CWE-304

CWE-304 · 3 records · 1 with a public proof-of-concept

Records the NVD classes under CWE-304, highest CVSS first.

  1. CRITICAL 9.1CVE-2026-94052

    A missing check in LdapPasswordAuthenticator in component sshd-ldap in Apache MINA SSHD versions 1.2.0 to 2.19.0 or 3.0.0-M1 to 3.0.0-M5 bypassed authentication checks. Apache MINA SSHD is a Java library for client-side and server-side SSH. The optional ss…

    AI risk analysis on Exploit-DB.ai →

  2. HIGH 8.1CVE-2026-93994

    Apache MINA SSHD is a Java library for client-side and server-side SSH. SSH servers can be configured to require multi-authentication schemes, for instance two different public keys, not just one. In OpenSSH, this would be done by setting in sshd_config Authen…

    AI risk analysis on Exploit-DB.ai →

  3. MEDIUM 5.3CVE-2026-100667public PoC

    grav-plugin-login (the Grav CMS Login plugin) versions >= 3.8.7 and < 3.9.7 allow the two-factor authentication challenge to be bypassed for content gated by the authenticated() Twig function or the [authenticated] shortcode. On sites with 2FA enabled, Login::…

    AI risk analysis on Exploit-DB.ai →