cwe-306
Safeguard articles tagged "cwe-306" — guides, analysis, and best practices for software supply chain and application security.
42 articles
CVE-2025-0108: Palo Alto Networks PAN-OS Authentication Bypass Vulnerability
CVE-2025-0108 affects Palo Alto Networks PAN-OS and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2025-02-18.
CVE-2025-3248: Langflow Missing Authentication Vulnerability
CVE-2025-3248 affects Langflow Langflow and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2025-05-05.
CVE-2025-32433: Erlang Erlang/OTP SSH Server Missing Authentication for Critical Function Vulnerability
CVE-2025-32433 affects Erlang Erlang/OTP and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2025-06-09.
CVE-2020-24363: TP-link TL-WA855RE Missing Authentication for Critical Function Vulnerability
CVE-2020-24363 affects TP-Link TL-WA855RE and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2025-09-02.
CVE-2025-4008: Smartbedded Meteobridge Command Injection Vulnerability
CVE-2025-4008 affects Smartbedded Meteobridge and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2025-10-02.
CVE-2025-61757: Oracle Fusion Middleware Missing Authentication for Critical Function Vulnerability
CVE-2025-61757 affects Oracle Fusion Middleware and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2025-11-21.
CVE-2026-24423: SmarterTools SmarterMail Missing Authentication for Critical Function Vulnerability
CVE-2026-24423 affects SmarterTools SmarterMail and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2026-02-05.
CVE-2026-33017: Langflow Code Injection Vulnerability
CVE-2026-33017 affects Langflow Langflow and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2026-03-25.
CVE-2026-39987: Marimo Remote Code Execution Vulnerability
CVE-2026-39987 affects Marimo Marimo and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2026-04-23.
CVE-2026-41940: WebPros cPanel & WHM and WP2 (WordPress Squared) Missing Authentication for Critical Function Vulnerability
CVE-2026-41940 affects WebPros cPanel & WHM and WP2 (WordPress Squared) and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2026-04-30.
CVE-2026-35273: Oracle PeopleSoft Enterprise PeopleTools Missing Authentication for Critical Function Vulnerability
CVE-2026-35273 affects Oracle PeopleSoft Enterprise PeopleTools and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2026-06-12.
CVE-2026-20253: Splunk Enterprise Missing Authentication for Critical Function Vulnerability
CVE-2026-20253 affects Splunk Enterprise and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2026-06-18.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.