CWE-305

CWE-305 · 3 records · 2 with a public proof-of-concept

Records the NVD classes under CWE-305, highest CVSS first.

  1. MEDIUM 6.5CVE-2026-88837

    BusyBox httpd treats yescrypt ($y$) password hashes as plaintext during Basic Authentication, inverting the authentication check.

    AI risk analysis on Exploit-DB.ai →

  2. MEDIUM 4.6CVE-2026-59563public PoC

    Zscaler MCP Server versions 0.7.0 and 0.7.1 has an issue where HMAC confirmation tokens were not bound to the target resource identifier, allowing an MCP client or agent to replay a token generated for one resource to affect another resource of the same type. …

    AI risk analysis on Exploit-DB.ai →

  3. UNSCOREDCVE-2026-85500public PoC

    Authentication Bypass by Primary Weakness vulnerability in team-alembic AshAuthentication allows an unconfirmed user to obtain a session, defeating a mandatory email confirmation requirement. AshAuthentication.Strategy.Password.Actions.check_user/2 decides wh…

    AI risk analysis on Exploit-DB.ai →