VulnSea

CWE-306

CVEs classified under CWE-306, newest first.

632 CVEsRSS

CVE-2026-2603High· 8.1
6mo ago

A flaw was found in Keycloak

A flaw was found in Keycloak. A remote attacker could bypass security controls by sending a valid SAML response from an external Identity Provider (IdP) to the Keycloak SAML endpoint for IdP-initiated broker logins. This allows the attac…

▾ Twilightredhat · build_of_keycloakEPSS 0.72%via NVD
CVE-2026-32594Medium
6mo ago

Parse Server's GraphQL WebSocket endpoint bypasses security middleware

Parse Server's GraphQL WebSocket endpoint bypasses security middleware

▾ Sunlitparse-server · parse-serverEPSS 0.47%via GHSA
CVE-2026-27446Critical· 9.8
6mo ago

Missing Authentication for Critical Function (CWE-306) vulnerability in Apache Artemis, Apache ActiveMQ Artemis

Missing Authentication for Critical Function (CWE-306) vulnerability in Apache Artemis, Apache ActiveMQ Artemis. An unauthenticated remote attacker can use the Core protocol to force a target broker to establish an outbound Core federati…

▾ Midnightapache · artemisEPSS 1.1%via NVD
CVE-2026-27595High· 7.5
7mo ago

Parse Dashboard is a standalone dashboard for managing Parse Server apps

Parse Dashboard is a standalone dashboard for managing Parse Server apps. In versions 7.3.0-alpha.42 through 9.0.0-alpha.7, the AI Agent API endpoint (POST `/apps/:appId/agent`) has multiple security vulnerabilities that, when chained, a…

▾ TwilightEPSS 0.64%via NVD
CVE-2025-70141Critical· 9.4PoC
7mo ago

SourceCodester Customer Support System 1.0 contains an incorrect access control vulnerability in ajax.php

SourceCodester Customer Support System 1.0 contains an incorrect access control vulnerability in ajax.php. The AJAX dispatcher does not enforce authentication or authorization before invoking administrative methods in admin_class.php bas…

▾ Abyssaloretnom23 · customer_support_systemEPSS 0.69%via NVD
CVE-2025-70147High· 7.5PoC
7mo ago

Missing authentication in /admin/student.php and /admin/teacher.php in ProjectWorlds Online Time Table Generator 1.0 allows remote attackers to obtain sensitive information (including plaintext password field values) via direct HTTP GET …

Missing authentication in /admin/student.php and /admin/teacher.php in ProjectWorlds Online Time Table Generator 1.0 allows remote attackers to obtain sensitive information (including plaintext password field values) via direct HTTP GET …

▾ Midnightprojectworlds · online_time_table_generatorEPSS 0.52%via NVD
CVE-2025-70146Critical· 9.1PoC
7mo ago

Missing authentication in multiple administrative action scripts under /admin/ in ProjectWorlds Online Time Table Generator 1.0 allows remote attackers to perform unauthorized administrative operations (e.g.,adding records, deleting reco…

Missing authentication in multiple administrative action scripts under /admin/ in ProjectWorlds Online Time Table Generator 1.0 allows remote attackers to perform unauthorized administrative operations (e.g.,adding records, deleting reco…

▾ Abyssalprojectworlds · online_time_table_generatorEPSS 0.57%via NVD
CVE-2026-24423Critical· 9.8CISA KEVPoC
8mo ago

SmarterTools SmarterMail versions prior to build 9511 contain an unauthenticated remote code execution vulnerability in the ConnectToHub API method

SmarterTools SmarterMail versions prior to build 9511 contain an unauthenticated remote code execution vulnerability in the ConnectToHub API method. The attacker could point the SmarterMail to the malicious HTTP server, which serves the …

▾ Hadalsmartertools · smartermailEPSS 88%via NVD
CVE-2025-12548Critical· 9.0PoC
8mo ago

A flaw was found in Eclipse Che che-machine-exec

A flaw was found in Eclipse Che che-machine-exec. This vulnerability allows unauthenticated remote arbitrary command execution and secret exfiltration (SSH keys, tokens, etc.) from other users' Developer Workspace containers, via an unau…

▾ AbyssalRed Hat · devspaces/code-rhel9EPSS 1.3%via NVD
CVE-2026-20803High· 7.2
8mo ago

Missing authentication for critical function in SQL Server allows an authorized attacker to elevate privileges over a network.

Missing authentication for critical function in SQL Server allows an authorized attacker to elevate privileges over a network.

▾ Twilightmicrosoft · sql_server_2022EPSS 1.3%via NVD
CVE-2026-0650NonePoC
8mo ago

OpenFlagr versions prior to and including 1.1.18 contain an authentication bypass vulnerability in the HTTP middleware

OpenFlagr versions prior to and including 1.1.18 contain an authentication bypass vulnerability in the HTTP middleware. Due to improper handling of path normalization in the whitelist logic, crafted requests can bypass authentication and…

▾ TwilightEPSS 1.5%via NVD
CVE-2025-3646High· 7.3
8mo ago

Petlibro Smart Pet Feeder Platform versions up to 1.7.31 contains an authorization bypass vulnerability that allows unauthorized users to add users as shared owners to any device by exploiting missing permission checks

Petlibro Smart Pet Feeder Platform versions up to 1.7.31 contains an authorization bypass vulnerability that allows unauthorized users to add users as shared owners to any device by exploiting missing permission checks. Attackers can sen…

▾ Twilightpetlibro · petlibroEPSS 0.22%via NVD
CVE-2020-36904High· 7.5
9mo ago

Selea CarPlateServer 4.0.1.6 contains a remote program execution vulnerability that allows attackers to execute arbitrary Windows binaries by manipulating the NO_LIST_EXE_PATH configuration parameter

Selea CarPlateServer 4.0.1.6 contains a remote program execution vulnerability that allows attackers to execute arbitrary Windows binaries by manipulating the NO_LIST_EXE_PATH configuration parameter. Attackers can bypass authentication …

▾ TwilightEPSS 0.48%via NVD
CVE-2025-65856Critical· 9.8PoC
9mo ago

Authentication bypass vulnerability in Xiongmai XM530 IP cameras on Firmware V5.00.R02.000807D8.10010.346624.S.ONVIF 21.06 allows unauthenticated remote attackers to access sensitive device information and live video streams

Authentication bypass vulnerability in Xiongmai XM530 IP cameras on Firmware V5.00.R02.000807D8.10010.346624.S.ONVIF 21.06 allows unauthenticated remote attackers to access sensitive device information and live video streams. The ONVIF i…

▾ Abyssalxiongmaitech · xm530v200_x6-weq_8m_firmwareEPSS 0.74%via NVD
CVE-2025-14300High· 8.1
9mo ago

The HTTPS service on Tapo C200 v3, v5, C425 v1.2 and C100 v5  exposes a connectAP interface without proper authentication

The HTTPS service on Tapo C200 v3, v5, C425 v1.2 and C100 v5  exposes a connectAP interface without proper authentication. An unauthenticated attacker on the same local network segment can exploit this to modify the device’s Wi-Fi config…

▾ Twilighttp-link · tapo_c200_firmwareEPSS 0.37%via NVD
CVE-2025-67780Medium· 4.2PoC
9mo ago

SpaceX Starlink Dish devices with firmware 2024.12.04.mr46620 (e.g., on Mini1_prod2) allow administrative actions via unauthenticated LAN gRPC requests, aka MARMALADE 2

SpaceX Starlink Dish devices with firmware 2024.12.04.mr46620 (e.g., on Mini1_prod2) allow administrative actions via unauthenticated LAN gRPC requests, aka MARMALADE 2. The cross-origin policy can be bypassed by omitting a Referer heade…

▾ TwilightEPSS 0.17%via NVD
CVE-2025-65828Medium· 6.5
9mo ago

An unauthenticated attacker within proximity of the Meatmeet device can issue several commands over Bluetooth Low Energy (BLE) to these devices which would result in a Denial of Service

An unauthenticated attacker within proximity of the Meatmeet device can issue several commands over Bluetooth Low Energy (BLE) to these devices which would result in a Denial of Service. These commands include: shutdown, restart, clear c…

▾ Sunlitmeatmeet · meatmeet_pro_wifi_&_bluetooth_meat_thermometer_firmwareEPSS 0.28%via NVD
CVE-2025-65824High· 8.8
9mo ago

An unauthenticated attacker within proximity of the Meatmeet device can perform an unauthorized Over The Air (OTA) firmware upgrade using Bluetooth Low Energy (BLE), resulting in the firmware on the device being overwritten with the atta…

An unauthenticated attacker within proximity of the Meatmeet device can perform an unauthorized Over The Air (OTA) firmware upgrade using Bluetooth Low Energy (BLE), resulting in the firmware on the device being overwritten with the atta…

▾ Twilightmeatmeet · meatmeet_pro_wifi_&_bluetooth_meat_thermometer_firmwareEPSS 0.56%via NVD
CVE-2025-54158High· 7.8
9mo ago

Missing authentication for critical function vulnerability in BeeDrive in Synology BeeDrive for desktop before 1.4.2-13960 allows local users to execute arbitrary code via unspecified vectors.

Missing authentication for critical function vulnerability in BeeDrive in Synology BeeDrive for desktop before 1.4.2-13960 allows local users to execute arbitrary code via unspecified vectors.

▾ Twilightsynology · beedriveEPSS 0.18%via NVD
CVE-2025-59695Critical· 9.8
9mo ago

Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.0 (STS)), allow a user with OS root access to alter firmware on the Chassis Management Board (without Authentication)

Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.0 (STS)), allow a user with OS root access to alter firmware on the Chassis Management Board (without Authentication). T…

▾ Midnightentrust · nshield_5c_firmwareEPSS 0.67%via NVD
CVE-2024-49572High· 7.2
10mo ago

A denial of service vulnerability exists in the Modbus TCP functionality of Socomec DIRIS Digiware M-70 1.6.9

A denial of service vulnerability exists in the Modbus TCP functionality of Socomec DIRIS Digiware M-70 1.6.9. A specially crafted network packet can lead to denial of service and weaken credentials resulting in default documented creden…

▾ Twilightsocomec · diris_m-70_firmwareEPSS 0.34%via NVD
CVE-2024-48882High· 8.6
10mo ago

A denial of service vulnerability exists in the Modbus TCP functionality of Socomec DIRIS Digiware M-70 1.6.9

A denial of service vulnerability exists in the Modbus TCP functionality of Socomec DIRIS Digiware M-70 1.6.9. A specially crafted network packet can lead to denial of service. An attacker can send an unauthenticated packet to trigger th…

▾ Twilightsocomec · diris_m-70_firmwareEPSS 0.54%via NVD
CVE-2025-55222High· 8.6
10mo ago

A denial of service vulnerability exists in the Modbus TCP and Modbus RTU over TCP USB Function functionality of Socomec DIRIS Digiware M-70 1.6.9

A denial of service vulnerability exists in the Modbus TCP and Modbus RTU over TCP USB Function functionality of Socomec DIRIS Digiware M-70 1.6.9. A specially crafted network packet can lead to a denial of service. An attacker can send …

▾ Twilightsocomec · diris_m-70_firmwareEPSS 0.42%via NVD
CVE-2025-55221High· 8.6
10mo ago

A denial of service vulnerability exists in the Modbus TCP and Modbus RTU over TCP USB Function functionality of Socomec DIRIS Digiware M-70 1.6.9

A denial of service vulnerability exists in the Modbus TCP and Modbus RTU over TCP USB Function functionality of Socomec DIRIS Digiware M-70 1.6.9. A specially crafted network packet can lead to a denial of service. An attacker can send …

▾ Twilightsocomec · diris_m-70_firmwareEPSS 0.42%via NVD
CVE-2025-54851High· 7.5
10mo ago

A denial of service vulnerability exists in the Modbus TCP and Modbus RTU over TCP functionality of Socomec DIRIS Digiware M-70 1.6.9

A denial of service vulnerability exists in the Modbus TCP and Modbus RTU over TCP functionality of Socomec DIRIS Digiware M-70 1.6.9. A specially crafted series of network requests can lead to a denial of service. An attacker can send a…

▾ Twilightsocomec · diris_m-70_firmwareEPSS 0.43%via NVD
CVE-2025-54850High· 7.5
10mo ago

A denial of service vulnerability exists in the Modbus TCP and Modbus RTU over TCP functionality of Socomec DIRIS Digiware M-70 1.6.9

A denial of service vulnerability exists in the Modbus TCP and Modbus RTU over TCP functionality of Socomec DIRIS Digiware M-70 1.6.9. A specially crafted series of network requests can lead to a denial of service. An attacker can send a…

▾ Twilightsocomec · diris_m-70_firmwareEPSS 0.32%via NVD
CVE-2025-54849High· 7.5
10mo ago

A denial of service vulnerability exists in the Modbus TCP and Modbus RTU over TCP functionality of Socomec DIRIS Digiware M-70 1.6.9

A denial of service vulnerability exists in the Modbus TCP and Modbus RTU over TCP functionality of Socomec DIRIS Digiware M-70 1.6.9. A specially crafted series of network requests can lead to a denial of service. An attacker can send a…

▾ Twilightsocomec · diris_digiware_m-70_firmwareEPSS 0.32%via NVD
CVE-2025-54848High· 7.5
10mo ago

A denial of service vulnerability exists in the Modbus TCP and Modbus RTU over TCP functionality of Socomec DIRIS Digiware M-70 1.6.9

A denial of service vulnerability exists in the Modbus TCP and Modbus RTU over TCP functionality of Socomec DIRIS Digiware M-70 1.6.9. A specially crafted series of network requests can lead to a denial of service. An attacker can send a…

▾ Twilightsocomec · diris_digiware_m-70_firmwareEPSS 0.42%via NVD
CVE-2025-23417High· 8.6
10mo ago

A denial of service vulnerability exists in the Modbus RTU over TCP functionality of Socomec DIRIS Digiware M-70 1.6.9

A denial of service vulnerability exists in the Modbus RTU over TCP functionality of Socomec DIRIS Digiware M-70 1.6.9. A specially crafted network packet can lead to denial of service. An attacker can send an unauthenticated packet to t…

▾ Twilightsocomec · diris_m-70_firmwareEPSS 0.54%via NVD
CVE-2025-20085High· 7.2
10mo ago

A denial of service vulnerability exists in the Modbus RTU over TCP functionality of Socomec DIRIS Digiware M-70 1.6.9

A denial of service vulnerability exists in the Modbus RTU over TCP functionality of Socomec DIRIS Digiware M-70 1.6.9. A specially crafted network packet can lead to denial of service and weaken credentials resulting in default document…

▾ Twilightsocomec · diris_m-70_firmwareEPSS 0.34%via NVD
CWE-306 vulnerabilities (CVEs) — page 20 · VulnSea