Skip to main content

CWE archive

CWE-287 CVEs

Programmatic archive

4,492 CVEs tagged with CWE-2871,229 Critical, 1,570 High, 1,547 Medium, 144 Low, 2 Unrated.

CVE-2026-44058

Published May 21, 2026

An authentication bypass vulnerability in Netatalk 2.2.2 through 4.4.2 allows a remote privileged user to authenticate as an arbitrary user via the admin auth user mechanism.

CVSS 7.2 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-40165

Published May 21, 2026

authentik is an open-source identity provider. Versions 2025.12.4 and prior, and versions 2026.2.0-rc1 through 2026.2.2 were vulnerable to Authentication Bypass through SAML NameI…

CVSS 8.7 · High
evidence mentions
3
Buzz score
18.9

CVE-2026-9084

Published May 20, 2026

MISP’s OIDC authentication plugin allowed automatic linking of an OIDC identity to an existing local user account based on the email claim when the local account had no stored sub…

CVSS 6.0 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-6456

Published May 20, 2026

The Account Switcher plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.0.2. This is due to the `rememberLogin` REST API endpoint u…

CVSS 8.8 · High
evidence mentions
4
Buzz score
31.1

CVE-2026-36829

Published May 19, 2026

An authentication bypass vulnerability exists in the embedded HTTP server of Panabit PAP-XM320 up to and including v7.7. The server validates session cookies using a filesystem ex…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
17.5

CVE-2026-45434

Published May 19, 2026

Improper Authentication vulnerability in Apache OFBiz via Password-Change Logic Flaw Leading to Remote Code Execution This issue affects Apache OFBiz: before 24.09.06. Users are…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-31387

Published May 19, 2026

Improper Authentication vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade to version 24.09.06, which fixes the is…

CVSS 5.3 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-8737

Published May 17, 2026

A weakness has been identified in Sanluan PublicCMS 5.202506.d. This issue affects the function execute of the file publiccms-trade/src/main/java/com/publiccms/views/directive/tra…

CVSS 5.5 · Medium
evidence mentions
4
Buzz score
26.1

CVE-2026-44551

Published May 15, 2026

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, the LDAP authentication endpoint does not validate that the subm…

CVSS 9.1 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-5229

Published May 15, 2026

The Form Notify plugin for WordPress is vulnerable to Authentication Bypass in versions up to and including 1.1.10. This is due to the plugin trusting user-controlled cookie data…

CVSS 9.8 · Critical
evidence mentions
10
Buzz score
39.0

CVE-2026-8621

Published May 14, 2026

Crabbox prior to v0.12.0 contains an authentication bypass vulnerability that allows non-admin shared-token callers to impersonate other owners or organizations by spoofing identi…

CVSS 8.7 · High
evidence mentions
4
Buzz score
22.6

CVE-2026-8181

Published May 14, 2026

The Burst Statistics – Privacy-Friendly WordPress Analytics (Google Analytics Alternative) plugin for WordPress is vulnerable to Authentication Bypass in versions 3.4.0 to 3.4.1.1…

CVSS 9.8 · Critical
evidence mentions
10
Buzz score
39.0

CVE-2026-44478

Published May 13, 2026

hoppscotch is an open source API development ecosystem. The fix for CVE-2026-28215 in version 2026.2.0 addresses the unauthenticated POST /v1/onboarding/config endpoint by checkin…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-44351

Published May 13, 2026

fast-jwt provides fast JSON Web Token (JWT) implementation. Prior to 6.2.4, a critical authentication-bypass vulnerability in fast-jwt's async key-resolver flow allows any unauthe…

CVSS 9.1 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-33377

Published May 13, 2026

An Editor can overwrite a dashboard not owned by them to acquire admin on that specific dashboard. The user must have write access to the dashboard to escalate privilege.

CVSS 7.1 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-44547

Published May 12, 2026

ChurchCRM is an open-source church management system. From 7.2.0 to 7.2.2, The fix for CVE-2026-4058 is incomplete. The hardening commit was merged and then silently stripped from…

CVSS 9.6 · Critical
evidence mentions
2
Buzz score
16.0

CVE-2026-42855

Published May 12, 2026

arduino-esp32 is an Arduino core for the ESP32, ESP32-S2, ESP32-S3, ESP32-C3, ESP32-C6 and ESP32-H2 microcontrollers. Prior to 3.3.8, the WebServer Digest authentication implement…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-44196

Published May 12, 2026

Pingvin Share X is a secure and easy self-hosted file sharing platform. From 1.14.1 to 1.16.2, a critical authentication bypass vulnerability allows an attacker who has obtained a…

CVSS 9.1 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-44166

Published May 12, 2026

Pocketbase is an open source web backend written in go. Prior to 0.22.42 and 0.37.4, in some situations, if an attacker knows the email address of the victim they can create and l…

CVSS 6.1 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-33117

Published May 12, 2026

The Java Key Vault Keys library in the Azure SDK for Java contains an issue in the local cryptographic verification path where authentication tag comparison was implemented incorr…

CVSS 9.1 · Critical
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2026-8321

Published May 11, 2026

A vulnerability was detected in inkeep agents 0.58.14. This vulnerability affects the function createDevContext of the file agents-api/src/middleware/runAuth.ts of the component r…

CVSS 5.5 · Medium
evidence mentions
5
Buzz score
24.4
Showing 251-275 of 4,492 CVEsPage 11 of 180