026-43674Medium· 4.6
1w ago

An authentication issue was addressed with improved state management

An authentication issue was addressed with improved state management. This issue is fixed in iOS 27 and iPadOS 27. An attacker with physical access to an unlocked device may be able to view Wi-Fi passwords without authentication.

▾ Sunlitapple · ipadosEPSS 0.22%via NVD
CVE-2026-84606High· 7.5
1w ago

A privacy issue was addressed with improved handling of identifiers

A privacy issue was addressed with improved handling of identifiers. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, visionOS 27. An app may be able to identify a user across reinstalls.

▾ Twilightapple · ipadosEPSS 0.41%via NVD
CWE-287 vulnerabilities (CVEs) — page 5 · VulnSea