VulnSea

CWE-287

CVEs classified under CWE-287, newest first.

461 CVEsRSS

CVE-2026-87924Medium· 6.5PoC
2w ago

A security vulnerability has been detected in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5dc9ecd5c77900e03f

A security vulnerability has been detected in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5dc9ecd5c77900e03f. This affects an unknown part of the file includes/invoice_bill.php of the component Invoice Generation. Su…

▾ TwilightRizwan17 · inventory-management-systemEPSS 0.76%via NVD
CVE-2026-87922High· 7.3PoC
2w ago

A security flaw has been discovered in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5dc9ecd5c77900e03f

A security flaw has been discovered in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5dc9ecd5c77900e03f. Affected by this vulnerability is the function DBOperation.addCategory of the file includes/process.php of the co…

▾ MidnightRizwan17 · inventory-management-systemEPSS 0.69%via NVD
CVE-2026-87806High· 7.4
2w ago

Parse Server versions <= 8.6.87 and >= 9.0.0 < 9.10.1-alpha.7 contain an authentication bypass in the built-in LDAP authentication adapter

Parse Server versions <= 8.6.87 and >= 9.0.0 < 9.10.1-alpha.7 contain an authentication bypass in the built-in LDAP authentication adapter. The adapter forwarded the client-supplied password to the directory without verifying that a pass…

▾ Twilightparse-community · parse-serverEPSS 0.51%via NVD
CVE-2026-76009High· 8.1
2w ago

The Next-Cart Store to WooCommerce Migration plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 3.9.8 via the `NCWM_Kitconnect::run()` function

The Next-Cart Store to WooCommerce Migration plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 3.9.8 via the `NCWM_Kitconnect::run()` function. This is due to the plugin registering the `/w…

▾ Twilightmartinnguyen1990 · Next-Cart Store to WooCommerce MigrationEPSS 0.90%via NVD
CVE-2026-80099High· 8.8PoC
2w ago

Several Newfold plugins are vulnerable to Authentication Bypass

Several Newfold plugins are vulnerable to Authentication Bypass. The vulnerability exists because the plugins bundle the wp-module-data module. In the module, the `authenticate()` method — registered on the `rest_authentication_errors` f…

▾ MidnightNewfold · WP Plugin WebEPSS 2.9%via NVD
CVE-2026-47156Critical· 9.3
2w ago

MantisBT: SOAP API Authentication Bypass with Privilege Escalation to Administrator

MantisBT is an open source bug tracker. Versions 2.28.3 and earlier contain a critical authentication bypass in the SOAP API's mci_check_login() function. Any user knowing any valid cookie_string can authenticate as any other user (knowi…

▾ Midnightmantisbt · mantisbtEPSS 0.69%via CVEORG
CVE-2026-86810High· 7.3
2w ago

A vulnerability was detected in Open-Web-Analytics up to 1.9.1

A vulnerability was detected in Open-Web-Analytics up to 1.9.1. The impacted element is the function checkCapabilityAndAuthenticateUser of the file Core/Controller.php of the component Controller. Performing a manipulation results in imp…

▾ TwilightEPSS 0.84%via NVD
CVE-2026-78560Medium· 4.8
2w ago

The Okta Access Gateway includes an optional pass-through authentication source that accepts user identity from a client-supplied HTTP header without cryptographic validation

The Okta Access Gateway includes an optional pass-through authentication source that accepts user identity from a client-supplied HTTP header without cryptographic validation. In architectures where this optional source is enabled withou…

▾ Sunlitokta · access_gatewayEPSS 0.20%via NVD
CVE-2026-86808High· 7.3PoC
2w ago

A security vulnerability has been detected in moltis-org moltis up to 20260818.10

A security vulnerability has been detected in moltis-org moltis up to 20260818.10. The affected element is the function vault_unlock_handler/vault_recovery_handler of the file vault.rs. Such manipulation leads to missing authentication. …

▾ Midnightmoltis-org · moltisEPSS 0.84%via NVD
CVE-2026-28606Critical· 9.8
2w ago

In handleBondStateChanged of AdapterService.java, there is a possible way to skip pairing due to a logic error in the code

In handleBondStateChanged of AdapterService.java, there is a possible way to skip pairing due to a logic error in the code. This could lead to remote escalation of privilege without user consent with no additional execution privileges ne…

▾ Midnightgoogle · androidEPSS 0.39%via NVD
CVE-2026-86669High· 7.3PoC
2w ago

A vulnerability was detected in aircheng-org iWebShop-5 up to 5.15

A vulnerability was detected in aircheng-org iWebShop-5 up to 5.15. This affects the function Login of the file controllers/systemseller.php. Performing a manipulation of the argument Name results in improper authentication. It is possib…

▾ Midnightaircheng-org · iWebShop-5EPSS 0.69%via NVD
CVE-2026-80097High· 8.6
2w ago

Improper authentication in Microsoft Authenticator allows an unauthorized attacker to elevate privileges locally.

Improper authentication in Microsoft Authenticator allows an unauthorized attacker to elevate privileges locally.

▾ Twilightmicrosoft · authenticatorEPSS 0.44%via NVD
CVE-2026-69854Critical· 9.0
2w ago

Improper authentication in Spring Cloud Azure allows an unauthorized attacker to elevate privileges over a network.

Improper authentication in Spring Cloud Azure allows an unauthorized attacker to elevate privileges over a network.

▾ MidnightMicrosoft · Spring Cloud AzureEPSS 0.67%via NVD
CVE-2026-86723High· 8.1
2w ago

AVideo through c3edcc274c389816d434acadac07ee78eaf330c1 contains an authentication bypass vulnerability in LoginControl::verifyChallenge() that uses loose comparison (==) instead of strict comparison (===) against unset session values

AVideo through c3edcc274c389816d434acadac07ee78eaf330c1 contains an authentication bypass vulnerability in LoginControl::verifyChallenge() that uses loose comparison (==) instead of strict comparison (===) against unset session values. A…

▾ TwilightWWBN · AVideoEPSS 0.47%via NVD
CVE-2026-86722High· 8.1PoC
2w ago

AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains an authentication bypass vulnerability where sqlDAL caches empty result sets that writeSql never invalidates

AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains an authentication bypass vulnerability where sqlDAL caches empty result sets that writeSql never invalidates. Attackers with a valid password can bypass email two-fa…

▾ MidnightWWBN · AVideoEPSS 0.47%via NVD
CVE-2026-86721High· 7.5
2w ago

AVideo through commit c3edcc274c contains an authorization bypass vulnerability where a session cookie named 'key' with value 'value' overrides the $_REQUEST['key'] parameter in saveLive.php and related endpoints

AVideo through commit c3edcc274c contains an authorization bypass vulnerability where a session cookie named 'key' with value 'value' overrides the $_REQUEST['key'] parameter in saveLive.php and related endpoints. Attackers can publish t…

▾ TwilightWWBN · AVideoEPSS 0.50%via NVD
CVE-2026-79576Critical· 9.8PoC
2w ago

An issue in the Single-Sign On (SSO) component of Digital-Infrastructure v9.6.7 allows attackers to authenticate as any user, including the Admin, without a password.

An issue in the Single-Sign On (SSO) component of Digital-Infrastructure v9.6.7 allows attackers to authenticate as any user, including the Admin, without a password.

▾ AbyssalEPSS 0.48%via NVD
CVE-2026-82758Medium· 6.3
2w ago

Improper Authentication vulnerability in ash-project ash_authentication_oauth2_server allows an unauthenticated attacker to register OAuth clients even when Dynamic Client Registration is gated by an initial access token. resolve_secret…

Improper Authentication vulnerability in ash-project ash_authentication_oauth2_server allows an unauthenticated attacker to register OAuth clients even when Dynamic Client Registration is gated by an initial access token. resolve_secret…

▾ Sunlitash-project · ash_authentication_oauth2_serverEPSS 0.69%via NVD
CVE-2026-80128Medium· 6.4
2w ago

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Authentication vulnerability

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Authentication vulnerability. A low privileged attacker with remote access could potentially exploit this…

▾ Sunlitdell · secure_connect_gatewayEPSS 0.32%via NVD
CVE-2026-18922Critical· 9.8
2w ago

A flaw was found in 389 Directory Server

A flaw was found in 389 Directory Server. During SASL PLAIN authentication, a stale identity carried in a Cyrus SASL auxiliary property from a prior failed bind attempt can be installed on a connection following a subsequent, unrelated s…

▾ MidnightRed Hat · redhat-ds:11EPSS 0.56%via NVD
CVE-2026-86426Critical· 9.8PoC
2w ago

LibreNMS before 26.8.0 contains an authentication bypass vulnerability in the REST API that allows unauthenticated attackers to access protected endpoints by sending numeric values instead of string tokens

LibreNMS before 26.8.0 contains an authentication bypass vulnerability in the REST API that allows unauthenticated attackers to access protected endpoints by sending numeric values instead of string tokens. Attackers can exploit MySQL ty…

▾ Abyssallibrenms · librenmsEPSS 3.9%via NVD
CVE-2026-86306High· 7.3PoC
2w ago

A weakness has been identified in light0011 cms c774dce31c6df0055568a8d5c53d964d99be199d/f72cf46f601efb2a0618c3814cc2f61380b38930

A weakness has been identified in light0011 cms c774dce31c6df0055568a8d5c53d964d99be199d/f72cf46f601efb2a0618c3814cc2f61380b38930. This affects an unknown part of the file App/Home/Model/UserModel.class.php of the component Cookie Helper…

▾ Midnightlight0011 · cmsEPSS 0.69%via NVD
CVE-2026-86300High· 7.3PoC
2w ago

A flaw has been found in Tenda AC9 15.03.05.14

A flaw has been found in Tenda AC9 15.03.05.14. This impacts the function R7WebsSecurityHandler of the component Web Management. This manipulation causes improper authentication. The attack may be initiated remotely. The exploit has been…

▾ MidnightTenda · AC9EPSS 0.84%via NVD
CVE-2026-86293Medium· 6.5PoC
2w ago

A flaw has been found in SourceCodester Simple Traffic Offense System 1.0

A flaw has been found in SourceCodester Simple Traffic Offense System 1.0. Affected by this vulnerability is an unknown functionality of the file delete-user.php of the component Deletion Endpoint. Executing a manipulation of the argumen…

▾ TwilightSourceCodester · Simple Traffic Offense SystemEPSS 0.76%via NVD
CVE-2026-86292High· 7.3PoC
2w ago

A vulnerability was detected in SourceCodester Simple Traffic Offense System 1.0

A vulnerability was detected in SourceCodester Simple Traffic Offense System 1.0. Affected is an unknown function of the file saveuser.php of the component User Creation. Performing a manipulation of the argument position results in miss…

▾ MidnightSourceCodester · Simple Traffic Offense SystemEPSS 0.69%via NVD
CVE-2026-86214High· 7.3PoC
3w ago

A vulnerability was determined in Mstfakts College-Management-System

A vulnerability was determined in Mstfakts College-Management-System. Impacted is an unknown function of the file Front-end/login.php. This manipulation of the argument email causes improper authentication. It is possible to initiate the…

▾ MidnightEPSS 0.65%via NVD
CVE-2026-75816Critical· 9.8PoC
3w ago

The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Authentication Bypass to Account Takeover in all versions up to, and including, 3.29.12

The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Authentication Bypass to Account Takeover in all versions up to, and including, 3.29.12. This is due to the pre_update_value function lacking any capability or owners…

▾ AbyssalEPSS 0.91%via NVD
CVE-2026-18056High· 7.5
3w ago

The HivePress Authentication plugin for WordPress is vulnerable to Authentication Bypass via the access_token parameter in all versions up to, and including, 1.1.4

The HivePress Authentication plugin for WordPress is vulnerable to Authentication Bypass via the access_token parameter in all versions up to, and including, 1.1.4. This is due to the authenticate_user function's Facebook authenticator r…

▾ TwilightEPSS 0.34%via NVD
CVE-2026-86117High· 8.1
3w ago

Coolify through 4.3.17 contains an authentication bypass vulnerability in the OAuth callback handler that signs users into existing accounts based solely on email address without verifying provider assertions or binding OAuth identities.…

Coolify through 4.3.17 contains an authentication bypass vulnerability in the OAuth callback handler that signs users into existing accounts based solely on email address without verifying provider assertions or binding OAuth identities.…

▾ Twilightcoollabsio · coolifyEPSS 0.67%via NVD
CVE-2026-77826High· 8.8
3w ago

The RegistrationMagic WordPress plugin before 6.0.9.9 does not verify which application a Facebook access token was issued to before accepting it as proof of identity, allowing unauthenticated attackers to log in as an existing user who…

The RegistrationMagic WordPress plugin before 6.0.9.9 does not verify which application a Facebook access token was issued to before accepting it as proof of identity, allowing unauthenticated attackers to log in as an existing user who…

▾ TwilightEPSS 0.41%via NVD
CWE-287 vulnerabilities (CVEs) — page 7 · VulnSea