Skip to main content

CWE archive

CWE-306 CVEs

Programmatic archive

2,580 CVEs tagged with CWE-306941 Critical, 982 High, 608 Medium, 49 Low, 0 Unrated.

CVE-2026-20223

Published May 20, 2026

A vulnerability in the access validation of internal REST APIs of Cisco Secure Workload could allow an unauthenticated, remote attacker to access site resources with the priv…

CVSS 10.0 · Critical
evidence mentions
6
Buzz score
37.5
Vendor/product tagsBeta · best-effort

CVE-2026-8602

Published May 19, 2026

In ScadaBR version 1.2.0, a Missing Authentication for Critical Function vulnerability could allow an unauthenticated attacker to send a HTTP GET requests to the SCADA system and…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-8706

Published May 19, 2026

Firefox for iOS hosted Reader mode on an unauthenticated local web server, allowing another application on the same device to request arbitrary URLs and receive the response rende…

CVSS 6.5 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-31071

Published May 19, 2026

API endpoints in LalanaChami Pharmacy Management System (commit 5c3d028) lack authentication middleware. Unauthenticated remote attackers can exploit this to dump all user records…

CVSS 9.1 · Critical
evidence mentions
2
Buzz score
17.5

CVE-2018-25335

Published May 17, 2026

WordPress Plugin Peugeot Music 1.0 contains an arbitrary file upload vulnerability that allows unauthenticated attackers to upload malicious files by sending POST requests to the…

CVSS 9.3 · Critical

CVE-2018-25332

Published May 17, 2026

GitBucket 4.23.1 contains an unauthenticated remote code execution vulnerability that allows attackers to execute arbitrary commands by exploiting weak secret token generation and…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2026-8737

Published May 17, 2026

A weakness has been identified in Sanluan PublicCMS 5.202506.d. This issue affects the function execute of the file publiccms-trade/src/main/java/com/publiccms/views/directive/tra…

CVSS 5.5 · Medium
evidence mentions
4
Buzz score
26.1

CVE-2026-45397

Published May 15, 2026

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.5, GET /api/v1/retrieval/ returns live RAG pipeline configuration t…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-45248

Published May 14, 2026

Hedera Guardian through 3.5.1 contains an authentication bypass vulnerability in the GET /api/v1/demo/registered-users endpoint that allows unauthenticated attackers to retrieve s…

CVSS 6.9 · Medium
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2026-44592

Published May 14, 2026

Gradient is a nix-based continuous integration system. In 1.1.0, when GRADIENT_DISCOVERABLE=true (the default, and the NixOS module default), anyone who can reach /proto can regis…

CVSS 9.4 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-42283

Published May 14, 2026

DevSpace is a client-only developer tool for cloud-native development with Kubernetes. Prior to 6.3.21, DevSpace's UI server WebSocket accepts connections from all origins by defa…

CVSS 7.7 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-62619

Published May 14, 2026

Missing authentication in the KVM key download endpoint could allow an unauthenticated attacker with knowledge of the exposed URL to retrieve sensitive keys, potentially leading t…

CVSS 6.3 · Medium

CVE-2026-42289

Published May 12, 2026

ChurchCRM is an open-source church management system. Prior to 7.3.2, UserEditor.php processes user account creation and permission updates entirely through $_POST parameters with…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-42303

Published May 12, 2026

Fides is an open-source privacy engineering platform. From 2.75.0 to before 2.83.2, Fides deployments that enable both subject identity verification and duplicate privacy request…

CVSS 6.1 · Medium
evidence mentions
6
Buzz score
24.5

CVE-2026-31245

Published May 12, 2026

The mem0 1.0.0 server lacks authentication and authorization controls for its memory creation API endpoint (POST /memories). The endpoint allows unauthenticated users to submit ar…

CVSS 5.3 · Medium
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2026-31244

Published May 12, 2026

The mem0 1.0.0 server lacks authentication and authorization controls for its memory deletion API endpoint (DELETE /memories/{memory_id}). The endpoint allows unauthenticated user…

CVSS 6.5 · Medium
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2026-31243

Published May 12, 2026

The mem0 1.0.0 server lacks authentication and authorization controls for its memory reset and table re-creation functionality accessible via the DELETE /memories endpoint. An una…

CVSS 6.5 · Medium
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2026-31242

Published May 12, 2026

The mem0 v1.0.0 server lacks authentication and authorization controls for its memory reset functionality accessible via the DELETE /memories endpoint. An unauthenticated attacker…

CVSS 9.1 · Critical
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2026-31241

Published May 12, 2026

The mem0 1.0.0 server lacks authentication and authorization controls for its memory deletion API endpoint (DELETE /memories). The endpoint allows unauthenticated users to delete…

CVSS 6.5 · Medium
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2026-31240

Published May 12, 2026

The mem0 1.0.0 server lacks authentication and authorization controls for its memory management API endpoints. Critical functions such as updating memory records (PUT /memories/{m…

CVSS 7.5 · High
evidence mentions
2
Buzz score
17.5

CVE-2026-5029

Published May 12, 2026

A remote code execution vulnerability exists in Code Runner MCP Server when run with the --transport http option, which exposes the /mcp JSON-RPC endpoint without authentication o…

CVSS 8.7 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-43881

Published May 11, 2026

WWBN AVideo is an open source video platform. In versions up to and including 29.0, objects/users.json.php exposes two unauthenticated paths that disclose the full set of register…

CVSS 5.3 · Medium
evidence mentions
2
Buzz score
16.0
Showing 326-350 of 2,580 CVEsPage 14 of 104