VulnSea

CWE-304

CVEs classified under CWE-304, newest first.

5 CVEsRSS

CVE-2026-54723Medium· 6.5
1w ago

devpi is a Python package index staging server and packaging, testing, and release tool

devpi is a Python package index staging server and packaging, testing, and release tool. Prior to 6.20.2 and 7.0.0b3, a server configured with the primary or deprecated master role allows an unauthenticated, modified GET request to the +…

Sunlitdevpi · devpiEPSS 0.32%via NVD
CVE-2023-54391Critical· 9.8PoC
3w ago

Proxmox Virtual Environment (VE) 7.0 through 8.0 contains an authentication bypass vulnerability in libpve-access-control before 8.0.4 that allows unauthenticated attackers to authenticate as any existing enabled user without a configure…

Proxmox Virtual Environment (VE) 7.0 through 8.0 contains an authentication bypass vulnerability in libpve-access-control before 8.0.4 that allows unauthenticated attackers to authenticate as any existing enabled user without a configure…

AbyssalEPSS 1.7%via NVD
CVE-2026-49467High· 8.8
1mo ago

Pingvin Share X is a secure and easy self-hosted file sharing platform

Pingvin Share X is a secure and easy self-hosted file sharing platform. A vulnerability in versions 1.5.0 through 1.18.0 allow an attacker to bypass password verification when managing Time-based One-Time Password (TOTP) settings. The ro…

TwilightEPSS 0.41%via NVD
CVE-2026-67351High· 8.8
1mo ago

Serendipity before 2.6.1 contains an authentication context confusion vulnerability where password validation and session loading operate independently without ensuring both use the same user record

Serendipity before 2.6.1 contains an authentication context confusion vulnerability where password validation and session loading operate independently without ensuring both use the same user record. An authenticated Editor can create a …

TwilightEPSS 0.37%via NVD
CVE-2026-40542High· 7.3
5mo ago

Missing critical step in authentication in Apache HttpClient 5.6 allows an attacker to cause the client to accept SCRAM-SHA-256 authentication without proper mutual authentication verification

Missing critical step in authentication in Apache HttpClient 5.6 allows an attacker to cause the client to accept SCRAM-SHA-256 authentication without proper mutual authentication verification. Users are recommended to upgrade to version…

Twilightapache · httpclientEPSS 0.56%via NVD
CWE-304 vulnerabilities (CVEs) · VulnSea