CWE-303

CWE-303 · 4 records · 3 with a public proof-of-concept

Records the NVD classes under CWE-303, highest CVSS first.

  1. CRITICAL 10CVE-2026-77244public PoC

    MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, the HTTP transport accepts requests without a verified user identity and downstream fetcher construction falls back to the operator's globally…

    AI risk analysis on Exploit-DB.ai →

  2. CRITICAL 9.1CVE-2026-10050public PoC

    In Eclipse Jetty, the Digest authentication server-side component uses ISO-8859-1 to encode the password as bytes. This was done because the initial specification for HTTP did not specify explicitly a charset, and it was assumed to be ISO-8859-1 for histori…

    jetty

    AI risk analysis on Exploit-DB.ai →

  3. HIGH 7.5CVE-2026-101878public PoC

    Bitwarden Server 2025.6.0 before 2026.5.0 declares the @ExternalId parameter of the User_ReadBySsoUserOrganizationIdExternalId stored procedure as NVARCHAR(50) while the column it queries stores NVARCHAR(300), silently truncating the SSO login identifier on SQ…

    AI risk analysis on Exploit-DB.ai →

  4. MEDIUM 4.7CVE-2026-73444

    On affected platforms running Arista EOS with VRRPv2 IP Authentication Header (IP-AH) authentication configured, an unauthenticated attacker with access to the layer 2 network segment on which VRRP is running could bypass VRRP authentication and claim the virt…

    AI risk analysis on Exploit-DB.ai →