CWE-288

CWE-288 · 4 records · 1 with a public proof-of-concept

Records the NVD classes under CWE-288, highest CVSS first.

  1. CRITICAL 9.8CVE-2026-27546

    An unauthenticated remote attacker can exploit an authentication bypass in the _account_log function to log in as an admin, even when accounts are properly configured.

    AI risk analysis on Exploit-DB.ai →

  2. CRITICAL 9.8CVE-2026-24254public PoC

    NVIDIA Dynamo for Linux contains a vulnerability in the multimodal serving topology, where an attacker could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, denial

    dynamo · linux kernel

    AI risk analysis on Exploit-DB.ai →

  3. UNSCOREDCVE-2026-14917

    A SAML authentication bypass vulnerability affects the Kong SAML plugin when the validate_assertion_signature option is explicitly set to false. This option is enabled by default. When disabled, the plugin may extract the SAML identity from an unsigned asserti

    AI risk analysis on Exploit-DB.ai →

  4. UNSCOREDCVE-2026-58073

    A vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to impersonate a managed agent andobtain that agent's credentials.

    AI risk analysis on Exploit-DB.ai →