VulnSea

CWE-306

CVEs classified under CWE-306, newest first.

526 CVEsRSS

CVE-2026-54504High· 8.8PoC
4d ago

MCP Documentation Server is a local-first document management and semantic search server for AI coding agents

MCP Documentation Server is a local-first document management and semantic search server for AI coding agents. From 1.13.0 until 1.13.1, the automatically started Web UI in src/server.ts calls startWebServer in src/web-server.ts with STA…

Midnightandrea9293 · mcp-documentation-serverEPSS 0.67%via NVD
CVE-2026-54446High· 8.1PoC
4d ago

NetLicensing MCP Server is a natural-language interface that enables agentic applications to manage the software-licensing lifecycle in Labs64 NetLicensing

NetLicensing MCP Server is a natural-language interface that enables agentic applications to manage the software-licensing lifecycle in Labs64 NetLicensing. Prior to 0.1.6, network-reachable HTTP transport requests to /mcp that omit x-ne…

MidnightLabs64 · NetLicensing-MCPEPSS 0.47%via NVD
CVE-2026-89034Medium· 6.5PoC
5d ago

TCH QRing smart ring model R20_B006 running firmware RT09R20_1.00.00_250318 contains an unauthenticated Bluetooth Low Energy access vulnerability that allows any nearby attacker to connect to the device without pairing, authentication, o…

TCH QRing smart ring model R20_B006 running firmware RT09R20_1.00.00_250318 contains an unauthenticated Bluetooth Low Energy access vulnerability that allows any nearby attacker to connect to the device without pairing, authentication, o…

TwilightTCH · QRingEPSS 0.29%via NVD
CVE-2026-61594Critical· 9.1
5d ago

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, the live (WebSocket) transport authorizes a mount via `check_view_auth`, not Django's `View.dispatch()…

Midnightdjust-org · djustEPSS 0.43%via NVD
CVE-2026-92805Critical· 9.8PoC
5d ago

UVdesk Community Skeleton through 1.1.8 fails to authenticate or validate installation state on wizard endpoints in ConfigureHelpdesk controller actions

UVdesk Community Skeleton through 1.1.8 fails to authenticate or validate installation state on wizard endpoints in ConfigureHelpdesk controller actions. Unauthenticated attackers can repoint the database and create super administrator a…

Abyssaluvdesk · community-skeletonEPSS 0.35%via NVD
CVE-2026-92808Critical· 10.0
5d ago

A server-side request forgery (SSRF) vulnerability exists in the UnifiedLogin service of Altium Enterprise Server

A server-side request forgery (SSRF) vulnerability exists in the UnifiedLogin service of Altium Enterprise Server. An unauthenticated network attacker can cause the server to issue outbound HTTP requests to a destination of the attacker'…

MidnightAltium · Altium Enterprise ServerEPSS 0.32%via NVD
CVE-2026-92729High· 8.2PoC
5d ago

SigNoz versions 0.88.0 through 0.141.0 fail to apply authorization wrappers to trace-funnel analytics endpoints in the HTTP handler

SigNoz versions 0.88.0 through 0.141.0 fail to apply authorization wrappers to trace-funnel analytics endpoints in the HTTP handler. Unauthenticated attackers can submit arbitrary funnel definitions to retrieve trace analytics including …

MidnightSigNoz · signozEPSS 0.54%via NVD
CVE-2026-86003High· 7.5
5d ago

CoreDNS is a DNS server written in Go

CoreDNS is a DNS server written in Go. Prior to 1.14.7, the DNS-over-HTTPS, DNS-over-HTTP/3, DNS-over-QUIC, and DNS-over-gRPC listeners in plugin/pkg/doh/doh.go, core/dnsserver/server_quic.go, and core/dnsserver/server_grpc.go call dns.M…

Twilightcoredns · corednsEPSS 0.44%via NVD
CVE-2026-92717Critical· 9.1PoC
5d ago

Covenant through 0.6 registers the CovenantHub SignalR hub without an Authorize attribute, allowing unauthenticated callers to invoke CreateHttpListener and receive a signed JWT token

Covenant through 0.6 registers the CovenantHub SignalR hub without an Authorize attribute, allowing unauthenticated callers to invoke CreateHttpListener and receive a signed JWT token. Attackers can use the obtained token to authenticate…

Abyssalcobbr · CovenantEPSS 0.36%via NVD
CVE-2026-92720Critical· 9.1
5d ago

Kubero through 3.1.1 fails to apply authentication guards to the notifications API endpoints, allowing unauthenticated attackers to read webhook secrets and service URLs

Kubero through 3.1.1 fails to apply authentication guards to the notifications API endpoints, allowing unauthenticated attackers to read webhook secrets and service URLs. Attackers can retrieve stored credentials and register malicious w…

Midnightkubero-dev · kuberoEPSS 0.47%via NVD
CVE-2026-20343High· 7.5
5d ago

A vulnerability in a critical API for Cisco Secure FMC Software could allow an unauthenticated, remote attacker to download sensitive files and use unbounded disk space. This vulnerability exists because a critical API lacks authentic…

A vulnerability in a critical API for Cisco Secure FMC Software could allow an unauthenticated, remote attacker to download sensitive files and use unbounded disk space. This vulnerability exists because a critical API lacks authentic…

TwilightCisco · Cisco Secure Firewall Management Center (FMC)EPSS 0.45%via NVD
CVE-2026-20326Critical· 9.8
5d ago

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Nexus Dashboard engineering team has conducted a comprehensive internal security review

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Nexus Dashboard engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that…

MidnightCisco · Cisco Nexus DashboardEPSS 0.39%via NVD
CVE-2026-76444Medium· 5.3
5d ago

A vulnerability in an internal service of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to retrieve sensitive configuration information from an affected device. This vulnerability is due to missing authen…

A vulnerability in an internal service of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to retrieve sensitive configuration information from an affected device. This vulnerability is due to missing authen…

SunlitCisco · Cisco Identity Services Engine SoftwareEPSS 0.29%via NVD
CVE-2026-76447Medium· 5.3
5d ago

A vulnerability in the Online Certificate Status Protocol (OCSP) responder of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to cause an administrative reload of the OCSP responder certificate and key materia…

A vulnerability in the Online Certificate Status Protocol (OCSP) responder of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to cause an administrative reload of the OCSP responder certificate and key materia…

SunlitCisco · Cisco Identity Services Engine SoftwareEPSS 0.28%via NVD
CVE-2026-76439Medium· 5.3
5d ago

A vulnerability in the endpoint posture status reporting functionality of the guest portal web application of Cisco ISE could allow an unauthenticated, remote attacker to submit forged posture status events into the endpoint posture pipe…

A vulnerability in the endpoint posture status reporting functionality of the guest portal web application of Cisco ISE could allow an unauthenticated, remote attacker to submit forged posture status events into the endpoint posture pipe…

SunlitCisco · Cisco Identity Services Engine SoftwareEPSS 0.32%via NVD
CVE-2026-92625High· 7.5
5d ago

Control iD iDSecure versions prior to 4.8.3.0 are affected by an unauthenticated Denial of Service. The /api/license/restartService endpoint is reachable without authentication and invokes an internal routine that terminates the iDSecu…

Control iD iDSecure versions prior to 4.8.3.0 are affected by an unauthenticated Denial of Service. The /api/license/restartService endpoint is reachable without authentication and invokes an internal routine that terminates the iDSecu…

TwilightControl iD · iDSecureEPSS 0.52%via NVD
CVE-2026-61590High· 7.4
5d ago

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, djust's observability endpoints expose live view/session state and a remote method-invocation surface …

Twilightdjust-org · djustEPSS 0.33%via NVD
CVE-2026-73173High· 8.8
5d ago

Nozomi Networks Labs identified a CWE-306: Missing Authentication for Critical Function vulnerability in the edgserver management protocol of Advantech EKI-1242EIMS in firmware version V1.06.01 that allows a remote unauthenticated attack…

Nozomi Networks Labs identified a CWE-306: Missing Authentication for Critical Function vulnerability in the edgserver management protocol of Advantech EKI-1242EIMS in firmware version V1.06.01 that allows a remote unauthenticated attack…

TwilightAdvantech · EKI-1242IEIMSEPSS 0.68%via NVD
CVE-2026-40856High· 7.1
5d ago

WNC T-Mobile 5G Box IDU router is vulnerable to improper access control

WNC T-Mobile 5G Box IDU router is vulnerable to improper access control. The vulnerability exists in the wnc_maccheck.cgi endpoint, which is accessible without authentication. It allows a remote attacker to retrieve sensitive configurati…

TwilightWNC · T-Mobile 5G Box IDUEPSS 0.32%via NVD
CVE-2026-86106Critical· 9.6
5d ago

An unauthenticated actor with network access to the private HA interconnect may trigger sensitive HA peer functions without verification

An unauthenticated actor with network access to the private HA interconnect may trigger sensitive HA peer functions without verification. This could result in elevated command execution on Edge units where HA is enabled.

MidnightArista Networks · VeloCloud EdgeEPSS 0.38%via NVD
CVE-2026-88263High· 7.5
5d ago

XikeStor Layer3 switches miss authentication for downloading configuration data

XikeStor Layer3 switches miss authentication for downloading configuration data. Unauthenticated attacker may retrieve the configuration data containing network configurations and passwords to operate the affected product improperly or t…

TwilightXikeStor · SKS8310-8XEPSS 0.56%via NVD
CVE-2026-88065High· 7.5
6d ago

`tts-be` is a backend for a timetable selector that aims to help students better choose their class schedules

`tts-be` is a backend for a timetable selector that aims to help students better choose their class schedules. Versions prior to 2.1.0 have a Broken Access Control vulnerability across several API endpoints (such as `/api/student/{id}/ph…

TwilightNIAEFEUP · tts-beEPSS 0.37%via NVD
CVE-2026-68953Medium· 6.5
6d ago

The affected products are vulnerable to an authentication bypass that allows unauthenticated remote attackers to disclose sensitive device information, including administrator credentials in plaintext, by sending crafted HTTP(S) requests.

The affected products are vulnerable to an authentication bypass that allows unauthenticated remote attackers to disclose sensitive device information, including administrator credentials in plaintext, by sending crafted HTTP(S) requests.

SunlitDigital Watchdog · VMAX A1 G4 DVREPSS 0.37%via NVD
CVE-2026-68070High· 8.8
6d ago

The affected products are missing authentication for a critical function, which could allow an attacker to run as root and pass received bytes directly to a system command.

The affected products are missing authentication for a critical function, which could allow an attacker to run as root and pass received bytes directly to a system command.

TwilightDigital Watchdog · VMAX A1 G4 DVREPSS 0.27%via NVD
CVE-2026-89027Medium· 6.5
6d ago

miniOrange JWT Authentication for WP REST APIs plugin for WordPress before 4.8.0 contains an authentication method downgrade vulnerability that allows unauthenticated attackers to bypass administrator-configured authentication by supplyi…

miniOrange JWT Authentication for WP REST APIs plugin for WordPress before 4.8.0 contains an authentication method downgrade vulnerability that allows unauthenticated attackers to bypass administrator-configured authentication by supplyi…

SunlitminiOrange · JWT Authentication for WP REST APIsEPSS 0.36%via NVD
CVE-2026-87223Critical· 9.1
6d ago

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security)

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows unauthenticated attacker with …

MidnightOracle Corporation · Oracle Hyperion Financial ManagementEPSS 0.30%via NVD
CVE-2026-87217Critical· 9.1
6d ago

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security)

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows unauthenticated attacker with …

Midnightoracle · hyperion_financial_managementEPSS 0.38%via NVD
CVE-2026-87205High· 7.5
6d ago

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security)

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows unauthenticated attacker with …

Twilightoracle · hyperion_financial_managementEPSS 0.40%via NVD
CVE-2026-87200High· 8.2
6d ago

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security)

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows unauthenticated attacker with …

Twilightoracle · hyperion_financial_managementEPSS 0.29%via NVD
CVE-2026-87197High· 8.2
6d ago

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security)

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows unauthenticated attacker with …

Twilightoracle · hyperion_financial_managementEPSS 0.34%via NVD
CWE-306 vulnerabilities (CVEs) — page 2 · VulnSea