VulnSea

CWE-306

CVEs classified under CWE-306, newest first.

631 CVEsRSS

CVE-2026-76640High· 7.5
1mo ago

Unitree G1 EDU firmware through 1.5.2 contains multiple chained vulnerabilities in the BLE GATT server and WiFi provisioning stack that allow unauthenticated proximate attackers to achieve root code execution without pairing or credentia…

Unitree G1 EDU firmware through 1.5.2 contains multiple chained vulnerabilities in the BLE GATT server and WiFi provisioning stack that allow unauthenticated proximate attackers to achieve root code execution without pairing or credentia…

▾ TwilightEPSS 0.34%via NVD
CVE-2026-76639High· 8.8PoC
1mo ago

Unitree G1 EDU firmware through 1.5.2 contains an unauthenticated remote code execution vulnerability that allows network-adjacent attackers to execute arbitrary commands as root by chaining three weaknesses: an unauthenticated WebRTC-to…

Unitree G1 EDU firmware through 1.5.2 contains an unauthenticated remote code execution vulnerability that allows network-adjacent attackers to execute arbitrary commands as root by chaining three weaknesses: an unauthenticated WebRTC-to…

▾ MidnightEPSS 0.67%via NVD
CVE-2026-81032Critical· 9.8
1mo ago

NebulaGraph exposes its runtime configuration over an unauthenticated HTTP service

NebulaGraph exposes its runtime configuration over an unauthenticated HTTP service. Each daemon starts the web service defined in src/webservice/WebService.cpp, whose bind address defaults to all interfaces, and registers routes for read…

▾ MidnightEPSS 0.36%via NVD
CVE-2026-65956None
1mo ago

KubePi is a Kubernetes multi-cluster management panel

KubePi is a Kubernetes multi-cluster management panel. In versions up to and including 1.6.15, the SSO configuration API endpoints are exposed on the same public routing boundary as the SSO login and callback endpoints, so SSO, OIDC, and…

▾ SunlitEPSS 0.64%via NVD
CVE-2026-75601Medium· 4.3
1mo ago

Static Web Server (SWS) is a production-ready web server suitable for static web files or assets

Static Web Server (SWS) is a production-ready web server suitable for static web files or assets. Through 2.43.0, instances with both basic-auth and metrics features enabled process the /metrics endpoint before the basic-auth check in sr…

▾ SunlitEPSS 0.39%via NVD
CVE-2026-57910Critical· 9.3
1mo ago

Improper authentication in the WatchGuard Agent allows an unauthenticated attacker with network access to cause the agent to execute arbitrary code with elevated privileges.

Improper authentication in the WatchGuard Agent allows an unauthenticated attacker with network access to cause the agent to execute arbitrary code with elevated privileges.

▾ MidnightWatchGuard · WatchGuard AgentEPSS 0.24%via NVD
CVE-2026-55605Medium· 5.3
1mo ago

@arikusi/deepseek-mcp-server: Missing Authentication on Self-Hosted HTTP MCP Endpoint

@arikusi/deepseek-mcp-server: Missing Authentication on Self-Hosted HTTP MCP Endpoint

▾ Sunlitarikusi · @arikusi/deepseek-mcp-serverEPSS 0.60%via GHSA
CVE-2026-55640Critical· 9.1
1mo ago

nextcloud-mcp-server: Unauthenticated `POST /webhooks/nextcloud` allows arbitrary vector data deletion when `WEBHOOK_SECRET` is unset ( d…

nextcloud-mcp-server: Unauthenticated `POST /webhooks/nextcloud` allows arbitrary vector data deletion when `WEBHOOK_SECRET` is unset ( default )

▾ Midnightnextcloud-mcp-server · nextcloud-mcp-serverEPSS 0.73%via OSV
CVE-2026-55571High· 8.2
1mo ago

djust authentication bypass: a login_required / on_mount LiveView mount redirect does not close the WebSocket, allowing an unauthenticate…

djust authentication bypass: a login_required / on_mount LiveView mount redirect does not close the WebSocket, allowing an unauthenticated client to dispatch event-handler calls

▾ Twilightdjust · djustEPSS 0.51%via OSV
CVE-2026-55529Medium· 6.9
1mo ago

PraisonAI has an origin validation bypass in MCP HTTP Stream transport that allows browser-mediated unauthenticated tool execution on loc…

PraisonAI has an origin validation bypass in MCP HTTP Stream transport that allows browser-mediated unauthenticated tool execution on local MCP server

▾ Sunlitpraisonai · praisonaiEPSS 0.18%via OSV
CVE-2026-55528High· 8.2
1mo ago

praisonaiagents: AgentServer declares auth_token but never enforces it on any route

praisonaiagents: AgentServer declares auth_token but never enforces it on any route

▾ Twilightpraisonaiagents · praisonaiagentsEPSS 0.49%via OSV
CVE-2026-55534High· 8.6
1mo ago

PraisonAI serve agents --api-key is ignored, allowing unauthenticated remote agent execution

PraisonAI serve agents --api-key is ignored, allowing unauthenticated remote agent execution

▾ Twilightpraisonai · praisonaiEPSS 0.45%via OSV
CVE-2026-55538High· 7.3
1mo ago

PraisonAI: [Auth Bypass] `praisonai serve agents --api-key` is silently ignored — agent-invocation routes (`POST /agents`, `POST /agents/…

PraisonAI: [Auth Bypass] `praisonai serve agents --api-key` is silently ignored — agent-invocation routes (`POST /agents`, `POST /agents/{agent_name}`) run unauthenticated

▾ Twilightpraisonai · praisonaiEPSS 0.45%via OSV
CVE-2026-55539High· 8.6
1mo ago

PraisonAI: [Auth Bypass] PraisonAI async Jobs API (`/api/v1/runs`) has no authentication — unauthenticated job execution, result theft, c…

PraisonAI: [Auth Bypass] PraisonAI async Jobs API (`/api/v1/runs`) has no authentication — unauthenticated job execution, result theft, cancel and delete

▾ Twilightpraisonai · praisonaiEPSS 0.57%via OSV
CVE-2026-55533High· 8.2
1mo ago

PraisonAI: Authentication fail-open in Recipe server allows unauthenticated access when API key or JWT auth is configured without a secret

PraisonAI: Authentication fail-open in Recipe server allows unauthenticated access when API key or JWT auth is configured without a secret

▾ Twilightpraisonai · praisonaiEPSS 0.49%via OSV
CVE-2026-77915Critical· 9.8
1mo ago

rConfig Core 8.0.0 before 8.2.10 contains an authentication bypass vulnerability that allows unauthenticated attackers to self-register accounts with full Administrator privileges due to a duplicate bare Auth::routes() call in routes/web…

rConfig Core 8.0.0 before 8.2.10 contains an authentication bypass vulnerability that allows unauthenticated attackers to self-register accounts with full Administrator privileges due to a duplicate bare Auth::routes() call in routes/web…

▾ MidnightEPSS 0.77%via NVD
CVE-2026-59808High· 8.8
1mo ago

AVideo through commit 9c39d8c8 contains an authentication bypass vulnerability where deduplicateByEncoderQueueId() returns video_id_hash credentials for any video by encoder_queue_id without ownership verification, and useVideoHashOrLogi…

AVideo through commit 9c39d8c8 contains an authentication bypass vulnerability where deduplicateByEncoderQueueId() returns video_id_hash credentials for any video by encoder_queue_id without ownership verification, and useVideoHashOrLogi…

▾ TwilightEPSS 0.59%via NVD
CVE-2026-48106High· 8.3
1mo ago

Arc is an open, SQL-native time-series database for telemetry

Arc is an open, SQL-native time-series database for telemetry. Prior to version 26.06.1, Arc Enterprise's cluster replication receiver at `internal/cluster/replication/receiver.go` validates only the wire-format envelope (length, opcode)…

▾ TwilightBasekick-Labs · arcEPSS 0.22%via NVD
CVE-2026-30866High· 7.5
1mo ago

Combodo iTop is a web based IT service management tool

Combodo iTop is a web based IT service management tool. Prior to 3.2.3, unauthenticated users can access uploaded sensitive via sniffed url. This issue has been fixed in version 3.2.3.

▾ TwilightCombodo · iTopEPSS 0.46%via NVD
CVE-2026-69228Medium· 5.3
1mo ago

There is a missing authentication vulnerability in Esri Portal for ArcGIS versions 12.0 and prior that may allow a remote, unauthenticated attacker to access a specific resource (not user content) that should only be accessible by authen…

There is a missing authentication vulnerability in Esri Portal for ArcGIS versions 12.0 and prior that may allow a remote, unauthenticated attacker to access a specific resource (not user content) that should only be accessible by authen…

▾ Sunlitesri · portal_for_arcgisEPSS 0.48%via NVD
CVE-2026-34949Medium· 6.5
1mo ago

Combodo iTop is a web based IT service management tool.Prior to 3.2.3, an unauthenticated user could delete the .readonly file on iTop instances — a file created during the setup process that prevents users from performing write actions.…

Combodo iTop is a web based IT service management tool.Prior to 3.2.3, an unauthenticated user could delete the .readonly file on iTop instances — a file created during the setup process that prevents users from performing write actions.…

▾ SunlitEPSS 0.37%via NVD
CVE-2026-34741High· 8.6
1mo ago

Combodo iTop is a web based IT service management tool

Combodo iTop is a web based IT service management tool. Prior to 3.2.3, authentication bypass allows unauthenticated remote attackers to execute arbitrary PHP files from the env-production directory on a new iTop instance in the producti…

▾ TwilightEPSS 0.64%via NVD
CVE-2026-75501High· 7.5
1mo ago

Rejected reason: Vendor could not replicate the vul, and reporter is unavailable to comment.

Rejected reason: Vendor could not replicate the vul, and reporter is unavailable to comment.

▾ TwilightEPSS 0.59%via NVD
CVE-2026-48050High· 8.2
1mo ago

Arc is an open, SQL-native time-series database for telemetry

Arc is an open, SQL-native time-series database for telemetry. Versions prior to 26.06.1 register Go's `net/http/pprof` handlers at `/debug/pprof/*` via `app.Use(pprof.New())` in `internal/api/server.go`, and `/debug/pprof` is added to `…

▾ TwilightRed Hat · Red Hat Edge Manager 1EPSS 0.64%via NVD
CVE-2026-49217High· 7.5
1mo ago

Mailu is a mail server as a set of Docker images

Mailu is a mail server as a set of Docker images. Prior to version 2024.06.52, a missing authorization check in the Mailu admin REST API allows any unauthenticated attacker to remove any potential IP restriction or update the comment fie…

▾ TwilightEPSS 0.36%via NVD
CVE-2026-55642Critical· 9.8
1mo ago

dbx is a cross-platform database client for databases

dbx is a cross-platform database client for databases. Prior to 0.5.51, dbx-web auth_middleware in crates/dbx-web/src/auth.rs passes every protected request to the handler chain when password_hash is None. A fresh deployment reaches that…

▾ MidnightEPSS 0.69%via NVD
CVE-2026-77644None
1mo ago

A critical bypass access control vulnerability has been reported in PTC Windchill Risk and Reliability (WRR) Enterprise Edition.

A critical bypass access control vulnerability has been reported in PTC Windchill Risk and Reliability (WRR) Enterprise Edition.

▾ SunlitEPSS 0.43%via NVD
CVE-2025-52182High· 7.5
1mo ago

The Library Corporation LS2 Admin v5.7 to v5.8.0 was discovered to contain an information disclosure vulnerability.

The Library Corporation LS2 Admin v5.7 to v5.8.0 was discovered to contain an information disclosure vulnerability.

▾ TwilightEPSS 0.35%via NVD
CVE-2026-9033Medium· 4.3
1mo ago

An unauthenticated attacker with network access to the captive portal service of an affected device can terminate active captive portal sessions, including forcing logout of specific users or clearing all active sessions

An unauthenticated attacker with network access to the captive portal service of an affected device can terminate active captive portal sessions, including forcing logout of specific users or clearing all active sessions. Affected users …

▾ Sunlittp-link · er7212pc_firmwareEPSS 0.28%via NVD
CVE-2026-54061Critical· 9.1
1mo ago

Dgraph Alpha group stores can be replaced via unauthenticated external snapshot import

Dgraph Alpha group stores can be replaced via unauthenticated external snapshot import

▾ Midnightdgraph-io · github.com/dgraph-io/dgraph/v25EPSS 0.58%via GHSA
CWE-306 vulnerabilities (CVEs) — page 11 · VulnSea