VulnSea

CWE-306

CVEs classified under CWE-306, newest first.

526 CVEsRSS

CVE-2026-94151Medium· 5.3PoC
today

A weakness has been identified in Omega Solution HRM OS up to 20260717

A weakness has been identified in Omega Solution HRM OS up to 20260717. This affects an unknown function of the file /role-permission/permission of the component Role Permission API. Executing a manipulation of the argument roleId can le…

TwilightOmega Solution · HRM OSEPSS 0.39%via NVD
CVE-2026-92254Medium· 6.9
yesterday

Missing Authorization in the IOCTL handlers of the wsdkd.sys kernel drivers in Watchdog WatchDog Antivirus 1.8.640 (driver versions 1.3.0.0 and earlier) on Microsoft Windows allows local, low-privileged attackers to delete arbitrary file…

Missing Authorization in the IOCTL handlers of the wsdkd.sys kernel drivers in Watchdog WatchDog Antivirus 1.8.640 (driver versions 1.3.0.0 and earlier) on Microsoft Windows allows local, low-privileged attackers to delete arbitrary file…

SunlitWatchdog · Anti-VirusEPSS 0.10%via NVD
CVE-2026-93964Medium· 5.3
yesterday

A vulnerability was detected in NginxProxyManager nginx-proxy-manager up to 2.15.1

A vulnerability was detected in NginxProxyManager nginx-proxy-manager up to 2.15.1. This impacts the function internalCertificate.validate of the file backend/internal/certificate.js of the component Validate Route. The manipulation resu…

SunlitNginxProxyManager · nginx-proxy-managerEPSS 0.27%via NVD
CVE-2026-93960Medium· 4.3
yesterday

A vulnerability was identified in Pixelfed up to 0.12.11

A vulnerability was identified in Pixelfed up to 0.12.11. Impacted is the function instancePeers of the file app/Http/Controllers/Api/ApiV1Controller.php of the component OAuth Scope Handler. Such manipulation of the argument ID leads to…

SunlitEPSS 0.37%via NVD
CVE-2026-84078Critical· 9.9
3d ago

IBM Guardium Data Protection 12.2 is vulnerable to a missing authentication vulnerability in the LoadBalancerServlet

IBM Guardium Data Protection 12.2 is vulnerable to a missing authentication vulnerability in the LoadBalancerServlet. An unauthenticated user can access privileged load-balancer operations, potentially resulting in unauthorized actions a…

MidnightIBM · Guardium Data ProtectionEPSS 0.28%via NVD
CVE-2026-84075Critical· 9.9
3d ago

IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions due to missing authentication for the ChangeTrackerServlet.

IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions due to missing authentication for the ChangeTrackerServlet.

MidnightIBM · Guardium Data ProtectionEPSS 0.35%via NVD
CVE-2026-76902Medium· 5.0
3d ago

CordysCRM is an open source AI-powered customer relationship management system that supports private deployment

CordysCRM is an open source AI-powered customer relationship management system that supports private deployment. Prior to 1.7.4, ShiroFilter configures /attachment/preview/{id} and /pic/preview/{id} as anonymous, and both routes call Att…

Sunlit1Panel-dev · CordysCRMEPSS 0.22%via NVD
CVE-2026-63647Critical· 9.3PoC
3d ago

CordysCRM is an open source AI-powered customer relationship management system that supports private deployment

CordysCRM is an open source AI-powered customer relationship management system that supports private deployment. Prior to 1.7.2, SseController exposes the anonymous /sse/subscribe, /sse/broadcast, and /sse/close endpoints because ShiroFi…

Abyssal1Panel-dev · CordysCRMEPSS 0.47%via NVD
CVE-2026-11539Medium· 5.3
3d ago

IBM WebSphere Application Server 9.0 and 8.5 is affected by an authentication bypass vulnerability in the SOAP/JMX connector.

IBM WebSphere Application Server 9.0 and 8.5 is affected by an authentication bypass vulnerability in the SOAP/JMX connector.

SunlitIBM · WebSphere Application ServerEPSS 0.30%via NVD
CVE-2026-93839Critical· 9.8
3d ago

LightLLM through 1.2.0 contains an authentication bypass vulnerability in the /pd_register WebSocket endpoint that allows unauthenticated attackers to register arbitrary nodes by supplying crafted JSON without peer address validation

LightLLM through 1.2.0 contains an authentication bypass vulnerability in the /pd_register WebSocket endpoint that allows unauthenticated attackers to register arbitrary nodes by supplying crafted JSON without peer address validation. At…

MidnightModelTC · LightLLMEPSS 0.60%via NVD
CVE-2026-82967Critical· 9.8
3d ago

IBM Guardium Data Protection 12.2 is vulnerable to an authentication bypass that allows an unauthenticated remote attacker to bypass IP-based access controls and access the Guardium management interface.

IBM Guardium Data Protection 12.2 is vulnerable to an authentication bypass that allows an unauthenticated remote attacker to bypass IP-based access controls and access the Guardium management interface.

MidnightIBM · Guardium Data ProtectionEPSS 0.43%via NVD
CVE-2026-93559High· 7.3
3d ago

A vulnerability was identified in Forget-C Jellyfish AI Short Drama Studio 0.1.0-alpha/0.2.0/0.3.0/0.3.1/0.3.2

A vulnerability was identified in Forget-C Jellyfish AI Short Drama Studio 0.1.0-alpha/0.2.0/0.3.0/0.3.1/0.3.2. This affects an unknown function of the file backend/app/dependencies.py of the component FastAPI. The manipulation leads to …

TwilightForget-C · Jellyfish AI Short Drama StudioEPSS 0.38%via NVD
CVE-2026-85478Low· 3.5
3d ago

A CM2507 IP camera running firmware version HMT.CM2507 v251211.1507 exposes an interactive bootloader through a physical debug interface without requiring authentication

A CM2507 IP camera running firmware version HMT.CM2507 v251211.1507 exposes an interactive bootloader through a physical debug interface without requiring authentication. An attacker with physical access could interrupt the normal boot p…

SunlitCareCam · HMT.CM2507 FirmwareEPSS 0.16%via NVD
CVE-2026-77339Medium· 5.1PoC
3d ago

Process Compose is a scheduler and orchestrator for non-containerized applications

Process Compose is a scheduler and orchestrator for non-containerized applications. Prior to 1.120.0, the MCP SSE listener in src/mcp/server.go accepts browser-origin requests to /sse and the returned message endpoint without validating …

Twilightf1bonacc1 · github.com/f1bonacc1/process-composeEPSS 0.21%via NVD
CVE-2026-58197High· 8.8PoC
3d ago

ToolHive is a utility designed to simplify the deployment and management of Model Context Protocol servers

ToolHive is a utility designed to simplify the deployment and management of Model Context Protocol servers. Prior to ToolHive CLI 0.30.1 and ToolHive Studio 0.38.0, locally run MCP server containers use the default network permission pro…

Midnightstacklok · github.com/stacklok/toolhiveEPSS 0.36%via NVD
CVE-2026-88259High· 7.5
3d ago

CareCam CM2507 IP cameras do not require authentication for access to its network video streaming service

CareCam CM2507 IP cameras do not require authentication for access to its network video streaming service. An unauthenticated attacker with network access to the affected device could retrieve live camera video.

TwilightCareCam · HMT.CM2507 FirmwareEPSS 0.30%via NVD
CVE-2026-84400Low· 3.1
3d ago

CareCam CM2507 IP cameras contain an insufficiently protected network maintenance mechanism that can activate a remote debugging service

CareCam CM2507 IP cameras contain an insufficiently protected network maintenance mechanism that can activate a remote debugging service. An attacker on the same local network who satisfies certain device state conditions could make the …

SunlitCareCam · HMT.CM2507 FirmwareEPSS 0.14%via NVD
CVE-2026-79954High· 8.7
3d ago

NASA CryptoLib 1.5.0 contains an authentication downgrade vulnerability in the Telecommand (TC) receive path

NASA CryptoLib 1.5.0 contains an authentication downgrade vulnerability in the Telecommand (TC) receive path. The receiver selects the Security Association used for SDLS processing solely from the SPI field inside the incoming frame, but…

TwilightNASA · CryptoLibEPSS 0.32%via NVD
CVE-2026-85889Critical· 10.0
4d ago

Missing authentication for critical function in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a network.

Missing authentication for critical function in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a network.

MidnightMicrosoft · Azure AI FoundryEPSS 0.49%via NVD
CVE-2026-54767Critical· 9.1PoC
4d ago

WeGIA is a web manager for charitable institutions

WeGIA is a web manager for charitable institutions. Prior to 3.8.5, web/html/socio/sistema/controller/deletar_socios.php exposes an unauthenticated GET endpoint whose chave parameter is checked only against a hardcoded chave_correta valu…

AbyssalLabRedesCefetRJ · WeGIAEPSS 0.43%via NVD
CVE-2026-54670Critical· 9.1
4d ago

WeGIA is a web manager for charitable institutions

WeGIA is a web manager for charitable institutions. Prior to 3.8.5, the contribution request dispatcher in web/html/contribuicao/controller/control.php accepts attacker-controlled nomeClasse and metodo values without a complete controlle…

MidnightLabRedesCefetRJ · WeGIAEPSS 0.55%via NVD
CVE-2026-54460Critical· 9.8
4d ago

OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform

OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to 1.1.1, POST /api/auth/passkeys accepts a request-body userId and attacker-supplied passkey without an authenticated sess…

Midnightopen-reception · appointment-booking-softwareEPSS 0.60%via NVD
CVE-2026-54618Critical· 9.4
4d ago

Obsidian Web MCP is a secure remote MCP server for Obsidian vaults

Obsidian Web MCP is a secure remote MCP server for Obsidian vaults. Prior to 0.2.0, /oauth/authorize issues an authorization code without a login, consent, or session check, and /oauth/token can exchange that code for the static VAULT_MC…

Midnightjimprosser · obsidian-web-mcpEPSS 0.40%via NVD
CVE-2026-92972High· 8.6
4d ago

SGLang through 0.5.19 in prefill/decode disaggregation mode contains an unauthenticated PUT /route endpoint on the prefill bootstrap service that allows attackers to poison the KV transfer routing table

SGLang through 0.5.19 in prefill/decode disaggregation mode contains an unauthenticated PUT /route endpoint on the prefill bootstrap service that allows attackers to poison the KV transfer routing table. Attackers can supply arbitrary ra…

Twilightsgl-project · sglangEPSS 0.33%via NVD
CVE-2026-71568Medium· 5.3
4d ago

In BMCtest, Ironic is started without authentication and TLS for the duration of the test. Exploiting the problem requires winning the race with bmctest itself, which reduces the attack window and significantly increases its complexity.

In BMCtest, Ironic is started without authentication and TLS for the duration of the test. Exploiting the problem requires winning the race with bmctest itself, which reduces the attack window and significantly increases its complexity.

Sunlitopenshift-metal3 · bmctestEPSS 0.16%via NVD
CVE-2026-81475High· 8.1
4d ago

Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Missing Authentication for Critical Function vulnerability

Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading…

TwilightDell · OpenManage Server Administrator Managed Node (Patch) for WindowsEPSS 0.70%via NVD
CVE-2026-81441Medium· 4.0
4d ago

Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Missing Authentication for Critical Function vulnerability

Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability, leading …

SunlitDell · OpenManage Server Administrator Managed Node (Patch) for WindowsEPSS 0.17%via NVD
CVE-2026-50608Low· 1.2
4d ago

A vulnerability has been identified in the Acer System Monitoring component included with NitroSense and PredatorSense

A vulnerability has been identified in the Acer System Monitoring component included with NitroSense and PredatorSense. The WebSocket handshake process does not properly require authentication before allowing connections to the service. …

SunlitAcer · System MonitoringEPSS 0.14%via NVD
CVE-2026-86801High· 8.8
4d ago

The To Do List Member WordPress plugin from 1.4 through 1.6 ships a file upload endpoint that does not load WordPress and therefore applies no authentication, capability or nonce check of any kind, and validates only the name of an uploa…

The To Do List Member WordPress plugin from 1.4 through 1.6 ships a file upload endpoint that does not load WordPress and therefore applies no authentication, capability or nonce check of any kind, and validates only the name of an uploa…

TwilightEPSS 0.34%via NVD
CVE-2026-50604Medium· 4.9
4d ago

A vulnerability has been identified in the Acer Agent Service component included with NitroSense and PredatorSense

A vulnerability has been identified in the Acer Agent Service component included with NitroSense and PredatorSense. The socket handshake process does not properly require authentication before granting access to the service. Under certai…

SunlitAcer · Agent ServiceEPSS 0.14%via NVD
CWE-306 vulnerabilities (CVEs) · VulnSea