CVE-2026-6274
Improper Authentication, Missing authentication for critical function, Weak Authentication vulnerability in DTS Electronics Industry and Tra
CVSS
9.8
Critical
EPSS
0.5%
p37
KEV
—
Exploit Today
11
0-100
Published: Jun 5, 2026 · Last modified: Jul 23, 2026 · CWE-287 · CWE-306 · CWE-1390
0.5%EPSS · 30 days0.5%
2026-06-302026-07-23
Improper Authentication, Missing authentication for critical function, Weak Authentication vulnerability in DTS Electronics Industry and Trade Ltd. Co. Redline WR3200 allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Redline WR3200: from 7.1.3 before 7.1.8.
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-6481210.0 CRI—
——0In JetBrains IntelliJ IDEA before 2026.2 unauthorized input injection was possible in a Remote Development session6hCVE-2026-595547.5 HIG—
——0Unauthenticated Broken Authentication in Ziina <= 1.2.21 versions.6hCVE-2026-153486.3 MED—
——0The Premium Packages – Sell Digital Products Securely plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 7.0.4 via the `wpdmppdl` parameter. This is due to the `download()` function — hooked to the unauthenticated WordPress `wp` action — decoding the attacker-controlled `wpdmppdl` parameter using only `base64_decode()` and `json_decode()` with no HMAC, cryptographic signature, or nonce verification, and then issuing WordPress authentication cookies after a domain check that is trivially bypassed because both sides of the comparison are attacker-supplied values. This makes it possible for unauthenticated attackers to authenticate as any non-administrator WordPress user, including subscribers, customers, contributors, authors, editors, and shop managers, who owns an order, gaining full session-level access to that account.8hCVE-2026-650125.3 MED35.9%
——11InvokeAI before 6.13.7 contains an unauthenticated directory enumeration vulnerability in the GET /api/v2/models/scan_folder endpoint that accepts attacker-controlled scan_path parameters. Unauthenticated attackers can recursively enumerate arbitrary server filesystem directories and use HTTP response codes to determine file existence and readability, bypassing multi-user mode access controls.1dCVE-2026-621449.1 CRI59.4%
——18An authentication bypass vulnerability in Check Point Security Management and Multi-Domain Security Management allows an unauthenticated remote attacker to execute administrative commands on the Management Server. Successful exploitation may also allow command execution on managed Security Gateways. Exploitation requires network access to the Management Server without firewall protection or a configuration that does not restrict Trusted Clients.21hCVE-2026-162329.1 CRI61.5%
KEV—68Check Point SmartConsole Improper Authentication Vulnerability13h