VulnSea

CWE-636

CVEs classified under CWE-636, newest first.

28 CVEsRSS

CVE-2026-77560High· 8.1
today

Tinyauth is an authentication and authorization server

Tinyauth is an authentication and authorization server. Prior to 5.1.2, Tinyauth compares forwarded hostnames case-sensitively while reverse proxies route equivalent hostnames case-insensitively, allowing an authenticated low-privilege u…

Twilighttinyauthapp · tinyauthvia NVD
CVE-2026-92591Medium· 5.9
5d ago

Craft CMS 5.0.0 through 5.10.12 treats a database connection failure as meaning that Craft is not installed, which makes anonymous installer actions — including install/validate-site — reachable on an installed production site whenever P…

Craft CMS 5.0.0 through 5.10.12 treats a database connection failure as meaning that Craft is not installed, which makes anonymous installer actions — including install/validate-site — reachable on an installed production site whenever P…

Sunlitcraftcms · cmsEPSS 0.24%via NVD
CVE-2026-61595High· 7.7
5d ago

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, `djust.tenants` isolation was enforced only on the HTTP path. The current tenant was stored in `thread…

Twilightdjust · djustEPSS 0.38%via NVD
CVE-2026-53459Critical· 9.3
6d ago

Bambuddy is a self-hosted print archive and management system for Bambu Lab 3D printers

Bambuddy is a self-hosted print archive and management system for Bambu Lab 3D printers. Starting in version 0.1.6 and prior to version 0.2.4.4, a fail-open in the authentication code allows any attacker to bypass authentication by flood…

Midnightmaziggy · bambuddyEPSS 0.42%via NVD
CVE-2026-77866Critical· 9.0
6d ago

Server-Side Request Forgery (SSRF) vulnerability in Slab safeurl allows an attacker who controls a validated URL to reach internal network destinations the library is configured to block. Only IPv4 addresses are matched against the rese…

Server-Side Request Forgery (SSRF) vulnerability in Slab safeurl allows an attacker who controls a validated URL to reach internal network destinations the library is configured to block. Only IPv4 addresses are matched against the rese…

MidnightSlab · safeurlEPSS 0.46%via NVD
CVE-2026-81379High· 8.2
1w ago

Not failing securely ('failing open') in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.

Not failing securely ('failing open') in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.

Twilightmicrosoft · visual_studio_codeEPSS 0.32%via NVD
CVE-2026-86120Medium· 4.3
2w ago

APITable through 1.13.0-beta.1 contains an incorrect authorization vulnerability in NodePermissionGuard that fails to enforce node-level access control when permission lookups throw exceptions

APITable through 1.13.0-beta.1 contains an incorrect authorization vulnerability in NodePermissionGuard that fails to enforce node-level access control when permission lookups throw exceptions. Attackers with valid Fusion API tokens can …

Sunlitapitable · apitableEPSS 0.21%via NVD
CVE-2026-85649High· 7.9PoC
2w ago

(Holloway) Chew, Kean Ho's Actualizer v1.2.0 and earlier contains a fail-open password validation vulnerability in the Alpha user and root user password loops of Shell/debian-minbase-install.sh

(Holloway) Chew, Kean Ho's Actualizer v1.2.0 and earlier contains a fail-open password validation vulnerability in the Alpha user and root user password loops of Shell/debian-minbase-install.sh. The installer invokes mkpasswd to generate…

MidnightEPSS 0.21%via NVD
GHSA-73p9-6hrp-8qhrMedium
3w ago

AIIR verification and policy gates could report success without enforcing the control (fail-open)

AIIR verification and policy gates could report success without enforcing the control (fail-open)

Sunlitaiir · aiirvia GHSA
CVE-2026-46482Medium· 5.3
1mo ago

### Impact The registration component does not validate the text-based _Security Question_ CAPTCHA correctly, allowing attackers to bypass the challenge via a specially crafted value. [CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N](http…

### Impact The registration component does not validate the text-based _Security Question_ CAPTCHA correctly, allowing attackers to bypass the challenge via a specially crafted value. [CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N](http…

SunlitEPSS 0.33%via NVD
CVE-2026-73421None
1mo ago

NextAuth.js provides authentication for Next.js

NextAuth.js provides authentication for Next.js. From next-auth 5.0.0-beta.0 until 5.0.0-beta.32, applications that gate access by checking only for the existence of the auth object returned by the auth() wrapper can fail open when Auth.…

SunlitEPSS 0.46%via NVD
CVE-2026-70452High· 7.4
1mo ago

rsync 3.1.0 before 3.5.0 contains an access control bypass vulnerability that allows remote attackers to circumvent hosts deny rules by inducing DNS resolution failures during hostname-based access control evaluation

rsync 3.1.0 before 3.5.0 contains an access control bypass vulnerability that allows remote attackers to circumvent hosts deny rules by inducing DNS resolution failures during hostname-based access control evaluation. When a DNS lookup f…

TwilightRed Hat · Red Hat Enterprise Linux BaseOS (v. 10)EPSS 0.46%via NVD
CVE-2026-69306High· 8.2
1mo ago

Not failing securely ('failing open') in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.

Not failing securely ('failing open') in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.

Twilightmicrosoft · visual_studio_codeEPSS 0.41%via NVD
GHSA-hc4m-q9jh-xw4jMedium· 6.6
1mo ago

nono-cli'scregistry pack verification can fail open when provenance metadata is absent

nono-cli'scregistry pack verification can fail open when provenance metadata is absent

Sunlitnono-cli · nono-clivia GHSA
GHSA-8fpg-xm3f-6cx3Critical
2mo ago

Auth.js: Configuration errors can cause existence-based auth checks to fail open (auth object populated with an error)

Auth.js: Configuration errors can cause existence-based auth checks to fail open (auth object populated with an error)

Midnightnext-auth · next-authvia GHSA
GHSA-whvh-wf3x-g77jLow
2mo ago

JupyterLab: Allowlist/blocklist check in `PyPIExtensionManager.install()` not enforced for direct callers (missing `await`)

JupyterLab: Allowlist/blocklist check in `PyPIExtensionManager.install()` not enforced for direct callers (missing `await`)

Sunlitjupyterlab · jupyterlabvia GHSA
CVE-2026-54291High
2mo ago

PostgreSQL JDBC Driver: Silent channel-binding authentication downgrade via unsupported certificate algorithms

PostgreSQL JDBC Driver: Silent channel-binding authentication downgrade via unsupported certificate algorithms

Twilightpostgresql · org.postgresql:postgresqlEPSS 0.24%via GHSA
CVE-2026-50528High· 8.2
2mo ago

.NET Security Feature Bypass Vulnerability

Incorrect authorization in .NET allows an unauthorized attacker to bypass a security feature over a network.

TwilightMicrosoft · .NET 10.0EPSS 0.56%via CVEORG
GHSA-gp79-m99v-gjmhMedium
2mo ago

OpenClaw: Mattermost handlers could fall open when channel type was missing

OpenClaw: Mattermost handlers could fall open when channel type was missing

Sunlitopenclaw · openclawvia GHSA
CVE-2026-53712High
2mo ago

OnGres SCRAM silent channel-binding authentication downgrade via unsupported certificate algorithms

OnGres SCRAM silent channel-binding authentication downgrade via unsupported certificate algorithms

Twilightongres · com.ongres.scram:scram-clientEPSS 0.26%via GHSA
CVE-2026-55568Medium· 5.9
3mo ago

guzzlehttp/guzzle: Silent HTTPS-Proxy Downgrade to Cleartext

guzzlehttp/guzzle: Silent HTTPS-Proxy Downgrade to Cleartext

Sunlitguzzlehttp · guzzlehttp/guzzleEPSS 0.15%via GHSA
CVE-2026-54762High· 8.6
3mo ago

Traefik Kubernetes Ingress NGINX provider fails open when auth-secret resolution fails

Traefik Kubernetes Ingress NGINX provider fails open when auth-secret resolution fails

Twilighttraefik · github.com/traefik/traefik/v3EPSS 0.43%via OSV
CVE-2026-53852Low· 5.4
3mo ago

OpenClaw: Empty-scope device re-pairing could confuse caller scope containment

OpenClaw: Empty-scope device re-pairing could confuse caller scope containment

Sunlitopenclaw · openclawEPSS 0.21%via GHSA
GHSA-hc4w-hm59-9w88Low· 5.4
3mo ago

Duplicate Advisory: Empty-scope device re-pairing could confuse caller scope containment

Duplicate Advisory: Empty-scope device re-pairing could confuse caller scope containment

Sunlitopenclaw · openclawvia GHSA
CVE-2026-42246High· 7.4
4mo ago

Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby

Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to versions 0.3.10, 0.4.24, 0.5.14, and 0.6.4, a man-in-the-middle attacker can cause Net::IMAP#starttls to return "successfully", without s…

Twilightruby-lang · net::imapEPSS 0.31%via NVD
CVE-2026-32970Low· 2.5
5mo ago

OpenClaw before 2026.3.11 contains a credential fallback vulnerability where unavailable local gateway.auth.token and gateway.auth.password SecretRefs are treated as unset, allowing fallback to remote credentials in local mode

OpenClaw before 2026.3.11 contains a credential fallback vulnerability where unavailable local gateway.auth.token and gateway.auth.password SecretRefs are treated as unset, allowing fallback to remote credentials in local mode. Attackers…

Sunlitopenclaw · openclawEPSS 0.10%via NVD
CVE-2023-28840High· 7.5
3y ago

Moby is an open source container framework developed by Docker Inc

Moby is an open source container framework developed by Docker Inc. that is distributed as Docker, Mirantis Container Runtime, and various other downstream projects/products. The Moby daemon component (`dockerd`), which is developed as m…

Twilightmobyproject · mobyEPSS 2.6%via NVD
CVE-2023-28841Medium· 6.8
3y ago

Moby is an open source container framework developed by Docker Inc

Moby is an open source container framework developed by Docker Inc. that is distributed as Docker, Mirantis Container Runtime, and various other downstream projects/products. The Moby daemon component (`dockerd`), which is developed as m…

Sunlitmobyproject · mobyEPSS 0.69%via NVD
CWE-636 vulnerabilities (CVEs) · VulnSea