Skip to main content

CWE archive

CWE-306 CVEs

Programmatic archive

2,580 CVEs tagged with CWE-306941 Critical, 982 High, 608 Medium, 49 Low, 0 Unrated.

CVE-2026-56321

Published Jun 22, 2026

Capgo (backend Supabase edge functions) before 12.128.2 does not apply the global authentication middleware to the GET /private/role_bindings/:org_id endpoint, unlike the POST and…

CVSS 6.9 · Medium
evidence mentions
2
Buzz score
17.5

CVE-2026-41047

Published Jun 22, 2026

Lack of authentication when using the "snapshot diff" functions in qSnapper before version 1.3.3 allowed a local attacker to see otherwise read protected information.

CVSS 6.9 · Medium
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort

CVE-2026-6673

Published Jun 22, 2026

Mattermost versions 11.7.x <= 11.7.0, 11.6.x <= 11.6.2, 11.5.x <= 11.5.5, 10.11.x <= 10.11.17 fail to authenticate Atlassian Connect installed callbacks, allowing a remote unauthe…

CVSS 6.4 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-56299

Published Jun 21, 2026

Capgo before 12.128.2 contains an authentication bypass vulnerability in the /build/upload/:jobId/* endpoint that allows unauthenticated attackers to trigger consistent 500 errors…

CVSS 6.9 · Medium
evidence mentions
2
Buzz score
17.5

CVE-2026-12795

Published Jun 21, 2026

A vulnerability was determined in BerriAI litellm up to 1.82.2. This affects the function json.dumps of the file litellm/proxy/management_endpoints/ui_sso.py of the component SSO…

CVSS 5.5 · Medium
evidence mentions
5
Buzz score
24.4
Vendor/product tagsBeta · best-effort

CVE-2026-56346

Published Jun 20, 2026

AVideo through version 25.0 contains an authentication bypass vulnerability in the decryptMessage.json.php endpoint that allows unauthenticated users to decrypt PGP messages. Remo…

CVSS 6.9 · Medium
evidence mentions
2
Buzz score
17.5

CVE-2026-9142

Published Jun 19, 2026

There is an insecure default credentials vulnerability in NI grpc-device when TLS configuration is not present and the server is bound beyond loopback.  This may allow an unauthen…

CVSS 9.3 · Critical
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-49357

Published Jun 19, 2026

Line Desktop MCP is a project that, while unaffiliated with the official line-bot-mcp-server, allows users to directly operate the LINE Desktop application on Windows or Mac via M…

CVSS 8.8 · High
evidence mentions
2
Buzz score
16.0

CVE-2026-50242

Published Jun 19, 2026

In JetBrains Hub before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 authentication bypass via direct database access leading to adminis…

CVSS 10.0 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-12046

Published Jun 19, 2026

Two state-mutating endpoints in pgAdmin 4's SQL Editor blueprint -- DELETE /sqleditor/close/<trans_id> and POST /sqleditor/initialize/sqleditor/update_connection/<sgid>/<sid>/<did…

CVSS 9.5 · Critical
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-54130

Published Jun 18, 2026

Missing authentication for critical function in M365 Copilot allows an unauthorized attacker to disclose information over a network.

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-49257

Published Jun 18, 2026

mcp-pinot is a Python-based Model Context Protocol (MCP) server for interacting with Apache Pinot. In versions 3.0.1 and below, mcp-pinot defaults to running an HTTP MCP server bo…

CVSS 10.0 · Critical
evidence mentions
4
Buzz score
21.1

CVE-2026-54103

Published Jun 18, 2026

The U.S. Government Accountability Office (GAO) Electronic Protest Docketing System (EPDS) and Civilian Board of Contract Appeals (CBCA) Electronic Docketing System (EDS) does not…

CVSS 9.3 · Critical
evidence mentions
4
Buzz score
32.6

CVE-2026-12527

Published Jun 18, 2026

A broken authorization boundary in the RTSP media delivery pipeline of Shenzhen Liandian Communication Technology LTD V380 IP Camera firmware AppFHE1_V1.0.6.020230803 enables unau…

CVSS 6.0 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-48989

Published Jun 17, 2026

Windows-MCP is an open-source project that integrates AI agents with Windows. In versions prior to 0.7.5, certain HTTP modes exposed the MCP control plane without authentication w…

CVSS 8.9 · High
evidence mentions
2
Buzz score
16.0

CVE-2026-48814

Published Jun 17, 2026

Network-AI is a TypeScript/Node.js multi-agent orchestrator. In versions 5.7.1 and earlier, the MCP SSE server allows unauthenticated cross-origin MCP tool invocation due to an em…

CVSS 9.1 · Critical
evidence mentions
3
Buzz score
18.9

CVE-2026-55196

Published Jun 17, 2026

Hermes WebUI before 0.51.409 contains an authentication bypass vulnerability in passkey registration endpoints that allows unauthenticated remote attackers to register arbitrary p…

CVSS 9.1 · Critical
evidence mentions
5
Buzz score
24.4

CVE-2026-53869

Published Jun 17, 2026

Hermes Agent before 0.16.0 contains a DNS rebinding vulnerability in WebSocket endpoints that allows remote attackers to bypass Host and Origin validation. FastAPI HTTP middleware…

CVSS 8.7 · High
evidence mentions
5
Buzz score
24.4

CVE-2026-30799

Published Jun 17, 2026

Missing Authentication for Critical Function vulnerability in RTI Connext Professional (Security Plugins) allows Identity Spoofing.This issue affects Connext Professional: from 7.…

CVSS 6.1 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-2675

Published Jun 17, 2026

Missing Authentication for Critical Function vulnerability in RTI Connext Professional (Security Plugins) allows Fake the Source of Data.This issue affects Connext Professional: f…

CVSS 6.0 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-35065

Published Jun 17, 2026

Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with adjacent network acc…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-12199

Published Jun 17, 2026

A vulnerability in `nltk.app.wordnet_app` up to version 3.9.3 allows unauthenticated remote shutdown of the local WordNet Browser HTTP server when started in its default mode. The…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-46966

Published Jun 17, 2026

Vulnerability in the Oracle Universal Work Queue product of Oracle E-Business Suite (component: Work Provider Site Level Administration). Supported versions that are affected are…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort
Showing 151-175 of 2,580 CVEsPage 7 of 104