VulnSea

CWE-290

CVEs classified under CWE-290, newest first.

111 CVEsRSS

CVE-2026-21391Critical· 9.5
1w ago

An improper validation vulnerability exists within PingAM where a well-crafted request allows arbitrary or protected ID Token claims to be set or overridden

An improper validation vulnerability exists within PingAM where a well-crafted request allows arbitrary or protected ID Token claims to be set or overridden. In certain configurations this could allow an attacker to bypass authentication…

MidnightPing Identity · PingAMEPSS 0.45%via NVD
CVE-2026-45056Medium· 6.9⚖ disputed
1w ago

matrix-sdk-crypto is a no-network-IO implementation of a state machine that handles end-to-end encryption for Matrix clients

matrix-sdk-crypto is a no-network-IO implementation of a state machine that handles end-to-end encryption for Matrix clients. Starting in version 0.12.0 and prior to version 0.17.0, the matrix-sdk-crypto crate was missing a check for the…

Sunlitmatrix-org · matrix-rust-sdkEPSS 0.23%via NVD
CVE-2026-90447High· 7.1
1w ago

A routing rule selects between two different authentication mechanisms for the same downstream service based on the value of a client-supplied request header, rather than on any property the client cannot control

A routing rule selects between two different authentication mechanisms for the same downstream service based on the value of a client-supplied request header, rather than on any property the client cannot control. An authenticated user i…

TwilightCISA · MalcolmEPSS 0.27%via NVD
CVE-2026-63427High· 7.8
1w ago

An authentication bypass vulnerability was discovered in Lenovo Software Fix that could allow a local authenticated user to perform arbitrary code execution with elevated privileges.

An authentication bypass vulnerability was discovered in Lenovo Software Fix that could allow a local authenticated user to perform arbitrary code execution with elevated privileges.

TwilightLenovo · Software FixEPSS 0.14%via NVD
CVE-2026-66674Medium· 5.6
1w ago

Unauthenticated Bypass Vulnerability in Simple Cloudflare Turnstile <= 1.42.1 versions.

Unauthenticated Bypass Vulnerability in Simple Cloudflare Turnstile <= 1.42.1 versions.

SunlitElliot Sowers/ RelyWP · simple-cloudflare-turnstileEPSS 0.20%via NVD
CVE-2026-88011High· 8.1⚖ disputed
1w ago

Traefik is an open source HTTP reverse proxy and load balancer

Traefik is an open source HTTP reverse proxy and load balancer. Prior to 2.11.56, and from 3.0.0 until 3.7.12, a client-supplied dot-form header such as X.Authenticated.User survives ForwardAuth replacement and underscoreHeadersStrategy …

Twilighttraefik · traefikEPSS 0.24%via NVD
CVE-2026-88879High· 8.2⚖ disputed
1w ago

Traefik is an HTTP reverse proxy and load balancer

Traefik is an HTTP reverse proxy and load balancer. In Traefik v1.x, v2.x through v2.11.55, and v3.0.0 through v3.7.11, header names are canonicalized only on dashes, so X-Auth-User, X_Auth_User and X.Auth.User are treated as three disti…

Twilighttraefik · traefikEPSS 0.21%via NVD
CVE-2026-82563High· 7.6
1w ago

An attacker could impersonate the camera and place themselves in a man-in-the-middle or device-emulation position

An attacker could impersonate the camera and place themselves in a man-in-the-middle or device-emulation position. This permits manipulation of device status responses, observation of application requests, and potential triggering of fir…

TwilightSoftish · EarVision Android applicationEPSS 0.15%via NVD
CVE-2026-82530Medium· 5.3
1w ago

IP2Location Country Blocker plugin for WordPress before 2.45.0 contains an access control bypass vulnerability that allows unauthenticated remote attackers to circumvent IP-based restrictions by forging the X-Real-IP HTTP header

IP2Location Country Blocker plugin for WordPress before 2.45.0 contains an access control bypass vulnerability that allows unauthenticated remote attackers to circumvent IP-based restrictions by forging the X-Real-IP HTTP header. Attacke…

SunlitIP2Location · IP2Location Country BlockerEPSS 0.27%via NVD
CVE-2026-62759High· 7.5
1w ago

Authentication bypass by spoofing in Windows Netlogon allows an unauthorized attacker to perform spoofing over an adjacent network.

Authentication bypass by spoofing in Windows Netlogon allows an unauthorized attacker to perform spoofing over an adjacent network.

Twilightmicrosoft · windows_10_1607EPSS 0.25%via NVD
CVE-2026-77089Critical· 9.8
1w ago

Command Center API contained an authentication bypass issue affecting privilege management

Command Center API contained an authentication bypass issue affecting privilege management. Software customers upgrade to resolved maintenance release. Update Command Center.

Midnightcommvault · commvaultEPSS 0.33%via NVD
CVE-2026-84186Medium· 6.9
2w ago

Vulnerability involving incorrect access control in the Tools::getRemoteAddr() function in PrestaShop, which allows the client’s IP address to be spoofed via the X-Forwarded-For header when the application is running behind a reverse pro…

Vulnerability involving incorrect access control in the Tools::getRemoteAddr() function in PrestaShop, which allows the client’s IP address to be spoofed via the X-Forwarded-For header when the application is running behind a reverse pro…

SunlitPrestaShop · PrestaShopEPSS 0.35%via NVD
CVE-2026-86478Critical· 9.8
2w ago

In JetBrains YouTrack before 2025.3.161254, 2026.1.14042 improper authentication in YouTrack Helpdesk allowed unauthenticated account takeover via a self-asserted email address

In JetBrains YouTrack before 2025.3.161254, 2026.1.14042 improper authentication in YouTrack Helpdesk allowed unauthenticated account takeover via a self-asserted email address

MidnightJetBrains · YouTrackEPSS 0.36%via NVD
CVE-2026-86196High· 8.7PoC
2w ago

Grav API plugin versions before 1.0.20 build password reset links from the untrusted Host header in the forgot-password endpoint, allowing unauthenticated attackers to redirect reset tokens to attacker-controlled domains

Grav API plugin versions before 1.0.20 build password reset links from the untrusted Host header in the forgot-password endpoint, allowing unauthenticated attackers to redirect reset tokens to attacker-controlled domains. Attackers can s…

Midnightgetgrav · grav-plugin-apiEPSS 0.26%via NVD
CVE-2026-85432High· 8.2
2w ago

MOOS core-moos through 10.4.0 fails to validate client identity in MOOSDB message processing, allowing authenticated attackers to attribute writes to other clients by supplying arbitrary source identifiers in serialized messages

MOOS core-moos through 10.4.0 fails to validate client identity in MOOSDB message processing, allowing authenticated attackers to attribute writes to other clients by supplying arbitrary source identifiers in serialized messages. Attacke…

TwilightEPSS 0.29%via NVD
CVE-2026-84766Medium· 5.9
2w ago

Unauthenticated Bypass Vulnerability in FluentBooking Pro <= 2.2.1 versions.

Unauthenticated Bypass Vulnerability in FluentBooking Pro <= 2.2.1 versions.

SunlitEPSS 0.20%via NVD
CVE-2026-14199High· 7.1
2w ago

Only self-managed Grafana instances with Auth Proxy authentication and identity caching enabled (sync_ttl greater than zero) are affected

Only self-managed Grafana instances with Auth Proxy authentication and identity caching enabled (sync_ttl greater than zero) are affected. The Auth Proxy cache key concatenated the username and forwarded identity attributes without a del…

Twilightgrafana · grafanaEPSS 0.31%via NVD
CVE-2026-84479Critical· 9.1
2w ago

WWBN AVideo (current e01e41ecc and earlier) makes three login-time security controls depend solely on the client-supplied User-Agent header

WWBN AVideo (current e01e41ecc and earlier) makes three login-time security controls depend solely on the client-supplied User-Agent header. The isAVideoEncoder()/isAVideoMobileApp() checks match HTTP_USER_AGENT against a hardcoded liter…

MidnightEPSS 0.32%via NVD
CVE-2026-84476High· 7.5
2w ago

WWBN AVideo fails to validate trusted proxies before accepting X-Real-IP and X-Forwarded-For headers, allowing attackers to spoof the client address used by enforceRateLimit()

WWBN AVideo fails to validate trusted proxies before accepting X-Real-IP and X-Forwarded-For headers, allowing attackers to spoof the client address used by enforceRateLimit(). Attackers can rotate the header value per request to bypass …

TwilightEPSS 0.26%via NVD
CVE-2026-55584High· 7.5PoC
3w ago

phpSysInfo is a customizable PHP script that displays system information

phpSysInfo is a customizable PHP script that displays system information. Prior to 3.4.6, the PSI_ALLOWED access-control check in read_config.php trusts attacker-controlled X-Forwarded-For and Client-IP HTTP headers before REMOTE_ADDR. A…

Midnightphpsysinfo · phpsysinfo/phpsysinfoEPSS 2.4%via NVD
CVE-2026-19538High· 7.5
3w ago

The BLOCKED access control list items that are evaluated to deny access on the the proxy protocol port can be bypassed completely when connecting over TCP or TLS and sending the query twice on connection that is kept open.

The BLOCKED access control list items that are evaluated to deny access on the the proxy protocol port can be bypassed completely when connecting over TCP or TLS and sending the query twice on connection that is kept open.

Twilightnlnetlabs · nsdEPSS 0.30%via NVD
CVE-2026-49757CriticalPoC
3w ago

AshAuthentication vulnerable to OAuth2/OIDC account takeover via email-based user matching

AshAuthentication vulnerable to OAuth2/OIDC account takeover via email-based user matching

Abyssalash_authentication · ash_authenticationEPSS 0.61%via GHSA
CVE-2026-77337None
4w ago

CakePHP Authentication is an authentication plugin for CakePHP that can also be used in PSR-7 based applications

CakePHP Authentication is an authentication plugin for CakePHP that can also be used in PSR-7 based applications. Versions before 2.11.2, from 3.0.0 through 3.3.6, and from 4.0.0 through 4.2.0 allow authentication bypass and potential CP…

SunlitEPSS 0.39%via NVD
CVE-2026-75509Medium· 6.5
4w ago

joserfc is a Python library that provides an implementation of several JSON Object Signing and Encryption (JOSE) standards

joserfc is a Python library that provides an implementation of several JSON Object Signing and Encryption (JOSE) standards. Prior to version 1.7.3, JWTClaimsRegistry applies membership matching to list-valued iss and sub claims, allowing…

SunlitEPSS 0.09%via NVD
CVE-2026-69183High· 7.5
1mo ago

Monkeytype is a minimalistic and customizable typing test

Monkeytype is a minimalistic and customizable typing test. In 26.26.0 and earlier, the backend rate-limit key generator in backend/src/middlewares/rate-limit.ts uses client-controlled cf-connecting-ip and x-forwarded-for headers before t…

TwilightEPSS 0.33%via NVD
CVE-2026-71485Critical· 9.1
1mo ago

Centrifugo is an open-source scalable real-time messaging server

Centrifugo is an open-source scalable real-time messaging server. Prior to 6.9.0, Centrifugo copies the client-controlled protocol.ConnectRequest.headers map through OnClientConnecting in internal/client/handler.go, ConnectEvent.Headers,…

Midnightcentrifugal · github.com/centrifugal/centrifugoEPSS 0.42%via NVD
CVE-2026-72816Medium· 6.5
1mo ago

go-chi/chi through 5.2.1 contains an IP spoofing vulnerability in the RealIP middleware (middleware/realip.go)

go-chi/chi through 5.2.1 contains an IP spoofing vulnerability in the RealIP middleware (middleware/realip.go). The realIP() function reads client-controlled headers (True-Client-IP, X-Real-IP, and X-Forwarded-For) and overwrites r.Remot…

Sunlitgo-chi · github.com/go-chi/chi/middlewareEPSS 0.22%via NVD
CVE-2026-0292Medium· 6.0⚖ disputed
1mo ago

An authentication bypass vulnerability in the network driver of Palo Alto Networks Prisma® Access Agent on Windows enables a local administrator to bypass security inspection, subsequently allowing them to inject and intercept arbitrary…

An authentication bypass vulnerability in the network driver of Palo Alto Networks Prisma® Access Agent on Windows enables a local administrator to bypass security inspection, subsequently allowing them to inject and intercept arbitrary…

Sunlitpaloaltonetworks · prisma_access_agentEPSS 0.13%via NVD
CVE-2026-19291High· 8.8
1mo ago

Bluetooth re-pairing with an existing device can use a lower security level

Bluetooth re-pairing with an existing device can use a lower security level. RS9116W and SiWx91x impacted. See V3 in the BLERP paper linked below.

TwilightEPSS 0.21%via NVD
CVE-2026-16101High· 8.8
1mo ago

Spoofing an already bonded device can force either RS9116W or SiWx917 to re-pair/bond with a rogue device

Spoofing an already bonded device can force either RS9116W or SiWx917 to re-pair/bond with a rogue device. See V1 in BLERP paper below

TwilightEPSS 0.21%via NVD
CWE-290 vulnerabilities (CVEs) — page 2 · VulnSea