Skip to main content

CWE archive

CWE-306 CVEs

Programmatic archive

2,835 CVEs tagged with CWE-3061,067 Critical, 1,097 High, 620 Medium, 51 Low, 0 Unrated.

CVE-2026-12722

Published Jul 30, 2026

Missing authentication for critical function vulnerability in FTC Software IT Services FTC E-Commerce Management Panel allows Authentication Bypass. This issue affects FTC E-Comm…

CVSS 8.2 · High
evidence mentions
1

CVE-2026-54367

Published Jul 30, 2026

CentreStack before 17.2 contains an authentication bypass vulnerability that allows unauthenticated attackers to read, write, or delete arbitrary account settings by exploiting ex…

CVSS 8.8 · High
evidence mentions
2

CVE-2026-54365

Published Jul 30, 2026

CentreStack before 17.3 contains an unauthenticated deserialization vulnerability in GSNamespace.dll that allows unauthenticated attackers to create arbitrary local OS user accoun…

CVSS 8.7 · High
evidence mentions
2

CVE-2026-44101

Published Jul 30, 2026

Due to missing authentication the CHARX OCPP Agent service allows an unauthenticated remote attacker to reconfigure the backend connection. This can lead to Denial-of-Service and…

CVSS 9.3 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-44100

Published Jul 30, 2026

The CHARX JupiCore service allows an unauthenticated remote attacker to reconfigure charging points. This can lead to disclosure of charging point UIDs, Denial-of-Service and file…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-44090

Published Jul 30, 2026

Due to missing authentication, an unauthenticated remote attacker may access the MQTT broker, which is only protected from external access by a firewall. This may lead to the devi…

CVSS 9.3 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-47858

Published Jul 30, 2026

Starting Spring Boot applications in the Spring Tools with the live information mode enabled makes the running application vulnerable against JMX-based remote code execution. Affe…

CVSS 8.0 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-13306

Published Jul 29, 2026

Autel MaxiCharger AC Elite Home USB Authentication Bypass Vulnerability. This vulnerability allows physically present attackers to bypass authentication on affected installations…

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-5057

Published Jul 29, 2026

ATEN Unizon RpcProvider Missing Authentication Denial-of-Service Vulnerability. This vulnerability allows remote attackers to create a denial-of-service condition on affected inst…

CVSS 7.5 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-67426

Published Jul 29, 2026

Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.7, the standalone flyto-verification service in src/core/verification_service.py exposes un…

CVSS 9.3 · Critical
evidence mentions
3
Buzz score
18.9

CVE-2026-14529

Published Jul 29, 2026

IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 traditional is vulnerable to server-side request forgery (SS…

CVSS 9.4 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-60113

Published Jul 29, 2026

AMMOS Instrument Toolkit (AIT) Deep Space Network (DSN) Interface before 2.2.2 contains a missing authentication vulnerability in the Space Link Extension (SLE) interface manager…

CVSS 9.3 · Critical
evidence mentions
5
Buzz score
24.4

CVE-2026-60112

Published Jul 29, 2026

AMMOS Instrument Toolkit (AIT) GUI before 2.5.1 contains a missing authentication vulnerability that allows any unauthenticated network attacker to obtain a valid session and issu…

CVSS 9.3 · Critical
evidence mentions
4
Buzz score
22.6

CVE-2026-62325

Published Jul 28, 2026

goshs is a feature-rich single-binary file server for red teamers and developers. From 2.1.3 until 2.1.4, the sftpserver/sftpserver.go password handler used Username != "" && Pass…

CVSS 9.1 · Critical
evidence mentions
3
Buzz score
18.9

CVE-2026-14976

Published Jul 28, 2026

IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is affected by remote code execution with the collectiveController-1.0 feature enabled.

CVSS 7.1 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-14446

Published Jul 28, 2026

IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to broken access control/privilege escalation in the administrative console.

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-16771

Published Jul 28, 2026

In firmware versions 2.7.7 and earlier, the Arris BGW210‑700 gateway fails to enforce any server‑side authentication on its /cgi-bin/*.ha management endpoints, relying solely on c…

CVSS 8.8 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-7187

Published Jul 28, 2026

Missing authentication for critical function vulnerability in Universal Software Inc. UKBS allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects UKB…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-12989

Published Jul 27, 2026

A lack of authentication in the mobile app (APK v5.5.0) for Ghost Robotics' Vision 60 robot allows an unauthenticated attacker connected to the device's internal Wi-Fi network to…

CVSS 8.7 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-66006

Published Jul 24, 2026

lakeFS through 1.83.0, fixed in commit 71a45ee, contains an authentication bypass vulnerability in the /setup_comm_prefs endpoint that allows unauthenticated attackers to overwrit…

CVSS 6.9 · Medium
evidence mentions
4
Buzz score
22.6

CVE-2026-56163

Published Jul 24, 2026

Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network.

CVSS 10.0 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-66139

Published Jul 24, 2026

OpenStack Zaqar through 22.0.0 allows authentication bypass via an EXTRA-SPEC header when a UUID is known.

CVSS 4.8 · Medium
evidence mentions
3
Buzz score
20.4

CVE-2026-63765

Published Jul 23, 2026

Chatwoot before 4.16.0 contains an authentication bypass vulnerability in the direct uploads controller that allows unauthenticated attackers to create arbitrary ActiveStorage blo…

CVSS 8.8 · High
evidence mentions
5
Buzz score
24.4

CVE-2026-47769

Published Jul 23, 2026

APIFold reads an OpenAPI 3.x or Swagger 2.x specification and generates a live, production-ready MCP server endpoint. Prior to commit 7f19b52280f414f57af2b79a95333d1c8fbeece5, the…

CVSS 5.3 · Medium
evidence mentions
3
Buzz score
18.9

CVE-2026-64812

Published Jul 23, 2026

In JetBrains IntelliJ IDEA before 2026.2 unauthorized input injection was possible in a Remote Development session

CVSS 10.0 · Critical
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort
Showing 1-25 of 2,835 CVEsPage 1 of 114