VulnSea

CWE-306

CVEs classified under CWE-306, newest first.

630 CVEsRSS

CVE-2026-82787Critical· 9.8
1w ago

Missing authentication for critical function vulnerability exists in CPSL-08P1EN

Missing authentication for critical function vulnerability exists in CPSL-08P1EN. If this vulnerability is exploited, an affected product may be operated by a remote attacker without authentication.

▾ MidnightContec Co., Ltd. · CPSL-08P1ENEPSS 0.67%via NVD
CVE-2026-82784Medium· 6.5
1w ago

Missing authentication for critical function vulnerability exists in Remote I/O Coupler Unit (Server Type) CPSN-MCB271-*

Missing authentication for critical function vulnerability exists in Remote I/O Coupler Unit (Server Type) CPSN-MCB271-*. An attacker may execute a REST API without authentication, which could allow the attacker to retrieve I/O values an…

▾ SunlitContec Co., Ltd. · Remote I/O Coupler Unit (Server Type) CPSN-MCB271-*EPSS 0.34%via NVD
CVE-2026-90620High· 7.3PoC
1w ago

A vulnerability was determined in 0x4m4 HexStrike AI up to d689933ff579d839c676c82b231f8e98326c5f04

A vulnerability was determined in 0x4m4 HexStrike AI up to d689933ff579d839c676c82b231f8e98326c5f04. The impacted element is an unknown function of the file hexstrike_server.py of the component API Command Endpoint. This manipulation cau…

▾ Midnight0x4m4 · HexStrike AIEPSS 0.65%via NVD
CVE-2026-90938High· 8.6PoC
1w ago

LangBot's plugin runtime (pip package langbot_plugin) through 0.4.17 starts a debug WebSocket server on 0.0.0.0:5401 (/plugin/ws) whose authentication is gated on plugin_debug_key, which defaults to an empty string and is never set by th…

LangBot's plugin runtime (pip package langbot_plugin) through 0.4.17 starts a debug WebSocket server on 0.0.0.0:5401 (/plugin/ws) whose authentication is gated on plugin_debug_key, which defaults to an empty string and is never set by th…

▾ Midnightlangbot-app · LangBotEPSS 0.57%via NVD
CVE-2026-57123Critical· 9.8
1w ago

PraisonAI is a multi-agent teams system

PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.59, ToolsMCPServer.run_sse and launch_tools_mcp_server bind to 0.0.0.0 and create /sse and /messages/ routes without invoking the available SecurityConfig authenticati…

▾ MidnightMervinPraison · praisonaiagentsEPSS 0.90%via NVD
CVE-2026-57124Critical· 9.8PoC
1w ago

PraisonAI is a multi-agent teams system

PraisonAI is a multi-agent teams system. Prior to 4.6.59, the default UI host applications expose POST /api/mcp/connect without mandatory authentication and accept caller-controlled command and args values that PraisonAIUI passes to Stdi…

▾ AbyssalMervinPraison · PraisonAIEPSS 1.0%via NVD
CVE-2026-57127Critical· 9.8PoC
1w ago

PraisonAI is a multi-agent teams system

PraisonAI is a multi-agent teams system. Prior to 4.6.58, recipe serve installs APIKeyAuthMiddleware or JWTAuthMiddleware when an operator selects api-key or JWT authentication, but each middleware forwards requests when PRAISONAI_API_KE…

▾ AbyssalMervinPraison · PraisonAIEPSS 0.90%via NVD
CVE-2026-57131Critical· 9.8PoC
1w ago

PraisonAI is a multi-agent teams system

PraisonAI is a multi-agent teams system. Prior to 4.6.58, praisonai.jobs.server.create_app mounts praisonai.jobs.router.create_router under /api/v1/runs without authentication or per-job authorization. Network clients can submit attacker…

▾ AbyssalMervinPraison · PraisonAIEPSS 0.97%via NVD
CVE-2026-57125Critical· 9.8PoC
1w ago

PraisonAI is a multi-agent teams system

PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.59 and praisonaiagents 1.6.59, the unauthenticated POST /api/v1/runs Jobs API accepts attacker-controlled agent_yaml, and the approve field can mark execute_command as YAML-…

▾ AbyssalMervinPraison · PraisonAIEPSS 0.60%via NVD
CVE-2026-57128Medium· 4.3PoC
1w ago

PraisonAI is a multi-agent teams system

PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.58, the SSE server in src/praisonai-agents/praisonaiagents/server/server.py does not consult ServerConfig.auth_token before handling /publish, /events, or /info reques…

▾ TwilightMervinPraison · PraisonAIEPSS 0.25%via NVD
CVE-2026-54246Medium· 5.7
1w ago

Skipper is an HTTP router and reverse proxy for service composition

Skipper is an HTTP router and reverse proxy for service composition. Prior to 0.27.13, the routesrv component serves cluster-wide control-plane data without application-layer authentication through /routes, /routes/{zone}, /swarm/redis/s…

▾ Sunlitzalando · skipperEPSS 0.34%via NVD
CVE-2026-53714High· 7.4
1w ago

Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway

Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway. Prior to 1.7.4 and 1.8.1, the xDS gRPC server in GatewayNamespaceMode, configured through provider.kubernetes.deplo…

▾ Twilightenvoyproxy · gatewayEPSS 0.35%via NVD
CVE-2026-55837Medium· 6.8PoC
1w ago

dbt-mcp is a Model Context Protocol server for interacting with dbt

dbt-mcp is a Model Context Protocol server for interacting with dbt. Prior to 1.20.0, the local OAuth helper in src/dbt_mcp/oauth/fastapi_app.py exposes GET /dbt_platform_context without authentication or Host validation after a user com…

▾ Twilightdbt-labs · dbt-mcpEPSS 0.27%via NVD
CVE-2026-90504High· 7.3PoC
2w ago

A vulnerability has been found in vvbbnn00 WARP-Clash-API up to c7bf2360073959861219b422e51ae86411051b46

A vulnerability has been found in vvbbnn00 WARP-Clash-API up to c7bf2360073959861219b422e51ae86411051b46. The impacted element is the function authorized. The manipulation of the argument SECRET_KEY leads to missing authentication. The a…

▾ Midnightvvbbnn00 · WARP-Clash-APIEPSS 0.65%via NVD
CVE-2026-90513Medium· 6.5
2w ago

A flaw has been found in simalexan api-lambda-send-email-ses up to bda6869aa81371d1e872242e74fe7d953edb818d

A flaw has been found in simalexan api-lambda-send-email-ses up to bda6869aa81371d1e872242e74fe7d953edb818d. This issue affects the function SES.sendEmail of the file template.yml of the component API Gateway Endpoint. This manipulation …

▾ Sunlitsimalexan · api-lambda-send-email-sesEPSS 0.76%via NVD
CVE-2026-90524High· 7.3PoC
2w ago

A security flaw has been discovered in jaychouchannel Tourism-Management-System up to 229956e20dbd4a80eeff14535e44d3099502af09

A security flaw has been discovered in jaychouchannel Tourism-Management-System up to 229956e20dbd4a80eeff14535e44d3099502af09. The impacted element is an unknown function of the component Update Endpoint. Performing a manipulation resul…

▾ Midnightjaychouchannel · Tourism-Management-SystemEPSS 0.69%via NVD
CVE-2026-90579High· 7.3PoC
2w ago

A vulnerability has been found in cheshire-cat-ai Cheshire Cat AI up to 1.9.2

A vulnerability has been found in cheshire-cat-ai Cheshire Cat AI up to 1.9.2. This affects the function _authorize_http_key of the file core/cat/factory/custom_auth_handler.py. The manipulation of the argument user_id leads to missing a…

▾ Midnightcheshire-cat-ai · Cheshire Cat AIEPSS 0.65%via NVD
CVE-2026-90543Medium· 5.3PoC
2w ago

WWBN AVideo at commit c3edcc274c389816d434acadac07ee78eaf330c1 and earlier, with the Live plugin enabled, contains a missing authentication vulnerability in plugin/Live/socketMessageLiveOwner.json.php

WWBN AVideo at commit c3edcc274c389816d434acadac07ee78eaf330c1 and earlier, with the Live plugin enabled, contains a missing authentication vulnerability in plugin/Live/socketMessageLiveOwner.json.php. The script reads the `key` and `msg…

▾ TwilightWWBN · AVideoEPSS 0.60%via NVD
CVE-2026-50025Medium· 6.9
2w ago

Mousehole is a background service to update a seedbox IP for MAM and web app to manage it

Mousehole is a background service to update a seedbox IP for MAM and web app to manage it. Prior to version 0.4.05, Mousehole's HTTP/WebSocket management boundary is reachable without application-layer authentication or browser/LAN prove…

▾ Sunlitt-mart · mouseholeEPSS 0.26%via NVD
CVE-2026-90449Medium· 6.9
2w ago

When a particular authentication mode is configured, the reverse proxy forwards requests for a bundled third-party administrative interface directly to that interface without applying the gateway's own authentication requirement first

When a particular authentication mode is configured, the reverse proxy forwards requests for a bundled third-party administrative interface directly to that interface without applying the gateway's own authentication requirement first. A…

▾ SunlitCISA · MalcolmEPSS 0.54%via NVD
CVE-2026-89261Medium· 6.5PoC
2w ago

MoguBlog through 6.2 Missing Authentication for Elasticsearch Index Management Endpoints

MoguBlog through 6.2 exposes Elasticsearch index management endpoints in the mogu_search service without authentication, allowing remote attackers to delete, recreate, or alter the blog search index. Attackers can invoke POST endpoints t…

▾ Twilightmoxi624 · MoguBlogEPSS 0.83%via CVEORG
CVE-2026-53952Critical· 9.8
2w ago

GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS

GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS. A logic flaw in GetSimple CMS (v3.4.0a and below) and GetSimpleCMS-CE (v3.3.22 and below) allows unauthenticated attackers to …

▾ MidnightGetSimpleCMS-CE · GetSimpleCMS-CEEPSS 0.55%via NVD
CVE-2026-89250High· 7.5PoC
2w ago

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains an unauthenticated file read vulnerability in the getRecordedFile.php endpoint that streams recorded FLV files from the temporary directory

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains an unauthenticated file read vulnerability in the getRecordedFile.php endpoint that streams recorded FLV files from the temporary directory. Attackers can reque…

▾ MidnightWWBN · AVideoEPSS 0.50%via NVD
CVE-2026-80462Critical· 10.0
2w ago

A vulnerability in the Chef Automate API gateway and identity validation path may allow an unauthenticated actor to gain elevated access to protected Chef Automate functionality under specific conditions.

A vulnerability in the Chef Automate API gateway and identity validation path may allow an unauthenticated actor to gain elevated access to protected Chef Automate functionality under specific conditions.

▾ MidnightProgress Software · Chef AutomateEPSS 0.48%via NVD
CVE-2026-89263Medium· 5.3PoC
2w ago

MoguBlog through 6.2 fails to authenticate requests to the /web/comment/closeEmailNotification endpoint, allowing unauthenticated attackers to disable email notifications for arbitrary users

MoguBlog through 6.2 fails to authenticate requests to the /web/comment/closeEmailNotification endpoint, allowing unauthenticated attackers to disable email notifications for arbitrary users. Remote callers can modify the startEmailNotif…

▾ Twilightmoxi624 · MoguBlogEPSS 0.45%via NVD
CVE-2026-89176High· 8.8
2w ago

WeenyGenius, a computer lab management system developed by Howyar Technologies, has a Missing Authentication vulnerability

WeenyGenius, a computer lab management system developed by Howyar Technologies, has a Missing Authentication vulnerability. Unauthenticated attackers on the same network can easily spoof student or teacher endpoints. Impersonating a stud…

▾ TwilightHowyar · WeenyGeniusEPSS 0.40%via NVD
CVE-2026-88018Critical· 9.8PoC
2w ago

rclone is a command-line program to sync files and directories to and from different cloud storage providers

rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.75.1, rclone serve s3 configured with --auth-proxy but without --auth-key allows authPairMiddleware to register any …

▾ Abyssalrclone · rcloneEPSS 0.75%via NVD
CVE-2026-88062Critical· 9.5PoC
2w ago

OmniRoute ACP Custom-Agent Remote Code Execution (RCE)

OmniRoute is an open-source AI gateway providing a single endpoint for multiple model providers. In 3.8.49 and earlier, the OmniRoute POST /api/acp/agents custom ACP agent endpoint accepted attacker-controlled binary and versionCommand v…

▾ Abyssaldiegosouzapw · OmniRouteEPSS 1.4%via CVEORG
CVE-2026-67593Critical· 9.1
2w ago

A remote attacker can craft an Openwire RemoveSubscriptionInfo command to cause the deletion of a queue on the Artemis broker before the connection authentication and authorization stage or at any time thereafter

A remote attacker can craft an Openwire RemoveSubscriptionInfo command to cause the deletion of a queue on the Artemis broker before the connection authentication and authorization stage or at any time thereafter. This issue affects …

▾ Midnightapache · artemisEPSS 0.86%via NVD
CVE-2026-49362High· 7.5
2w ago

An unauthenticated remote attacker can create arbitrary durable queues via the CORE protocol, leading to unauthorized broker state manipulation and potential denial of service. This issue affects Apache Artemis: from 2.50.0 through 2.56…

An unauthenticated remote attacker can create arbitrary durable queues via the CORE protocol, leading to unauthorized broker state manipulation and potential denial of service. This issue affects Apache Artemis: from 2.50.0 through 2.56…

▾ Twilightapache · artemisEPSS 0.82%via NVD
CWE-306 vulnerabilities (CVEs) — page 7 · VulnSea