CVE-2026-59545
Unauthenticated Broken Authentication in miniOrange Discord Integration <= 2.2.4 versions.
CVSS
8.1
High
EPSS
—
KEV
—
Exploit Today
0
0-100
Published: Jul 23, 2026 · Last modified: Jul 23, 2026 · CWE-288
Not enough EPSS history yet.
Unauthenticated Broken Authentication in miniOrange Discord Integration <= 2.2.4 versions.
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-595246.5 MED—
——0Unauthenticated Broken Authentication in Easy Digital Downloads <= 3.6.7 versions.5hCVE-2026-22049—39.9%
——12ONTAP versions 9.16.1 and higher with WebAuthn multi-factor authentication (MFA) configured are susceptible to a vulnerability related to the Relying Party ID which when successfully exploited could allow an attacker with valid credentials to bypass MFA.21hCVE-2026-43945—54.8%
——16FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Versions 1.2.11 until 1.3.1 allow an unauthenticated remote attacker to achieve Full Remote Code Execution (RCE) as root. The exploit succeeds even when the platform is configured in its most secure state (Secure Mode Enabled and Node-RED Secure Auth Enabled). Version 1.3.1 fixes the issue.22hCVE-2026-61425—16.8%
——5The Joomla extension Gridbox is vulnerable an authenticated bypass, potentially leading to full admin access.2dCVE-2026-39385—12.5%
——4Frappe LMS is an open source learning management system. In version 2.51.0 and earlier, a user could bypass payment validation for courses by using unrelated batch. This has been patched in 2.52.0 with enrollment now validating that the batch is linked to course.20hCVE-2026-161985.6 MED45.4%
——14A vulnerability was detected in Sipeed PicoClaw up to 0.2.9. The impacted element is an unknown function of the file web/backend/middleware/access_control.go of the component First Run Setup. Performing a manipulation of the argument allowed_cidrs results in authentication bypass using alternate channel. The attack may be initiated remotely. The attack's complexity is rated as high. The exploitability is regarded as difficult. The exploit is now public and may be used. The patch is named 017601354be38cb027ff3ffb01aed79bd5d12610. Applying a patch is the recommended action to fix this issue.2d