VulnSea

CWE-306

CVEs classified under CWE-306, newest first.

631 CVEsRSS

CVE-2026-73842Critical· 9.0
1mo ago

OpenChoreo is a complete, open-source developer platform for Kubernetes

OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.0.3, 1.1.3, and 1.2.0-rc.2, internal/cluster-gateway/server.go exposed /api/proxy/, /api/exec/, and /api/wirelogs/ on an internal listener without requir…

▾ Midnightopenchoreo · github.com/openchoreo/openchoreoEPSS 0.27%via NVD
CVE-2026-73843Critical· 9.6
1mo ago

OpenChoreo is a complete, open-source developer platform for Kubernetes

OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.0.2 and 1.1.2, internal/cluster-gateway/server.go served caller-facing management APIs on the externally reachable agent listener without authentication,…

▾ Midnightopenchoreo · github.com/openchoreo/openchoreoEPSS 0.48%via NVD
CVE-2026-73296Critical· 9.4PoC
1mo ago

Microsoft UFO open-source framework for intelligent automation across devices and platforms

Microsoft UFO open-source framework for intelligent automation across devices and platforms. Prior to 3.0.8, create_mobile_data_collection_server and create_mobile_action_server in ufo/client/mcp/http_servers/mobile_mcp_server.py exposed…

▾ AbyssalEPSS 3.7%via NVD
CVE-2026-65941High· 8.8
1mo ago

In WhatsUp Gold versions released before 2026.0.2, an unauthenticated remote attacker with network access to the affected service can execute arbitrary code in the context of the IIS application service account.

In WhatsUp Gold versions released before 2026.0.2, an unauthenticated remote attacker with network access to the affected service can execute arbitrary code in the context of the IIS application service account.

▾ TwilightEPSS 0.68%via NVD
CVE-2026-73501Critical· 9.1
1mo ago

kin-openapi is a Go project for handling OpenAPI files

kin-openapi is a Go project for handling OpenAPI files. Prior to 0.144.0, ValidationHandler.Load() in openapi3filter/validation_handler.go silently replaces a nil AuthenticationFunc with NoopAuthenticationFunc, which returns nil without …

▾ MidnightRed Hat · Red Hat Edge Manager 1EPSS 0.59%via NVD
CVE-2026-15563High· 7.4
1mo ago

A flaw was found in EAP's IIOP

A flaw was found in EAP's IIOP. The listener's NameService would accept bind operations without authentication, allowing an attacker to hijack JNDI lookups and binding them to a malicious ORB, achieving MITM or DoS on further invocations.

▾ TwilightRed Hat · org.jboss.eap/wildfly-iiop-openjdkEPSS 0.39%via NVD
CVE-2026-73246High· 7.5
1mo ago

Kestra is an open-source, event-driven orchestration platform

Kestra is an open-source, event-driven orchestration platform. Prior to 2.0.0-rc6, Kestra's worker/src/main/java/io/kestra/worker/endpoint/WorkerEndpoint.java serves GET /worker without authentication and serializes the complete live Tas…

▾ TwilightEPSS 0.60%via NVD
CVE-2026-73245Medium· 6.5
1mo ago

Kestra is an open-source, event-driven orchestration platform

Kestra is an open-source, event-driven orchestration platform. Prior to 2.0.0-rc6, Kestra's cli/src/main/resources/application.yml serves Micronaut management endpoints on port 8081 without authentication even when Basic Auth protects /a…

▾ Sunlitkestra · io.kestra:kestraEPSS 0.33%via NVD
CVE-2026-72748Critical· 9.1
1mo ago

AVideo contains an unauthenticated arbitrary file write vulnerability in the aVideoEncoderChunk.json.php endpoint that allows remote attackers to write up to 4 GB of arbitrary content to the server filesystem via HTTP PUT requests withou…

AVideo contains an unauthenticated arbitrary file write vulnerability in the aVideoEncoderChunk.json.php endpoint that allows remote attackers to write up to 4 GB of arbitrary content to the server filesystem via HTTP PUT requests withou…

▾ MidnightEPSS 1.2%via NVD
CVE-2026-62777High· 7.8
1mo ago

Windows License Manager Elevation of Privilege Vulnerability

Missing authentication for critical function in Windows License Manager allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 10 Version 1607EPSS 0.30%via CVEORG
CVE-2026-64921High· 8.8
1mo ago

Microsoft SharePoint Server Elevation of Privilege Vulnerability

Missing authentication for critical function in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.

▾ TwilightMicrosoft · Microsoft SharePoint Enterprise Server 2016EPSS 0.94%via CVEORG
CVE-2026-50516Critical· 9.4
1mo ago

Microsoft Azure Kubernetes Service Elevation of Privilege Vulnerability

Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network.

▾ MidnightMicrosoft · Azure Kubernetes ServiceEPSS 0.83%via CVEORG
CVE-2026-73222High· 8.8
1mo ago

Claude Code Templates is a CLI tool for configuring and monitoring Claude Code

Claude Code Templates is a CLI tool for configuring and monitoring Claude Code. Prior to 1.29.4, the Claude Code Studio server launched by the --studio option in cli-tool/src/sandbox-server.js binds to all interfaces on port 3444, permit…

▾ Twilightclaude-code-templates · claude-code-templatesEPSS 0.32%via NVD
CVE-2026-72920Critical· 9.8
1mo ago

SeaweedFS is a distributed storage system

SeaweedFS is a distributed storage system. Prior to 4.24, the filer registers the SeaweedIdentityAccessManagement gRPC service without mandatory authentication when jwt.filer_signing.key is unset, allowing any client that can reach the f…

▾ Midnightseaweedfs · github.com/seaweedfs/seaweedfsEPSS 0.78%via NVD
CVE-2026-61367High· 7.8
1mo ago

Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.

Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.

▾ Twilightmicrosoft · windows_10_1607EPSS 0.30%via NVD
CVE-2026-61365High· 7.8
1mo ago

Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.

Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.

▾ Twilightmicrosoft · windows_10_1607EPSS 0.30%via NVD
CVE-2026-61364High· 7.8
1mo ago

Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.

Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.

▾ Twilightmicrosoft · windows_10_1607EPSS 0.30%via NVD
CVE-2026-61356High· 7.8
1mo ago

Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.

Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.

▾ Twilightmicrosoft · windows_10_1809EPSS 0.30%via NVD
CVE-2026-42976High· 7.8
1mo ago

Missing authentication for critical function in Windows RPC API allows an authorized attacker to elevate privileges locally.

Missing authentication for critical function in Windows RPC API allows an authorized attacker to elevate privileges locally.

▾ Twilightmicrosoft · windows_10_1607EPSS 0.30%via NVD
CVE-2026-15581High· 8.0
1mo ago

A flaw was found in the TrustyAI Service (TAS) deployment

A flaw was found in the TrustyAI Service (TAS) deployment. This vulnerability allows any pod on the cluster network to bypass authentication and directly access the TAS backend API. An attacker can exploit this to read, tamper with, or d…

▾ TwilightRed Hat · rhoai/odh-trustyai-service-operator-rhel9EPSS 0.42%via NVD
CVE-2026-72871High· 7.5
1mo ago

Dokploy is a free, self-hostable Platform as a Service (PaaS)

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the unauthenticated /api/providers/github/setup route in apps/dokploy/pages/api/providers/github/setup.ts trusts gh_init organizationId and userId values fr…

▾ TwilightEPSS 0.49%via NVD
CVE-2026-72593Critical· 9.8
1mo ago

A missing authentication vulnerability in dulldusk/phpfm through 1.8.0 allows an unauthenticated remote attacker to access the full file manager functionality including reading, writing, deleting, and uploading files anywhere on the serv…

A missing authentication vulnerability in dulldusk/phpfm through 1.8.0 allows an unauthenticated remote attacker to access the full file manager functionality including reading, writing, deleting, and uploading files anywhere on the serv…

▾ MidnightEPSS 0.79%via NVD
CVE-2026-72586High· 7.5
1mo ago

A missing authentication vulnerability in frangoteam/FUXA through 1.3.3 allows an unauthenticated remote attacker to query all historical sensor data via the DAQ_QUERY Socket.IO event

A missing authentication vulnerability in frangoteam/FUXA through 1.3.3 allows an unauthenticated remote attacker to query all historical sensor data via the DAQ_QUERY Socket.IO event. When secureEnabled=true, all other sensitive Socket.…

▾ TwilightEPSS 0.63%via NVD
CVE-2026-72577Critical· 9.8
1mo ago

Multiple vulnerabilities in NASA fprime-gds through 3.4.3 allow an unauthenticated remote attacker to achieve arbitrary code execution on the ground station host and inject arbitrary commands to connected spacecraft

Multiple vulnerabilities in NASA fprime-gds through 3.4.3 allow an unauthenticated remote attacker to achieve arbitrary code execution on the ground station host and inject arbitrary commands to connected spacecraft. The Flask applicatio…

▾ MidnightEPSS 1.3%via NVD
CVE-2026-46409Critical· 9.6
1mo ago

OpenYak is a local-first agent runtime for reliable tool-using models, with a desktop workspace built on top

OpenYak is a local-first agent runtime for reliable tool-using models, with a desktop workspace built on top. Prior to version 1.1.3, the OpenYak desktop backend binds an HTTP API to `127.0.0.1:<random port>` (commonly 19141) without ser…

▾ MidnightEPSS 0.28%via NVD
CVE-2026-61808Critical· 9.8PoC
1mo ago

LightRAG provides simple and fast retrieval-augmented generation

LightRAG provides simple and fast retrieval-augmented generation. Through version 1.5.4, the LightRAG API server binds to all network interfaces with authentication disabled by default, allowing an unauthenticated network attacker to rea…

▾ AbyssalEPSS 2.5%via NVD
CVE-2025-71409High· 7.1
1mo ago

Lack of authentication for Very High Frequency Data Link messages allows rogue ground stations to inject CPDLC messages leading to unexpected or misleading clearances and potential pilot confusion

Lack of authentication for Very High Frequency Data Link messages allows rogue ground stations to inject CPDLC messages leading to unexpected or misleading clearances and potential pilot confusion. This type of attack can be carried out …

▾ TwilightEPSS 0.33%via NVD
CVE-2026-70559High· 7.5PoC
1mo ago

Dinky's SysConfigController.getAll() handler for GET /api/sysConfig/getAll carries a method-level @SaIgnore annotation that short-circuits the class-level @SaCheckLogin, so the Sa-Token interceptor lets the request through with no sessio…

Dinky's SysConfigController.getAll() handler for GET /api/sysConfig/getAll carries a method-level @SaIgnore annotation that short-circuits the class-level @SaCheckLogin, so the Sa-Token interceptor lets the request through with no sessio…

▾ MidnightEPSS 0.45%via NVD
CVE-2026-53984Critical· 9.1
1mo ago

Ground Station prior to 0.6.0 contains an unauthenticated database-destruction and arbitrary-data-injection vulnerability in the Socket.IO server's database_backup event handler that allows any unauthenticated network peer to wipe or rep…

Ground Station prior to 0.6.0 contains an unauthenticated database-destruction and arbitrary-data-injection vulnerability in the Socket.IO server's database_backup event handler that allows any unauthenticated network peer to wipe or rep…

▾ MidnightEPSS 0.73%via NVD
CVE-2026-53985High· 7.5
1mo ago

Ground Station prior to 0.6.0 contains an unauthenticated denial-of-service vulnerability in the Socket.IO server's service_control event handler that allows any unauthenticated network peer to forcibly terminate the ground-station proce…

Ground Station prior to 0.6.0 contains an unauthenticated denial-of-service vulnerability in the Socket.IO server's service_control event handler that allows any unauthenticated network peer to forcibly terminate the ground-station proce…

▾ TwilightEPSS 0.71%via NVD
CWE-306 vulnerabilities (CVEs) — page 13 · VulnSea