CWE-289
CWE-289 · 4 records · 2 with a public proof-of-concept
Records the NVD classes under CWE-289, highest CVSS first.
- CRITICAL 9.8CVE-2026-76183
Authentication Bypass by Alternate Name vulnerability in Apache Tomcat allowed the security constraints for any WebSocket endpoint to be bypassed. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.25, from 10.1.0-M1 through 10.1.59, from 9.0.0.M…
- MEDIUM 6.8CVE-2026-57176public PoC
Python Social Auth is a social authentication/registration mechanism. Prior to version 5.0.0, the Vend OAuth2 backend used only the numeric Vend user_id as the social-auth UID. When multiple Vend shops authenticate through the same application, users from diff…
- MEDIUM 5.3CVE-2026-95514
Unauthenticated Bypass Vulnerability in Netgsm <= 2.10.0 versions.
- MEDIUM 5.3CVE-2026-73511public PoC
Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, Envoy normally matches the raw request path, while servlet backends such as Apache Tomcat strip semicolon matrix parameters fro…