VulnSea

CWE-287

CVEs classified under CWE-287, newest first.

461 CVEsRSS

CVE-2026-13447Critical· 9.8PoC
3w ago

The Mstore Api plugin for WordPress is vulnerable to Authentication Bypass via JWT Forgery in versions up to, and including, 4.20.0 This is due to missing cryptographic signature verification in the FirebasePhoneAuthHelper::verify_id_tok…

The Mstore Api plugin for WordPress is vulnerable to Authentication Bypass via JWT Forgery in versions up to, and including, 4.20.0 This is due to missing cryptographic signature verification in the FirebasePhoneAuthHelper::verify_id_tok…

▾ AbyssalEPSS 0.45%via NVD
CVE-2026-53761None
3w ago

Frappe CRM is an open-source customer relationship management tool

Frappe CRM is an open-source customer relationship management tool. Prior to version 1.73.0, there is an authentication bypass vulnerability via logged invitation keys in crm/api. This issue has been patched in version 1.73.0.

▾ SunlitEPSS 0.60%via NVD
CVE-2026-75429Critical· 9.8PoC
3w ago

PowerJob versions 4.x through 5.1.2 contain an unauthenticated remote code execution vulnerability in the /friend/process endpoint of the Server-Worker transport layer

PowerJob versions 4.x through 5.1.2 contain an unauthenticated remote code execution vulnerability in the /friend/process endpoint of the Server-Worker transport layer

▾ AbyssalEPSS 0.98%via NVD
CVE-2026-85702High· 7.3PoC
3w ago

A security vulnerability has been detected in ramon-victor freegpt-webui up to 098db3dfeb41555c2ca9269df0f13e10ec1c35dc

A security vulnerability has been detected in ramon-victor freegpt-webui up to 098db3dfeb41555c2ca9269df0f13e10ec1c35dc. Affected is the function _conversation of the file server/backend.py of the component Backend Conversation API. Such…

▾ Midnightramon-victor · freegpt-webuiEPSS 0.66%via NVD
CVE-2026-85701Medium· 5.3PoC
3w ago

A vulnerability has been found in ramon-victor freegpt-webui up to 098db3dfeb41555c2ca9269df0f13e10ec1c35dc

A vulnerability has been found in ramon-victor freegpt-webui up to 098db3dfeb41555c2ca9269df0f13e10ec1c35dc. This issue affects the function ChatCompletion.create of the file g4f/__init__.py of the component Authentication Check. Such ma…

▾ Twilightramon-victor · freegpt-webuiEPSS 0.63%via NVD
CVE-2026-85637Medium· 5.3
3w ago

A security flaw has been discovered in jofpin trape 1.0.0/2.0

A security flaw has been discovered in jofpin trape 1.0.0/2.0. Affected by this issue is the function join_room of the file core/sockets.py of the component Admin Endpoint. The manipulation results in missing authentication. The attack m…

▾ SunlitEPSS 0.74%via NVD
CVE-2026-85636Medium· 5.3PoC
3w ago

A vulnerability was identified in jofpin trape 1.0.0

A vulnerability was identified in jofpin trape 1.0.0. Affected by this vulnerability is an unknown functionality of the file core/stats.py of the component Login Endpoint. The manipulation leads to missing authentication. The attack may …

▾ Twilightjofpin · trapeEPSS 0.75%via NVD
CVE-2026-18221High· 8.1
3w ago

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to gain unauthorized access due to improper validation of client-supplied authentication parameters.

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to gain unauthorized access due to improper validation of client-supplied authentication parameters.

▾ Twilightibm · iEPSS 0.34%via NVD
CVE-2026-16892Medium· 5.4
3w ago

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrictions due to improper authentication during service-name matching.

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrictions due to improper authentication during service-name matching.

▾ Sunlitibm · iEPSS 0.25%via NVD
CVE-2026-85596Critical· 9.8⚖ disputed
3w ago

Traefik versions >= v3.7.0 and <= v3.7.10 contain an authentication bypass in the Kubernetes Ingress NGINX provider

Traefik versions >= v3.7.0 and <= v3.7.10 contain an authentication bypass in the Kubernetes Ingress NGINX provider. The TLS option generated for an Ingress carrying the nginx.ingress.kubernetes.io/auth-tls-secret annotation was named af…

▾ Midnighttraefik · traefikEPSS 0.43%via NVD
CVE-2026-85595Critical· 9.8
3w ago

Traefik versions before v2.11.55 and versions v3.0.0 through v3.7.10 contain an authentication bypass vulnerability in the digestAuth middleware where unknown usernames receive an empty secret instead of rejection

Traefik versions before v2.11.55 and versions v3.0.0 through v3.7.10 contain an authentication bypass vulnerability in the digestAuth middleware where unknown usernames receive an empty secret instead of rejection. Attackers can compute …

▾ Midnighttraefik · traefikEPSS 0.69%via NVD
CVE-2026-83961High· 7.1
3w ago

ColdFusion is affected by an Improper Authentication vulnerability that could result in privilege escalation

ColdFusion is affected by an Improper Authentication vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain limited read and write access. The vulnerable component is restricted to …

▾ Twilightadobe · coldfusionEPSS 0.42%via NVD
CVE-2026-61641High· 8.1
3w ago

Wallos is an open-source, self-hostable personal subscription tracker

Wallos is an open-source, self-hostable personal subscription tracker. From version 4.0.0 to before version 4.9.6, Wallos's OIDC login links an incoming OIDC identity to an existing local account by matching the email claim alone, withou…

▾ TwilightEPSS 0.53%via NVD
CVE-2026-54600None
3w ago

Wallos is an open-source, self-hostable personal subscription tracker

Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.9.4, endpoints/db/import.php has no authentication. The only guard is a user-table row count — if zero (fresh/unconfigured install), an unauthentic…

▾ SunlitEPSS 0.58%via NVD
CVE-2026-82547Medium· 6.5PoC
4w ago

A vulnerability was found in Linux Foundation Magma 1.9.0

A vulnerability was found in Linux Foundation Magma 1.9.0. The affected element is an unknown function of the file tasks/amf/amf_fsm.cpp of the component Registration Complete Message Handler. The manipulation results in improper authent…

▾ TwilightLinux Foundation · MagmaEPSS 0.76%via NVD
CVE-2026-75807High· 7.5
4w ago

The SAML Single Sign On – SSO Login plugin for WordPress is vulnerable to Authentication Bypass in versions up to, and including, 5.4.6

The SAML Single Sign On – SSO Login plugin for WordPress is vulnerable to Authentication Bypass in versions up to, and including, 5.4.6. This is due to the mo_saml_login_validate() ACS handler persisting the X.509 certificate extracted f…

▾ TwilightEPSS 0.41%via NVD
CVE-2026-82466High· 8.7
4w ago

Rodauth before 2.46.0 contains an authentication bypass vulnerability in the webauthn_login route that allows logged-in users to authenticate as any other account

Rodauth before 2.46.0 contains an authentication bypass vulnerability in the webauthn_login route that allows logged-in users to authenticate as any other account. Attackers can exploit improper account resolution logic that falls back t…

▾ TwilightEPSS 0.61%via NVD
CVE-2026-76548High· 8.2
4w ago

The User Profile Builder WordPress plugin before 4.0.1 does not properly restrict its front-end file upload feature, granting unauthenticated visitors capabilities reserved to privileged roles

The User Profile Builder WordPress plugin before 4.0.1 does not properly restrict its front-end file upload feature, granting unauthenticated visitors capabilities reserved to privileged roles. This allows them to list the site's media …

▾ TwilightEPSS 0.32%via NVD
CVE-2026-55761High· 5.9
1mo ago

Portainer has Unauthenticated Restore Endpoint that Allows Admin Takeover on Uninitialized Instances

Portainer has Unauthenticated Restore Endpoint that Allows Admin Takeover on Uninitialized Instances

▾ Twilightportainer · github.com/portainer/portainerEPSS 0.49%via GHSA
CVE-2026-55678Medium
1mo ago

Arc is an open, SQL-native time-series database for telemetry

Arc is an open, SQL-native time-series database for telemetry. From 26.02.1 until 26.06.2, Arc Enterprise clustering accepts cluster join requests without authentication when cluster.enabled is true but cluster.shared_secret is not confi…

▾ Sunlitbasekick-labs · github.com/basekick-labs/arcEPSS 0.66%via NVD
CVE-2026-37006Critical· 9.8
1mo ago

A vulnerability in the WebSocket endpoint of gpt-researcher v0.14.7 and before allows an unauthenticated remote attacker to achieve code execution via malicious Model Context Protocol configurations.

A vulnerability in the WebSocket endpoint of gpt-researcher v0.14.7 and before allows an unauthenticated remote attacker to achieve code execution via malicious Model Context Protocol configurations.

▾ MidnightEPSS 0.89%via NVD
CVE-2026-75325Critical· 9.8
1mo ago

DWSurvey v6.14.0 is is vulnerable to authentication bypass via the '/api/dwsurvey/none/' and '/api/dwsurvey/up/**' parameters.

DWSurvey v6.14.0 is is vulnerable to authentication bypass via the '/api/dwsurvey/none/' and '/api/dwsurvey/up/**' parameters.

▾ MidnightEPSS 0.64%via NVD
CVE-2026-80192High· 8.1
1mo ago

@better-auth/sso before 1.6.27 (and before 1.4.8 in the 1.4.x line and before 1.7.0-rc.5 in the 1.7 prerelease line) contains two domain-ownership flaws

@better-auth/sso before 1.6.27 (and before 1.4.8 in the 1.4.x line and before 1.7.0-rc.5 in the 1.7 prerelease line) contains two domain-ownership flaws. When domain verification is disabled, automatic organization assignment accepts unv…

▾ TwilightEPSS 0.36%via NVD
CVE-2026-79787Critical· 9.8
1mo ago

Alluxio's S3 REST proxy fails to verify AWS Signature Version 4 signatures in its default configuration, allowing unauthenticated attackers to spoof user identity

Alluxio's S3 REST proxy fails to verify AWS Signature Version 4 signatures in its default configuration, allowing unauthenticated attackers to spoof user identity. Attackers can extract usernames from unsigned Authorization headers and i…

▾ MidnightEPSS 0.46%via NVD
CVE-2026-68569High· 8.1
1mo ago

Improper Authentication vulnerability in Apache Tomcat meant that in some circumstances (e.g

Improper Authentication vulnerability in Apache Tomcat meant that in some circumstances (e.g. CLIENT-CERT, SPNEGO) that a user would be authenticated even if the user did not exist in the DataSourceRealm. This issue affects Apache Tom…

▾ Twilightapache · tomcatEPSS 0.60%via NVD
CVE-2026-44476Medium· 6.3PoC
1mo ago

Doorkeeper is an OAuth 2 provider for Ruby on Rails

Doorkeeper is an OAuth 2 provider for Ruby on Rails. In version 1.9.0, an attacker who knows only a dynamically registered client's client_id, which is public information, can authenticate as that client at the token endpoint and obtain …

▾ Twilightdoorkeeper-gem · doorkeeper-openid_connectEPSS 0.56%via NVD
CVE-2026-55533High· 8.2
1mo ago

PraisonAI: Authentication fail-open in Recipe server allows unauthenticated access when API key or JWT auth is configured without a secret

PraisonAI: Authentication fail-open in Recipe server allows unauthenticated access when API key or JWT auth is configured without a secret

▾ Twilightpraisonai · praisonaiEPSS 0.49%via OSV
CVE-2026-77567High· 8.1
1mo ago

Filament is a collection of full-stack components for accelerated Laravel development

Filament is a collection of full-stack components for accelerated Laravel development. Prior to versions 4.12.0 and 5.7.0, incorrect challenge-form required-field handling allows app-based multi-factor authentication to be bypassed when …

▾ Twilightfilament · filament/filamentEPSS 0.55%via NVD
CVE-2026-46355High· 7.1
1mo ago

BigBlueButton is an open-source virtual classroom

BigBlueButton is an open-source virtual classroom. Prior to 3.0.23, BigBlueButton exposed /bigbluebutton/api/handleJoinExistingUser through bigbluebutton-web/grails-app/controllers/org/bigbluebutton/web/controllers/ApiController.groovy. …

▾ TwilightEPSS 0.37%via NVD
CVE-2026-62669High· 7.4
1mo ago

Grav Login Plugin adds login, basic ACL, and session wide messages to Grav

Grav Login Plugin adds login, basic ACL, and session wide messages to Grav. Prior to 3.8.11, the Grav Login plugin login.regenerate2FASecret task checks only that the pending-session user exists rather than requiring $user->authorized. A…

▾ Twilightgetgrav · getgrav/gravEPSS 0.50%via NVD
CWE-287 vulnerabilities (CVEs) — page 8 · VulnSea