Skip to main content

CWE archive

CWE-306 CVEs

Programmatic archive

2,580 CVEs tagged with CWE-306941 Critical, 982 High, 608 Medium, 49 Low, 0 Unrated.

CVE-2026-10617

Published Jun 2, 2026

A security vulnerability has been detected in nextlevelbuilder GoClaw up to 3.11.3. This affects the function resolveAuth of the file internal/http/auth.go of the component Webhoo…

CVSS 5.5 · Medium
evidence mentions
6
Buzz score
26.0

CVE-2026-42074

Published Jun 2, 2026

OpenClaude is an open-source coding-agent command line interface for cloud and local model providers. Prior to version 0.5.1, the dangerouslyDisableSandbox parameter is exposed as…

CVSS 9.3 · Critical
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2026-0611

Published Jun 2, 2026

Spacelabs Healthcare Sentinel versions 10.5.x and higher and 11.x.x before 11.6.0 contain an unauthenticated remote code execution vulnerability through a deprecated .NET Remoting…

CVSS 9.2 · Critical
evidence mentions
3
Buzz score
23.9

CVE-2026-10283

Published Jun 1, 2026

A vulnerability was detected in Bottelet DaybydayCRM up to 2.2.1. Affected is an unknown function of the component Setting Handler. Performing a manipulation results in missing au…

CVSS 5.3 · Medium
evidence mentions
8
Buzz score
28.5

CVE-2026-10281

Published Jun 1, 2026

A weakness has been identified in Enderfga claw-orchestrator up to 3.5.5. This affects the function EmbeddedServer of the file src/embedded-server.ts of the component API Endpoint…

CVSS 5.5 · Medium
evidence mentions
8
Buzz score
28.5

CVE-2026-44211

Published Jun 1, 2026

Cline is an autonomous coding agent as an SDK, IDE extension, or CLI assistant. In versions 2.13.0 and prior, there is a cross-origin WebSocket hijack vulnerability in Cline Kanba…

CVSS 9.6 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-25599

Published Jun 1, 2026

Missing authentication and clear‑text transmission of data from the heat pumps to the control server, combined with the absence of input validation on aggregated data, can lead to…

CVSS 6.3 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-10243

Published Jun 1, 2026

A security vulnerability has been detected in code-projects Smart Parking System 1.0. Affected is an unknown function of the component Admin Endpoint. Such manipulation leads to m…

CVSS 5.5 · Medium
evidence mentions
6
Buzz score
31.0

CVE-2018-25412

Published May 30, 2026

Delta Sql 1.8.2 contains an arbitrary file upload vulnerability that allows unauthenticated attackers to upload malicious files by sending POST requests to docs_upload.php with cr…

CVSS 9.3 · Critical
evidence mentions
5
Buzz score
34.4
Vendor/product tagsBeta · best-effort

CVE-2026-9051

Published May 29, 2026

There is an authentication bypass vulnerability in the NI SystemLink Enterprise Dashboard application that may allow an unauthenticated remote attacker to bypass authentication co…

CVSS 9.3 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-44649

Published May 29, 2026

SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice mode…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-5768

Published May 29, 2026

The Frontier X2 device allows unauthenticated BLE read/write access to critical GATT characteristics without enforcing pairing authentication or authorization. This allows attacke…

CVSS 8.8 · High
evidence mentions
3
Buzz score
28.9

CVE-2026-45577

Published May 29, 2026

Neotoma provides versioned records that persist across agent runs. From 0.6.0 to before 0.11.1, Neotoma can treat public reverse-proxied requests as local when the app receives th…

CVSS 6.9 · Medium
evidence mentions
2
Buzz score
16.0

CVE-2026-45610

Published May 29, 2026

WWBN AVideo is an open source video platform. In 29.0 and earlier, there is a cross-site request forgery vulnerability on the 2FA toggle. plugin/LoginControl/set.json.php accepts…

CVSS 5.7 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-8732

Published May 29, 2026

The WP Maps Pro plugin for WordPress is vulnerable to Privilege Escalation via Administrator Account Creation in all versions up to, and including, 6.1.0. This is due to the wpgmp…

CVSS 9.8 · Critical
evidence mentions
6
Buzz score
39.5

CVE-2026-46840

Published May 28, 2026

Vulnerability in Oracle REST Data Services (component: Backend-as-a-Service). Supported versions that are affected are 24.2.0-26.1.0. Easily exploitable vulnerability allows unau…

CVSS 10.0 · Critical
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-46827

Published May 28, 2026

Vulnerability in the Oracle Payroll product of Oracle E-Business Suite (component: Self Service Manager). Supported versions that are affected are 12.2.3-12.2.15. Easily exploita…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-46826

Published May 28, 2026

Vulnerability in the Oracle Payroll product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitab…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-46824

Published May 28, 2026

Vulnerability in the Oracle Universal Work Queue product of Oracle E-Business Suite (component: Work Provider Site Level Administration). Supported versions that are affected are…

CVSS 9.9 · Critical
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-46817

Published May 28, 2026

Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitabl…

CVSS 9.8 · Critical
evidence mentions
20
Buzz score
75.0
Vendor/product tagsBeta · best-effort

CVE-2026-47136

Published May 28, 2026

RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.2, the RustFS console endpoint GET /rustfs/console/license returns parsed license metadata without…

CVSS 6.9 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-46685

Published May 28, 2026

RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.2, when RUSTFS_CORS_ALLOWED_ORIGINS is unset, the RustFS S3 listener's ConditionalCorsLayer reflec…

CVSS 6.0 · Medium
evidence mentions
1
Buzz score
11.9
Showing 276-300 of 2,580 CVEsPage 12 of 104