Skip to main content

CWE archive

CWE-306 CVEs

Programmatic archive

2,580 CVEs tagged with CWE-306941 Critical, 982 High, 608 Medium, 49 Low, 0 Unrated.

CVE-2026-35273

Published Jun 11, 2026

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Updates Environment Management). Supported versions that are affected are 8.61 and…

CVSS 9.8 · Critical
evidence mentions
21
Buzz score
75.0
KEV listed
Vendor/product tagsBeta · best-effort

CVE-2026-46612

Published Jun 10, 2026

Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior to version 1.23.0, the Fission…

CVSS 8.8 · High
evidence mentions
4
Buzz score
21.1

CVE-2026-20253

Published Jun 10, 2026

In Splunk Enterprise 10.2 versions below 10.2.4 and 10 versions below 10.0.7, an unauthenticated user could create or truncate arbitrary files through a PostgreSQL sidecar service…

CVSS 9.8 · Critical
evidence mentions
11
Buzz score
69.8
KEV listed
Vendor/product tagsBeta · best-effort

CVE-2026-45567

Published Jun 10, 2026

Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, there is an authentication bypass vulnerability via 'api' sub…

CVSS 8.3 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-9045

Published Jun 10, 2026

During an internal security assessment, a potential vulnerability was discovered in Lenovo Accessories and Display Manager for Enterprise for Windows that could allow a local auth…

CVSS 8.5 · High
evidence mentions
2
Buzz score
16.0

CVE-2026-8335

Published Jun 10, 2026

A missing authentication check on the Aix‑DB "/llm/process_llm_out" endpoint allows unauthenticated clients to execute arbitrary "SELECT" SQL queries and retrieve database data, a…

CVSS 7.1 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-53469

Published Jun 10, 2026

A flaw was found in migration-planner. An authenticated user can exploit this vulnerability by sending a DELETE request to the /api/v1/sources route, which lacks proper authorizat…

CVSS 9.1 · Critical
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort

CVE-2026-50512

Published Jun 9, 2026

Missing authentication for critical function in Microsoft PC Manager allows an authorized attacker to elevate privileges locally.

CVSS 7.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-54352

Published Jun 8, 2026

WordPress Seotheme contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary PHP code by uploading malicious files to the theme dir…

CVSS 9.3 · Critical

CVE-2023-54350

Published Jun 8, 2026

WordPress Augmented-Reality plugin contains a remote code execution vulnerability in the elFinder connector that allows unauthenticated attackers to upload and execute arbitrary P…

CVSS 8.7 · High

CVE-2026-11429

Published Jun 5, 2026

Two endpoints in the Vault Service ScriptsController, shared by Altium Enterprise Server and Altium 365, accept file uploads where a user-supplied filename component is used to co…

CVSS 10.0 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-11420

Published Jun 5, 2026

Two path traversal vulnerabilities in the Network Installation Service (NIS) of Altium Enterprise Server allow an unauthenticated network attacker to write arbitrary files to any…

CVSS 10.0 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-45327

Published Jun 5, 2026

TinyIce is a streaming server for audio and video. In versions 0.8.95 through 2.4.1, missing authentication on WebRTC ingest endpoint allows unauthenticated stream injection. Vers…

CVSS 8.2 · High
evidence mentions
3
Buzz score
18.9

CVE-2025-71318

Published Jun 5, 2026

NetMan 204 fails to enforce authentication on its administrative pages and command endpoints. A remote, unauthenticated attacker can directly request administrative pages (such as…

CVSS 9.3 · Critical

CVE-2026-6274

Published Jun 5, 2026

Improper Authentication, Missing authentication for critical function, Weak Authentication vulnerability in DTS Electronics Industry and Trade Ltd. Co. Redline WR3200 allows Acces…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
21.0

CVE-2024-27892

Published Jun 4, 2026

Affected platforms running Arista EOS with OpenConfig configured, a gNMI Set request can be run when it should have been rejected. This can result in unexpected configuration bein…

CVSS 7.2 · High
evidence mentions
1
Buzz score
11.9

CVE-2024-27890

Published Jun 4, 2026

Affected platforms running Arista EOS with OpenConfig configured, a gNMI Set request can be run when it should have been rejected. This can result in unexpected configuration bein…

CVSS 7.2 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-25550

Published Jun 4, 2026

Seagull Software BarTender 2010, 2016, and 2019 contain an unauthenticated remote code execution vulnerability in the .NET Remoting service exposed on TCP port 7375 via BtSystem.S…

CVSS 9.3 · Critical
evidence mentions
2
Buzz score
21.0

CVE-2019-25738

Published Jun 4, 2026

WordPress Hybrid Composer 1.4.6 contains an unauthenticated settings change vulnerability that allows unauthenticated attackers to modify WordPress options by exploiting the hc_aj…

CVSS 9.3 · Critical
evidence mentions
6
Buzz score
37.5

CVE-2026-36603

Published Jun 3, 2026

Mercusys AC12G (EU) V1 router with firmware AC12G(EU)_V1_200909 exposes 15 of 18 UPnP IGD actions without authentication on port 1900, including AddPortMapping and GetExternalIPAd…

CVSS 8.1 · High
evidence mentions
1
Buzz score
11.9
Showing 251-275 of 2,580 CVEsPage 11 of 104