Skip to main content

CWE archive

CWE-306 CVEs

Programmatic archive

2,880 CVEs tagged with CWE-3061,083 Critical, 1,120 High, 626 Medium, 51 Low, 0 Unrated.

CVE-2026-63098

Published Jul 17, 2026

TheHive through 4.1.24 contains an unauthenticated information disclosure vulnerability that allows unauthenticated attackers to retrieve sensitive configuration data by sending a…

CVSS 6.9 · Medium
evidence mentions
2
Buzz score
22.0
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2026-16015

Published Jul 17, 2026

A vulnerability was determined in poco-ai poco-claw up to 0.5.4. This vulnerability affects the function create_task of the file executor_manager/app/api/v1/tasks.py of the compon…

CVSS 2.1 · Low
evidence mentions
13
Buzz score
32.9

CVE-2026-62241

Published Jul 17, 2026

clawvet self-hosted API server (apps/api) before 0.7.5 hard-codes a fallback JWT secret ('clawvet-dev-secret-change-me') in auth.ts and ships it as the default in .env.example. Be…

CVSS 9.3 · Critical
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2024-34268

Published Jul 16, 2026

EQ-3 Eqiva CC-RT-BLE Bluetooth Smart Radiator Thermostat Firmware up to the latest version 1.46 was discovered to allow unsecured bluetooth connections. This vulnerability allows…

CVSS 7.1 · High
evidence mentions
2
Buzz score
17.5

CVE-2026-6511

Published Jul 16, 2026

During an internal security assessment, a potential improper access control vulnerability was discovered in Lenovo Smart Connect for Windows that could allow a local authenticated…

CVSS 6.8 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2026-63087

Published Jul 16, 2026

Grafana OnCall through 1.16.11 contains an unauthenticated access vulnerability that allows remote attackers to obtain a valid PluginAuthToken by sending a POST request to the int…

CVSS 9.3 · Critical
evidence mentions
2
Buzz score
17.5

CVE-2026-57206

Published Jul 16, 2026

SimpleChat is a secure AI conversation application with personal and group workspaces for document-grounded interactions. Prior to 0.241.206, several plugin validation routes in a…

CVSS 8.6 · High
evidence mentions
3
Buzz score
18.9

CVE-2026-45695

Published Jul 16, 2026

Kopia is a cross-platform backup tool for Windows, macOS, and Linux with fast incremental backups, client-side end-to-end encryption, compression, and data deduplication. Prior to…

CVSS 9.8 · Critical
evidence mentions
4
Buzz score
21.1

CVE-2026-46339

Published Jul 15, 2026

9Router is an AI router & token saver. From 0.4.30 until 0.4.37, 9Router's src/proxy.js middleware did not protect /api/cli-tools/* and /api/mcp/*, allowing unauthenticated regist…

CVSS 10.0 · Critical
evidence mentions
2
Buzz score
16.0

CVE-2026-58658

Published Jul 15, 2026

GPUStack through 2.2.1, fixed in commit 4e20551, contains an unauthenticated information disclosure vulnerability that allows unauthenticated attackers to access sensitive inferen…

CVSS 8.8 · High
evidence mentions
3
Buzz score
20.4

CVE-2026-53512

Published Jul 15, 2026

Better Auth is an authentication and authorization library for TypeScript. Prior to 1.6.11, the legacy oidcProvider and mcp plugins expose OAuth token endpoints whose refresh_toke…

CVSS 9.1 · Critical
evidence mentions
4
Buzz score
21.1
Vendor/product tagsBeta · best-effort

CVE-2026-61613

Published Jul 15, 2026

Cursor is a code editor built for programming with AI. Prior to the Cloud Agent fix on 03/31/2026, browser-enabled Cursor Cloud Agent sessions allowed attacker-controlled web cont…

CVSS 7.7 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-48325

Published Jul 14, 2026

ColdFusion is affected by a Missing Authentication for Critical Function vulnerability that could result in arbitrary code execution in the context of the current user. Exploitati…

CVSS 9.3 · Critical
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-24259

Published Jul 14, 2026

NVIDIA TensorRT-LLM for Linux contains a vulnerability where an attacker could cause missing authentication for a critical function. A successful exploit of this vulnerability mig…

CVSS 6.4 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2026-24229

Published Jul 14, 2026

NVIDIA TensorRT-LLM for Linux contains a vulnerability in the disaggregated orchestrator component, where an attacker could read, write, or delete internal cluster state by sendin…

CVSS 7.3 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-48252

Published Jul 14, 2026

Adobe Experience Manager is affected by a Missing Authentication for Critical Function vulnerability that could result in a Security feature bypass. An attacker could leverage thi…

CVSS 8.6 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-47212

Published Jul 14, 2026

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 6.4.40, 7.4.12, and 8.0.12, TwilioRequestParser::doParse() received the…

CVSS 6.9 · Medium
evidence mentions
5
Buzz score
22.9
Vendor/product tagsBeta · best-effort

CVE-2026-45755

Published Jul 14, 2026

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 7.4.12 and 8.0.12, MailtrapRequestParser::doParse() received the configu…

CVSS 6.9 · Medium
evidence mentions
4
Buzz score
21.1
Vendor/product tagsBeta · best-effort

CVE-2026-45754

Published Jul 14, 2026

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 6.4.40, 7.4.12, and 8.0.12, the Mailjet mailer bridge and LOX24 notifier…

CVSS 6.9 · Medium
evidence mentions
6
Buzz score
24.5
Vendor/product tagsBeta · best-effort

CVE-2026-50451

Published Jul 14, 2026

Missing authentication for critical function in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally.

CVSS 7.1 · High
evidence mentions
5
Buzz score
32.4

CVE-2026-57969

Published Jul 14, 2026

Missing authentication for critical function in Azure CycleCloud allows an authorized attacker to elevate privileges over a network.

CVSS 8.8 · High
evidence mentions
4
Buzz score
29.1
Vendor/product tagsBeta · best-effort

CVE-2026-56164

Published Jul 14, 2026

Missing authentication for critical function in Microsoft Office SharePoint allows an unauthorized attacker to elevate privileges over a network.

CVSS 5.3 · Medium
evidence mentions
36
Buzz score
75.0
KEV listed
Vendor/product tagsBeta · best-effort

CVE-2026-50333

Published Jul 14, 2026

Missing authentication for critical function in Windows Spaceport.sys allows an authorized attacker to elevate privileges locally.

CVSS 7.8 · High
evidence mentions
4
Buzz score
29.1

CVE-2026-49174

Published Jul 14, 2026

Missing authentication for critical function in Microsoft Windows DNS allows an authorized attacker to perform tampering locally.

CVSS 6.1 · Medium
evidence mentions
4
Buzz score
29.1
Showing 351-375 of 2,880 CVEsPage 15 of 116