VulnSea

CWE-306

CVEs classified under CWE-306, newest first.

630 CVEsRSS

CVE-2026-73956Critical· 9.8
1w ago

Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Composer)

Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Composer). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacke…

▾ Midnightoracle · webcenter_portalEPSS 0.51%via NVD
CVE-2026-73953Critical· 9.8
1w ago

Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Portlet Services)

Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Portlet Services). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated…

▾ Midnightoracle · webcenter_portalEPSS 0.51%via NVD
CVE-2026-73952Critical· 9.1
1w ago

Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Portlet Services)

Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Portlet Services). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated…

▾ Midnightoracle · webcenter_portalEPSS 0.43%via NVD
CVE-2026-73950Critical· 9.8
1w ago

Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine)

Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthentica…

▾ Midnightoracle · access_managerEPSS 0.51%via NVD
CVE-2026-73947Critical· 9.8
1w ago

Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine)

Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthentica…

▾ Midnightoracle · access_managerEPSS 0.51%via NVD
CVE-2026-73944Critical· 9.1
1w ago

Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine)

Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthentica…

▾ Midnightoracle · access_managerEPSS 0.43%via NVD
CVE-2026-73940Critical· 9.8
1w ago

Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine)

Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthentica…

▾ Midnightoracle · access_managerEPSS 0.51%via NVD
CVE-2026-71133Critical· 10.0
1w ago

Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine)

Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthentica…

▾ Midnightoracle · access_managerEPSS 0.51%via NVD
CVE-2026-70913Critical· 9.8
1w ago

Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: Core)

Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker wi…

▾ Midnightoracle · identity_managerEPSS 0.51%via NVD
CVE-2026-70757Critical· 9.8
1w ago

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core)

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unau…

▾ MidnightOracle Corporation · Oracle WebLogic ServerEPSS 0.48%via NVD
CVE-2026-70756Critical· 9.8
1w ago

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core)

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unau…

▾ MidnightOracle Corporation · Oracle WebLogic ServerEPSS 0.48%via NVD
CVE-2026-70748Critical· 9.8
1w ago

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core)

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unau…

▾ MidnightOracle Corporation · Oracle WebLogic ServerEPSS 0.48%via NVD
CVE-2026-76701Medium· 5.9
1w ago

A vulnerability in the API endpoint of HPE Networking EdgeConnect SD-WAN Gateways could allow an unauthenticated remote attacker to access sensitive information

A vulnerability in the API endpoint of HPE Networking EdgeConnect SD-WAN Gateways could allow an unauthenticated remote attacker to access sensitive information. Successful exploitation could allow an attacker to retrieve information whi…

▾ SunlitHewlett Packard Enterprise (HPE) · EdgeConnect SD-WAN GatewaysEPSS 0.39%via NVD
CVE-2026-81238High· 7.5
1w ago

Dell Wyse Management Suite, versions prior to 2605.0.3.683, contain a Missing Authentication for Critical Function vulnerability

Dell Wyse Management Suite, versions prior to 2605.0.3.683, contain a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Una…

▾ Twilightdell · wyse_management_suiteEPSS 0.27%via NVD
CVE-2026-12910Medium· 5.4
1w ago

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.6 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that under certain conditions could have allowed an authenticated user to bypass SAML SSO sign-in r…

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.6 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that under certain conditions could have allowed an authenticated user to bypass SAML SSO sign-in r…

▾ SunlitGitLab · GitLabEPSS 0.19%via NVD
CVE-2026-18111High· 8.5
1w ago

Concrete CMS 9 before 9.5.3 was vulnerable to stored cross-site scripting (XSS) in the Feature, Feature Link, Hero Image, and Image blocks and before Concrete 8.5.21 in the feature and Image blocks because the external link URL was insuf…

Concrete CMS 9 before 9.5.3 was vulnerable to stored cross-site scripting (XSS) in the Feature, Feature Link, Hero Image, and Image blocks and before Concrete 8.5.21 in the feature and Image blocks because the external link URL was insuf…

▾ TwilightConcrete CMS · Concrete CMSEPSS 0.34%via NVD
CVE-2026-91996High· 7.5PoC
1w ago

lamp-cloud through 5.10.0 whitelists the path pattern /*/anno/** for anonymous access, allowing unauthenticated attackers to read the server's full JVM system property map

lamp-cloud through 5.10.0 whitelists the path pattern /*/anno/** for anonymous access, allowing unauthenticated attackers to read the server's full JVM system property map. Attackers can send POST requests to /defGenProject/anno/getPrope…

▾ Midnightdromara · lamp-cloudEPSS 0.50%via NVD
CVE-2026-57139Critical· 9.8PoC
1w ago

PraisonAI is a multi-agent teams system

PraisonAI is a multi-agent teams system. From 1.5.0 until 1.7.2, MCPServer.startHttp() in src/praisonai-ts/src/mcp/server.ts binds without a host restriction and forwards every HTTP POST request to handleRequest() without authentication …

▾ AbyssalMervinPraison · PraisonAIEPSS 0.75%via NVD
CVE-2026-57140Critical· 9.4
1w ago

PraisonAI is a multi-agent teams system

PraisonAI is a multi-agent teams system. From 1.6.0 until 1.7.2, AgentOS in src/praisonai-ts/src/os/agentos.ts uses the 0.0.0.0 default from src/praisonai-ts/src/os/config.ts and registers GET /api/agents and POST /api/chat without authe…

▾ MidnightMervinPraison · PraisonAIEPSS 0.64%via NVD
CVE-2026-91002Medium· 5.3PoC
1w ago

A weakness has been identified in stamparm maltrail up to 3.0.1

A weakness has been identified in stamparm maltrail up to 3.0.1. This vulnerability affects the function _blacklist of the file core/httpd.py of the component Blacklist Endpoint. Executing a manipulation can lead to missing authenticatio…

▾ Twilightstamparm · maltrailEPSS 0.77%via NVD
CVE-2026-59971Critical· 10.0
1w ago

MySQL MCP Server is a Model Context Protocol server that enables secure interaction with MySQL databases

MySQL MCP Server is a Model Context Protocol server that enables secure interaction with MySQL databases. Prior to 0.4.2, setting MCP_TRANSPORT=sse causes src/mysql_mcp_server/server.py to construct SseServerTransport without security_se…

▾ Midnightdesigncomputer · mysql_mcp_serverEPSS 0.42%via NVD
CVE-2026-59160High· 8.8PoC
1w ago

Yeger is a monorepo for npm packages maintained under the yeger scope

Yeger is a monorepo for npm packages maintained under the yeger scope. Prior to 2.8.9, the turbo-graph package starts its embedded Next.js server from packages/turbo-graph/src/index.ts on all interfaces, including 0.0.0.0:29312 by defaul…

▾ MidnightDerYeger · yegerEPSS 0.49%via NVD
CVE-2026-57112High· 8.3PoC
1w ago

PraisonAI is a multi-agent teams system

PraisonAI is a multi-agent teams system. From praisonaiagents 0.6.0 until 1.6.59 and PraisonAI 3.10.0 until 4.6.59, ToolsMCPServer.run_sse() in src/praisonai-agents/praisonaiagents/mcp/mcp_server.py mounts SseServerTransport on the legac…

▾ MidnightMervinPraison · PraisonAIEPSS 0.22%via NVD
CVE-2026-49254Low· 2.9
1w ago

Dragonfly is an open source P2P-based file distribution and image acceleration system

Dragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.4.4, manager/router/router.go registers GET /api/v1/oauth and GET /api/v1/oauth/:id without jwt.MiddlewareFunc() or RBAC(), while manager/h…

▾ Sunlitdragonflyoss · dragonflyEPSS 0.48%via NVD
CVE-2026-55701Medium· 6.9
1w ago

The OpenTelemetry Collector Contrib repository contains components for the OpenTelemetry Collector

The OpenTelemetry Collector Contrib repository contains components for the OpenTelemetry Collector. Prior to 0.151.0, the githubreceiver validates the receiver/githubreceiver/config.go RequiredHeaders configuration at startup, but receiv…

▾ Sunlitopen-telemetry · opentelemetry-collector-contribEPSS 0.70%via NVD
CVE-2026-12763Medium· 4.2
1w ago

IBM Langflow OSS 1.0.0 through 1.11.5 could allow an authenticated attacker to access another user's MCP server context due to improper cache key isolation in the MCP Tools component.

IBM Langflow OSS 1.0.0 through 1.11.5 could allow an authenticated attacker to access another user's MCP server context due to improper cache key isolation in the MCP Tools component.

▾ SunlitIBM · Langflow OSSEPSS 0.15%via NVD
CVE-2026-90896High· 8.2
1w ago

Missing Authentication for Critical Function (CWE-306) in the checkout session lookup handler (src/app/api/stripe/checkout_sessions/route.ts), exposed at GET /api/stripe/checkout_sessions, in MarcosCamara01 Ecommerce Template before comm…

Missing Authentication for Critical Function (CWE-306) in the checkout session lookup handler (src/app/api/stripe/checkout_sessions/route.ts), exposed at GET /api/stripe/checkout_sessions, in MarcosCamara01 Ecommerce Template before comm…

▾ TwilightMarcosCamara01 · Ecommerce TemplateEPSS 0.71%via NVD
CVE-2026-90944High· 8.2PoC
1w ago

Krayin CRM through 2.2.6 exposes the POST /admin/mail/inbound-parse endpoint without authentication, allowing unauthenticated attackers to inject arbitrary emails into the CRM inbox

Krayin CRM through 2.2.6 exposes the POST /admin/mail/inbound-parse endpoint without authentication, allowing unauthenticated attackers to inject arbitrary emails into the CRM inbox. Attackers can supply crafted RFC 2822 messages with fo…

▾ Midnightkrayin · laravel-crmEPSS 0.66%via NVD
CVE-2026-59178Critical· 9.8
1w ago

ESPHome Device Builder Dashboard is a dashboard for the ESPHome home management software

ESPHome Device Builder Dashboard is a dashboard for the ESPHome home management software. Prior to version 1.0.12, the dashboard reads its authentication credentials from `$ESPHOME_USERNAME` and `$ESPHOME_PASSWORD`. Earlier versions, and…

▾ Midnightesphome · device-builderEPSS 0.78%via NVD
CVE-2026-90898Critical· 9.8PoC
1w ago

Bifrost registers MCP clients through its management API

Bifrost registers MCP clients through its management API. A stdio client is a command plus args. Bifrost starts that program in the gateway the moment the client is added. No MCP handshake required. The default is governance.auth_conf…

▾ Abyssalmaximhq · github.com/maximhq/bifrost/transportsEPSS 0.62%via NVD
CWE-306 vulnerabilities (CVEs) — page 6 · VulnSea