CWE-288
CWE-288 · 4 records · 1 with a public proof-of-concept
Records the NVD classes under CWE-288, highest CVSS first.
- CRITICAL 9.8CVE-2026-27546
An unauthenticated remote attacker can exploit an authentication bypass in the _account_log function to log in as an admin, even when accounts are properly configured.
- CRITICAL 9.8CVE-2026-24254public PoC
NVIDIA Dynamo for Linux contains a vulnerability in the multimodal serving topology, where an attacker could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, denial…
dynamo · linux kernel
- UNSCOREDCVE-2026-14917
A SAML authentication bypass vulnerability affects the Kong SAML plugin when the validate_assertion_signature option is explicitly set to false. This option is enabled by default. When disabled, the plugin may extract the SAML identity from an unsigned asserti…
- UNSCOREDCVE-2026-58073
A vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to impersonate a managed agent andobtain that agent's credentials.