CWE-302
CVEs classified under CWE-302, newest first.
4 CVEsRSS
CVE-2026-61682Critical· 9.9kcp is a Kubernetes-like control plane for form-factors and use-cases beyond Kubernetes and container workloads
kcp is a Kubernetes-like control plane for form-factors and use-cases beyond Kubernetes and container workloads. Prior to 0.31.4 and 0.32.2, the kcp front-proxy does not remove inbound X-Remote-User, X-Remote-Group, or X-Remote-Extra-* i…
CVE-2026-77508Low· 3.5Weblate is a web based localization tool
Weblate is a web based localization tool. Prior to 2026.8, an authenticated user can change the account's primary email through PUT or PATCH requests to /api/users/{username}/ without verifying the new address, allowing a later team invi…
CVE-2026-47303High· 8.8ASP.NET Core Elevation of Privilege Vulnerability
Authentication bypass by assumed-immutable data in ASP.NET Core allows an authorized attacker to elevate privileges over a network.
CVE-2026-50528High· 8.2.NET Security Feature Bypass Vulnerability
Incorrect authorization in .NET allows an unauthorized attacker to bypass a security feature over a network.