VulnSea

CWE-306

CVEs classified under CWE-306, newest first.

632 CVEsRSS

CVE-2026-41603High· 7.4
5mo ago

Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue.

Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue.

▾ Twilightapache · thriftEPSS 0.57%via NVD
CVE-2024-54013High· 8.8
5mo ago

Penetration Testing engineers at Amazon have identified a security flaw related to request handling in the web server component that could, under certain conditions, lead to unintended access to protected functions

Penetration Testing engineers at Amazon have identified a security flaw related to request handling in the web server component that could, under certain conditions, lead to unintended access to protected functions. The manufacturer has …

▾ TwilightEPSS 0.19%via NVD
CVE-2026-41176Critical· 9.8PoC
5mo ago

Rclone is a command-line program to sync files and directories to and from different cloud storage providers

Rclone is a command-line program to sync files and directories to and from different cloud storage providers. The RC endpoint `options/set` is exposed without `AuthRequired: true`, but it can mutate global runtime configuration, includin…

▾ Abyssalrclone · rcloneEPSS 3.2%via NVD
CVE-2026-26160High· 7.8
5mo ago

Remote Desktop Licensing Service Elevation of Privilege Vulnerability

Missing authentication for critical function in Windows Remote Desktop Licensing Service allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 10 Version 1607EPSS 0.30%via CVEORG
CVE-2026-26159High· 7.8
5mo ago

Remote Desktop Licensing Service Elevation of Privilege Vulnerability

Missing authentication for critical function in Windows Remote Desktop Licensing Service allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 10 Version 1607EPSS 0.30%via CVEORG
CVE-2026-5724NonePoC
5mo ago

The frontend gRPC server's streaming interceptor chain did not include the authorization interceptor

The frontend gRPC server's streaming interceptor chain did not include the authorization interceptor. When a ClaimMapper and Authorizer are configured, unary RPCs enforce authentication and authorization, but the streaming AdminService/S…

▾ TwilightEPSS 0.66%via NVD
CVE-2026-39848Medium· 6.5
5mo ago

Dockyard is a Docker container management app

Dockyard is a Docker container management app. Prior to 1.1.0, Docker container start and stop operations are performed through GET requests without CSRF protection. A remote attacker can cause a logged-in administrator's browser to requ…

▾ Sunlit10ij · dockyardEPSS 0.15%via NVD
CVE-2026-33788High· 7.8
5mo ago

A Missing Authentication for Critical Function vulnerability in the Flexible PIC Concentrators (FPCs) of Juniper Networks Junos OS Evolved on PTX Series allows a local, authenticated attacker with low privileges to gain direct access to …

A Missing Authentication for Critical Function vulnerability in the Flexible PIC Concentrators (FPCs) of Juniper Networks Junos OS Evolved on PTX Series allows a local, authenticated attacker with low privileges to gain direct access to …

▾ Twilightjuniper · junosEPSS 0.17%via NVD
CVE-2025-30650Medium· 6.7
5mo ago

A Missing Authentication for Critical Function vulnerability in command processing of Juniper Networks Junos OS allows a privileged local attacker to gain access to Linux-based line cards as root. This issue affects systems running Juno…

A Missing Authentication for Critical Function vulnerability in command processing of Juniper Networks Junos OS allows a privileged local attacker to gain access to Linux-based line cards as root. This issue affects systems running Juno…

▾ SunlitEPSS 0.14%via NVD
CVE-2026-39363High· 7.5PoC
5mo ago

Vite is a frontend tooling framework for JavaScript

Vite is a frontend tooling framework for JavaScript. From 6.0.0 to before 6.4.2, 7.3.2, and 8.0.5, if it is possible to connect to the Vite dev server’s WebSocket without an Origin header, an attacker can invoke fetchModule via the custo…

▾ Midnightvitejs · viteEPSS 2.6%via NVD
CVE-2026-5676High· 7.3
5mo ago

A vulnerability was identified in Totolink A8000R 5.9c.681_B20180413

A vulnerability was identified in Totolink A8000R 5.9c.681_B20180413. This issue affects the function setLanguageCfg of the file /cgi-bin/cstecgi.cgi. Such manipulation of the argument langType leads to missing authentication. The attack…

▾ TwilightEPSS 0.69%via NVD
CVE-2026-5632High· 7.3
5mo ago

A vulnerability was found in assafelovic gpt-researcher up to 3.4.3

A vulnerability was found in assafelovic gpt-researcher up to 3.4.3. This impacts an unknown function of the component HTTP REST API Endpoint. Performing a manipulation results in missing authentication. It is possible to initiate the at…

▾ TwilightEPSS 0.65%via NVD
CVE-2026-5616High· 7.3
5mo ago

A security vulnerability has been detected in JeecgBoot 3.9.0/3.9.1

A security vulnerability has been detected in JeecgBoot 3.9.0/3.9.1. The impacted element is an unknown function of the file jeecg-boot/jeecg-module-system/jeecg-system-biz/src/main/java/org/jeecg/modules/airag/JeecgBizToolsProvider.java…

▾ TwilightEPSS 0.69%via NVD
CVE-2018-25246High· 7.5
5mo ago

Wikipedia 12.0 contains a denial of service vulnerability that allows unauthenticated attackers to crash the application by submitting oversized input through the search functionality

Wikipedia 12.0 contains a denial of service vulnerability that allows unauthenticated attackers to crash the application by submitting oversized input through the search functionality. Attackers can paste a large buffer of repeated chara…

▾ TwilightEPSS 0.36%via NVD
CVE-2018-25241High· 7.5
5mo ago

VPN Browser+ 1.1.0.0 contains a denial of service vulnerability that allows unauthenticated attackers to crash the application by submitting oversized input through the search functionality

VPN Browser+ 1.1.0.0 contains a denial of service vulnerability that allows unauthenticated attackers to crash the application by submitting oversized input through the search functionality. Attackers can paste a large buffer of characte…

▾ TwilightEPSS 0.36%via NVD
CVE-2026-32646High· 7.5PoC
5mo ago

A specific administrative endpoint is accessible without proper authentication, exposing device management functions.

A specific administrative endpoint is accessible without proper authentication, exposing device management functions.

▾ Midnightmygardyn · cloud_apiEPSS 0.68%via NVD
CVE-2026-28767Medium· 5.3PoC
5mo ago

A specific administrative endpoint notifications is accessible without proper authentication.

A specific administrative endpoint notifications is accessible without proper authentication.

▾ Twilightmygardyn · cloud_apiEPSS 0.53%via NVD
CVE-2026-28766Critical· 9.3PoC
5mo ago

A specific endpoint exposes all user account information for registered Gardyn users without requiring authentication.

A specific endpoint exposes all user account information for registered Gardyn users without requiring authentication.

▾ Abyssalmygardyn · cloud_apiEPSS 0.60%via NVD
CVE-2026-0545Critical· 9.8PoC
5mo ago

In mlflow/mlflow, the FastAPI job endpoints under `/ajax-api/3.0/jobs/*` are not protected by authentication or authorization when the `basic-auth` app is enabled

In mlflow/mlflow, the FastAPI job endpoints under `/ajax-api/3.0/jobs/*` are not protected by authentication or authorization when the `basic-auth` app is enabled. This vulnerability affects the latest version of the repository. If job e…

▾ Abyssallfprojects · mlflowEPSS 4.4%via NVD
CVE-2026-32211Critical· 9.1
5mo ago

Azure MCP Server Information Disclosure Vulnerability

Missing authentication for critical function in Azure MCP Server allows an unauthorized attacker to disclose information over a network.

▾ MidnightMicrosoft · Azure Web AppsEPSS 1.00%via CVEORG
CVE-2026-1579Critical· 9.8
6mo ago

The MAVLink communication protocol does not require cryptographic authentication by default

The MAVLink communication protocol does not require cryptographic authentication by default. When MAVLink 2.0 message signing is not enabled, any message -- including SERIAL_CONTROL, which provides interactive shell access -- can be s…

▾ Midnightpx4 · autopilotEPSS 0.93%via NVD
CVE-2026-34200High· 7.5PoC
6mo ago

Nhost is an open source Firebase alternative with GraphQL

Nhost is an open source Firebase alternative with GraphQL. Prior to version 1.41.0, The Nhost CLI MCP server, when explicitly configured to listen on a network port, applies no inbound authentication and does not enforce strict CORS. Thi…

▾ Midnightnhost · cliEPSS 0.60%via NVD
CVE-2026-34162Critical· 10.0
6mo ago

FastGPT is an AI Agent building platform

FastGPT is an AI Agent building platform. Prior to version 4.14.9.5, the FastGPT HTTP tools testing endpoint (/api/core/app/httpTools/runTool) is exposed without any authentication. This endpoint acts as a full HTTP proxy — it accepts a …

▾ Midnightfastgpt · fastgptEPSS 0.62%via NVD
CVE-2026-34227High· 8.8PoC
6mo ago

Sliver is a command and control framework that uses a custom Wireguard netstack

Sliver is a command and control framework that uses a custom Wireguard netstack. Prior to version 1.7.4, a single click on a malicious link gives an unauthenticated attacker immediate, silent control over every active C2 session or beaco…

▾ Midnightbishopfox · sliverEPSS 0.47%via NVD
CVE-2026-31846Medium· 6.5
6mo ago

Missing authentication in the /goform/ate endpoint in Nexxt Solutions Nebula 300+ firmware through version 12.01.01.37 allows an adjacent unauthenticated attacker to retrieve sensitive device information, including the administrator pass…

Missing authentication in the /goform/ate endpoint in Nexxt Solutions Nebula 300+ firmware through version 12.01.01.37 allows an adjacent unauthenticated attacker to retrieve sensitive device information, including the administrator pass…

▾ SunlitEPSS 0.39%via NVD
CVE-2026-32896Medium· 4.8
6mo ago

The BlueBubbles webhook handler in OpenClaw versions prior to 2026.2.21 contains a passwordless fallback authentication path that allows unauthenticated webhook events in certain reverse-proxy or local routing configurations

The BlueBubbles webhook handler in OpenClaw versions prior to 2026.2.21 contains a passwordless fallback authentication path that allows unauthenticated webhook events in certain reverse-proxy or local routing configurations. Attackers c…

▾ Sunlitopenclaw · openclawEPSS 0.43%via NVD
CVE-2026-2756Medium· 5.0
6mo ago

A security vulnerability has been detected in OmniPEMF NeoRhythm up to 20260308

A security vulnerability has been detected in OmniPEMF NeoRhythm up to 20260308. This affects an unknown function of the component BLE Interface. Such manipulation leads to missing authentication. The attack can only be initiated within …

▾ SunlitOmniPEMF · NeoRhythmEPSS 0.41%via NVD
CVE-2026-33231High· 7.5PoC
6mo ago

NLTK (Natural Language Toolkit) is a suite of open source Python modules, data sets, and tutorials supporting research and development in Natural Language Processing

NLTK (Natural Language Toolkit) is a suite of open source Python modules, data sets, and tutorials supporting research and development in Natural Language Processing. In versions 3.9.3 and prior, `nltk.app.wordnet_app` allows unauthentic…

▾ Midnightnltk · nltkEPSS 1.5%via NVD
CVE-2026-56346Medium
6mo ago

AVideo has Unauthenticated PGP Message Decryption via Public Endpoint

AVideo has Unauthenticated PGP Message Decryption via Public Endpoint

▾ Sunlitwwbn · wwbn/avideoEPSS 0.61%via GHSA
CVE-2025-71257High· 7.3PoC
6mo ago

BMC FootPrints ITSM versions 20.20.02 through 20.24.01.001 contain an authentication bypass vulnerability due to improper enforcement of security filters on restricted REST API endpoints and servlets

BMC FootPrints ITSM versions 20.20.02 through 20.24.01.001 contain an authentication bypass vulnerability due to improper enforcement of security filters on restricted REST API endpoints and servlets. Unauthenticated remote attackers can…

▾ Midnightbmc · footprintsEPSS 45%via NVD
CWE-306 vulnerabilities (CVEs) — page 19 · VulnSea