VulnSea

CWE-306

CVEs classified under CWE-306, newest first.

632 CVEsRSS

GHSA-x8cv-xmq7-p8xpCritical· 9.8
3mo ago

PraisonAI AgentTeam.launch exposes unauthenticated remote agent listing and invocation endpoints

PraisonAI AgentTeam.launch exposes unauthenticated remote agent listing and invocation endpoints

▾ Midnightpraisonaiagents · praisonaiagentsvia GHSA
GHSA-892r-p3jq-jp24Critical· 9.8
3mo ago

PraisonAI: AgentOS remains unauthenticated after incomplete fix version and allows remote agent invocation

PraisonAI: AgentOS remains unauthenticated after incomplete fix version and allows remote agent invocation

▾ Midnightpraisonai · praisonaivia GHSA
GHSA-p75f-6fp4-p57wCritical· 9.8
3mo ago

PraisonAI: Missing Authentication for Critical Function and Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in praisonai

PraisonAI: Missing Authentication for Critical Function and Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in praisonai

▾ Midnightpraisonai · praisonaivia GHSA
GHSA-9752-mhqh-h34fCritical· 9.4
3mo ago

npm PraisonAI AgentOS exposes unauthenticated agent listing and invocation

npm PraisonAI AgentOS exposes unauthenticated agent listing and invocation

▾ Midnightpraisonai · praisonaivia GHSA
GHSA-j4f3-55x4-r6q2Critical· 9.8
3mo ago

npm PraisonAI MCPServer exposes unauthenticated HTTP tools/call

npm PraisonAI MCPServer exposes unauthenticated HTTP tools/call

▾ Midnightpraisonai · praisonaivia GHSA
GHSA-jxcw-qp4h-6jfqHigh· 7.5
3mo ago

PraisonAI A2U incomplete authentication fix leaves current serve command unauthenticated by default

PraisonAI A2U incomplete authentication fix leaves current serve command unauthenticated by default

▾ Twilightpraisonai · praisonaivia GHSA
GHSA-fq4x-789w-jg5hHigh
3mo ago

AgenticMail: Unauthenticated inbound mail triggers bypassPermissions resume of the operator's Claude Code session (bridge-wake)

AgenticMail: Unauthenticated inbound mail triggers bypassPermissions resume of the operator's Claude Code session (bridge-wake)

▾ Twilightagenticmail · @agenticmail/corevia GHSA
CVE-2026-2675Medium· 6.5
3mo ago

Missing Authentication for Critical Function vulnerability in RTI Connext Professional (Security Plugins) allows Fake the Source of Data

Missing Authentication for Critical Function vulnerability in RTI Connext Professional (Security Plugins) allows Fake the Source of Data. This issue affects Connext Professional: from 7.4.0 before 7.7.0, from 7.0.0 before 7.3.1.3, from 6…

▾ Sunlitrti · connext_professionalEPSS 0.37%via NVD
CVE-2026-30799High· 8.1⚖ disputed
3mo ago

Missing Authentication for Critical Function vulnerability in RTI Connext Professional (Security Plugins) allows Identity Spoofing

Missing Authentication for Critical Function vulnerability in RTI Connext Professional (Security Plugins) allows Identity Spoofing. This issue affects Connext Professional: from 7.4.0 before 7.7.0, from 7.0.0 before 7.3.1.6, from 6.1.0 b…

▾ Twilightrti · connext_professionalEPSS 0.47%via NVD
CVE-2026-55196Critical· 9.1
3mo ago

Hermes WebUI before 0.51.409 contains an authentication bypass vulnerability in passkey registration endpoints that allows unauthenticated remote attackers to register arbitrary passkeys

Hermes WebUI before 0.51.409 contains an authentication bypass vulnerability in passkey registration endpoints that allows unauthenticated remote attackers to register arbitrary passkeys. When HERMES_WEBUI_PASSKEY=1 is enabled with no ex…

▾ Midnighthermes-webui · hermes-webuiEPSS 0.82%via NVD
CVE-2026-55450Critical· 9.3PoC
3mo ago

Langflow: Unauthenticated file upload leads to DoS (space exhaustion) and information leak

Langflow: Unauthenticated file upload leads to DoS (space exhaustion) and information leak

▾ Abyssallangflow · langflowEPSS 1.2%via GHSA
CVE-2026-53869High· 7.5
3mo ago

Hermes Agent contains a DNS rebinding vulnerability in WebSocket endpoints that allows remote attackers to bypass Host and Origin validation

Hermes Agent contains a DNS rebinding vulnerability in WebSocket endpoints that allows remote attackers to bypass Host and Origin validation

▾ Twilighthermes-agent · hermes-agentEPSS 0.81%via GHSA
CVE-2026-56266Critical· 9.8
3mo ago

Crawl4AI: Multiple Docker API Vulnerabilities - File Write, SSRF, Auth Bypass, XSS, JS Execution

Crawl4AI: Multiple Docker API Vulnerabilities - File Write, SSRF, Auth Bypass, XSS, JS Execution

▾ Midnightcrawl4ai · crawl4aiEPSS 0.48%via GHSA
CVE-2026-54309High· 10.0
3mo ago

n8n: MCP Browser HTTP Transport Exposes Unauthenticated Browser-Control Sessions

n8n: MCP Browser HTTP Transport Exposes Unauthenticated Browser-Control Sessions

▾ Twilightn8n · n8nEPSS 0.55%via GHSA
CVE-2026-49980Critical· 9.8
3mo ago

Rclone: Unauthenticated command execution in `rclone rcd --rc-serve` via inline remote instantiation, bypassing CVE-2026-41179 fix

Rclone: Unauthenticated command execution in `rclone rcd --rc-serve` via inline remote instantiation, bypassing CVE-2026-41179 fix

▾ Midnightrclone · github.com/rclone/rcloneEPSS 0.78%via GHSA
CVE-2026-12183Critical· 9.8
3mo ago

Nefteprodukttekhnika BUK TS-G Gas Station Automation System 2.9.1 through 2.10.2 on Linux contains an Improper Authentication vulnerability (CWE-287) in the system configuration module.

Nefteprodukttekhnika BUK TS-G Gas Station Automation System 2.9.1 through 2.10.2 on Linux contains an Improper Authentication vulnerability (CWE-287) in the system configuration module.

▾ MidnightEPSS 0.44%via NVD
CVE-2026-53868High· 7.5
3mo ago

Capgo < 12.128.2 - Denial of Service via Unverified Email Account Registration and Deletion

Capgo before 12.128.2 contains a denial of service vulnerability allowing attackers to register accounts using arbitrary email addresses without verification, then initiate deletion to lock emails in pending deletion state. Attackers can…

▾ TwilightCapgo · CapgoEPSS 0.45%via CVEORG
CVE-2026-47281Critical· 9.6
3mo ago

Visual Studio Code Elevation of Privilege Vulnerability

Missing authorization in Visual Studio Code allows an unauthorized attacker to elevate privileges over a network.

▾ MidnightMicrosoft · Visual Studio CodeEPSS 0.76%via CVEORG
CVE-2026-50507Medium· 6.8PoC
3mo ago

Windows BitLocker Security Feature Bypass Vulnerability

Missing authentication for critical function in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.

▾ TwilightMicrosoft · Windows 10 Version 1607EPSS 0.40%via CVEORG
CVE-2026-50512High· 7.8
3mo ago

Microsoft PC Manager Elevation of Privilege Vulnerability

Missing authentication for critical function in Microsoft PC Manager allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Microsoft PC ManagerEPSS 0.30%via CVEORG
CVE-2026-25550Critical· 9.8
3mo ago

Seagull Software BarTender 2010, 2016, and 2019 contain an unauthenticated remote code execution vulnerability in the .NET Remoting service exposed on TCP port 7375 via BtSystem.Service.exe

Seagull Software BarTender 2010, 2016, and 2019 contain an unauthenticated remote code execution vulnerability in the .NET Remoting service exposed on TCP port 7375 via BtSystem.Service.exe. The service registers an unauthenticated singl…

▾ MidnightSeagull Software, LLC. · BarTender 2010EPSS 1.4%via NVD
CVE-2026-44649Critical· 9.8
4mo ago

SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models

SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models. Prior to 1.18.0, SillyTavern accepts Remote-User (Auth…

▾ MidnightEPSS 0.29%via NVD
CVE-2026-5768High· 8.8
4mo ago

The Frontier X2 device allows unauthenticated BLE read/write access to critical GATT characteristics without enforcing pairing authentication or authorization

The Frontier X2 device allows unauthenticated BLE read/write access to critical GATT characteristics without enforcing pairing authentication or authorization. This allows attackers within BLE range to perform unauthorized control of dev…

▾ TwilightEPSS 0.43%via NVD
CVE-2026-46817Critical· 9.8CISA KEVPoC
4mo ago

Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission)

Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with netwo…

▾ Hadaloracle · e-business_suiteEPSS 0.81%via NVD
CVE-2026-9141Critical· 9.8PoC
4mo ago

Taiko AG1000-01A Rev 7.3/8 Authentication Bypass via Web Interface

Taiko AG1000-01A SMS Alert Gateway Rev 7.3 and Rev 8 contains an authentication bypass vulnerability in the embedded web configuration interface that allows unauthenticated attackers to access internal application pages without any sessi…

▾ AbyssalTaiko Network Communications Pte Ltd. · AG1000-01A SMS Alert GatewayEPSS 0.71%via CVEORG
CVE-2026-39310High· 8.6
4mo ago

Trilium Notes is a cross-platform, hierarchical note taking application focused on building large personal knowledge bases

Trilium Notes is a cross-platform, hierarchical note taking application focused on building large personal knowledge bases. In versions 0.102.1 and prior, the Clipper API in Trilium Desktop (v0.101.3) allows full authentication bypass wh…

▾ TwilightEPSS 0.50%via NVD
CVE-2026-20223Critical· 10.0PoC
4mo ago

A vulnerability in the&nbsp;access validation of internal REST APIs of Cisco Secure Workload could allow an unauthenticated, remote attacker to access site resources with the privileges of the&nbsp;Site Admin role. This vulnerability …

A vulnerability in the&nbsp;access validation of internal REST APIs of Cisco Secure Workload could allow an unauthenticated, remote attacker to access site resources with the privileges of the&nbsp;Site Admin role. This vulnerability …

▾ Abyssalcisco · secure_workloadEPSS 0.83%via NVD
CVE-2026-8602Critical· 9.1
4mo ago

In ScadaBR version 1.2.0, a Missing Authentication for Critical Function vulnerability could allow an unauthenticated attacker to send a HTTP GET requests to the SCADA system and inject arbitrary sensor readings.

In ScadaBR version 1.2.0, a Missing Authentication for Critical Function vulnerability could allow an unauthenticated attacker to send a HTTP GET requests to the SCADA system and inject arbitrary sensor readings.

▾ Midnightscadabr · scadabrEPSS 0.58%via NVD
CVE-2026-8706Medium· 6.5
4mo ago

Firefox for iOS hosted Reader mode on an unauthenticated local web server, allowing another application on the same device to request arbitrary URLs and receive the response rendered with the signed-in user's cookies

Firefox for iOS hosted Reader mode on an unauthenticated local web server, allowing another application on the same device to request arbitrary URLs and receive the response rendered with the signed-in user's cookies. This vulnerability …

▾ Sunlitmozilla · firefoxEPSS 0.23%via NVD
CVE-2026-22924Critical· 9.1
4mo ago

A vulnerability has been identified in SIMATIC CN 4100 (All versions < V5.0)

A vulnerability has been identified in SIMATIC CN 4100 (All versions < V5.0). The affected application does not properly restrict unauthenticated connections and is susceptible to resource exhaustion conditions. This could allow an atta…

▾ MidnightEPSS 0.30%via NVD
CWE-306 vulnerabilities (CVEs) — page 18 · VulnSea