Skip to main content

CWE archive

CWE-306 CVEs

Programmatic archive

2,580 CVEs tagged with CWE-306941 Critical, 982 High, 608 Medium, 49 Low, 0 Unrated.

CVE-2026-45332

Published May 28, 2026

Automad is a flat-file content management system and template engine. From 2.0.0-alpha.1 to 2.0.0-beta.27, a Broken Access Control vulnerability allows an unauthenticated attacker…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-45044

Published May 28, 2026

RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.2, the admin router explicitly whitelists /profile/cpu and /profile/memory from the authentication…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-45083

Published May 27, 2026

The Goobi viewer is a web application that allows digitised material to be displayed in a web browser. From 4.8.0 to before 26.04.1, the Goobi viewer REST endpoint POST /api/v1/in…

CVSS 9.8 · Critical
evidence mentions
3
Buzz score
18.9

CVE-2026-8364

Published May 27, 2026

Gladinet Triofox Cloud Server Agent Access Service (GladServerAgentService.exe) listens on TCP port 7878 and processes remote HTTP messages with URL paths starting with /resources…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-45089

Published May 27, 2026

Dalfox is a powerful open-source XSS scanner and utility focused on automation. Prior to 2.13.0, when dalfox is run in REST API server mode, the output, output-all, and debug fiel…

CVSS 8.2 · High
evidence mentions
2
Buzz score
16.0

CVE-2026-45088

Published May 27, 2026

Dalfox is a powerful open-source XSS scanner and utility focused on automation. Prior to 2.13.0, when dalfox is run in REST API server mode, the custom-payload-file field in model…

CVSS 7.5 · High
evidence mentions
2
Buzz score
16.0

CVE-2026-45087

Published May 27, 2026

Dalfox is a powerful open-source XSS scanner and utility focused on automation. Prior to 2.13.0, when dalfox is started in REST API server mode (dalfox server), the server binds t…

CVSS 10.0 · Critical
evidence mentions
3
Buzz score
23.9

CVE-2026-44460

Published May 27, 2026

FileRise is a self-hosted web-based file manager with multi-file upload, editing, and batch operations. Prior to 3.12.0, /api/totp_setup.php is callable from a session that has on…

CVSS 7.4 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-44329

Published May 27, 2026

free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's SMF mounts the UPI management route group without OAuth2/bearer-token authorization midd…

CVSS 10.0 · Critical
evidence mentions
4
Buzz score
25.6
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2026-44328

Published May 27, 2026

free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's SMF mounts the UPI management route group without inbound OAuth2 middleware. On top of t…

CVSS 8.2 · High
evidence mentions
4
Buzz score
25.6
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2026-44327

Published May 27, 2026

free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's NEF mounts the nnef-oam route group without inbound OAuth2/bearer-token authorization. A…

CVSS 10.0 · Critical
evidence mentions
3
Buzz score
23.4
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2026-44321

Published May 27, 2026

free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's SMF mounts the UPI management route group without inbound OAuth2 middleware. The POST /u…

CVSS 7.5 · High
evidence mentions
4
Buzz score
25.6
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2026-44320

Published May 27, 2026

free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's NEF mounts the nnef-callback route group without inbound OAuth2/bearer-token authorizati…

CVSS 7.3 · High
evidence mentions
3
Buzz score
23.4
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2026-44830

Published May 27, 2026

Nocturne Memory is a lightweight, rollbackable, and visual Long-Term Memory Server for MCP Agents. Prior to 2.4.1, when API_TOKEN is unset or empty, the BearerTokenAuthMiddleware…

CVSS 8.7 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-44895

Published May 26, 2026

GitLab MCP Server lets an AI agent talk directly to GitLab. Prior to 0.6.0, the HTTP transport in src/transport.ts ships with no authentication layer at all and a wildcard Access-…

CVSS 9.2 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-47672

Published May 26, 2026

epa4all-client is the Java Client for epa4all / ePA 3.0 in the Telematik Infrastruktur. In 1.2.4 and earlier, any network-reachable caller can write arbitrary documents to any pat…

CVSS 6.5 · Medium
evidence mentions
2
Buzz score
16.0

CVE-2026-44847

Published May 26, 2026

MaxKB is an open-source AI assistant for enterprise. Prior to 2.9.0, MaxKB's webhook trigger endpoint (/api/trigger/v1/webhook/{trigger_id}) is accessible without authentication.…

CVSS 7.5 · High
evidence mentions
2
Buzz score
16.0

CVE-2026-44775

Published May 26, 2026

Kavita is a cross platform reading server. Prior to 0.9.0, the ReaderController.GetImage endpoint is decorated with [AllowAnonymous], allowing completely unauthenticated access to…

CVSS 6.9 · Medium
evidence mentions
2
Buzz score
16.0

CVE-2026-44668

Published May 26, 2026

FACTION is a PenTesting Report Generation and Collaboration Framework. Prior to 1.8.3, AccessControlInterceptor, the authentication gate for all Struts2 actions, unconditionally c…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
16.0

CVE-2026-48692

Published May 26, 2026

FastNetMon Community Edition through 1.2.9 exposes a gRPC API server on port 50052 with no authentication mechanism. The server is initialized with grpc::InsecureServerCredentials…

CVSS 8.1 · High
evidence mentions
4
Buzz score
22.6
Vendor/product tagsBeta · best-effort

CVE-2026-9371

Published May 24, 2026

A security vulnerability has been detected in ItzCrazyKns Vane up to 1.12.1. Affected by this issue is some unknown functionality of the file route.ts of the component API. The ma…

CVSS 2.9 · Low
evidence mentions
7
Buzz score
27.3

CVE-2026-9152

Published May 21, 2026

A missing authentication vulnerability exists in the Altium 365 SearchService. A legacy SOAP endpoint exposes search index operations without requiring authentication, session tok…

CVSS 10.0 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-9141

Published May 20, 2026

Taiko AG1000-01A SMS Alert Gateway Rev 7.3 and Rev 8 contains an authentication bypass vulnerability in the embedded web configuration interface that allows unauthenticated attack…

CVSS 9.3 · Critical
evidence mentions
2
Buzz score
17.5

CVE-2026-39310

Published May 20, 2026

Trilium Notes is a cross-platform, hierarchical note taking application focused on building large personal knowledge bases. In versions 0.102.1 and prior, the Clipper API in Trili…

CVSS 8.6 · High
evidence mentions
2
Buzz score
16.0
Showing 301-325 of 2,580 CVEsPage 13 of 104