VulnSea

CWE-287

CVEs classified under CWE-287, newest first.

461 CVEsRSS

CVE-2026-19273Medium· 5.4
1w ago

IBM Sterling B2B Integrator 6.2.0.0 through 6.2.0.6_2, 6.2.1.0 - 6.2.1.2, 6.2.2.0 - 6.2.2.1 and IBM Sterling File Gateway 6.2.0.0 through 6.2.0.6_2, 6.2.1.0 - 6.2.1.2, 6.2.2.0 - 6.2.2.1 Standard Edition could allow a remote authenticated…

IBM Sterling B2B Integrator 6.2.0.0 through 6.2.0.6_2, 6.2.1.0 - 6.2.1.2, 6.2.2.0 - 6.2.2.1 and IBM Sterling File Gateway 6.2.0.0 through 6.2.0.6_2, 6.2.1.0 - 6.2.1.2, 6.2.2.0 - 6.2.2.1 Standard Edition could allow a remote authenticated…

▾ SunlitIBM · Sterling B2B IntegratorEPSS 0.30%via NVD
CVE-2026-17628Medium· 5.4
1w ago

IBM Langflow OSS 1.0.0 through 1.10.2 could allow a remote authenticated attacker to change the password of an account due to improper authentication.

IBM Langflow OSS 1.0.0 through 1.10.2 could allow a remote authenticated attacker to change the password of an account due to improper authentication.

▾ SunlitIBM · Langflow OSSEPSS 0.34%via NVD
CVE-2026-90623Low· 3.7PoC
1w ago

A weakness has been identified in andreashappe cochise up to 0.4.1

A weakness has been identified in andreashappe cochise up to 0.4.1. Affected is the function asyncssh.connect of the file src/cochise/ssh_connection.py of the component SSH Host Key Handler. Executing a manipulation can lead to improper …

▾ Twilightandreashappe · cochiseEPSS 0.28%via NVD
CVE-2026-90620High· 7.3PoC
1w ago

A vulnerability was determined in 0x4m4 HexStrike AI up to d689933ff579d839c676c82b231f8e98326c5f04

A vulnerability was determined in 0x4m4 HexStrike AI up to d689933ff579d839c676c82b231f8e98326c5f04. The impacted element is an unknown function of the file hexstrike_server.py of the component API Command Endpoint. This manipulation cau…

▾ Midnight0x4m4 · HexStrike AIEPSS 0.65%via NVD
CVE-2026-90961Critical· 9.3
1w ago

The LdapAuth and LinOTPAuth authentication plugins in MISP contain an authentication bypass vulnerability

The LdapAuth and LinOTPAuth authentication plugins in MISP contain an authentication bypass vulnerability. Both LdapAuthenticate and LinOTPAuthenticate replace CakePHP's FormAuthenticate class but fail to replicate its _checkFields() inp…

▾ MidnightMISP · MISPEPSS 0.64%via NVD
CVE-2026-54176Medium· 6.5
1w ago

backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages that help users build custom administration panels

backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages that help users build custom administration panels. From 6.0.0 until 6.8.14 and 7.0.38, MyAccountController::postAccount…

▾ SunlitLaravel-Backpack · CRUDEPSS 0.65%via NVD
CVE-2026-55235Medium· 5.9
1w ago

langgraph-api implements the LangGraph API for rapid development and testing

langgraph-api implements the LangGraph API for rapid development and testing. Prior to 0.10.0, langgraph-api permits a run or cron to specify a relative webhook target that is delivered through an in-process loopback transport, and the a…

▾ Sunlitlanggraph-api · langgraph-apiEPSS 0.36%via NVD
CVE-2026-57132High· 8.2PoC
1w ago

PraisonAI is a multi-agent teams system

PraisonAI is a multi-agent teams system. Prior to 4.6.62, setting PRAISONAI_CALL_AUTH to disabled makes verify_token accept requests to /api/v1/agents/{id}/invoke without CALL_SERVER_TOKEN authentication. Deployments that use the applica…

▾ MidnightMervinPraison · PraisonAIEPSS 0.51%via NVD
CVE-2026-90504High· 7.3PoC
2w ago

A vulnerability has been found in vvbbnn00 WARP-Clash-API up to c7bf2360073959861219b422e51ae86411051b46

A vulnerability has been found in vvbbnn00 WARP-Clash-API up to c7bf2360073959861219b422e51ae86411051b46. The impacted element is the function authorized. The manipulation of the argument SECRET_KEY leads to missing authentication. The a…

▾ Midnightvvbbnn00 · WARP-Clash-APIEPSS 0.65%via NVD
CVE-2026-90513Medium· 6.5
2w ago

A flaw has been found in simalexan api-lambda-send-email-ses up to bda6869aa81371d1e872242e74fe7d953edb818d

A flaw has been found in simalexan api-lambda-send-email-ses up to bda6869aa81371d1e872242e74fe7d953edb818d. This issue affects the function SES.sendEmail of the file template.yml of the component API Gateway Endpoint. This manipulation …

▾ Sunlitsimalexan · api-lambda-send-email-sesEPSS 0.76%via NVD
CVE-2026-89080High· 7.5
2w ago

The Really Simple Security WordPress plugin before 9.8.1 does not prevent an unauthenticated request from resetting an account's completed email two-factor enrolment, allowing an attacker who already knows the account's password to bypa…

The Really Simple Security WordPress plugin before 9.8.1 does not prevent an unauthenticated request from resetting an account's completed email two-factor enrolment, allowing an attacker who already knows the account's password to bypa…

▾ TwilightEPSS 0.34%via NVD
CVE-2026-90524High· 7.3PoC
2w ago

A security flaw has been discovered in jaychouchannel Tourism-Management-System up to 229956e20dbd4a80eeff14535e44d3099502af09

A security flaw has been discovered in jaychouchannel Tourism-Management-System up to 229956e20dbd4a80eeff14535e44d3099502af09. The impacted element is an unknown function of the component Update Endpoint. Performing a manipulation resul…

▾ Midnightjaychouchannel · Tourism-Management-SystemEPSS 0.69%via NVD
CVE-2026-90579High· 7.3PoC
2w ago

A vulnerability has been found in cheshire-cat-ai Cheshire Cat AI up to 1.9.2

A vulnerability has been found in cheshire-cat-ai Cheshire Cat AI up to 1.9.2. This affects the function _authorize_http_key of the file core/cat/factory/custom_auth_handler.py. The manipulation of the argument user_id leads to missing a…

▾ Midnightcheshire-cat-ai · Cheshire Cat AIEPSS 0.65%via NVD
CVE-2026-90601High· 7.3PoC
2w ago

A vulnerability was found in getzep graphiti up to 0.30.2

A vulnerability was found in getzep graphiti up to 0.30.2. Affected is an unknown function of the file server/graph_service/main.py of the component REST API. The manipulation results in improper authentication. The attack can be launche…

▾ Midnightgetzep · graphitiEPSS 0.69%via NVD
CVE-2026-90474Medium· 6.8PoC
2w ago

MCPHub before 1.0.32 contains an authentication bypass vulnerability in its embedded OAuth 2.0 authorization server where client authentication is disabled by default and PKCE enforcement is optional

MCPHub before 1.0.32 contains an authentication bypass vulnerability in its embedded OAuth 2.0 authorization server where client authentication is disabled by default and PKCE enforcement is optional. Attackers who obtain an authorizatio…

▾ Twilightsamanhappy · mcphubEPSS 0.55%via NVD
CVE-2026-75800Critical· 9.8
2w ago

The Frontegg SAML SSO WordPress plugin through 1.0.1 does not verify the signature or issuer of SAML authentication responses before establishing a session, allowing unauthenticated attackers to log in as any user, including administrato…

The Frontegg SAML SSO WordPress plugin through 1.0.1 does not verify the signature or issuer of SAML authentication responses before establishing a session, allowing unauthenticated attackers to log in as any user, including administrato…

▾ MidnightEPSS 0.63%via NVD
CVE-2026-14559Critical· 9.8
2w ago

The teddy-bear-customize-addon WordPress plugin through 1.0.5 does not verify a user's password before authenticating them, allowing unauthenticated attackers to log in as any registered user, including administrators, by supplying only …

The teddy-bear-customize-addon WordPress plugin through 1.0.5 does not verify a user's password before authenticating them, allowing unauthenticated attackers to log in as any registered user, including administrators, by supplying only …

▾ MidnightEPSS 0.28%via NVD
CVE-2026-14563Critical· 9.8
2w ago

The advanced-customized-prompts WordPress plugin through 1.0.1 does not verify the password before issuing an authenticated session for a supplied email address in an unauthenticated action, allowing unauthenticated attackers to log in a…

The advanced-customized-prompts WordPress plugin through 1.0.1 does not verify the password before issuing an authenticated session for a supplied email address in an unauthenticated action, allowing unauthenticated attackers to log in a…

▾ MidnightEPSS 0.28%via NVD
CVE-2026-79395Critical· 9.8
2w ago

An improper authentication vulnerability in the WS-Security (wsse:UsernameToken) verification routine within the Sofia IPC daemon in Xiongmai IP Camera XM530 firmware HMT.CM2005-v220608.1837 and earlier allows remote attackers to bypass …

An improper authentication vulnerability in the WS-Security (wsse:UsernameToken) verification routine within the Sofia IPC daemon in Xiongmai IP Camera XM530 firmware HMT.CM2005-v220608.1837 and earlier allows remote attackers to bypass …

▾ MidnightEPSS 0.77%via NVD
CVE-2026-54047Critical· 9.2
2w ago

Laci Synchroni is a decentralized mod and appearance sync server and plugin for Dalamud

Laci Synchroni is a decentralized mod and appearance sync server and plugin for Dalamud. Versions of the backend prior to 1.2.3 have an improper authentication vulnerability in the application's OAuth2 login flow. The application relies …

▾ MidnightLaciSynchroni · serverEPSS 0.30%via NVD
CVE-2026-86781Medium· 5.3
2w ago

The SSL Zen — SSL Certificate Installer & HTTPS Redirects WordPress plugin before 4.7.40 does not perform capability or nonce checks on a certificate-file download routine that runs early in the WordPress admin request lifecycle, allowin…

The SSL Zen — SSL Certificate Installer & HTTPS Redirects WordPress plugin before 4.7.40 does not perform capability or nonce checks on a certificate-file download routine that runs early in the WordPress admin request lifecycle, allowin…

▾ SunlitEPSS 0.18%via NVD
CVE-2026-71416High· 8.8PoC
2w ago

Headroom compresses data before the data reaches a large language model

Headroom compresses data before the data reaches a large language model. Prior to version 0.35.0, the Headroom WebSocket server does not validate the `Origin` header of incoming client WebSocket requests before forwarding the request to …

▾ Midnightheadroomlabs-ai · headroomEPSS 0.22%via NVD
CVE-2026-59151Critical· 9.6
2w ago

Prowler: SAML Domain Claiming Enables Cross-Tenant Account Takeover

Prowler: SAML Domain Claiming Enables Cross-Tenant Account Takeover

▾ Midnightprowler-cloud · prowler-cloudEPSS 0.53%via OSV
CVE-2026-88018Critical· 9.8PoC
2w ago

rclone is a command-line program to sync files and directories to and from different cloud storage providers

rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.75.1, rclone serve s3 configured with --auth-proxy but without --auth-key allows authPairMiddleware to register any …

▾ Abyssalrclone · rcloneEPSS 0.75%via NVD
CVE-2026-88895High· 7.2
2w ago

CyberPanel before 3.0.5 Authentication Bypass via API

CyberPanel before 3.0.5 fails to enforce two-factor authentication on API endpoints, allowing attackers to bypass TOTP requirements using password-derived tokens. Attackers who obtain an administrator's password can derive API tokens and…

▾ Twilightusmannasir · cyberpanelEPSS 0.65%via CVEORG
CVE-2026-82107Critical· 9.6
2w ago

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain sensitive information and bypass security restrictions due to improper authentication.

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain sensitive information and bypass security restrictions due to improper authentication.

▾ Midnightibm · datastage_on_cloud_pak_for_dataEPSS 0.54%via NVD
CVE-2026-88007Critical· 9.1
2w ago

Traefik is an open source HTTP reverse proxy and load balancer

Traefik is an open source HTTP reverse proxy and load balancer. From 2.11.0 until 2.11.57 and 3.7.13, the HTTP/3 entrypoint ConnContext does not call service.AddTransportOnContext, so kerberosRoundTripper uses a shared backend transport …

▾ Midnighttraefik · traefikEPSS 0.60%via NVD
CVE-2026-77771High· 7.5PoC
2w ago

The miniOrange 2FA WordPress plugin before 6.3.1, miniOrange 2FA WordPress plugin before 19.3 does not scope its second-factor attempt limit to the account being attacked, keying it instead to an identifier the client supplies and can …

The miniOrange 2FA WordPress plugin before 6.3.1, miniOrange 2FA WordPress plugin before 19.3 does not scope its second-factor attempt limit to the account being attacked, keying it instead to an identifier the client supplies and can …

▾ MidnightEPSS 0.32%via NVD
CVE-2026-87016High· 8.1PoC
2w ago

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.6.41 until 0.11.1, get_user_by_oauth_sub and get_user_by_scim_external_id in backend/open_webui/models/users.py used JSON contains matching that…

▾ Midnightopenwebui · open_webuiEPSS 0.60%via NVD
CVE-2026-79974Medium· 6.4
2w ago

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Authentication vulnerability

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Authentication vulnerability. A low privileged attacker with remote access could potentially exploit this…

▾ Sunlitdell · secure_connect_gatewayEPSS 0.30%via NVD
CWE-287 vulnerabilities (CVEs) — page 6 · VulnSea