VulnSea

CWE-306

CVEs classified under CWE-306, newest first.

632 CVEsRSS

CVE-2026-0283High· 7.2
2mo ago

An authentication bypass vulnerability in Large Scale VPN ( LSVPN) functionality of Palo Alto Networks PAN-OS software allows an attacker with network access to bypass security restrictions and establish an unauthorized site-to-site VPN …

An authentication bypass vulnerability in Large Scale VPN ( LSVPN) functionality of Palo Alto Networks PAN-OS software allows an attacker with network access to bypass security restrictions and establish an unauthorized site-to-site VPN …

▾ Twilightpaloaltonetworks · pan-osEPSS 0.38%via NVD
CVE-2026-59822High· 8.2CISA KEVPoC
2mo ago

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.84.0, LiteLLM's MCP Streamable HTTP endpoint allowed an unauthenticated attacker to use a fabricated Authorization header to trigger an OAut…

▾ Abyssallitellm · litellmEPSS 0.84%via NVD
CVE-2026-49471High· 8.3
2mo ago

Serena: Unauthenticated Flask dashboard on fixed port enables DNS rebinding → memory poisoning → RCE

Serena: Unauthenticated Flask dashboard on fixed port enables DNS rebinding → memory poisoning → RCE

▾ Twilightserena-agent · serena-agentEPSS 0.37%via GHSA
CVE-2026-59706Critical· 9.3PoC
2mo ago

mem0 - Unauthenticated Config API Exposure and SSRF via ollama_base_url

mem0 contains unauthenticated config API endpoints that expose LLM API keys in plaintext and allow server-side request forgery via attacker-controlled ollama_base_url parameter. Unauthenticated attackers can retrieve stored secrets like …

▾ Abyssalmem0 · mem0EPSS 0.44%via CVEORG
CVE-2026-59705Critical· 9.8PoC
2mo ago

mem0 - OpenMemory API Unauthenticated Access via Memory Endpoints

mem0's openmemory/api component contains an unauthenticated access vulnerability that allows unauthenticated attackers to read, write, and delete arbitrary user memories by accessing API routers registered without authentication middlewa…

▾ Abyssalmem0 · mem0EPSS 0.80%via CVEORG
GHSA-q855-8rh5-jfgqMedium· 6.5
2mo ago

ha-mcp: Add-on settings and policy routes are reachable without authentication at the bare root path

ha-mcp: Add-on settings and policy routes are reachable without authentication at the bare root path

▾ Sunlitha-mcp · ha-mcpvia GHSA
CVE-2026-53512Critical· 9.1
2mo ago

Better Auth: OAuth refresh-token replay via missing client authentication on oidc-provider and mcp plugins

Better Auth: OAuth refresh-token replay via missing client authentication on oidc-provider and mcp plugins

▾ Midnightbetter-auth · better-authEPSS 0.27%via GHSA
GHSA-vjc7-jrh9-9j86Critical· 10.0
2mo ago

9router has unauthenticated CRUD on /api/providers and Full API Key Leak via /api/usage/stats

9router has unauthenticated CRUD on /api/providers and Full API Key Leak via /api/usage/stats

▾ Midnight9router · 9routervia GHSA
CVE-2026-55786High· 8.4
2mo ago

flyto-core has Unauthenticated Command Execution via HTTP MCP `execute_module`

flyto-core has Unauthenticated Command Execution via HTTP MCP `execute_module`

▾ Twilightflyto-core · flyto-corevia GHSA
CVE-2026-14622High· 7.3
2mo ago

A vulnerability was found in jairiidriss restaurant-website-php-mysql up to 521428b5b612449df0cf4a5d15ee40cba67f3d35

A vulnerability was found in jairiidriss restaurant-website-php-mysql up to 521428b5b612449df0cf4a5d15ee40cba67f3d35. This vulnerability affects unknown code of the file /admin/ajax_files of the component AJAX Endpoint. Performing a mani…

▾ TwilightEPSS 0.69%via NVD
CVE-2026-10054High· 8.8
2mo ago

In affected versions of Eclipse Theia (1.8.1 and later), the browser backend exposes privileged terminal RPC over WebSocket (/services/shell-terminal, /services/terminals/:id) without service-level authentication. WebSocket origin va…

In affected versions of Eclipse Theia (1.8.1 and later), the browser backend exposes privileged terminal RPC over WebSocket (/services/shell-terminal, /services/terminals/:id) without service-level authentication. WebSocket origin va…

▾ TwilightEPSS 0.22%via NVD
CVE-2026-49257Critical· 10.0
3mo ago

mcp-pinot: Unauthenticated tool invocation via default oauth_enabled=False + host 0.0.0.0 bind

mcp-pinot: Unauthenticated tool invocation via default oauth_enabled=False + host 0.0.0.0 bind

▾ Midnightmcp-pinot-server · mcp-pinot-serverEPSS 0.93%via GHSA
CVE-2026-49357High
3mo ago

Streamable HTTP mode exposes LINE Desktop read/send tools without MCP authentication

Streamable HTTP mode exposes LINE Desktop read/send tools without MCP authentication

▾ Twilightline-desktop-mcp · line-desktop-mcpEPSS 0.56%via GHSA
CVE-2026-44025High· 7.5
3mo ago

Fluentd is Vulnerable to Exposure of Sensitive Information via Monitor Agent API

Fluentd is Vulnerable to Exposure of Sensitive Information via Monitor Agent API

▾ Twilightfluentd · fluentdEPSS 0.47%via GHSA
GHSA-qxvg-h7q2-hcxhCritical· 9.8
3mo ago

motionEye: LFI → pass‑the‑hash admin → unsafe restore → unauth action exec (RCE)

motionEye: LFI → pass‑the‑hash admin → unsafe restore → unauth action exec (RCE)

▾ Midnightmotioneye · motioneyevia GHSA
CVE-2026-6673Medium· 6.4
3mo ago

Mattermost doesn't authenticate Atlassian Connect installed callbacks, allowing a remote unauthenticated attacker to inject a rogue share…

Mattermost doesn't authenticate Atlassian Connect installed callbacks, allowing a remote unauthenticated attacker to inject a rogue sharedSecret

▾ Sunlitmattermost · github.com/mattermost/mattermost-serverEPSS 0.30%via OSV
GHSA-xj9w-cgqg-q897Medium· 6.5
3mo ago

Duplicate Advisory: AVideo has Unauthenticated PGP Message Decryption via Public Endpoint

Duplicate Advisory: AVideo has Unauthenticated PGP Message Decryption via Public Endpoint

▾ Sunlitwwbn · wwbn/avideovia GHSA
CVE-2026-48814Critical· 9.1
3mo ago

Network-AI: CVE-2026-46701 fix incomplete — empty default secret still authorizes all requests

Network-AI: CVE-2026-46701 fix incomplete — empty default secret still authorizes all requests

▾ Midnightnetwork-ai · network-aiEPSS 0.52%via GHSA
CVE-2026-55884Critical
3mo ago

Tilt: Missing authentication on the network-exposed Tilt HUD server

Tilt: Missing authentication on the network-exposed Tilt HUD server

▾ Midnighttilt-dev · github.com/tilt-dev/tiltEPSS 0.50%via GHSA
CVE-2026-54317High· 7.6
3mo ago

Home Assistant: Konnected alarm-panel switch state and zone topology disclosed to unauthenticated actors on the LAN

Home Assistant: Konnected alarm-panel switch state and zone topology disclosed to unauthenticated actors on the LAN

▾ Twilighthomeassistant · homeassistantEPSS 0.31%via GHSA
CVE-2026-54776Medium· 4.4
3mo ago

CoreWCF: Unix Domain Socket PosixIdentity transport accepts connections that skip the security upgrade

CoreWCF: Unix Domain Socket PosixIdentity transport accepts connections that skip the security upgrade

▾ SunlitCoreWCF · CoreWCF.UnixDomainSocketEPSS 0.15%via GHSA
CVE-2026-54130Critical· 9.8
3mo ago

M365 Copilot Information Disclosure Vulnerability

Missing authentication for critical function in M365 Copilot allows an unauthorized attacker to disclose information over a network.

▾ MidnightMicrosoft · Microsoft 365 CopilotEPSS 1.1%via CVEORG
GHSA-35w5-pcw4-jx94Medium· 4.3
3mo ago

PraisonAI: Unauthenticated Event Injection via SSE `/publish` Endpoint

PraisonAI: Unauthenticated Event Injection via SSE `/publish` Endpoint

▾ Sunlitpraisonaiagents · praisonaiagentsvia GHSA
GHSA-vmf9-xx9w-86wxHigh· 8.3
3mo ago

PraisonAI ToolsMCPServer legacy SSE transport accepts attacker Host/Origin and exposes registered tools

PraisonAI ToolsMCPServer legacy SSE transport accepts attacker Host/Origin and exposes registered tools

▾ Twilightpraisonaiagents · praisonaiagentsvia GHSA
GHSA-5qw8-f2g9-ff29High· 8.2
3mo ago

PraisonAI recipe serve Typer command bypasses the non-localhost authentication guard

PraisonAI recipe serve Typer command bypasses the non-localhost authentication guard

▾ Twilightpraisonai · praisonaivia GHSA
GHSA-fc26-m9pf-v56qHigh· 8.6
3mo ago

PraisonAI LinearBot processes unsigned webhooks when LINEAR_WEBHOOK_SECRET is missing

PraisonAI LinearBot processes unsigned webhooks when LINEAR_WEBHOOK_SECRET is missing

▾ Twilightpraisonai · praisonaivia GHSA
GHSA-x227-pf99-vffgCritical· 9.8
3mo ago

PraisonAI: MCP SSE transport binds 0.0.0.0 with no authentication and no Origin validation; bundled SecurityConfig is never wired in

PraisonAI: MCP SSE transport binds 0.0.0.0 with no authentication and no Origin validation; bundled SecurityConfig is never wired in

▾ Midnightpraisonaiagents · praisonaiagentsvia GHSA
GHSA-4869-x4pr-q22xCritical· 9.8
3mo ago

PraisonAI: Unauthenticated RCE via Jobs API + Approval Bypass

PraisonAI: Unauthenticated RCE via Jobs API + Approval Bypass

▾ Midnightpraisonai · praisonaivia GHSA
GHSA-j4hj-7hfh-g2f4Critical· 9.8
3mo ago

praisonai: recipe serve auth middleware silently disables itself when no secret is set

praisonai: recipe serve auth middleware silently disables itself when no secret is set

▾ Midnightpraisonai · praisonaivia GHSA
GHSA-fq2m-6wqh-x44gCritical· 9.8
3mo ago

PraisonAI: Jobs API exposes agent-execution endpoints with no authentication

PraisonAI: Jobs API exposes agent-execution endpoints with no authentication

▾ Midnightpraisonai · praisonaivia GHSA
CWE-306 vulnerabilities (CVEs) — page 17 · VulnSea