VulnSea

CWE-306

CVEs classified under CWE-306, newest first.

631 CVEsRSS

CVE-2026-53977High· 7.5
1mo ago

OpenChamber 1.11.7 contains an authentication bypass vulnerability that allows unauthenticated remote attackers to terminate the server process by sending a POST request to the /api/system/shutdown endpoint, which is registered before th…

OpenChamber 1.11.7 contains an authentication bypass vulnerability that allows unauthenticated remote attackers to terminate the server process by sending a POST request to the /api/system/shutdown endpoint, which is registered before th…

▾ TwilightEPSS 0.97%via NVD
CVE-2026-63508Critical· 10.0
1mo ago

Microsoft Planetary Computer Pro Elevation of Privilege Vulnerability

Missing authentication for critical function in Microsoft Planetary Computer Pro allows an unauthorized attacker to elevate privileges over a network.

▾ MidnightMicrosoft · Microsoft Planetary Computer Pro (GeoCatalog)EPSS 0.80%via CVEORG
CVE-2026-69111High· 7.5
1mo ago

Milvus through 2.6.22 and 3.0.0 contains an unauthenticated denial of service vulnerability that allows remote attackers to terminate service components by sending a crafted HTTP GET request to the management server on port 9091

Milvus through 2.6.22 and 3.0.0 contains an unauthenticated denial of service vulnerability that allows remote attackers to terminate service components by sending a crafted HTTP GET request to the management server on port 9091. Attacke…

▾ TwilightEPSS 1.1%via NVD
CVE-2026-71214Critical· 9.8
1mo ago

The Aerie/PlanDev sequencing-server's authorization middleware (sequencing-server/src/app.ts) derives the caller's Hasura session role via getHasuraSession, which prefers a session_variables object taken directly from the client-supplied…

The Aerie/PlanDev sequencing-server's authorization middleware (sequencing-server/src/app.ts) derives the caller's Hasura session role via getHasuraSession, which prefers a session_variables object taken directly from the client-supplied…

▾ MidnightEPSS 0.48%via NVD
CVE-2026-71203Medium· 5.3PoC
1mo ago

changedetection.io's REST API resources are protected by an @auth.check_token decorator validating the caller's x-api-key header, except the Spec resource registered at /api/v1/full-spec (changedetectionio/api/Spec.py), whose get method …

changedetection.io's REST API resources are protected by an @auth.check_token decorator validating the caller's x-api-key header, except the Spec resource registered at /api/v1/full-spec (changedetectionio/api/Spec.py), whose get method …

▾ TwilightEPSS 0.31%via NVD
CVE-2026-71319Critical· 9.6
1mo ago

Nuxt is an open-source web development framework for Vue.js

Nuxt is an open-source web development framework for Vue.js. Prior to 3.3.1, Nuxt DevTools (development mode only) exposes a bidirectional RPC channel over the Vite HMR WebSocket via the nuxt:devtools:rpc plugin. On affected versions the…

▾ Midnightnuxt · @nuxt/devtoolsEPSS 0.63%via NVD
CVE-2026-70552Critical· 9.8
1mo ago

MaxSite CMS 109.5 Unauthenticated AJAX Dispatcher Bypass via ajax.php

MaxSite CMS 109.5 and earlier contains an authentication bypass vulnerability in the AJAX dispatcher that allows unauthenticated attackers to access admin-gated endpoints by supplying any X-Requested-With header and requesting a base64-e…

▾ MidnightMaxSite · MaxSite CMSEPSS 0.83%via CVEORG
CVE-2026-69703Critical· 9.8PoC
1mo ago

Atlas-Livre contains an improper access control vulnerability in the admin controllers under Espace_admin/controleur/ that allows unauthenticated attackers to bypass session-based authentication guards by sending raw HTTP requests that i…

Atlas-Livre contains an improper access control vulnerability in the admin controllers under Espace_admin/controleur/ that allows unauthenticated attackers to bypass session-based authentication guards by sending raw HTTP requests that i…

▾ AbyssalmaximeAmini · Atals-LivreEPSS 0.58%via NVD
CVE-2026-61514Critical· 9.8
1mo ago

Puwell IP Camera firmware versions 2.x through 4.x contains an authentication bypass vulnerability that allows unauthenticated attackers to access device functions by sending protocol-conforming packets over TCP port 23456 without creden…

Puwell IP Camera firmware versions 2.x through 4.x contains an authentication bypass vulnerability that allows unauthenticated attackers to access device functions by sending protocol-conforming packets over TCP port 23456 without creden…

▾ MidnightEPSS 0.83%via NVD
CVE-2026-67610High· 8.1
1mo ago

OpenEMR through 8.2.0 contains an improper authentication vulnerability in the OAuth2 dynamic client registration endpoint that allows unauthenticated attackers to register a malicious client with system-level FHIR scopes by supplying a …

OpenEMR through 8.2.0 contains an improper authentication vulnerability in the OAuth2 dynamic client registration endpoint that allows unauthenticated attackers to register a malicious client with system-level FHIR scopes by supplying a …

▾ TwilightEPSS 0.48%via NVD
CVE-2026-41452Critical· 9.8PoC
1mo ago

Krayin CRM 2.2.4 contains a missing authentication vulnerability in the installer middleware that allows unauthenticated remote attackers to overwrite the primary administrator account by sending a crafted HTTP POST request with the X-Re…

Krayin CRM 2.2.4 contains a missing authentication vulnerability in the installer middleware that allows unauthenticated remote attackers to overwrite the primary administrator account by sending a crafted HTTP POST request with the X-Re…

▾ AbyssalEPSS 3.7%via NVD
CVE-2026-69091High· 7.5
1mo ago

Admidio before 5.0.11 contains an authentication bypass vulnerability in the forum module when configured in login-only mode

Admidio before 5.0.11 contains an authentication bypass vulnerability in the forum module when configured in login-only mode. The access control logic in modules/forum.php fails to validate the login-only configuration state, allowing un…

▾ TwilightEPSS 0.61%via NVD
CVE-2026-68578High· 7.5
1mo ago

ArcadeDB versions before 26.7.3 fail to bind the authenticated principal in the MCP HTTP transport, causing all engine permission checks to silently pass as no-ops

ArcadeDB versions before 26.7.3 fail to bind the authenticated principal in the MCP HTTP transport, causing all engine permission checks to silently pass as no-ops. Non-root MCP-allowed users can perform arbitrary database writes, DDL, s…

▾ TwilightEPSS 0.36%via NVD
CVE-2026-65310High· 7.5
1mo ago

ANDRITZ HIPASE-250 (formerly 250 SCALA), in the default configuration of affected versions, exposes its data and configuration endpoint without any authentication and permissive CORS on every response

ANDRITZ HIPASE-250 (formerly 250 SCALA), in the default configuration of affected versions, exposes its data and configuration endpoint without any authentication and permissive CORS on every response. An unauthenticated attacker with ne…

▾ TwilightEPSS 0.50%via NVD
GHSA-p7w7-4929-vpj5High· 7.5
1mo ago

`@dynatrace-oss/dynatrace-mcp-server` has Unauthenticated HTTP MCP Tool Invocation

`@dynatrace-oss/dynatrace-mcp-server` has Unauthenticated HTTP MCP Tool Invocation

▾ Twilightdynatrace-oss · @dynatrace-oss/dynatrace-mcp-servervia GHSA
CVE-2026-68502Critical· 9.8
1mo ago

LazyOwn RedTeam/APT Framework is an AI-powered C2 and red-team operations framework

LazyOwn RedTeam/APT Framework is an AI-powered C2 and red-team operations framework. Prior to 0.2.154, LazyOwn's lazyc2.py registers an unauthenticated Socket.IO input event handler that dispatches data.get('value') to LazyOwnShell.one_c…

▾ MidnightEPSS 0.97%via NVD
CVE-2026-12562High· 8.8
1mo ago

The RCU II+ and Multiload II+ are vulnerable to an unauthenticated service that exposes a debug interface granting full root-level access to the embedded system

The RCU II+ and Multiload II+ are vulnerable to an unauthenticated service that exposes a debug interface granting full root-level access to the embedded system. This vulnerability stems from a network-accessible port running a Target…

▾ TwilightEPSS 0.46%via NVD
CVE-2026-67349High· 7.5
1mo ago

OpenCost before 1.121.0 fails to authenticate the GET /helmValues endpoint, exposing base64-decoded HELM_VALUES environment variable containing cloud provider credentials

OpenCost before 1.121.0 fails to authenticate the GET /helmValues endpoint, exposing base64-decoded HELM_VALUES environment variable containing cloud provider credentials. Additionally, adminAuthMiddleware fails open when ADMIN_TOKEN is …

▾ TwilightEPSS 0.50%via NVD
CVE-2026-54365High· 7.5
1mo ago

CentreStack before 17.3 contains an unauthenticated deserialization vulnerability in GSNamespace.dll that allows unauthenticated attackers to create arbitrary local OS user accounts by supplying a crafted base64-encoded XML string to exp…

CentreStack before 17.3 contains an unauthenticated deserialization vulnerability in GSNamespace.dll that allows unauthenticated attackers to create arbitrary local OS user accounts by supplying a crafted base64-encoded XML string to exp…

▾ TwilightEPSS 0.37%via NVD
CVE-2026-44101Critical· 9.8
1mo ago

Due to missing authentication the CHARX OCPP Agent service allows an unauthenticated remote attacker to reconfigure the backend connection

Due to missing authentication the CHARX OCPP Agent service allows an unauthenticated remote attacker to reconfigure the backend connection. This can lead to Denial-of-Service and confidential data being disclosed to the attacker.

▾ MidnightEPSS 0.75%via NVD
CVE-2026-47858High· 8.0PoC
1mo ago

Starting Spring Boot applications in the Spring Tools with the live information mode enabled makes the running application vulnerable against JMX-based remote code execution. Affected Spring Products and Versions: Spring Tools for Eclips…

Starting Spring Boot applications in the Spring Tools with the live information mode enabled makes the running application vulnerable against JMX-based remote code execution. Affected Spring Products and Versions: Spring Tools for Eclips…

▾ Midnightbroadcom · spring_toolsEPSS 0.33%via NVD
CVE-2026-67426Critical· 9.3
1mo ago

Flyto2 Core: Unauthenticated flyto-verification /run: callback_url SSRF and internal runner-secret exfiltration

Flyto2 Core: Unauthenticated flyto-verification /run: callback_url SSRF and internal runner-secret exfiltration

▾ Midnightflyto-core · flyto-coreEPSS 0.51%via GHSA
CVE-2026-62325Critical· 9.1
2mo ago

goshs SFTP authentication bypass via empty password (incomplete fix of CVE-2026-40884)

goshs SFTP authentication bypass via empty password (incomplete fix of CVE-2026-40884)

▾ Midnightpatrickhener · github.com/patrickhener/goshs/v2EPSS 0.59%via GHSA
CVE-2026-56163Critical· 10.0
2mo ago

Microsoft Azure Kubernetes Service Elevation of Privilege Vulnerability

Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network.

▾ MidnightMicrosoft · Azure Kubernetes ServiceEPSS 0.90%via CVEORG
CVE-2026-61884Critical· 9.8
2mo ago

The Tycon Systems TPDIN-Monitor-WEB2 ships without HTTP credentials configured, intended for an installer to set them on first use

The Tycon Systems TPDIN-Monitor-WEB2 ships without HTTP credentials configured, intended for an installer to set them on first use. On firmware 2.4.4 and earlier, a unit left in this unconfigured state serves the web management interface…

▾ MidnightEPSS 0.56%via NVD
CVE-2026-59715Low· 3.1
2mo ago

Open WebUI: Unauthenticated WebSocket Access to Collaborative Document Handlers (ydoc:awareness:update, ydoc:document:leave)

Open WebUI: Unauthenticated WebSocket Access to Collaborative Document Handlers (ydoc:awareness:update, ydoc:document:leave)

▾ Sunlitopen-webui · open-webuiEPSS 0.36%via GHSA
CVE-2026-63765High· 8.2PoC
2mo ago

Chatwoot before 4.16.0 contains an authentication bypass vulnerability in the direct uploads controller that allows unauthenticated attackers to create arbitrary ActiveStorage blobs in any tenant account

Chatwoot before 4.16.0 contains an authentication bypass vulnerability in the direct uploads controller that allows unauthenticated attackers to create arbitrary ActiveStorage blobs in any tenant account. Attackers can exploit missing au…

▾ Midnightchatwoot · chatwootEPSS 0.70%via NVD
GHSA-h9fm-xcv2-qfw3Medium
2mo ago

Duplicate Advisory: Unauthenticated Endpoint Allows Cancellation of Any User's Active Test Webhook

Duplicate Advisory: Unauthenticated Endpoint Allows Cancellation of Any User's Active Test Webhook

▾ Sunlitn8n · n8nvia GHSA
CVE-2026-65014Medium
2mo ago

n8n: Unauthenticated Endpoint Allows Cancellation of Any User's Active Test Webhook

n8n: Unauthenticated Endpoint Allows Cancellation of Any User's Active Test Webhook

▾ Sunlitn8n · n8nEPSS 0.59%via GHSA
CVE-2026-65319High· 7.5PoC
2mo ago

Feedbin Unauthenticated Entry Content Disclosure via GET /api/v2/entries/:id/text

Feedbin (commit 739884a) contains an unauthenticated information disclosure vulnerability that allows unauthenticated attackers to retrieve private article content by sending requests to the entries text API endpoint, which skips the aut…

▾ MidnightFeedbin · FeedbinEPSS 0.51%via CVEORG
CWE-306 vulnerabilities (CVEs) — page 14 · VulnSea