VulnSea

CWE-306

CVEs classified under CWE-306, newest first.

632 CVEsRSS

CVE-2024-14007None
10mo ago

Shenzhen TVT Digital Technology Co., Ltd

Shenzhen TVT Digital Technology Co., Ltd. NVMS-9000 firmware (used by many white-labeled DVR/NVR/IPC products) versions prior to 1.3.4 contain an authentication bypass in the NVMS-9000 control protocol. By sending a single crafted TCP pa…

▾ SunlitEPSS 0.86%via NVD
CVE-2025-64307Medium· 6.5
10mo ago

The Brightpick Internal Logic Control web interface is accessible without requiring user authentication

The Brightpick Internal Logic Control web interface is accessible without requiring user authentication. An unauthorized user could exploit this interface to manipulate robot control functions, including initiating or halting runners, as…

▾ SunlitEPSS 0.23%via NVD
CVE-2025-10906High· 8.4
1y ago

A flaw has been found in Magnetism Studios Endurance up to 3.3.0 on macOS

A flaw has been found in Magnetism Studios Endurance up to 3.3.0 on macOS. This affects the function loadModuleNamed:WithReply of the file /Applications/Endurance.app/Contents/Library/LaunchServices/com.MagnetismStudios.endurance.helper …

▾ TwilightEPSS 0.22%via NVD
CVE-2025-41716Medium· 5.3
1y ago

The web application allows an unauthenticated remote attacker to learn information about existing user accounts with their corresponding role due to missing authentication for critical function.

The web application allows an unauthenticated remote attacker to learn information about existing user accounts with their corresponding role due to missing authentication for critical function.

▾ SunlitEPSS 0.38%via NVD
CVE-2025-41715Critical· 9.8
1y ago

The database for the web application is exposed without authentication, allowing an unauthenticated remote attacker to gain unauthorized access and potentially compromise it.

The database for the web application is exposed without authentication, allowing an unauthenticated remote attacker to gain unauthorized access and potentially compromise it.

▾ MidnightEPSS 0.49%via NVD
CVE-2025-56562High· 7.5
1y ago

An incorrect API discovered in Signify Wiz Connected 1.9.1 allows attackers to remotely launch a DoS on Wiz devices only requiring the MAC address.

An incorrect API discovered in Signify Wiz Connected 1.9.1 allows attackers to remotely launch a DoS on Wiz devices only requiring the MAC address.

▾ Twilightsignify · wiz_connectedEPSS 0.33%via NVD
CVE-2025-9994Critical· 9.8
1y ago

The Amp’ed RF BT-AP 111 Bluetooth access point's HTTP admin interface does not have an authentication feature, allowing unauthorized access to anyone with network access.

The Amp’ed RF BT-AP 111 Bluetooth access point's HTTP admin interface does not have an authentication feature, allowing unauthorized access to anyone with network access.

▾ MidnightEPSS 0.53%via NVD
CVE-2025-9815High· 7.8
1y ago

A weakness has been identified in alaneuler batteryKid up to 2.1 on macOS

A weakness has been identified in alaneuler batteryKid up to 2.1 on macOS. The affected element is an unknown function of the file PrivilegeHelper/PrivilegeHelper.swift of the component NSXPCListener. This manipulation causes missing aut…

▾ Twilightalaneuler · batterykidEPSS 0.27%via NVD
CVE-2025-5187Medium· 6.7
1y ago

kubernetes: kube-apiserver: Nodes can delete themselves by adding an OwnerReference (CVE-2025-5187)

A vulnerability was found in the kube-apiserver's NodeRestriction admission controller, where node users can delete their corresponding node object by setting their own OwnerReference to a cluster-scoped resource. This flaw allows an attac…

▾ SunlitRed Hat · Red Hat OpenShift Container Platform 4EPSS 0.55%via CSAF
CVE-2025-34115High· 8.7PoC
1y ago

An authenticated command injection vulnerability exists in OP5 Monitor through version 7.1.9 via the 'cmd_str' parameter in the command_test.php endpoint

An authenticated command injection vulnerability exists in OP5 Monitor through version 7.1.9 via the 'cmd_str' parameter in the command_test.php endpoint. A user with access to the web interface can exploit the 'Test this command' featur…

▾ MidnightITRS Group · OP5 MonitorEPSS 3.6%via NVD
CVE-2025-4382Medium· 5.9
1y ago

A flaw was found in systems utilizing LUKS-encrypted disks with GRUB configured for TPM-based auto-decryption

A flaw was found in systems utilizing LUKS-encrypted disks with GRUB configured for TPM-based auto-decryption. When GRUB is set to automatically decrypt disks using keys stored in the TPM, it reads the decryption key into system memory. …

▾ SunlitEPSS 0.34%via NVD
CVE-2025-3248Critical· 9.8CISA KEVPoC
1y ago

Langflow versions prior to 1.3.0 are susceptible to code injection in the /api/v1/validate/code endpoint

Langflow versions prior to 1.3.0 are susceptible to code injection in the /api/v1/validate/code endpoint. A remote and unauthenticated attacker can send crafted HTTP requests to execute arbitrary code.

▾ Hadallangflow · langflowEPSS 100%via NVD
CVE-2025-0108Critical· 9.1CISA KEVPoC
1y ago

An authentication bypass in the Palo Alto Networks PAN-OS software enables an unauthenticated attacker with network access to the management web interface to bypass the authentication otherwise required by the PAN-OS management web inter…

An authentication bypass in the Palo Alto Networks PAN-OS software enables an unauthenticated attacker with network access to the management web interface to bypass the authentication otherwise required by the PAN-OS management web inter…

▾ Hadalpaloaltonetworks · pan-osEPSS 98%via NVD
CVE-2024-11680Critical· 9.8CISA KEVPoC
1y ago

ProjectSend versions prior to r1720 are affected by an improper authentication vulnerability

ProjectSend versions prior to r1720 are affected by an improper authentication vulnerability. Remote, unauthenticated attackers can exploit this flaw by sending crafted HTTP requests to options.php, enabling unauthorized modification of …

▾ Hadalprojectsend · projectsendEPSS 92%via NVD
CVE-2024-0012Critical· 9.8CISA KEV0dayPoC
1y ago

An authentication bypass in Palo Alto Networks PAN-OS software enables an unauthenticated attacker with network access to the management web interface to gain PAN-OS administrator privileges to perform administrative actions, tamper with…

An authentication bypass in Palo Alto Networks PAN-OS software enables an unauthenticated attacker with network access to the management web interface to gain PAN-OS administrator privileges to perform administrative actions, tamper with…

▾ Hadalpaloaltonetworks · pan-osEPSS 100%via NVD
CVE-2024-51567Critical· 10.0CISA KEV0dayPoC
1y ago

upgrademysqlstatus in databases/views.py in CyberPanel (aka Cyber Panel) before 5b08cd6 allows remote attackers to bypass authentication and execute arbitrary commands via /dataBases/upgrademysqlstatus by bypassing secMiddleware (which i…

upgrademysqlstatus in databases/views.py in CyberPanel (aka Cyber Panel) before 5b08cd6 allows remote attackers to bypass authentication and execute arbitrary commands via /dataBases/upgrademysqlstatus by bypassing secMiddleware (which i…

▾ Hadalcyberpanel · cyberpanelEPSS 87%via NVD
CVE-2024-49604Critical· 9.8
1y ago

Authentication Bypass Using an Alternate Path or Channel vulnerability in N-Media Simple User Registration wp-registration allows Authentication Bypass.This issue affects Simple User Registration: from n/a through <= 6.7.

Authentication Bypass Using an Alternate Path or Channel vulnerability in N-Media Simple User Registration wp-registration allows Authentication Bypass.This issue affects Simple User Registration: from n/a through <= 6.7.

▾ Midnightnajeebmedia · memberheroEPSS 0.53%via NVD
CVE-2024-6592Critical· 9.1PoC
2y ago

An incorrect authorization vulnerability in the protocol communication between the WatchGuard Authentication Gateway (aka Single Sign-On Agent) on Windows and the WatchGuard Single Sign-On Client on Windows and MacOS allows an attacker w…

An incorrect authorization vulnerability in the protocol communication between the WatchGuard Authentication Gateway (aka Single Sign-On Agent) on Windows and the WatchGuard Single Sign-On Client on Windows and MacOS allows an attacker w…

▾ Abyssalwatchguard · authentication_gatewayEPSS 1.2%via NVD
CVE-2024-45229Medium· 6.6
2y ago

The Versa Director offers REST APIs for orchestration and management

The Versa Director offers REST APIs for orchestration and management. By design, certain APIs, such as the login screen, banner display, and device registration, do not require authentication. However, it was discovered that for Director…

▾ SunlitEPSS 0.51%via NVD
CVE-2024-8751High· 7.5
2y ago

A vulnerability allows a remote unauthenticated attacker to modify the prod uct’s IP address over the Sopas ET interface

A vulnerability allows a remote unauthenticated attacker to modify the prod uct’s IP address over the Sopas ET interface. This can lead to a Denial of Service attack.

▾ TwilightEPSS 0.93%via NVD
CVE-2023-28461Critical· 9.8CISA KEV
3y ago

Array Networks Array AG Series and vxAG (9.4.0.481 and earlier) allow remote code execution

Array Networks Array AG Series and vxAG (9.4.0.481 and earlier) allow remote code execution. An attacker can browse the filesystem on the SSL VPN gateway using a flags attribute in an HTTP header without authentication. The product could…

▾ Hadalarraynetworks · arrayos_agEPSS 68%via NVD
CVE-2022-21952High· 7.5
4y ago

A Missing Authentication for Critical Function vulnerability in spacewalk-java of SUSE Manager Server 4.1, SUSE Manager Server 4.2 allows remote attackers to easily exhaust available disk resources leading to DoS

A Missing Authentication for Critical Function vulnerability in spacewalk-java of SUSE Manager Server 4.1, SUSE Manager Server 4.2 allows remote attackers to easily exhaust available disk resources leading to DoS. This issue affects: SUS…

▾ Twilightsuse · manager_serverEPSS 1.5%via NVD
CVE-2022-24562Critical· 9.8PoC
4y ago

In IOBit IOTransfer 4.3.1.1561, an unauthenticated attacker can send GET and POST requests to Airserv and gain arbitrary read/write access to the entire file-system (with admin privileges) on the victim's endpoint, which can result in da…

In IOBit IOTransfer 4.3.1.1561, an unauthenticated attacker can send GET and POST requests to Airserv and gain arbitrary read/write access to the entire file-system (with admin privileges) on the victim's endpoint, which can result in da…

▾ Abyssaliobit · iotransferEPSS 54%via NVD
CVE-2020-27376High· 8.8
4y ago

Dr Trust USA iCheck Connect BP Monitor BP Testing 118 version 1.2.1 is vulnerable to Missing Authentication.

Dr Trust USA iCheck Connect BP Monitor BP Testing 118 version 1.2.1 is vulnerable to Missing Authentication.

▾ Twilightdrtrustusa · icheck_connect_bp_monitor_bp_testing_118_firmwareEPSS 0.99%via NVD
CVE-2021-46009Critical· 9.8
4y ago

In Totolink A3100R V5.9c.4577, multiple pages can be read by curl or Burp Suite without authentication

In Totolink A3100R V5.9c.4577, multiple pages can be read by curl or Burp Suite without authentication. Additionally, admin configurations can be set without cookies.

▾ Midnighttotolink · a3100r_firmwareEPSS 13%via NVD
CVE-2021-46006Medium· 6.5
4y ago

In Totolink A3100R V5.9c.4577, "test.asp" contains an API-like function, which is not authenticated

In Totolink A3100R V5.9c.4577, "test.asp" contains an API-like function, which is not authenticated. Using this function, an attacker can configure multiple settings without authentication.

▾ Sunlittotolink · a3100r_firmwareEPSS 5.5%via NVD
CVE-2022-23345High· 7.5
4y ago

BigAnt Software BigAnt Server v5.6.06 was discovered to contain incorrect access control.

BigAnt Software BigAnt Server v5.6.06 was discovered to contain incorrect access control.

▾ Twilightbigantsoft · bigant_serverEPSS 1.6%via NVD
CVE-2021-45420Critical· 9.8PoC
4y ago

Emerson Dixell XWEB-500 products are affected by arbitrary file write vulnerability in /cgi-bin/logo_extra_upload.cgi, /cgi-bin/cal_save.cgi, and /cgi-bin/lo_utils.cgi

Emerson Dixell XWEB-500 products are affected by arbitrary file write vulnerability in /cgi-bin/logo_extra_upload.cgi, /cgi-bin/cal_save.cgi, and /cgi-bin/lo_utils.cgi. An attacker will be able to write any file on the target system with…

▾ Abyssalemerson · dixell_xweb-500_firmwareEPSS 18%via NVD
CVE-2021-33259Medium· 5.3
4y ago

Several web interfaces in D-Link DIR-868LW 1.12b have no authentication requirements for access, allowing for attackers to obtain users' DNS query history.

Several web interfaces in D-Link DIR-868LW 1.12b have no authentication requirements for access, allowing for attackers to obtain users' DNS query history.

▾ Sunlitd-link · dir-868lw_firmwareEPSS 1.8%via NVD
CVE-2019-5591Medium· 6.5CISA KEVPoC
6y ago

A Default Configuration vulnerability in FortiOS may allow an unauthenticated attacker on the same subnet to intercept sensitive information by impersonating the LDAP server.

A Default Configuration vulnerability in FortiOS may allow an unauthenticated attacker on the same subnet to intercept sensitive information by impersonating the LDAP server.

▾ Midnightfortinet · fortiosEPSS 18%via NVD
CWE-306 vulnerabilities (CVEs) — page 21 · VulnSea