← Back to feed Search feed

CWE-306 Missing Authentication vulnerabilities

145 CVEs — updated 2026-09-19 · vulnfeed

CVE / IDTitleSeverityCVSSEPSSSourceDate
CVE-2026-59971MySQL MCP Server is a Model Context Protocol server that enables secure interaction with MySQL databases. Prior to 0.4.2CRITICAL10.033%ileNVD2026-09-15
CVE-2026-71133Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). SuppCRITICAL10.026%ileNVD2026-09-15
CVE-2026-83020Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized ThirdCRITICAL10.038%ileNVD2026-09-15
CVE-2026-83021Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Container). Supported vCRITICAL10.038%ileNVD2026-09-15
CVE-2026-83059Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware (component: OID LDAP Server). SupporCRITICAL10.041%ileNVD2026-09-15
CVE-2026-83099Vulnerability in the Oracle Forms product of Oracle Fusion Middleware (component: Forms Services, C/S, Charmode). SuppoCRITICAL10.030%ileNVD2026-09-15
CVE-2026-92808A server-side request forgery (SSRF) vulnerability exists in the UnifiedLogin service of Altium Enterprise Server. An unCRITICAL10.025%ileNVD2026-09-16
CVE-2026-85889Missing authentication for critical function in Azure AI Foundry allows an unauthorized attacker to elevate privileges oCRITICAL10.041%ileNVD2026-09-17
CVE-2026-84075IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions due to missing authenticCRITICAL9.9NVD2026-09-18
CVE-2026-84078IBM Guardium Data Protection 12.2 is vulnerable to a missing authentication vulnerability in the LoadBalancerServlet. AnCRITICAL9.9NVD2026-09-18
CVE-2026-90898Bifrost registers MCP clients through its management API. A stdio client is a command plus args. Bifrost starts that proCRITICAL9.828%ileNVD2026-09-14
CVE-2026-57123PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.59, ToolsMCPServer.run_sse and launch_tools_mcp_seCRITICAL9.840%ileNVD2026-09-14
CVE-2026-57125PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.59 and praisonaiagents 1.6.59, the unauthenticated POST CRITICAL9.835%ileNVD2026-09-14
CVE-2026-57124PraisonAI is a multi-agent teams system. Prior to 4.6.59, the default UI host applications expose POST /api/mcp/connect CRITICAL9.849%ileNVD2026-09-14
CVE-2026-57127PraisonAI is a multi-agent teams system. Prior to 4.6.58, recipe serve installs APIKeyAuthMiddleware or JWTAuthMiddlewarCRITICAL9.858%ileNVD2026-09-14
CVE-2026-57131PraisonAI is a multi-agent teams system. Prior to 4.6.58, praisonai.jobs.server.create_app mounts praisonai.jobs.router.CRITICAL9.860%ileNVD2026-09-14
CVE-2026-59178ESPHome Device Builder Dashboard is a dashboard for the ESPHome home management software. Prior to version 1.0.12, the dCRITICAL9.836%ileNVD2026-09-14
CVE-2026-57139PraisonAI is a multi-agent teams system. From 1.5.0 until 1.7.2, MCPServer.startHttp() in src/praisonai-ts/src/mcp/serveCRITICAL9.836%ileNVD2026-09-15
CVE-2026-70748Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions tCRITICAL9.826%ileNVD2026-09-15
CVE-2026-70756Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions tCRITICAL9.838%ileNVD2026-09-15
CVE-2026-70757Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions tCRITICAL9.826%ileNVD2026-09-15
CVE-2026-70913Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: Core). Supported versions CRITICAL9.826%ileNVD2026-09-15
CVE-2026-73940Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). SuppCRITICAL9.838%ileNVD2026-09-15
CVE-2026-73947Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). SuppCRITICAL9.826%ileNVD2026-09-15
CVE-2026-73950Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). SuppCRITICAL9.838%ileNVD2026-09-15
CVE-2026-73953Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Portlet Services). SupportCRITICAL9.829%ileNVD2026-09-15
CVE-2026-73956Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Composer). Supported versiCRITICAL9.841%ileNVD2026-09-15
CVE-2026-73961Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: ADF Faces). Supported versions tCRITICAL9.841%ileNVD2026-09-15
CVE-2026-73963Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Portlet Services). SupportCRITICAL9.829%ileNVD2026-09-15
CVE-2026-82994Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized ThirdCRITICAL9.841%ileNVD2026-09-15
CVE-2026-82995Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized ThirdCRITICAL9.841%ileNVD2026-09-15
CVE-2026-83000Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). SuppCRITICAL9.841%ileNVD2026-09-15
CVE-2026-83035Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). SupportedCRITICAL9.841%ileNVD2026-09-15
CVE-2026-83036Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). SupportedCRITICAL9.841%ileNVD2026-09-15
CVE-2026-83037Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). SupportedCRITICAL9.841%ileNVD2026-09-15
CVE-2026-83042Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: OIM Legacy UI). Supported CRITICAL9.841%ileNVD2026-09-15
CVE-2026-83054Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware (component: OID LDAP Server). SupporCRITICAL9.829%ileNVD2026-09-15
CVE-2026-83060Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware (component: OID LDAP Server). SupporCRITICAL9.841%ileNVD2026-09-15
CVE-2026-83061Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware (component: OID LDAP Server). SupporCRITICAL9.841%ileNVD2026-09-15
CVE-2026-83062Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware (component: OID LDAP Server). SupporCRITICAL9.841%ileNVD2026-09-15
CVE-2026-83066Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware (component: OID LDAP Server). SupporCRITICAL9.841%ileNVD2026-09-15
CVE-2026-83094Vulnerability in the Oracle Forms product of Oracle Fusion Middleware (component: Forms Services, C/S, Charmode). SuppoCRITICAL9.841%ileNVD2026-09-15
CVE-2026-83095Vulnerability in the Oracle Forms product of Oracle Fusion Middleware (component: Forms Services, C/S, Charmode). SuppoCRITICAL9.841%ileNVD2026-09-15
CVE-2026-83098Vulnerability in the Oracle Forms product of Oracle Fusion Middleware (component: Forms Services, C/S, Charmode). SuppoCRITICAL9.829%ileNVD2026-09-15
CVE-2026-83100Vulnerability in the Oracle Forms product of Oracle Fusion Middleware (component: Forms Services, C/S, Charmode). SuppoCRITICAL9.841%ileNVD2026-09-15
CVE-2026-83108Vulnerability in the Oracle Forms product of Oracle Fusion Middleware (component: Forms Services, C/S, Charmode). SuppoCRITICAL9.838%ileNVD2026-09-15
CVE-2026-83151Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). SuppCRITICAL9.829%ileNVD2026-09-15
CVE-2026-83232Vulnerability in the Oracle Data Integrator product of Oracle Fusion Middleware (component: Console / Repository ExploreCRITICAL9.826%ileNVD2026-09-15
CVE-2026-83261Vulnerability in the Oracle Product Lifecycle Analytics product of Oracle Supply Chain (component: Core). The supporteCRITICAL9.829%ileNVD2026-09-15
CVE-2026-83269Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: BI Platform Security). Supported versiCRITICAL9.829%ileNVD2026-09-15
CVE-2026-83283Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Platform SeCRITICAL9.838%ileNVD2026-09-15
CVE-2026-83327Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Personalization). SupCRITICAL9.841%ileNVD2026-09-15
CVE-2026-83339Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle).CRITICAL9.841%ileNVD2026-09-15
CVE-2026-83355Vulnerability in the Oracle Enterprise Manager for Fusion Middleware product of Oracle Enterprise Manager (component: MeCRITICAL9.829%ileNVD2026-09-15
CVE-2026-83452Vulnerability in the Oracle Document Management and Collaboration product of Oracle E-Business Suite (component: InternaCRITICAL9.841%ileNVD2026-09-15
CVE-2026-83462Vulnerability in the Oracle Mobile Application Server product of Oracle E-Business Suite (component: MWA Terminal ServerCRITICAL9.841%ileNVD2026-09-15
CVE-2026-87184Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supporCRITICAL9.841%ileNVD2026-09-15
CVE-2026-87188Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supporCRITICAL9.829%ileNVD2026-09-15
CVE-2026-20326As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Nexus Dashboard engineering tCRITICAL9.833%ileNVD2026-09-16
CVE-2026-54460OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to 1.1CRITICAL9.847%ileNVD2026-09-17
CVE-2026-82967IBM Guardium Data Protection 12.2 is vulnerable to an authentication bypass that allows an unauthenticated remote attackCRITICAL9.8NVD2026-09-18
CVE-2026-57140PraisonAI is a multi-agent teams system. From 1.6.0 until 1.7.2, AgentOS in src/praisonai-ts/src/os/agentos.ts uses the CRITICAL9.431%ileNVD2026-09-15
CVE-2026-54618Obsidian Web MCP is a secure remote MCP server for Obsidian vaults. Prior to 0.2.0, /oauth/authorize issues an authorizaCRITICAL9.434%ileNVD2026-09-17
CVE-2026-92717Covenant through 0.6 registers the CovenantHub SignalR hub without an Authorize attribute, allowing unauthenticated callCRITICAL9.330%ileNVD2026-09-16
CVE-2026-92720Kubero through 3.1.1 fails to apply authentication guards to the notifications API endpoints, allowing unauthenticated aCRITICAL9.340%ileNVD2026-09-16
CVE-2026-92805UVdesk Community Skeleton through 1.1.8 fails to authenticate or validate installation state on wizard endpoints in ConfCRITICAL9.328%ileNVD2026-09-16
CVE-2026-63647CordysCRM is an open source AI-powered customer relationship management system that supports private deployment. Prior tCRITICAL9.3NVD2026-09-18
CVE-2026-93839LightLLM through 1.2.0 contains an authentication bypass vulnerability in the /pd_register WebSocket endpoint that allowCRITICAL9.3NVD2026-09-18
CVE-2026-73944Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). SuppCRITICAL9.124%ileNVD2026-09-15
CVE-2026-73952Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Portlet Services). SupportCRITICAL9.124%ileNVD2026-09-15
CVE-2026-83104Vulnerability in the Oracle Forms product of Oracle Fusion Middleware (component: Forms Services, C/S, Charmode). SuppoCRITICAL9.134%ileNVD2026-09-15
CVE-2026-83154Vulnerability in the Siebel CRM End User product of Oracle Siebel CRM (component: Open UI). Supported versions that areCRITICAL9.124%ileNVD2026-09-15
CVE-2026-83201Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure). Supported vCRITICAL9.124%ileNVD2026-09-15
CVE-2026-83202Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure). Supported vCRITICAL9.134%ileNVD2026-09-15
CVE-2026-87128Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and secuCRITICAL9.134%ileNVD2026-09-15
CVE-2026-87129Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and secuCRITICAL9.124%ileNVD2026-09-15
CVE-2026-87170Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supporCRITICAL9.134%ileNVD2026-09-15
CVE-2026-87173Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supporCRITICAL9.134%ileNVD2026-09-15
CVE-2026-87175Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supporCRITICAL9.124%ileNVD2026-09-15
CVE-2026-87176Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supporCRITICAL9.134%ileNVD2026-09-15
CVE-2026-87217Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supporCRITICAL9.132%ileNVD2026-09-15
CVE-2026-87223Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supporCRITICAL9.126%ileNVD2026-09-15
CVE-2026-61594djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to CRITICAL9.136%ileNVD2026-09-16
CVE-2026-54670WeGIA is a web manager for charitable institutions. Prior to 3.8.5, the contribution request dispatcher in web/html/contCRITICAL9.145%ileNVD2026-09-17
CVE-2026-54767WeGIA is a web manager for charitable institutions. Prior to 3.8.5, web/html/socio/sistema/controller/deletar_socios.phpCRITICAL9.136%ileNVD2026-09-17
CVE-2026-90938LangBot's plugin runtime (pip package langbot_plugin) through 0.4.17 starts a debug WebSocket server on 0.0.0.0:5401 (/pHIGH8.828%ileNVD2026-09-14
CVE-2026-90944Krayin CRM through 2.2.6 exposes the POST /admin/mail/inbound-parse endpoint without authentication, allowing unauthentiHIGH8.852%ileNVD2026-09-14
CVE-2026-59160Yeger is a monorepo for npm packages maintained under the yeger scope. Prior to 2.8.9, the turbo-graph package starts itHIGH8.835%ileNVD2026-09-15
CVE-2026-73173Nozomi Networks Labs identified a CWE-306: Missing Authentication for Critical Function vulnerability in the edgserver mHIGH8.851%ileNVD2026-09-16
CVE-2026-92729SigNoz versions 0.88.0 through 0.141.0 fail to apply authorization wrappers to trace-funnel analytics endpoints in the HHIGH8.844%ileNVD2026-09-16
CVE-2026-86801The To Do List Member WordPress plugin from 1.4 through 1.6 ships a file upload endpoint that does not load WordPress anHIGH8.827%ileNVD2026-09-17
CVE-2026-92972SGLang through 0.5.19 in prefill/decode disaggregation mode contains an unauthenticated PUT /route endpoint on the prefiHIGH8.827%ileNVD2026-09-17
CVE-2026-54504MCP Documentation Server is a local-first document management and semantic search server for AI coding agents. From 1.13HIGH8.850%ileNVD2026-09-17
CVE-2026-58197ToolHive is a utility designed to simplify the deployment and management of Model Context Protocol servers. Prior to TooHIGH8.8NVD2026-09-18
CVE-2026-82787Missing authentication for critical function vulnerability exists in CPSL-08P1EN. If this vulnerability is exploited, anHIGH8.730%ileNVD2026-09-14
CVE-2026-91996lamp-cloud through 5.10.0 whitelists the path pattern /*/anno/** for anonymous access, allowing unauthenticated attackerHIGH8.730%ileNVD2026-09-15
CVE-2026-68070The affected products are missing authentication for a critical function, which could allow an attacker to run as root aHIGH8.720%ileNVD2026-09-15
CVE-2026-88263XikeStor Layer3 switches miss authentication for downloading configuration data. Unauthenticated attacker may retrieve tHIGH8.745%ileNVD2026-09-16
CVE-2026-86106An unauthenticated actor with network access to the private HA interconnect may trigger sensitive HA peer functions withHIGH8.732%ileNVD2026-09-16
CVE-2026-79954NASA CryptoLib 1.5.0 contains an authentication downgrade vulnerability in the Telecommand (TC) receive path. The receivHIGH8.726%ileNVD2026-09-18
CVE-2026-88259CareCam CM2507 IP cameras do not require authentication for access to its network video streaming service. An unauthentiHIGH8.7NVD2026-09-18
CVE-2026-18111Concrete CMS 9 before 9.5.3 was vulnerable to stored cross-site scripting (XSS) in the Feature, Feature Link, Hero ImageHIGH8.523%ileNVD2026-09-15
CVE-2026-57112PraisonAI is a multi-agent teams system. From praisonaiagents 0.6.0 until 1.6.59 and PraisonAI 3.10.0 until 4.6.59, ToolHIGH8.39%ileNVD2026-09-15
CVE-2026-90896Missing Authentication for Critical Function (CWE-306) in the checkout session lookup handler (src/app/api/stripe/checkoHIGH8.238%ileNVD2026-09-14
CVE-2026-81475Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Missing Authentication for Critical FunctioHIGH8.152%ileNVD2026-09-17
CVE-2026-54446NetLicensing MCP Server is a natural-language interface that enables agentic applications to manage the software-licensiHIGH8.140%ileNVD2026-09-17
CVE-2026-81238Dell Wyse Management Suite, versions prior to 2605.0.3.683, contain a Missing Authentication for Critical Function vulneHIGH7.517%ileNVD2026-09-15
CVE-2026-88065`tts-be` is a backend for a timetable selector that aims to help students better choose their class schedules. Versions HIGH7.531%ileNVD2026-09-15
CVE-2026-92625Control iD iDSecure versions prior to 4.8.3.0 are affected by an unauthenticated Denial of Service. The /api/license/rHIGH7.543%ileNVD2026-09-16
CVE-2026-20343A vulnerability in a critical API for Cisco Secure FMC Software could allow an unauthenticated, remote attacker to downlHIGH7.538%ileNVD2026-09-16
CVE-2026-53714Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gatewayHIGH7.421%ileNVD2026-09-14
CVE-2026-87195Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supporHIGH7.425%ileNVD2026-09-15
CVE-2026-61590djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to HIGH7.427%ileNVD2026-09-16
CVE-2026-68953The affected products are vulnerable to an authentication bypass that allows unauthenticated remote attackers to disclosHIGH7.131%ileNVD2026-09-15
CVE-2026-40856WNC T-Mobile 5G Box IDU router is vulnerable to improper access control. The vulnerability exists in the wnc_maccheck.cgHIGH7.125%ileNVD2026-09-16
CVE-2026-89034TCH QRing smart ring model R20_B006 running firmware RT09R20_1.00.00_250318 contains an unauthenticated Bluetooth Low EnHIGH7.122%ileNVD2026-09-16
CVE-2026-90539WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a missing authentication vulnerability in tMEDIUM6.916%ileNVD2026-09-12
CVE-2026-90543WWBN AVideo at commit c3edcc274c389816d434acadac07ee78eaf330c1 and earlier, with the Live plugin enabled, contains a misMEDIUM6.928%ileNVD2026-09-12
CVE-2026-90513A flaw has been found in simalexan api-lambda-send-email-ses up to bda6869aa81371d1e872242e74fe7d953edb818d. This issue MEDIUM6.938%ileNVD2026-09-13
CVE-2026-82784Missing authentication for critical function vulnerability exists in Remote I/O Coupler Unit (Server Type) CPSN-MCB271-*MEDIUM6.910%ileNVD2026-09-14
CVE-2026-89027miniOrange JWT Authentication for WP REST APIs plugin for WordPress before 4.8.0 contains an authentication method downgMEDIUM6.930%ileNVD2026-09-15
CVE-2026-93559A vulnerability was identified in Forget-C Jellyfish AI Short Drama Studio 0.1.0-alpha/0.2.0/0.3.0/0.3.1/0.3.2. This affMEDIUM6.9NVD2026-09-18
CVE-2026-55837dbt-mcp is a Model Context Protocol server for interacting with dbt. Prior to 1.20.0, the local OAuth helper in src/dbt_MEDIUM6.812%ileNVD2026-09-14
CVE-2026-54246Skipper is an HTTP router and reverse proxy for service composition. Prior to 0.27.13, the routesrv component serves cluMEDIUM5.727%ileNVD2026-09-14
CVE-2026-90504A vulnerability has been found in vvbbnn00 WARP-Clash-API up to c7bf2360073959861219b422e51ae86411051b46. The impacted eMEDIUM5.549%ileNVD2026-09-13
CVE-2026-90524A security flaw has been discovered in jaychouchannel Tourism-Management-System up to 229956e20dbd4a80eeff14535e44d30995MEDIUM5.551%ileNVD2026-09-13
CVE-2026-90579A vulnerability has been found in cheshire-cat-ai Cheshire Cat AI up to 1.9.2. This affects the function _authorize_httpMEDIUM5.533%ileNVD2026-09-13
CVE-2026-90620A vulnerability was determined in 0x4m4 HexStrike AI up to d689933ff579d839c676c82b231f8e98326c5f04. The impacted elemenMEDIUM5.533%ileNVD2026-09-14
CVE-2026-91002A weakness has been identified in stamparm maltrail up to 3.0.1. This vulnerability affects the function _blacklist of tMEDIUM5.538%ileNVD2026-09-15
CVE-2026-12910GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.6 before 19.1.8, 19.2 before 19.2.6, and 1MEDIUM5.425%ileNVD2026-09-15
CVE-2026-76439A vulnerability in the endpoint posture status reporting functionality of the guest portal web application of Cisco ISE MEDIUM5.326%ileNVD2026-09-16
CVE-2026-76444A vulnerability in an internal service of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker toMEDIUM5.321%ileNVD2026-09-16
CVE-2026-76447A vulnerability in the Online Certificate Status Protocol (OCSP) responder of Cisco ISE and Cisco ISE-PIC could allow anMEDIUM5.320%ileNVD2026-09-16
CVE-2026-71568In BMCtest, Ironic is started without authentication and TLS for the duration of the test. Exploiting the problem requirMEDIUM5.36%ileNVD2026-09-17
CVE-2026-11539IBM WebSphere Application Server 9.0 and 8.5 is affected by an authentication bypass vulnerability in the SOAP/JMX conneMEDIUM5.3NVD2026-09-18
CVE-2026-77339Process Compose is a scheduler and orchestrator for non-containerized applications. Prior to 1.120.0, the MCP SSE listenMEDIUM5.1NVD2026-09-18
CVE-2026-76902CordysCRM is an open source AI-powered customer relationship management system that supports private deployment. Prior tMEDIUM5.0NVD2026-09-18
CVE-2026-50604A vulnerability has been identified in the Acer Agent Service component included with NitroSense and PredatorSense. The MEDIUM4.94%ileNVD2026-09-17
CVE-2026-57128PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.58, the SSE server in src/praisonai-agents/praisonMEDIUM4.36%ileNVD2026-09-14
CVE-2026-12763IBM Langflow OSS 1.0.0 through 1.11.5 could allow an authenticated attacker to access another user's MCP server context MEDIUM4.24%ileNVD2026-09-14
CVE-2026-81441Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Missing Authentication for Critical FunctioMEDIUM4.07%ileNVD2026-09-17
CVE-2026-49254Dragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.4.4, manager/router/roLOW2.920%ileNVD2026-09-15
CVE-2026-85478A CM2507 IP camera running firmware version HMT.CM2507 v251211.1507 exposes an interactive bootloader through a physicalLOW2.4NVD2026-09-18
CVE-2026-84400CareCam CM2507 IP cameras contain an insufficiently protected network maintenance mechanism that can activate a remote dLOW2.3NVD2026-09-18
CVE-2026-50608A vulnerability has been identified in the Acer System Monitoring component included with NitroSense and PredatorSense. LOW1.24%ileNVD2026-09-17