Skip to main content

CWE archive

CWE-302 CVEs

Programmatic archive

40 CVEs tagged with CWE-3029 Critical, 17 High, 14 Medium, 0 Low, 0 Unrated.

CVE-2026-48117

Published Jun 17, 2026

DroneAware is a drone detection platform. The centralized DroneAware server backing droneaware.io was vulnerable to an account pre-hijacking attack in which an attacker could regi…

CVSS 6.8 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-48781

Published Jun 17, 2026

Postiz is an AI social media scheduling tool. In versions prior to 2.21.8, the Skool integration callback signed an attacker-controlled JSON blob into a session-shape JWT using th…

CVSS 9.9 · Critical
evidence mentions
4
Buzz score
26.1

CVE-2026-34460

Published Jun 2, 2026

NamelessMC is website software for Minecraft servers. In versions 2.2.4 and prior, the OAuth callback handling does not validate the state parameter server-side before exchanging…

CVSS 5.4 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-28510

Published May 5, 2026

eLabFTW is an open source electronic lab notebook. In elabftw versions through 5.4.1, the login flow did not reliably preserve the multi-factor authentication state across authent…

CVSS 5.9 · Medium
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-40285

Published Apr 17, 2026

WeGIA is a web manager for charitable institutions. Versions prior to 3.6.10 contain a SQL injection vulnerability in dao/memorando/UsuarioDAO.php. The cpf_usuario POST parameter…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-39429

Published Apr 8, 2026

kcp is a Kubernetes-like control plane for form-factors and use-cases beyond Kubernetes and container workloads. Prior to 0.30.3 and 0.29.3, the cache server is directly exposed b…

CVSS 8.2 · High
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2026-27840

Published Feb 26, 2026

ZITADEL is an open source identity management platform. Starting in version 2.31.0 and prior to versions 3.4.7 and 4.11.0, opaque OIDC access tokens in the v2 format truncated to…

CVSS 4.3 · Medium
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2024-45370

Published Dec 1, 2025

An authentication bypass vulnerability exists in the User profile management functionality of Socomec Easy Config System 2.6.1.0. A specially crafted database record can lead to u…

CVSS 7.3 · High

CVE-2025-8855

Published Nov 14, 2025

Authorization Bypass Through User-Controlled Key, Weak Password Recovery Mechanism for Forgotten Password, Authentication Bypass by Assumed-Immutable Data vulnerability in Optimus…

CVSS 8.1 · High

CVE-2025-47158

Published Jul 18, 2025

Authentication bypass by assumed-immutable data in Azure DevOps allows an unauthorized attacker to elevate privileges over a network.

CVSS 9.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-46647

Published Jul 2, 2025

A vulnerability of plugin openid-connect in Apache APISIX. This vulnerability will only have an impact if all of the following conditions are met: 1. Use the openid-connect plugi…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-29813

Published May 8, 2025

Authentication bypass by assumed-immutable data in Azure DevOps allows an unauthorized attacker to elevate privileges over a network.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-26522

Published Feb 14, 2025

This vulnerability exists in RupeeWeb trading platform due to improper implementation of OTP validation mechanism in certain API endpoints. A remote attacker with valid credential…

CVSS 7.5 · High

CVE-2025-24876

Published Feb 11, 2025

The SAP Approuter Node.js package version v16.7.1 and before is vulnerable to Authentication bypass. When trading an authorization code an attacker can steal the session of the vi…

CVSS 8.1 · High
evidence mentions
1
Buzz score
11.9

CVE-2024-56404

Published Jan 24, 2025

In One Identity Identity Manager 9.x before 9.3, an insecure direct object reference (IDOR) vulnerability allows privilege escalation. Only On-Premise installations are affected.

CVSS 9.9 · Critical

CVE-2024-12838

Published Dec 31, 2024

The passwordless login mechanism in CGFIDO from Changing Information Technology has an Authentication Bypass vulnerability, allowing remote attackers with regular privileges to se…

CVSS 8.8 · High

CVE-2024-43441

Published Dec 24, 2024

Authentication Bypass by Assumed-Immutable Data vulnerability in Apache HugeGraph-Server. This issue affects Apache HugeGraph-Server: from 1.0.0 before 1.5.0. Users are recommen…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-8475

Published Dec 17, 2024

Authentication Bypass by Assumed-Immutable Data vulnerability in Digital Operation Services WiFiBurada allows Manipulating User-Controlled Variables. This issue affects WiFiBurad…

CVSS 6.5 · Medium

CVE-2024-49056

Published Nov 12, 2024

Authentication bypass by assumed-immutable data on airlift.microsoft.com allows an authorized attacker to elevate privileges over a network.

CVSS 7.3 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort
Showing 1-25 of 40 CVEsPage 1 of 2