Skip to main content

CWE archive

CWE-1390 CVEs

Programmatic archive

86 CVEs tagged with CWE-139024 Critical, 33 High, 25 Medium, 4 Low, 0 Unrated.

CVE-2026-59554

Published Jul 23, 2026

Unauthenticated Broken Authentication in Ziina <= 1.2.21 versions.

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-50756

Published Jul 21, 2026

An issue in DayuanJiang next-ai-draw-io 0.4.13 allows a remote attacker to obtain sensitive information via the x-ai-provider component

CVSS 7.5 · High
evidence mentions
2
Buzz score
16.0

CVE-2026-55040

Published Jul 14, 2026

Weak authentication in Microsoft Office SharePoint allows an unauthorized attacker to bypass a security feature over a network.

CVSS 9.1 · Critical
evidence mentions
16
Buzz score
48.3
Vendor/product tagsBeta · best-effort

CVE-2026-10714

Published Jul 14, 2026

A security issue exists within FactoryTalk® Services Platform (FTSP), allowing an attacker to bypass JWT signature validation during Okta Web Authentication. The vulnerability ste…

CVSS 8.8 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-57352

Published Jul 2, 2026

Unauthenticated Broken Authentication in ALD – Dropshipping and Fulfillment for AliExpress and WooCommerce <= 2.2.0 versions.

CVSS 4.8 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2026-6274

Published Jun 5, 2026

Improper Authentication, Missing authentication for critical function, Weak Authentication vulnerability in DTS Electronics Industry and Trade Ltd. Co. Redline WR3200 allows Acces…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
21.0

CVE-2026-44237

Published May 29, 2026

FreePBX is an open source IP PBX. Prior to 17.0.8, the FreePBX api module's OAuth2 implementation does not sufficiently validate client credentials during token issuance. Knowledg…

CVSS 7.6 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-49323

Published May 29, 2026

Weak authentication between the Wireless Control Module (WCM) and the Engine Control Module (ECM) of the Indian Motorcycle Scout Bobber + Tech 2025 model year allows an adjacent-n…

CVSS 4.1 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-49322

Published May 29, 2026

Weak authentication in the Wireless Control Module (WCM) of the Indian Motorcycle Scout Bobber + Tech 2025 model year allows an adjacent-network attacker with read access to the i…

CVSS 4.1 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2025-70994

Published Apr 23, 2026

Yadea T5 Electric Bicycles (models manufactured in/after 2024) have a weak authentication mechanism in their keyless entry system. The system utilizes the EV1527 fixed-code RF pro…

CVSS 7.3 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-6886

Published Apr 23, 2026

Borg SPM 2007 (Sales Ended in 2008) developed by BorG Technology Corporation has a Authentication Bypass vulnerability, allowing unauthenticated remote attackers to log into the s…

CVSS 9.3 · Critical
evidence mentions
2
Buzz score
16.0

CVE-2026-4924

Published Apr 1, 2026

Improper authentication in the two-factor authentication (2FA) feature in Devolutions Server 2026.1.11 and earlier allows a remote attacker with valid credentials to bypass mul…

CVSS 8.2 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-4828

Published Apr 1, 2026

Improper authentication in the OAuth login functionality in Devolutions Server 2026.1.11 and earlier allows a remote attacker with valid credentials to bypass multi-factor authent…

CVSS 8.2 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-32497

Published Mar 25, 2026

Weak Authentication vulnerability in PickPlugins User Verification user-verification allows Authentication Abuse.This issue affects User Verification: from n/a through <= 2.0.45.

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2025-62844

Published Mar 20, 2026

A weak authentication vulnerability has been reported to affect QHora. If an attacker gains local network access, they can then exploit the vulnerability to gain sensitive informa…

CVSS 4.0 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-27478

Published Mar 11, 2026

Unity Catalog is an open, multi-modal Catalog for data and AI. In 0.4.0 and earlier, a critical authentication bypass vulnerability exists in the Unity Catalog token exchange endp…

CVSS 9.1 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-15595

Published Mar 3, 2026

Privilege escalation via dll hijacking in Inno Setup 6.2.1 and ealier versions.

CVSS 5.7 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-1693

Published Feb 26, 2026

The OAuth grant type Resource Owner Password Credentials (ROPC) flow is still used by the werbservices used by the WebVue, WebScheduler, TouchVue and Snapvue features of PcVue in…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-57713

Published Feb 11, 2026

A weak authentication vulnerability has been reported to affect File Station 5. The remote attackers can then exploit the vulnerability to gain sensitive information. We have alr…

CVSS 1.3 · Low
Vendor/product tagsBeta · best-effort
Showing 1-25 of 86 CVEsPage 1 of 4