Skip to main content

CWE archive

CWE-287 CVEs

Programmatic archive

4,556 CVEs tagged with CWE-2871,243 Critical, 1,614 High, 1,551 Medium, 146 Low, 2 Unrated.

CVE-2026-13690

Published Jul 29, 2026

The UsersWP WordPress plugin before 1.2.67 does not validate the selected authentication provider in its two-factor login handler, allowing an attacker who already knows a user's…

CVSS 7.4 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-49447

Published Jul 28, 2026

Cosmos provides users the ability self-host a home server by acting as a secure gateway to your application, as well as a server manager. In 0.22.18, `GET /cosmos/api/constellatio…

CVSS 5.3 · Medium
evidence mentions
3
Buzz score
18.9

CVE-2026-54635

Published Jul 28, 2026

pytonapi is a Python SDK for TONAPI that provides REST API, streaming, and webhook access to the TON blockchain. From 2.0.0 to 2.2.0, TonapiWebhookDispatcher fails to validate the…

CVSS 7.5 · High
evidence mentions
3
Buzz score
18.9

CVE-2026-64745

Published Jul 27, 2026

This issue was addressed with additional restrictions on the lock screen. This issue is fixed in macOS Sequoia 15.7.8, macOS Tahoe 26.6. A person with physical access to a locked…

CVSS 2.4 · Low
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-43766

Published Jul 27, 2026

An authorization issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An attacker with physical…

CVSS 4.6 · Medium
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2026-66014

Published Jul 27, 2026

JFrog Artifactory contains an authentication handling weakness in internal request processing that, under specific conditions, may allow an attacker to escalate privileges beyond…

CVSS 8.8 · High
evidence mentions
4
Buzz score
27.6

CVE-2026-9830

Published Jul 27, 2026

The bookingpress-appointment-booking-pro WordPress plugin before 5.7.3 does not correctly invoke its REST permission callback, leaving every route in one of its API namespaces rea…

CVSS 8.2 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-14568

Published Jul 27, 2026

The User Frontend: AI Powered Frontend Post Submission, User Directory, User Profile, Membership & User Registration WordPress plugin before 4.3.8 does not correctly verify owners…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-13597

Published Jul 27, 2026

The 微信二维码登陆 WordPress plugin through 1.3 does not properly validate WeChat webhook requests, as its signature check always passes, and it discloses the generated login code in the…

CVSS 9.1 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-13332

Published Jul 27, 2026

The Masteriyo LMS WordPress plugin before 2.3.1 does not correctly verify authorization on an unauthenticated AJAX action used to clear user sessions, allowing unauthenticated at…

CVSS 9.1 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-12493

Published Jul 27, 2026

The Clover Payment Gateway by Zaytech for WooCommerce WordPress plugin before 1.3.6 does not verify that an approved external payment record actually belongs to the WooCommerce or…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-12255

Published Jul 27, 2026

The MainWP Child WordPress plugin before 6.1.2 does not verify the requester's identity in its site-registration request handler when password authentication has been disabled fo…

CVSS 8.1 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-12504

Published Jul 24, 2026

Improper Authentication (CWE-287) in the PAM configuration in Loytec LIP-ME201C, L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS and L-PAD through 8.4.16 on LINX-A64 allows a local att…

CVSS 8.4 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-12877

Published Jul 24, 2026

The Project Management, Bug and Issue Tracking Plugin WordPress plugin before 5.1.0 does not sanitise and escape user supplied input before using it in a SQL query, allowing unau…

CVSS 9.1 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-62825

Published Jul 24, 2026

Improper authentication in Azure Key Vault allows an unauthorized attacker to elevate privileges over a network.

CVSS 10.0 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-56191

Published Jul 24, 2026

Improper authentication in Microsoft Exchange Online allows an unauthorized attacker to perform tampering over a network.

CVSS 10.0 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-15981

Published Jul 23, 2026

The SAML Single Sign On – SSO Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 5.4.4. This is due to the mo_saml_validate_si…

CVSS 9.8 · Critical
evidence mentions
7
Buzz score
27.3

CVE-2026-10697

Published Jul 23, 2026

Improper Authentication vulnerability in Progress MOVEit Transfer. This issue affects MOVEit Transfer: before 2025.1.5, from 2026.0.0 before 2026.0.3.

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-15611

Published Jul 23, 2026

Logto allows unverified email-based SSO account linking, enabling an attacker to register an identity at a permissive IdP using a victim’s email and gain unauthorized access to th…

CVSS 9.1 · Critical
evidence mentions
3
Buzz score
23.9

CVE-2026-15348

Published Jul 23, 2026

The Premium Packages – Sell Digital Products Securely plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 7.0.4 via the `wpdmppdl` pa…

CVSS 6.3 · Medium
evidence mentions
12
Buzz score
32.1

CVE-2026-14291

Published Jul 23, 2026

The security-ninja-premium WordPress plugin before 5.290 does not verify the second authentication factor in one of its two-factor authentication code paths, allowing an unauthent…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-62144

Published Jul 22, 2026

An authentication bypass vulnerability in Check Point Security Management and Multi-Domain Security Management allows an unauthenticated remote attacker to execute administrative…

CVSS 9.1 · Critical
evidence mentions
4
Buzz score
32.6

CVE-2026-62547

Published Jul 21, 2026

Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (component: Workflow Notification Mailer). Supported versions that are affected are 12.2.3-12.2.15. Diffic…

CVSS 8.1 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort
Showing 1-25 of 4,556 CVEsPage 1 of 183