VulnSea

CWE-306

CVEs classified under CWE-306, newest first.

630 CVEsRSS

CVE-2026-86486Low· 3.7
2w ago

In JetBrains YouTrack before 2026.2.18634 the generic VCS webhook handler failed open when its secret was blank

In JetBrains YouTrack before 2026.2.18634 the generic VCS webhook handler failed open when its secret was blank

▾ SunlitJetBrains · YouTrackEPSS 0.26%via NVD
CVE-2026-86480Critical· 9.8
2w ago

In JetBrains Hub before 2026.2.52442 an unauthenticated attacker could register a trusted service and gain superuser privileges

In JetBrains Hub before 2026.2.52442 an unauthenticated attacker could register a trusted service and gain superuser privileges

▾ MidnightJetBrains · HubEPSS 0.50%via NVD
CVE-2026-79645High· 8.2
2w ago

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Missing Authentication for Critical Function vulnerability

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with remote access could po…

▾ Twilightdell · secure_connect_gatewayEPSS 0.41%via NVD
CVE-2026-78480High· 7.5
2w ago

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Missing Authentication for Critical Function vulnerability

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with remote access could po…

▾ Twilightdell · secure_connect_gatewayEPSS 0.55%via NVD
CVE-2026-80132High· 8.1
2w ago

ell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Missing Authentication for Critical Function vulnerability

ell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with remote access could pot…

▾ Twilightdell · secure_connect_gatewayEPSS 0.47%via NVD
CVE-2026-76578Critical· 9.8PoC
2w ago

A flaw was found in FreeIPA

A flaw was found in FreeIPA. The self-managed OTP token ACI does not require authentication and does not restrict which attributes may be added alongside the token entry. An unauthenticated LDAP client can exploit this, combined with a r…

▾ AbyssalRed Hat · ipaEPSS 0.96%via NVD
CVE-2026-86293Medium· 6.5PoC
2w ago

A flaw has been found in SourceCodester Simple Traffic Offense System 1.0

A flaw has been found in SourceCodester Simple Traffic Offense System 1.0. Affected by this vulnerability is an unknown functionality of the file delete-user.php of the component Deletion Endpoint. Executing a manipulation of the argumen…

▾ TwilightSourceCodester · Simple Traffic Offense SystemEPSS 0.76%via NVD
CVE-2026-86292High· 7.3PoC
2w ago

A vulnerability was detected in SourceCodester Simple Traffic Offense System 1.0

A vulnerability was detected in SourceCodester Simple Traffic Offense System 1.0. Affected is an unknown function of the file saveuser.php of the component User Creation. Performing a manipulation of the argument position results in miss…

▾ MidnightSourceCodester · Simple Traffic Offense SystemEPSS 0.69%via NVD
CVE-2026-16876Critical· 9.3
2w ago

An authentication bypass vulnerability exists in the WebGUI of Series UNIVERGE IX-R/IX-V

An authentication bypass vulnerability exists in the WebGUI of Series UNIVERGE IX-R/IX-V. A user could bypass authentication and execute arbitrary CLI commands by tampering with WebGUI messages and sending them to the device via internet.

▾ MidnightNEC Corporation · UNIVERGE IX-R/IX-VEPSS 0.33%via NVD
CVE-2026-86259High· 7.5PoC
3w ago

OpenMAIC before 1.0.1 skips server-side request forgery validation in non-production builds, allowing unauthenticated attackers to reach cloud instance metadata services

OpenMAIC before 1.0.1 skips server-side request forgery validation in non-production builds, allowing unauthenticated attackers to reach cloud instance metadata services. Attackers can supply arbitrary provider URLs via the x-base-url he…

▾ MidnightTHU-MAIC · OpenMAICEPSS 0.42%via NVD
CVE-2026-86242High· 8.1
3w ago

Bifrost HTTP transport before 2.0.0 accepts an enabled custom plugin whose path is an HTTP URL through unauthenticated POST /api/plugins when management authentication is disabled (the default, governance.auth_config.is_enabled=false)

Bifrost HTTP transport before 2.0.0 accepts an enabled custom plugin whose path is an HTTP URL through unauthenticated POST /api/plugins when management authentication is disabled (the default, governance.auth_config.is_enabled=false). T…

▾ Twilightmaximhq · github.com/maximhq/bifrost/transportsEPSS 1.1%via NVD
CVE-2026-67277High· 8.2CISA KEVPoC
3w ago

RouterOS accepts a "related" btest connection before the corresponding primary session has completed authentication

RouterOS accepts a "related" btest connection before the corresponding primary session has completed authentication. An unauthenticated client can use this state to start an IPv4 UDP test. With "random-data=false", the sender transmits a…

▾ Abyssalmikrotik · routerosEPSS 1.6%via NVD
CVE-2026-86184Critical· 9.8
3w ago

Lara Dashboard before 1.3.0 contains an authentication bypass vulnerability in the screenshot-login route that allows unauthenticated attackers to authenticate as any user by email when APP_ENV is not production

Lara Dashboard before 1.3.0 contains an authentication bypass vulnerability in the screenshot-login route that allows unauthenticated attackers to authenticate as any user by email when APP_ENV is not production. Attackers can request th…

▾ Midnightlaradashboard · laradashboardEPSS 1.1%via NVD
CVE-2026-86124Critical· 9.8
3w ago

AutoAgent contains an unauthenticated remote code execution vulnerability in the TCP server that binds to all interfaces and executes attacker-supplied commands as root

AutoAgent contains an unauthenticated remote code execution vulnerability in the TCP server that binds to all interfaces and executes attacker-supplied commands as root. Attackers can connect to the exposed communication port and execute…

▾ MidnightHKUDS · AutoAgentEPSS 0.98%via NVD
CVE-2026-86121Critical· 9.8PoC
3w ago

Cua computer-server versions before 0.3.42 skip authentication when the CONTAINER_NAME environment variable is unset and bind to all interfaces by default, allowing unauthenticated attackers to execute arbitrary commands

Cua computer-server versions before 0.3.42 skip authentication when the CONTAINER_NAME environment variable is unset and bind to all interfaces by default, allowing unauthenticated attackers to execute arbitrary commands. Attackers can r…

▾ Abyssaltrycua · cua-computer-serverEPSS 1.1%via NVD
CVE-2026-85688Critical· 9.8PoC
3w ago

TEN Framework 0.11.71 contains unauthenticated arbitrary file read and write vulnerabilities in the TMAN Designer file-content API endpoints

TEN Framework 0.11.71 contains unauthenticated arbitrary file read and write vulnerabilities in the TMAN Designer file-content API endpoints. Attackers can submit POST and PUT requests to the /api/designer/v1/file-content endpoints to re…

▾ AbyssalTEN-framework · ten-frameworkEPSS 2.6%via NVD
CVE-2026-85671High· 7.5
3w ago

QAnything 2.0.0 contains an authentication bypass vulnerability in the /api/local_doc_qa/get_file_base64 and /api/local_doc_qa/get_doc endpoints that allows unauthenticated attackers to access any uploaded file or document

QAnything 2.0.0 contains an authentication bypass vulnerability in the /api/local_doc_qa/get_file_base64 and /api/local_doc_qa/get_doc endpoints that allows unauthenticated attackers to access any uploaded file or document. Attackers can…

▾ Twilightnetease-youdao · QAnythingEPSS 0.64%via NVD
CVE-2026-85695Critical· 9.4
3w ago

FastChat contains an authentication bypass vulnerability in the /register_worker endpoint that allows unauthenticated attackers to register arbitrary worker addresses and perform server-side request forgery

FastChat contains an authentication bypass vulnerability in the /register_worker endpoint that allows unauthenticated attackers to register arbitrary worker addresses and perform server-side request forgery. Attackers can register malici…

▾ MidnightEPSS 0.72%via NVD
CVE-2026-85663Critical· 9.8
3w ago

Aim 3.29.1 remote tracking server fails to authenticate requests and dispatches arbitrary methods through getattr without allowlist validation

Aim 3.29.1 remote tracking server fails to authenticate requests and dispatches arbitrary methods through getattr without allowlist validation. Unauthenticated attackers can register clients, instantiate Repo resources, and invoke arbitr…

▾ MidnightEPSS 0.70%via NVD
CVE-2026-75430Critical· 9.8PoC
3w ago

PowerJob Worker version 5.1.2 (and likely earlier versions) exposes the /worker/deployContainer HTTP endpoint without authentication on the default transport port

PowerJob Worker version 5.1.2 (and likely earlier versions) exposes the /worker/deployContainer HTTP endpoint without authentication on the default transport port. This allows a remote attacker to execute arbitrary code.

▾ AbyssalEPSS 1.2%via NVD
CVE-2026-9317High· 8.1
3w ago

Nango before 0.71.6 contains a missing authentication vulnerability in the runner tRPC server that allows unauthenticated attackers to execute arbitrary JavaScript code by invoking the exposed start procedure without credentials

Nango before 0.71.6 contains a missing authentication vulnerability in the runner tRPC server that allows unauthenticated attackers to execute arbitrary JavaScript code by invoking the exposed start procedure without credentials. Attacke…

▾ TwilightNangoHQ · nangoEPSS 1.3%via NVD
CVE-2026-85667Critical· 9.1PoC
3w ago

xiaobei through 5.5.2 fails to implement authentication or signature validation on webhook endpoints, allowing unauthenticated attackers to inject arbitrary messages into the agent pipeline

xiaobei through 5.5.2 fails to implement authentication or signature validation on webhook endpoints, allowing unauthenticated attackers to inject arbitrary messages into the agent pipeline. Attackers can publish malicious messages via t…

▾ AbyssalTeamWiseFlow · xiaobeiEPSS 0.69%via NVD
CVE-2026-85702High· 7.3PoC
3w ago

A security vulnerability has been detected in ramon-victor freegpt-webui up to 098db3dfeb41555c2ca9269df0f13e10ec1c35dc

A security vulnerability has been detected in ramon-victor freegpt-webui up to 098db3dfeb41555c2ca9269df0f13e10ec1c35dc. Affected is the function _conversation of the file server/backend.py of the component Backend Conversation API. Such…

▾ Midnightramon-victor · freegpt-webuiEPSS 0.66%via NVD
CVE-2026-85701Medium· 5.3PoC
3w ago

A vulnerability has been found in ramon-victor freegpt-webui up to 098db3dfeb41555c2ca9269df0f13e10ec1c35dc

A vulnerability has been found in ramon-victor freegpt-webui up to 098db3dfeb41555c2ca9269df0f13e10ec1c35dc. This issue affects the function ChatCompletion.create of the file g4f/__init__.py of the component Authentication Check. Such ma…

▾ Twilightramon-victor · freegpt-webuiEPSS 0.63%via NVD
CVE-2026-85637Medium· 5.3
3w ago

A security flaw has been discovered in jofpin trape 1.0.0/2.0

A security flaw has been discovered in jofpin trape 1.0.0/2.0. Affected by this issue is the function join_room of the file core/sockets.py of the component Admin Endpoint. The manipulation results in missing authentication. The attack m…

▾ SunlitEPSS 0.74%via NVD
CVE-2026-79391Critical· 9.8
3w ago

No authentication exists in the MQTT service of Trueview 6.0.23.4

No authentication exists in the MQTT service of Trueview 6.0.23.4. The MQTT broker accepts client connections on TCP port 1883 without requiring authentication, allowing a remote attacker with network access to establish an MQTT session …

▾ MidnightEPSS 0.72%via NVD
CVE-2026-85636Medium· 5.3PoC
3w ago

A vulnerability was identified in jofpin trape 1.0.0

A vulnerability was identified in jofpin trape 1.0.0. Affected by this vulnerability is an unknown functionality of the file core/stats.py of the component Login Endpoint. The manipulation leads to missing authentication. The attack may …

▾ Twilightjofpin · trapeEPSS 0.75%via NVD
CVE-2026-17057Medium· 6.5
3w ago

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service and affect data integrity due to missing authentication for critical functions.

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service and affect data integrity due to missing authentication for critical functions.

▾ Sunlitibm · iEPSS 0.38%via NVD
CVE-2026-75754Critical· 10.0
3w ago

Missing Authentication for Critical Function, Server-Side Request Forgery (SSRF), and Use of Hard-coded Credentials in ASUS Control Center allow an unauthorized user to obtain the encryption key via an HTTP request, causing a local servi…

Missing Authentication for Critical Function, Server-Side Request Forgery (SSRF), and Use of Hard-coded Credentials in ASUS Control Center allow an unauthorized user to obtain the encryption key via an HTTP request, causing a local servi…

▾ MidnightASUS · Control Center Enterprise (ACC)EPSS 0.34%via NVD
GHSA-7q9c-hpx7-9cwmHigh· 7.5
3w ago

TypeSpec: Unauthenticated Remote Shutdown of Spector Mock Server via POST /.admin/stop

TypeSpec: Unauthenticated Remote Shutdown of Spector Mock Server via POST /.admin/stop

▾ Twilighttypespec · @typespec/spectorvia GHSA
CWE-306 vulnerabilities (CVEs) — page 9 · VulnSea