VulnSea

CWE-288

CVEs classified under CWE-288, newest first.

73 CVEsRSS

CVE-2026-65641None
1mo ago

A vulnerability allowing an unauthenticated network attacker to coerce SMB authentication from the service account.

A vulnerability allowing an unauthenticated network attacker to coerce SMB authentication from the service account.

▾ SunlitEPSS 0.54%via NVD
CVE-2026-19490Critical· 9.8CISA KEVPoC
1mo ago

Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: from 14.1 through 73.32 and from 13.1 through 63.21; Gateway: from 14.1 through 73.32 and from 13.1 through 63.21.

Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: from 14.1 through 73.32 and from 13.1 through 63.21; Gateway: from 14.1 through 73.32 and from 13.1 through 63.21.

▾ Hadalcitrix · netscaler_application_delivery_controllerEPSS 7.0%via NVD
CVE-2026-75627Critical· 9.8PoC
1mo ago

Bastillion fails to properly validate request URI paths in its controller dispatcher, allowing unauthenticated attackers to bypass authentication filters by prefixing requests with arbitrary path segments

Bastillion fails to properly validate request URI paths in its controller dispatcher, allowing unauthenticated attackers to bypass authentication filters by prefixing requests with arbitrary path segments. Attackers can access administra…

▾ Abyssalbastillion-io · BastillionEPSS 0.84%via NVD
CVE-2026-50191High· 8.8
1mo ago

4gaBoards is a boards system for realtime project management

4gaBoards is a boards system for realtime project management. Prior to 3.3.8, 4gaBoards is vulnerable to pre-account takeover when registrationEnabled, localRegistrationEnabled, and ssoRegistrationEnabled are enabled and Google, GitHub, …

▾ TwilightEPSS 0.47%via NVD
CVE-2021-43718Medium· 5.3
1mo ago

An Authentication Bypass vulnerability exists in EPSON EH-TW5350 EPSON 150075647YWWV110, which could let a remote malicious user cause a Denial of Service via specially crafted series of HTTP..

An Authentication Bypass vulnerability exists in EPSON EH-TW5350 EPSON 150075647YWWV110, which could let a remote malicious user cause a Denial of Service via specially crafted series of HTTP..

▾ SunlitEPSS 0.52%via NVD
CVE-2026-75045Critical· 9.1
1mo ago

In JetBrains YouTrack before 2025.3.156085, 2026.1.13913, 2026.2.18112 an unauthenticated attacker could download database backups via shared draft signature

In JetBrains YouTrack before 2025.3.156085, 2026.1.13913, 2026.2.18112 an unauthenticated attacker could download database backups via shared draft signature

▾ Midnightjetbrains · youtrackEPSS 0.42%via NVD
CVE-2026-70468High· 8.1
1mo ago

A authentication bypass using an alternate path or channel vulnerability in Fortinet FortiManager 7.6.1, FortiManager 7.4.3 through 7.4.5, FortiManager 7.2.5 through 7.2.9, FortiManager Cloud 7.6.1, FortiManager Cloud 7.4.3 through 7.4.5…

A authentication bypass using an alternate path or channel vulnerability in Fortinet FortiManager 7.6.1, FortiManager 7.4.3 through 7.4.5, FortiManager 7.2.5 through 7.2.9, FortiManager Cloud 7.6.1, FortiManager Cloud 7.4.3 through 7.4.5…

▾ Twilightfortinet · fortimanagerEPSS 0.46%via NVD
CVE-2026-18636Medium· 6.8
1mo ago

The Velociraptor gRPC API has a VFSGetBuffer endpoint which allows reading files from the datastore

The Velociraptor gRPC API has a VFSGetBuffer endpoint which allows reading files from the datastore. To prevent users from reading sensitive files or accessing other orgs, the requested path is prefix checked against a list of denied pre…

▾ SunlitEPSS 0.40%via NVD
CVE-2026-66425Medium· 6.5
1mo ago

Unauthenticated Broken Authentication in Gutena Forms – Contact Form, Survey Form, Feedback Form, Booking Form, and Custom Form Builder <= 1.9.0 versions.

Unauthenticated Broken Authentication in Gutena Forms – Contact Form, Survey Form, Feedback Form, Booking Form, and Custom Form Builder <= 1.9.0 versions.

▾ SunlitEPSS 0.42%via NVD
CVE-2026-24254Critical· 9.8
1mo ago

NVIDIA Dynamo for Linux contains a vulnerability in the multimodal serving topology, where an attacker could cause an out-of-bounds write

NVIDIA Dynamo for Linux contains a vulnerability in the multimodal serving topology, where an attacker could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to code execution, escalation of privileges,…

▾ Midnightnvidia · dynamoEPSS 0.89%via NVD
GHSA-g64v-qqpg-v37hCritical· 8.6
1mo ago

Duplicate Advisory: Anonymous publish-password authentication bypass via getHeadingChildrenDOM / getHeading*Transaction / getBacklinkDoc (publish mode)

Duplicate Advisory: Anonymous publish-password authentication bypass via getHeadingChildrenDOM / getHeading*Transaction / getBacklinkDoc (publish mode)

▾ Midnightsiyuan-note · github.com/siyuan-note/siyuan/kernelvia GHSA
CVE-2026-18577NoneCISA KEV0dayPoC
1mo ago

An incomplete patch for CVE-2026-18556 allows for authentication bypass and account takeover in N-central Versions through 2026.3.1

An incomplete patch for CVE-2026-18556 allows for authentication bypass and account takeover in N-central Versions through 2026.3.1

▾ TwilightEPSS 15%via NVD
CVE-2026-18556NoneCISA KEVPoC
1mo ago

Authentication bypass using an alternate path or channel vulnerability in N-able N-central allows Authentication Bypass. This issue affects N-central: through 2026.1.

Authentication bypass using an alternate path or channel vulnerability in N-able N-central allows Authentication Bypass. This issue affects N-central: through 2026.1.

▾ TwilightEPSS 7.9%via NVD
CVE-2026-67337Medium· 6.5
1mo ago

better-auth versions before 1.4.9 contain a two-factor authentication bypass vulnerability when session.cookieCache is enabled

better-auth versions before 1.4.9 contain a two-factor authentication bypass vulnerability when session.cookieCache is enabled. Attackers with valid primary credentials can access authenticated routes without completing second-factor ver…

▾ SunlitEPSS 0.46%via NVD
CVE-2026-16198Medium· 5.6
2mo ago

A vulnerability was detected in Sipeed PicoClaw up to 0.2.9

A vulnerability was detected in Sipeed PicoClaw up to 0.2.9. The impacted element is an unknown function of the file web/backend/middleware/access_control.go of the component First Run Setup. Performing a manipulation of the argument all…

▾ SunlitEPSS 0.63%via NVD
CVE-2026-57980Medium· 5.4
2mo ago

Microsoft Edge (Chromium-based) Tampering Vulnerability

Authentication bypass using an alternate path or channel in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform tampering over a network.

▾ SunlitMicrosoft · Microsoft Edge (Chromium-based)EPSS 0.39%via CVEORG
CVE-2026-57807Critical· 9.8
2mo ago

Authentication Bypass Using an Alternate Path or Channel vulnerability in miniOrange Security Software Pvt Ltd

Authentication Bypass Using an Alternate Path or Channel vulnerability in miniOrange Security Software Pvt Ltd. OAuth Single Sign On - SSO (OAuth Client) allows Password Recovery Exploitation. This issue affects OAuth Single Sign On - S…

▾ MidnightEPSS 0.73%via NVD
CVE-2025-13475Low· 3.5
2mo ago

In multi-tenanted deployments, the application consent management mechanism fails to correctly isolate consent scopes between tenants

In multi-tenanted deployments, the application consent management mechanism fails to correctly isolate consent scopes between tenants. Consent granted by a user for a specific SaaS application within one tenant can be incorrectly applied…

▾ SunlitEPSS 0.27%via NVD
CVE-2026-50194High· 8.2
2mo ago

Steeltoe vulnerable to management-port isolation bypass via spoofed Host header

Steeltoe vulnerable to management-port isolation bypass via spoofed Host header

▾ TwilightSteeltoe · Steeltoe.Management.EndpointEPSS 0.41%via GHSA
GHSA-4qq2-2j2x-x62cHigh· 8.2
3mo ago

npm PraisonAI MCPSecurity Basic/OAuth authentication policies accept invalid credentials without validation

npm PraisonAI MCPSecurity Basic/OAuth authentication policies accept invalid credentials without validation

▾ Twilightpraisonai · praisonaivia GHSA
CVE-2026-48491High
3mo ago

Traefik: SNICheck ignores wildcard TLSOptions mappings, allowing domain-fronted mTLS bypass

Traefik: SNICheck ignores wildcard TLSOptions mappings, allowing domain-fronted mTLS bypass

▾ TwilightTraefik · TraefikEPSS 0.36%via GHSA
CVE-2026-53622High
3mo ago

Traefik: HTTP/3 mTLS bypass via exact SNI TLSOptions lookup for wildcard and mixed-case hosts

Traefik: HTTP/3 mTLS bypass via exact SNI TLSOptions lookup for wildcard and mixed-case hosts

▾ TwilightTraefik · TraefikEPSS 0.63%via GHSA
CVE-2026-48020HighPoC
3mo ago

Traefik has a StripPrefix Route-Level Auth Bypass via Path Normalization

Traefik has a StripPrefix Route-Level Auth Bypass via Path Normalization

▾ Midnighttraefik · github.com/traefik/traefik/v2EPSS 0.78%via GHSA
CVE-2026-33843Critical· 9.1
4mo ago

Authentication bypass using an alternate path or channel in Microsoft Azure Active Directory B2C allows an unauthorized attacker to elevate privileges over a network.

Authentication bypass using an alternate path or channel in Microsoft Azure Active Directory B2C allows an unauthorized attacker to elevate privileges over a network.

▾ Midnightmicrosoft · entra_idEPSS 0.86%via NVD
CVE-2026-45109High· 7.5
4mo ago

Next.js is a React framework for building full-stack web applications

Next.js is a React framework for building full-stack web applications. From 15.2.0 to before 15.5.18 and 16.2.6, it was found that the fix addressing CVE-2026-44575 did not apply to middleware.ts with Turbopack. This vulnerability is fix…

▾ Twilightvercel · next.jsEPSS 0.76%via NVD
CVE-2026-44575High· 7.5
4mo ago

Next.js is a React framework for building full-stack web applications

Next.js is a React framework for building full-stack web applications. From 15.2.0 to before 15.5.16 and 16.2.5, App Router applications that rely on middleware or proxy-based checks for authorization can allow unauthorized access throug…

▾ Twilightvercel · next.jsEPSS 0.76%via NVD
CVE-2026-44574High· 8.1
4mo ago

Next.js is a React framework for building full-stack web applications

Next.js is a React framework for building full-stack web applications. From 15.4.0 to before 15.5.16 and 16.2.5, applications that rely on middleware to protect dynamic routes can be vulnerable to authorization bypass. In affected deploy…

▾ Twilightvercel · next.jsEPSS 0.67%via NVD
CVE-2025-70082Critical· 9.8
6mo ago

An issue in Lantronix EDS3000PS v.3.1.0.0R2 allows an attacker to execute arbitrary code and obtain sensitive information via the ltrx_evo component

An issue in Lantronix EDS3000PS v.3.1.0.0R2 allows an attacker to execute arbitrary code and obtain sensitive information via the ltrx_evo component

▾ MidnightEPSS 0.46%via NVD
CVE-2025-67041Critical· 9.8
6mo ago

An issue was discovered in Lantronix EDS3000PS 3.1.0.0R2

An issue was discovered in Lantronix EDS3000PS 3.1.0.0R2. The host parameter of the TFTP client in the Filesystem Browser page is not properly sanitized. This can be exploited to escape from the original command and execute an arbitrary …

▾ MidnightEPSS 0.42%via NVD
CVE-2025-67039Critical· 9.1
6mo ago

An issue was discovered in Lantronix EDS3000PS 3.1.0.0R2

An issue was discovered in Lantronix EDS3000PS 3.1.0.0R2. The authentication on management pages can be bypassed by appending a specific suffix to the URL and by sending an Authorization header that uses "admin" as the username.

▾ MidnightEPSS 0.44%via NVD
CWE-288 vulnerabilities (CVEs) — page 2 · VulnSea