VulnSea

CWE-287

CVEs classified under CWE-287, newest first.

461 CVEsRSS

CVE-2026-44472High· 8.1
1mo ago

Saleor is an e-commerce platform

Saleor is an e-commerce platform. From 2.10.0rc1 until 3.21.67, 3.22.63, and 3.23.22, the account activation flow treats email verification as sufficient proof of account ownership and automatically associates anonymous commerce data wit…

▾ TwilightEPSS 0.63%via NVD
CVE-2026-53958High· 7.6
1mo ago

4gaBoards is a boards system for realtime project management

4gaBoards is a boards system for realtime project management. Prior to 3.3.9, 4gaBoards allows an authenticated user to modify ssoGoogleId, ssoGoogleEmail, ssoGithubId, ssoGithubUsername, ssoGithubEmail, ssoMicrosoftId, ssoMicrosoftEmail…

▾ TwilightEPSS 0.40%via NVD
CVE-2026-50191High· 8.8
1mo ago

4gaBoards is a boards system for realtime project management

4gaBoards is a boards system for realtime project management. Prior to 3.3.8, 4gaBoards is vulnerable to pre-account takeover when registrationEnabled, localRegistrationEnabled, and ssoRegistrationEnabled are enabled and Google, GitHub, …

▾ TwilightEPSS 0.47%via NVD
CVE-2026-52793High· 8.1
1mo ago

Froxlor is open source server administration software

Froxlor is open source server administration software. Prior to 2.3.7, the API authentication path in lib/Froxlor/Api/FroxlorRPC.php and FroxlorRPC::validateAuth accepts an API key and secret for an administrator or customer account with…

▾ TwilightEPSS 0.33%via NVD
CVE-2026-70922High· 8.8
1mo ago

Vulnerability in the Oracle Financial Services Enterprise Case Management product of Oracle Financial Services Applications (component: Web UI)

Vulnerability in the Oracle Financial Services Enterprise Case Management product of Oracle Financial Services Applications (component: Web UI). Supported versions that are affected are 8.0.8.2 and 8.1.2.11. Easily exploitable vulnerab…

▾ Twilightoracle · financial_services_enterprise_case_managementEPSS 0.43%via NVD
CVE-2026-70905Critical· 9.8
1mo ago

Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Agent infrastructure)

Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Agent infrastructure). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticat…

▾ Midnightoracle · access_managerEPSS 0.51%via NVD
CVE-2026-60679High· 7.5
1mo ago

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core)

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Difficult to exploit vulnerability allows lo…

▾ Twilightoracle · weblogic_serverEPSS 0.33%via NVD
CVE-2025-27621None
1mo ago

UpTrain is an open-source platform to evaluate and improve generative AI applications

UpTrain is an open-source platform to evaluate and improve generative AI applications. In version 0.7.1 and prior, the UpTrain backend creates a new default user with a static username, where the username is also used as the default API …

▾ SunlitEPSS 0.46%via NVD
CVE-2026-65329Medium· 5.9
1mo ago

An authentication issue was addressed with improved state management

An authentication issue was addressed with improved state management. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, iOS 27 and iPadOS 27. An attacker in a privileged network position may be able to bypass IPSec authentication and …

▾ Sunlitapple · ipadosEPSS 0.24%via NVD
CVE-2026-19924Critical· 9.8
1mo ago

A security vulnerability has been detected in Tenda AC10 16.03.10.09_multi_TDE01

A security vulnerability has been detected in Tenda AC10 16.03.10.09_multi_TDE01. This vulnerability affects the function R7WebsSecurityHandler of the component httpd. The manipulation leads to improper authentication. The attack may be …

▾ MidnightEPSS 1.4%via NVD
CVE-2026-73054High· 7.5
1mo ago

SiYuan versions before v3.7.4 contain an authentication bypass vulnerability in the WebSocket endpoint caused by differential parsing of query parameters between authentication exemption and session quarantine checks

SiYuan versions before v3.7.4 contain an authentication bypass vulnerability in the WebSocket endpoint caused by differential parsing of query parameters between authentication exemption and session quarantine checks. Unauthenticated att…

▾ TwilightEPSS 0.54%via NVD
CVE-2026-48528Critical· 9.8
1mo ago

Metacat is data repository software that helps researchers preserve, share, and discover data

Metacat is data repository software that helps researchers preserve, share, and discover data. Metacat versions 2.0.0 through 3.4.0 contain an unauthenticated SQL injection vulnerability in the `/cn/v1/object` and `/cn/v2/object` REST AP…

▾ MidnightEPSS 0.47%via NVD
CVE-2026-16739Medium· 5.9
1mo ago

The Epeken All Kurir for Woocommerce WordPress plugin through 2.1.4 does not verify that a payment-confirmation request originates from the owner of the targeted order, nor that any payment actually occurred, allowing unauthenticated att…

The Epeken All Kurir for Woocommerce WordPress plugin through 2.1.4 does not verify that a payment-confirmation request originates from the owner of the targeted order, nor that any payment actually occurred, allowing unauthenticated att…

▾ SunlitEPSS 0.29%via NVD
CVE-2026-35511High
1mo ago

Authorizer: Zero-click account takeover via OAuth identity linking to unverified email accounts

Authorizer: Zero-click account takeover via OAuth identity linking to unverified email accounts

▾ Twilightauthorizerdev · github.com/authorizerdev/authorizervia GHSA
CVE-2026-73655High· 7.4
1mo ago

Trigger.dev is a platform for building and deploying fully managed AI agents and workflows

Trigger.dev is a platform for building and deploying fully managed AI agents and workflows. Prior to 4.5.2, addGoogleStrategy() in apps/webapp/app/services/googleAuth.server.ts passes a Google profile email to findOrCreateGoogleUser() in…

▾ TwilightEPSS 0.47%via NVD
CVE-2026-73302None
1mo ago

Budibase is an open-source low-code platform

Budibase is an open-source low-code platform. Prior to 3.39.30, the OIDC flow in packages/backend-core/src/middleware/passport/sso/oidc.ts resolved an email without getEmailVerified or an email_verified requirement, and packages/backend-…

▾ SunlitEPSS 0.43%via NVD
CVE-2026-73840Medium· 5.3
1mo ago

OpenChoreo is a complete, open-source developer platform for Kubernetes

OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.0.3, 1.1.3, and 1.2.0-rc.2, the POST /api/v1alpha1/autobuild endpoint in internal/openchoreo-api/api/handlers/webhook_handler.go selected a webhook provi…

▾ Sunlitopenchoreo · github.com/openchoreo/openchoreoEPSS 0.35%via NVD
CVE-2024-27253Critical· 10.0
1mo ago

IBM DOORS Next 7.0.3 through 7.0.3 Interim Fix 018 could allow an authenticated user to bypass security logic to perform unauthorized activities.

IBM DOORS Next 7.0.3 through 7.0.3 Interim Fix 018 could allow an authenticated user to bypass security logic to perform unauthorized activities.

▾ MidnightEPSS 0.57%via NVD
CVE-2026-47718None
1mo ago

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. When `secureEnabled=true`, FUXA `1.3.0-2773` still allows guest and invalid-token requests to read project, alarms, and scheduler APIs. Version 1.3.1 fixes this is…

▾ SunlitEPSS 0.46%via NVD
CVE-2026-42018High· 7.5CISA KEVPoC
1mo ago

Anonymous user token generation exposure in JFrog Artifactory

JFrog Artifactory could return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled, potentially exposing sensitive resources.

▾ Abyssaljfrog · artifactoryEPSS 9.8%via CVEORG
CVE-2026-50561Critical· 9.4
1mo ago

Yuxi is a large-model-based intelligent knowledge base and knowledge graph agent development platform

Yuxi is a large-model-based intelligent knowledge base and knowledge graph agent development platform. Prior to version 0.6.2, the project's authentication mechanism contains a flaw. In affected versions, the system does not sufficiently…

▾ MidnightEPSS 0.68%via NVD
CVE-2026-26035Critical· 9.8
1mo ago

An Improper Authentication vulnerability [CWE-287] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4.0 through 7.4.11, FortiWeb 7.2.0 through 7.2.12, FortiWeb 7.0.0 through 7.0.12 may allo…

An Improper Authentication vulnerability [CWE-287] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4.0 through 7.4.11, FortiWeb 7.2.0 through 7.2.12, FortiWeb 7.0.0 through 7.0.12 may allo…

▾ Midnightfortinet · fortiwebEPSS 0.75%via NVD
CVE-2026-68760Medium· 5.3
1mo ago

An unauthenticated user may bypass authentication under specific cache conditions.

An unauthenticated user may bypass authentication under specific cache conditions.

▾ SunlitEPSS 0.46%via NVD
CVE-2026-73501Critical· 9.1
1mo ago

kin-openapi is a Go project for handling OpenAPI files

kin-openapi is a Go project for handling OpenAPI files. Prior to 0.144.0, ValidationHandler.Load() in openapi3filter/validation_handler.go silently replaces a nil AuthenticationFunc with NoopAuthenticationFunc, which returns nil without …

▾ MidnightRed Hat · Red Hat Edge Manager 1EPSS 0.59%via NVD
CVE-2026-73241High· 7.5
1mo ago

FreeRDP is a free implementation of the Remote Desktop Protocol

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.30.0, FreeRDP server-side RDSTLS in libfreerdp/core/rdstls.c accepts an attacker-supplied RDSTLS_TYPE_CAPABILITIES PDU while rdstls_server_authenticate is waitin…

▾ Twilightfreerdp · freerdpEPSS 0.47%via NVD
CVE-2026-73085None
1mo ago

Audiobookshelf is a self-hosted audiobook and podcast server

Audiobookshelf is a self-hosted audiobook and podcast server. Prior to 2.36.0, the jwtAuthCheck function in server/auth/TokenManager.js treats JWTs with the refresh token type as bearer access tokens on API and WebSocket resource endpoin…

▾ SunlitEPSS 0.46%via NVD
CVE-2026-72922High· 8.2
1mo ago

AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents

AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. Prior to 0.6.70, AutoGPT's autogpt_platform/backend/backend/api/features/integrations/router.py webhook_ingress_ge…

▾ TwilightEPSS 0.48%via NVD
CVE-2026-62827High· 8.8
1mo ago

Microsoft SharePoint Server Elevation of Privilege Vulnerability

Improper authentication in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.

▾ TwilightMicrosoft · Microsoft SharePoint Enterprise Server 2016EPSS 0.94%via CVEORG
CVE-2026-72917Medium· 5.9
1mo ago

AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting

AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. From 1.0.0 to 1.15.0, AnythingLLM's unauthenticated account-recovery flow in server/utils/PasswordRecovery/index.…

▾ SunlitEPSS 0.35%via NVD
CVE-2026-19342High· 7.3
1mo ago

A vulnerability was detected in code-projects Task Management System 1.0

A vulnerability was detected in code-projects Task Management System 1.0. Affected is an unknown function of the file /index.php of the component Login. Performing a manipulation of the argument Password results in improper authenticatio…

▾ TwilightEPSS 0.67%via NVD
CWE-287 vulnerabilities (CVEs) — page 9 · VulnSea