Skip to main content

CWE archive

CWE-287 CVEs

Programmatic archive

4,685 CVEs tagged with CWE-2871,276 Critical, 1,671 High, 1,583 Medium, 153 Low, 2 Unrated.

CVE-2026-55672

Published Jul 10, 2026

ZITADEL is an open source identity management platform. Prior to 3.4.12 and 4.15.2, ZITADEL's OAuth2 and OIDC CodeExchange, RefreshToken, and device token flows fail to verify tha…

CVSS 7.4 · High
evidence mentions
5
Buzz score
22.9

CVE-2026-56675

Published Jul 10, 2026

9Router is an AI router & token saver. Prior to 0.5.2, 9router treats loopback requests as trusted and allows /v1/* access without an API key, so a same-host reverse proxy that fo…

CVSS 8.3 · High
evidence mentions
3
Buzz score
18.9

CVE-2026-56312

Published Jul 10, 2026

Capgo before 12.128.2 contains an improper validation vulnerability in the accept_invitation endpoint that creates user accounts before captcha validation is enforced. Attackers c…

CVSS 6.9 · Medium
evidence mentions
2
Buzz score
17.5

CVE-2026-12598

Published Jul 10, 2026

The LoginPress Pro plugin for WordPress is vulnerable to authentication bypass in versions up to and including 6.2.3 via the Spotify Social Login addon. This is due to the loginpr…

CVSS 8.1 · High
evidence mentions
3
Buzz score
28.9

CVE-2026-12597

Published Jul 10, 2026

The LoginPress Pro plugin for WordPress is vulnerable to Authentication Bypass via the GitHub OAuth callback in versions up to, and including, 6.2.3. The vulnerability exists in t…

CVSS 8.1 · High
evidence mentions
3
Buzz score
28.9

CVE-2026-12595

Published Jul 10, 2026

The LoginPress Pro plugin for WordPress is vulnerable to Authentication Bypass via Unverified OAuth Email in all versions up to and including 6.2.3. The vulnerability exists in th…

CVSS 8.1 · High
evidence mentions
3
Buzz score
28.9

CVE-2026-55689

Published Jul 9, 2026

OpenFGA is an authorization/permission engine built for developers. Prior to 1.18.0, OpenFGA's OIDC authenticator skipped JWT audience validation when authn.method was set to oidc…

CVSS 6.8 · Medium
evidence mentions
5
Buzz score
22.9
Vendor/product tagsBeta · best-effort

CVE-2026-59224

Published Jul 9, 2026

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.10.0, backend/open_webui/routers/terminals.py built the ws_terminal upstream URL f…

CVSS 8.0 · High
evidence mentions
4
Buzz score
21.1
Vendor/product tagsBeta · best-effort

CVE-2026-15192

Published Jul 9, 2026

A vulnerability has been found in mettle sendportal up to 3.0.1. This issue affects the function sendgrid/postmark/postal/mailjet of the component APIv1 Webhooks. The manipulation…

CVSS 5.5 · Medium
evidence mentions
6
Buzz score
26.0

CVE-2026-59208

Published Jul 9, 2026

n8n is an open source workflow automation platform. Prior to 2.27.4 and from 2.28.0 prior to 2.28.1, n8n instances configured with more than one trusted token-exchange issuer reso…

CVSS 7.6 · High
evidence mentions
5
Buzz score
32.9
Vendor/product tagsBeta · best-effort

CVE-2026-54781

Published Jul 8, 2026

CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, CoreWCF SAML token validation does not enforce SubjectConfi…

CVSS 7.4 · High
evidence mentions
6
Buzz score
24.5

CVE-2026-59822

Published Jul 8, 2026

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.84.0, LiteLLM's MCP Streamable HTTP endpoint allowed an unauthenticated attacker t…

CVSS 8.8 · High
evidence mentions
4
Buzz score
21.1
Vendor/product tagsBeta · best-effort

CVE-2026-58253

Published Jul 8, 2026

NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.0, 2.12.7, and 2.11.16, when no_auth_user was configured, a parser…

CVSS 8.8 · High
evidence mentions
8
Buzz score
32.0
Vendor/product tagsBeta · best-effort

CVE-2026-55761

Published Jul 8, 2026

Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage Docker, Swarm, Kubernetes and ACI environments. In…

CVSS 7.1 · High
evidence mentions
6
Buzz score
24.5
Vendor/product tagsBeta · best-effort

CVE-2026-9695

Published Jul 8, 2026

An Improper Authentication vulnerability affecting DELMIA Apriso from Release 2020 through Release 2026 could allow an attacker to gain privileged access to the server.

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-55076

Published Jul 7, 2026

Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2, Coder's OIDC callback checked `email_v…

CVSS 7.4 · High
evidence mentions
7
Buzz score
25.8
Vendor/product tagsBeta · best-effort

CVE-2026-37271

Published Jul 7, 2026

Fire-Boltt Smartwatch FB BGS001 Firmware: MOY-JS14-2.0.4 is vulnerable to Improper Authentication, The device accepts GATT Write Request commands without sufficient authentication…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
16.0

CVE-2026-37270

Published Jul 7, 2026

Trueview Security camera T18161- AF v4.9.60.0 contains an authentication bypass vulnerability caused by improper password validation and the presence of hard-coded credentials in…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
16.0

CVE-2026-55075

Published Jul 7, 2026

Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2, two flaws in Coder's OIDC login chaine…

CVSS 7.4 · High
evidence mentions
7
Buzz score
25.8
Vendor/product tagsBeta · best-effort

CVE-2026-53483

Published Jul 7, 2026

Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release ve…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-55727

Published Jul 6, 2026

A flaw in the authentication mechanism for video stream requests in Genetec Security Center 5.14.0.0 prior to build 5.14.178.18 may allow an unauthenticated attacker to access liv…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-53913

Published Jul 6, 2026

Improper Authentication, Missing Authentication for Critical Function, Not Failing Securely ('Failing Open') vulnerability in Apache Camel Keycloak Component. The KeycloakSecurit…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-14714

Published Jul 5, 2026

A weakness has been identified in zhayujie chatgpt-on-wechat CowAgent 2.1.0. This issue affects the function verify_server of the file channel/wechatmp/common.py of the component…

CVSS 5.5 · Medium
evidence mentions
7
Buzz score
27.3
Showing 276-300 of 4,685 CVEsPage 12 of 188