VulnSea

CWE-306

CVEs classified under CWE-306, newest first.

630 CVEsRSS

CVE-2026-85428Critical· 9.8
3w ago

MOOS core-moos through 10.4.0 contains an authentication bypass vulnerability in the optional MOOSDB HTTP server that allows unauthenticated clients to write variables

MOOS core-moos through 10.4.0 contains an authentication bypass vulnerability in the optional MOOSDB HTTP server that allows unauthenticated clients to write variables. Attackers can send HTTP requests with variable names and values to t…

▾ Midnightthemoos · core-moosEPSS 0.82%via NVD
CVE-2026-85424Critical· 9.8
3w ago

MOOS core-moos through 10.4.0 lacks authentication in the wire protocol, allowing unauthenticated clients to connect with full publish, subscribe, and database clear privileges

MOOS core-moos through 10.4.0 lacks authentication in the wire protocol, allowing unauthenticated clients to connect with full publish, subscribe, and database clear privileges. Attackers can bypass the compile-time protocol string check…

▾ MidnightEPSS 0.82%via NVD
CVE-2026-70352Critical· 10.0
3w ago

Missing authentication for critical function in Azure AI Language allows an unauthorized attacker to elevate privileges over a network.

Missing authentication for critical function in Azure AI Language allows an unauthorized attacker to elevate privileges over a network.

▾ MidnightMicrosoft · Azure AI Language AuthoringEPSS 0.92%via NVD
CVE-2026-84700High· 8.6
3w ago

PikiwiDB (Pika) v3.5.7 exposes an internal protobuf replication server on a port derived from the client port plus 2000 (e.g

PikiwiDB (Pika) v3.5.7 exposes an internal protobuf replication server on a port derived from the client port plus 2000 (e.g. 11221 when the default client port 9221 is used) that does not authenticate incoming requests. Although require…

▾ TwilightEPSS 0.58%via NVD
CVE-2026-84485High· 7.5
3w ago

APITable through 1.13.0-beta.1 exposes the internal organization loadOrSearch endpoint without authentication, allowing unauthenticated attackers to retrieve member names, email addresses, and team hierarchy

APITable through 1.13.0-beta.1 exposes the internal organization loadOrSearch endpoint without authentication, allowing unauthenticated attackers to retrieve member names, email addresses, and team hierarchy. Attackers can query the endp…

▾ Twilightapitable · apitableEPSS 0.61%via NVD
CVE-2026-84696High· 8.2
3w ago

Phison PS3111-S11 controller firmware versions through SBFQT1.3 expose privileged vendor unique commands over the ATA interface with absent or defeatable authentication mechanisms

Phison PS3111-S11 controller firmware versions through SBFQT1.3 expose privileged vendor unique commands over the ATA interface with absent or defeatable authentication mechanisms. Attackers can bypass the weak CRC-16 based unlock handsh…

▾ TwilightEPSS 0.22%via NVD
CVE-2026-84452High
3w ago

Windows ML CLI is a command line tool for building portable, performant, and high-quality AI models for Windows ML

Windows ML CLI is a command line tool for building portable, performant, and high-quality AI models for Windows ML. Prior to 0.4.0, the src/winml/modelkit/serve/cli_api.py component exposes WinML CLI commands through a localhost HTTP API…

▾ Twilightwinml-cli · winml-cliEPSS 1.6%via NVD
CVE-2024-35585High· 8.6
3w ago

Oxford Nanopore MinKNOW before 24.06 relies on a client's source IP address for authentication.

Oxford Nanopore MinKNOW before 24.06 relies on a client's source IP address for authentication.

▾ TwilightEPSS 0.28%via NVD
CVE-2026-53649Critical· 9.6
3w ago

Joro is a web exploitation framework

Joro is a web exploitation framework. Prior to version 1.1.1, Joro's default proxy mode exposes a local API on 127.0.0.1:9090 that performs no authentication and applies a wildcard CORS policy. Because plugin uploads use the CORS-safelis…

▾ MidnightBishopFox · github.com/BishopFox/joroEPSS 0.33%via NVD
CVE-2026-54598High· 7.5
3w ago

Wallos is an open-source, self-hostable personal subscription tracker

Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.9.4, endpoints/db/migrate.php executes database schema migrations when called over HTTP with zero authentication. Any unauthenticated attacker can …

▾ TwilightEPSS 0.46%via NVD
CVE-2026-75133High· 7.5
3w ago

Keep Backup Daily plugin for WordPress before 2.1.4 contains a sensitive information exposure vulnerability that allows unauthenticated attackers to trigger a full MySQL database dump by accessing the publicly exposed `kbd_cron_process` …

Keep Backup Daily plugin for WordPress before 2.1.4 contains a sensitive information exposure vulnerability that allows unauthenticated attackers to trigger a full MySQL database dump by accessing the publicly exposed `kbd_cron_process` …

▾ TwilightEPSS 0.52%via NVD
CVE-2026-66047High· 8.1
3w ago

ProfilePress (wp-user-avatar) WordPress plugin before 4.17.2 contains an unauthenticated remote code execution vulnerability that allows unauthenticated attackers to install and activate arbitrary plugins by brute-forcing a weak 32-bit c…

ProfilePress (wp-user-avatar) WordPress plugin before 4.17.2 contains an unauthenticated remote code execution vulnerability that allows unauthenticated attackers to install and activate arbitrary plugins by brute-forcing a weak 32-bit c…

▾ TwilightEPSS 0.92%via NVD
CVE-2026-82641High· 8.6
4w ago

Keploy versions 3.1.0 through 3.6.25, fixed in 3.6.26, bind the agent control-plane HTTP server to all interfaces without authentication, exposing endpoints that stream TLS session keys and traffic data

Keploy versions 3.1.0 through 3.6.25, fixed in 3.6.26, bind the agent control-plane HTTP server to all interfaces without authentication, exposing endpoints that stream TLS session keys and traffic data. Attackers can access the /agent/p…

▾ TwilightEPSS 0.60%via NVD
CVE-2026-82473High· 8.2
4w ago

KubeEdge CloudCore through 1.23.1 accepts node task status reports on its HTTPS server without authentication verification

KubeEdge CloudCore through 1.23.1 accepts node task status reports on its HTTPS server without authentication verification. Attackers can reach CloudCore on port 10002 to mark upgrade jobs as succeeded or failed, deceiving the control pl…

▾ TwilightEPSS 0.64%via NVD
CVE-2026-82472High· 7.5
4w ago

Documenso before 2.13.0 accepts PDF file uploads on the /api/files/upload-pdf endpoint without requiring authentication, session tokens, or API credentials

Documenso before 2.13.0 accepts PDF file uploads on the /api/files/upload-pdf endpoint without requiring authentication, session tokens, or API credentials. Unauthenticated attackers can upload arbitrary PDF files indefinitely to exhaust…

▾ Twilightdocumenso · documensoEPSS 0.76%via NVD
CVE-2026-82452Critical· 9.8
4w ago

rust-iot-platform through commit 5df942ab contains an authentication bypass vulnerability where most REST API routes lack authentication guards in their handler signatures

rust-iot-platform through commit 5df942ab contains an authentication bypass vulnerability where most REST API routes lack authentication guards in their handler signatures. Unauthenticated attackers can create, update, list, retrieve, an…

▾ Midnightiot-ecology · rust-iot-platformEPSS 0.83%via NVD
CVE-2026-82265Medium· 6.5PoC
1mo ago

Zipkin through 3.6.1 exposes Spring Boot Actuator endpoints on the tracing API port without authentication, allowing unauthenticated attackers to access sensitive information

Zipkin through 3.6.1 exposes Spring Boot Actuator endpoints on the tracing API port without authentication, allowing unauthenticated attackers to access sensitive information. Attackers can read environment variables, bean configurations…

▾ Twilightopenzipkin · zipkinEPSS 0.45%via NVD
CVE-2026-82266Critical· 9.8
1mo ago

Redpanda through 26.2.2 binds the Admin API to 0.0.0.0:9644 with admin_api_require_auth defaulting to false, treating unauthenticated requests as superusers

Redpanda through 26.2.2 binds the Admin API to 0.0.0.0:9644 with admin_api_require_auth defaulting to false, treating unauthenticated requests as superusers. Attackers can reach port 9644 without credentials to create and delete broker a…

▾ Midnightredpanda-data · redpandaEPSS 0.62%via NVD
CVE-2026-82277Critical· 9.8
1mo ago

Argo Rollouts dashboard through 1.10.0 binds to all interfaces and exposes mutating Rollout operations without authentication, authorization, or CSRF protection

Argo Rollouts dashboard through 1.10.0 binds to all interfaces and exposes mutating Rollout operations without authentication, authorization, or CSRF protection. Attackers on the same network can invoke PromoteRollout, AbortRollout, Rest…

▾ Midnightargoproj · argo-rolloutsEPSS 0.78%via NVD
CVE-2026-82282High· 8.0
1mo ago

Atlantis through 0.47.1 fails to authenticate the /github-app/setup endpoint, allowing unauthenticated attackers to access GitHub App credentials

Atlantis through 0.47.1 fails to authenticate the /github-app/setup endpoint, allowing unauthenticated attackers to access GitHub App credentials. Attackers can observe or intercept the GitHub redirect during setup to obtain the RSA priv…

▾ Twilightrunatlantis · atlantisEPSS 0.44%via NVD
CVE-2026-82276Medium· 5.3PoC
1mo ago

StarRocks through 4.0.13 contains an authentication bypass vulnerability in five REST handler classes that override execute() directly instead of implementing executeWithoutPassword()

StarRocks through 4.0.13 contains an authentication bypass vulnerability in five REST handler classes that override execute() directly instead of implementing executeWithoutPassword(). Attackers can access six unauthenticated endpoints o…

▾ TwilightStarRocks · starrocksEPSS 0.38%via NVD
CVE-2026-68929NonePoC
1mo ago

FastGPT is an open-source LLM platform for building AI applications on a knowledge base

FastGPT is an open-source LLM platform for building AI applications on a knowledge base. In versions prior to 4.15.2, the WeChat (iLink) share-channel endpoints authorize requests using only the public shareId, with no authenticated iden…

▾ TwilightEPSS 0.43%via NVD
CVE-2026-55678Medium
1mo ago

Arc is an open, SQL-native time-series database for telemetry

Arc is an open, SQL-native time-series database for telemetry. From 26.02.1 until 26.06.2, Arc Enterprise clustering accepts cluster join requests without authentication when cluster.enabled is true but cluster.shared_secret is not confi…

▾ Sunlitbasekick-labs · github.com/basekick-labs/arcEPSS 0.66%via NVD
CVE-2026-81664Medium· 5.3
1mo ago

The OpenFaaS gateway registers GET /system/telemetry in gateway/main.go and, when basic_auth is enabled, wraps each administrative /system/* handler in auth.DecorateWithBasicAuth

The OpenFaaS gateway registers GET /system/telemetry in gateway/main.go and, when basic_auth is enabled, wraps each administrative /system/* handler in auth.DecorateWithBasicAuth. TelemetryHandler was left out of that wrap block from 0.2…

▾ SunlitEPSS 0.37%via NVD
CVE-2026-81098Critical· 9.1
1mo ago

The Telnyx MCP server exposed its HTTP transport on every interface and did not require a caller credential

The Telnyx MCP server exposed its HTTP transport on every interface and did not require a caller credential. packages/mcp-server/src/http.ts served MCP on the root path with a listener bound to all interfaces and parsed the caller's auth…

▾ MidnightEPSS 0.73%via NVD
CVE-2026-81735Critical· 10.0
1mo ago

startServer.ts in the mcp-http-server package of UI-TARS-desktop defaulted its listen address to '::' when no host was given, so startSseAndStreamableHttpMcpServer bound the Streamable HTTP and SSE MCP transports to every interface, and …

startServer.ts in the mcp-http-server package of UI-TARS-desktop defaulted its listen address to '::' when no host was given, so startSseAndStreamableHttpMcpServer bound the Streamable HTTP and SSE MCP transports to every interface, and …

▾ Midnightbytedance · UI-TARS-desktopEPSS 0.78%via NVD
CVE-2026-81094Critical· 9.1
1mo ago

The mcp-router CLI served its MCP aggregator on every interface and enforced authentication only when the operator asked for it

The mcp-router CLI served its MCP aggregator on every interface and enforced authentication only when the operator asked for it. The serve command in apps/cli/src/commands/serve.ts defaulted its host to the all-interfaces address on a fi…

▾ MidnightEPSS 0.61%via NVD
CVE-2026-80208High· 8.2
1mo ago

APITable through 1.13.0-beta.1 annotates both getUserHistories and closePausedUserAccount in InternalUserController with requiredLogin = false

APITable through 1.13.0-beta.1 annotates both getUserHistories and closePausedUserAccount in InternalUserController with requiredLogin = false. ResourceInterceptor honours that annotation by returning before any session or API key is val…

▾ Twilightapitable · apitableEPSS 0.44%via NVD
CVE-2026-80207Medium· 5.3PoC
1mo ago

APITable through 1.13.0-beta.1 annotates the create handler of InternalNotifyController with requiredLogin = false

APITable through 1.13.0-beta.1 annotates the create handler of InternalNotifyController with requiredLogin = false. ResourceInterceptor honours that annotation by returning before any session or API key is validated, and the nginx gatewa…

▾ Twilightapitable · apitableEPSS 0.35%via NVD
CVE-2026-76640High· 7.5
1mo ago

Unitree G1 EDU firmware through 1.5.2 contains multiple chained vulnerabilities in the BLE GATT server and WiFi provisioning stack that allow unauthenticated proximate attackers to achieve root code execution without pairing or credentia…

Unitree G1 EDU firmware through 1.5.2 contains multiple chained vulnerabilities in the BLE GATT server and WiFi provisioning stack that allow unauthenticated proximate attackers to achieve root code execution without pairing or credentia…

▾ TwilightEPSS 0.34%via NVD
CWE-306 vulnerabilities (CVEs) — page 10 · VulnSea