VulnSea

CWE-200

CVEs classified under CWE-200, newest first.

670 CVEsRSS

CVE-2026-61746Medium· 5.3PoC
today

InvenTree is an Open Source Inventory Management System

InvenTree is an Open Source Inventory Management System. Prior to 1.4.0, PluginSettingList, PluginAllSettingList, and PluginSettingDetail set GlobalSettingsPermissions without the IsAuthenticated permission used by the project default an…

Twilightinventree · InvenTreevia NVD
CVE-2026-94413Medium· 6.5
today

jshERP through 3.6 fails to redact password hashes in the /user/info endpoint, allowing authenticated users to retrieve unsalted MD5 password digests for any user

jshERP through 3.6 fails to redact password hashes in the /user/info endpoint, allowing authenticated users to retrieve unsalted MD5 password digests for any user. Attackers can request arbitrary user information by supplying user IDs to…

Sunlitjishenghua · jshERPvia NVD
CVE-2026-61749Medium· 6.5
today

InvenTree is an Open Source Inventory Management System

InvenTree is an Open Source Inventory Management System. Prior to 1.4.0, privileged staff users who can author report or label templates can cause WeasyPrint report rendering to retrieve attacker-selected resources through the HTTP and H…

Sunlitinventree · InvenTreevia NVD
CVE-2026-84990High· 8.8
today

ntopng is a web-based network traffic monitoring application

ntopng is a web-based network traffic monitoring application. Prior to 6.7.260718, scripts/lua/rest/v2/get/system/configurations/list_available_backups.lua and scripts/lua/rest/v2/get/system/configurations/download_backup.lua allow any a…

Twilightntop · ntopngvia NVD
CVE-2026-55870None
today

GoCD is a continuous deliver server

GoCD is a continuous deliver server. Prior to 26.1.0, GoCD can return unmasked credentials that administrators stored in the userinfo portion of source control material URLs through several read-only APIs available to regular authenticat…

Sunlitvia NVD
CVE-2026-75158Medium· 4.3
today

Apache Airflow's `/assets/events` API returned asset events for every Dag in the deployment, with no filter restricting them to the Dags the caller is authorized to read

Apache Airflow's `/assets/events` API returned asset events for every Dag in the deployment, with no filter restricting them to the Dags the caller is authorized to read. Any authenticated user holding asset-read access could therefore e…

SunlitApache Software Foundation · apache-airflowvia NVD
CVE-2026-94148Medium· 5.3PoC
today

A vulnerability was determined in ScadaBR up to 1.1

A vulnerability was determined in ScadaBR up to 1.1. Impacted is the function EmportDwr.createExportJSON of the file /ScadaBR/export_project.htm of the component Export Project Endpoint. This manipulation causes information disclosure. T…

TwilightEPSS 0.31%via NVD
CVE-2026-94185Medium· 5.5
today

nvm resolves a requested version or alias by treating it as a filename under $NVM_DIR/alias

nvm resolves a requested version or alias by treating it as a filename under $NVM_DIR/alias. Before 0.40.8, nvm_alias() concatenated the requested name onto that directory and read the result with no containment check, so a name containi…

Sunlitnvm-sh · nvmEPSS 0.29%via NVD
CVE-2026-94050Medium· 4.3
yesterday

A vulnerability has been found in D-Link DIR-X1860Z up to 1.0.2.220120.165402

A vulnerability has been found in D-Link DIR-X1860Z up to 1.0.2.220120.165402. Affected is the function routerd.wificfg_get/routerd.get_rand_key of the component ubus JSON-RPC interface. Such manipulation leads to information disclosure.…

SunlitD-Link · DIR-X1860ZEPSS 0.23%via NVD
CVE-2026-93971Medium· 5.3
yesterday

A weakness has been identified in aiyiyi121 SxDevOps 1.0/1.1

A weakness has been identified in aiyiyi121 SxDevOps 1.0/1.1. Impacted is an unknown function of the file backend/sxdevops/settings.py. This manipulation causes information disclosure. It is possible to initiate the attack remotely. Patc…

Sunlitaiyiyi121 · SxDevOpsEPSS 0.31%via NVD
CVE-2026-92423Low· 2.7
yesterday

The Meow Gallery WordPress plugin before 5.5.5 does not perform a proper capability check or restrict results to the requesting user's own posts before returning post data, allowing authenticated users with Author-level access and above …

The Meow Gallery WordPress plugin before 5.5.5 does not perform a proper capability check or restrict results to the requesting user's own posts before returning post data, allowing authenticated users with Author-level access and above …

SunlitEPSS 0.19%via NVD
CVE-2026-1255High· 7.5
2d ago

The YS LeadGen plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.1.4 due to the 'ysleadgen_get_captured_data' AJAX action being accessible to unauthenticated users

The YS LeadGen plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.1.4 due to the 'ysleadgen_get_captured_data' AJAX action being accessible to unauthenticated users. This makes it…

Twilightysinnovations · YS LeadGen – Popup Builder, Popup Maker & Form Builder for WordPress | Lead Generation, Email Marketing, Sales, Conversions, Opt-Ins & SubscribersEPSS 0.29%via NVD
CVE-2026-9289Medium· 5.3
2d ago

The WordLift – AI powered SEO – Schema plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.54.10 via the JSON-LD REST API endpoints

The WordLift – AI powered SEO – Schema plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.54.10 via the JSON-LD REST API endpoints. This is due to the plugin registering the /word…

Sunlitwordlift · WordLift – AI powered SEO – SchemaEPSS 0.36%via NVD
CVE-2026-16557Medium· 4.3
2d ago

The Nimble Page Builder WordPress plugin through 3.3.8 does not perform an authorization check when returning page-builder content through an authenticated AJAX action, allowing any authenticated user (Subscriber+) to disclose the page-b…

The Nimble Page Builder WordPress plugin through 3.3.8 does not perform an authorization check when returning page-builder content through an authenticated AJAX action, allowing any authenticated user (Subscriber+) to disclose the page-b…

SunlitEPSS 0.18%via NVD
CVE-2026-92404High· 7.5
2d ago

The MgoSync WordPress plugin before 2.1.7 does not have authorization controls on one of its REST API endpoints, allowing unauthenticated users to retrieve the stored WooCommerce API credentials, including a read/write consumer key and …

The MgoSync WordPress plugin before 2.1.7 does not have authorization controls on one of its REST API endpoints, allowing unauthenticated users to retrieve the stored WooCommerce API credentials, including a read/write consumer key and …

TwilightEPSS 0.26%via NVD
CVE-2026-92708High· 7.5
3d ago

Svelte devalue is a JavaScript library that serializes values into strings when JSON.stringify isn't sufficient for the job

Svelte devalue is a JavaScript library that serializes values into strings when JSON.stringify isn't sufficient for the job. In versions 5.1.0 through 5.9.2, stringify and uneval functions serialize a typed array by emitting its entire b…

Twilightsveltejs · devalueEPSS 0.34%via NVD
CVE-2026-63646Medium· 6.9PoC
3d ago

CordysCRM is an open source AI-powered customer relationship management system that supports private deployment

CordysCRM is an open source AI-powered customer relationship management system that supports private deployment. Prior to 1.7.2, GET /mcp/form/config/{formKey} calls McpController.getMcpField without authentication because ShiroFilter.ad…

Twilight1Panel-dev · CordysCRMEPSS 0.49%via NVD
CVE-2026-77568Medium· 4.2
3d ago

Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER

Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-15747. Reason: This candidate is a duplicate of CVE-2026-15747. Notes: All CVE users should reference CVE-2026-15747 instead of this candidate.

Sunlitmojolicious · mojoEPSS 0.10%via NVD
CVE-2026-93685Medium· 5.4
3d ago

A flaw was found in the multicluster-observability-addon

A flaw was found in the multicluster-observability-addon. A remote attacker can access a debug endpoint without authentication, due to a misconfiguration in the underlying addon-framework library. This allows for the disclosure of sensit…

SunlitRed Hat · redhat-user-workloads/multicluster-observability-addon-acm-213EPSS 0.36%via NVD
CVE-2026-56597Low· 3.1
3d ago

HCL BigFix Service Management is affected by a Sensitive Information Leakage vulnerability, which could allow an unauthenticated attacker to extract internal IP addresses from the application's responses, enabling them to map the underly…

HCL BigFix Service Management is affected by a Sensitive Information Leakage vulnerability, which could allow an unauthenticated attacker to extract internal IP addresses from the application's responses, enabling them to map the underly…

SunlitHCL Software · HCL BigFix Service ManagementEPSS 0.16%via NVD
CVE-2026-67100Critical· 9.8
3d ago

HCL BigFix Service Management is affected by SQL Injection flaw and a Cross-Tenant Data Exposure flaw vulnerabilities

HCL BigFix Service Management is affected by SQL Injection flaw and a Cross-Tenant Data Exposure flaw vulnerabilities. which could allow an authenticated attacker to inject database commands to extract sensitive system details, as well a…

MidnightHCL Software · HCL BigFix Service ManagementEPSS 0.35%via NVD
CVE-2026-89278Medium· 5.3
3d ago

The GPTranslate – Multilingual AI Translation Agent for WordPress: Translate Your Site with AI plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.34.6 via the enqueue_frontend_scr…

The GPTranslate – Multilingual AI Translation Agent for WordPress: Translate Your Site with AI plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.34.6 via the enqueue_frontend_scr…

Sunlitjohn-dagelmore · GPTranslate – Multilingual AI Translation Agent for WordPress: Translate Your Site with AIEPSS 0.26%via NVD
CVE-2026-89008Low· 2.7
3d ago

The Bookit — Booking & Appointment Calendar WordPress plugin before 2.6.0.5 does not perform an authorization check on one of its appointment-retrieval actions, allowing users with a low-privilege Bookit — Booking & Appointment Calendar …

The Bookit — Booking & Appointment Calendar WordPress plugin before 2.6.0.5 does not perform an authorization check on one of its appointment-retrieval actions, allowing users with a low-privilege Bookit — Booking & Appointment Calendar …

SunlitEPSS 0.19%via NVD
CVE-2026-84903Low· 2.7
3d ago

The King Addons for Elementor WordPress plugin before 51.1.81 does not perform any capability, post-status, or password check before rendering the content of a user-supplied post, allowing users with Contributor-level access and above t…

The King Addons for Elementor WordPress plugin before 51.1.81 does not perform any capability, post-status, or password check before rendering the content of a user-supplied post, allowing users with Contributor-level access and above t…

SunlitEPSS 0.23%via NVD
CVE-2026-93385Medium· 6.5
4d ago

Information leak in Paint in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to obtain sensitive information via a crafted HTML page

Information leak in Paint in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)

Sunlitgoogle · chromeEPSS 0.31%via NVD
CVE-2026-93383Medium· 4.3
4d ago

Information leak in Permissions in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to leak cross-origin data via a crafted HTML page

Information leak in Permissions in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

Sunlitgoogle · chromeEPSS 0.25%via NVD
CVE-2026-54565Medium· 4.7
4d ago

rhwp is an HWP viewer and editor implemented in Rust and WebAssembly

rhwp is an HWP viewer and editor implemented in Rust and WebAssembly. Prior to rhwp 0.7.15 and rhwp Chrome and Firefox extension 0.2.4, the browser extensions use an all-URLs host permission to detect HWP and HWPX links on visited pages,…

Sunlitedwardkim · rhwpEPSS 0.13%via NVD
CVE-2026-72698High· 6.5
4d ago

Grav: The system, site, and theme Twig variables bypass the content sandbox entirely and are never covered by config_denied_paths

Grav: The system, site, and theme Twig variables bypass the content sandbox entirely and are never covered by config_denied_paths

Twilightgetgrav · getgrav/gravEPSS 0.24%via GHSA
CVE-2026-45726High· 7.6
4d ago

Omni manages Kubernetes on bare metal, virtual machines, or in a cloud

Omni manages Kubernetes on bare metal, virtual machines, or in a cloud. From 1.3.0 until 1.6.6 and 1.7.3, importing a standalone Talos cluster creates an ImportedClusterSecrets resource containing the cluster's complete CA secrets bundle…

Twilightsiderolabs · omniEPSS 0.10%via NVD
CVE-2026-54649Low· 2.1
4d ago

punchin-email is a Cloudflare Email Worker that provides two-way role aliases while relaying mail to a private inbox

punchin-email is a Cloudflare Email Worker that provides two-way role aliases while relaying mail to a private inbox. Prior to 1.5.0, handleInbound delivers inbound alias mail with message.forward(), which silently drops the added Reply-…

SunlitPunchIn-App · punchin-emailEPSS 0.47%via NVD
CWE-200 vulnerabilities (CVEs) · VulnSea