VulnSea

CWE-200

CVEs classified under CWE-200, newest first.

814 CVEsRSS

CVE-2026-81531Medium· 6.9
2w ago

An information disclosure vulnerability has been identified in Omada Controller.  An API endpoint intended for Controller initialization remains accessible after completion and may disclose account-related information to unauthenticated …

An information disclosure vulnerability has been identified in Omada Controller.  An API endpoint intended for Controller initialization remains accessible after completion and may disclose account-related information to unauthenticated …

▾ SunlitTP-Link System Inc. · Omada Software ControllerEPSS 0.67%via NVD
CVE-2026-0860High· 7.5
2w ago

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows a local non-privileged user process to perform improper GPU memory p…

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows a local non-privileged user process to perform improper GPU memory p…

▾ TwilightArm Ltd · Valhall GPU Kernel DriverEPSS 0.24%via NVD
CVE-2026-77132Medium· 5.3
2w ago

It has been discovered that several AJAX routes used for the backend localization wizard failed to perform authorization checks

It has been discovered that several AJAX routes used for the backend localization wizard failed to perform authorization checks. This allowed authenticated, low-privileged backend users to access information about records and content ele…

▾ SunlitTYPO3 · typo3/cms-backendEPSS 0.43%via NVD
CVE-2026-86519Medium· 5.3PoC
2w ago

A vulnerability was found in code-projects Student Crud Operation 1.0

A vulnerability was found in code-projects Student Crud Operation 1.0. This impacts an unknown function of the file /card_activation.sql of the component Backup File Handler. The manipulation results in information disclosure. The attack…

▾ Twilightcode-projects · Student Crud OperationEPSS 0.53%via NVD
CVE-2026-78675High· 8.4⚖ disputed
2w ago

GitPython: Arbitrary local file content disclosure via [include] directive in untrusted .gitmodules (SubmoduleConfigParser never disables…

GitPython: Arbitrary local file content disclosure via [include] directive in untrusted .gitmodules (SubmoduleConfigParser never disables merge_includes)

▾ Twilightgitpython · gitpythonEPSS 0.18%via OSV
CVE-2026-86308Medium· 5.3PoC
2w ago

A vulnerability was detected in light0011 cms c774dce31c6df0055568a8d5c53d964d99be199d/f72cf46f601efb2a0618c3814cc2f61380b38930

A vulnerability was detected in light0011 cms c774dce31c6df0055568a8d5c53d964d99be199d/f72cf46f601efb2a0618c3814cc2f61380b38930. This issue affects some unknown processing of the file App/Common/Conf/config.php of the component Debug Mod…

▾ Twilightlight0011 · cmsEPSS 0.54%via NVD
CVE-2026-86441Medium· 4.3⚖ disputed
2w ago

Affected versions of MISP contain inconsistent authorization checks across dashboard widgets that display organisation information. Several organisation-related widgets did not honor Security.hide_organisation_index_from_users

Affected versions of MISP contain inconsistent authorization checks across dashboard widgets that display organisation information. Several organisation-related widgets did not honor Security.hide_organisation_index_from_users. As a re…

▾ Sunlitmisp-project · mispEPSS 0.28%via NVD
CVE-2026-86419Critical· 9.1⚖ disputed
2w ago

Affected versions of MISP contain insufficient validation of server-side outbound HTTP destinations in feed retrieval and TAXII discovery functionality. In feed processing, redirects were followed without validating the redirect scheme…

Affected versions of MISP contain insufficient validation of server-side outbound HTTP destinations in feed retrieval and TAXII discovery functionality. In feed processing, redirects were followed without validating the redirect scheme…

▾ Midnightmisp-project · mispEPSS 0.42%via NVD
CVE-2026-86418Medium· 4.3⚖ disputed
2w ago

Affected versions of MISP expose organisation metadata through the dashboard organisation picker without applying the same visibility restrictions enforced by the normal organisation index and per-organisation view. The affected endpoin…

Affected versions of MISP expose organisation metadata through the dashboard organisation picker without applying the same visibility restrictions enforced by the normal organisation index and per-organisation view. The affected endpoin…

▾ Sunlitmisp-project · mispEPSS 0.27%via NVD
CVE-2026-86417Medium· 4.3
2w ago

Affected versions of MISP inconsistently enforced email-address visibility in DashboardsController::listTemplates(). The query always fetched User.email, while redaction happened only inside the non-REST rendering branch

Affected versions of MISP inconsistently enforced email-address visibility in DashboardsController::listTemplates(). The query always fetched User.email, while redaction happened only inside the non-REST rendering branch. As a result, …

▾ Sunlitmisp-project · mispEPSS 0.27%via NVD
CVE-2026-86302Medium· 5.3PoC
2w ago

A vulnerability was found in code-projects Hospital Information System 1.0

A vulnerability was found in code-projects Hospital Information System 1.0. Affected by this vulnerability is an unknown functionality of the file /HIS/his.sql of the component SQL Database Backup File Handler. Performing a manipulation …

▾ Twilightcode-projects · Hospital Information SystemEPSS 0.53%via NVD
CVE-2026-86284Medium· 5.3PoC
2w ago

A security vulnerability has been detected in jaychouchannel Tourism-Management-System up to 8122bf020d91199eddfff3ee02d1632a70a9a132

A security vulnerability has been detected in jaychouchannel Tourism-Management-System up to 8122bf020d91199eddfff3ee02d1632a70a9a132. Affected by this vulnerability is the function getOption of the file travel/src/main/java/com/controll…

▾ Twilightjaychouchannel · Tourism-Management-SystemEPSS 0.55%via NVD
CVE-2026-86217Medium· 5.3PoC
3w ago

A vulnerability was detected in code-projects Hotel and Tourism Reservation in PHP 1.0

A vulnerability was detected in code-projects Hotel and Tourism Reservation in PHP 1.0. Affected is an unknown function of the file /ht/hotel_db%20(1).sql of the component Database Backup Handler. The manipulation results in information …

▾ Twilightcode-projects · Hotel and Tourism Reservation in PHPEPSS 0.53%via NVD
CVE-2026-86179Medium· 5.3PoC
3w ago

A flaw has been found in code-projects Daily Expense Manager 1.0

A flaw has been found in code-projects Daily Expense Manager 1.0. Affected is an unknown function of the file /Daily-Expense-Manager/exp_ak.sql of the component Database Backup Handler. Executing a manipulation can lead to information di…

▾ Twilightcode-projects · Daily Expense ManagerEPSS 0.53%via NVD
CVE-2026-86190Critical· 9.1PoC
3w ago

WWBN AVideo contains a broken access control vulnerability in videoViewsInfo endpoints that returns complete user records including password hashes, recovery tokens, and live session identifiers to unauthenticated callers when a hash par…

WWBN AVideo contains a broken access control vulnerability in videoViewsInfo endpoints that returns complete user records including password hashes, recovery tokens, and live session identifiers to unauthenticated callers when a hash par…

▾ AbyssalWWBN · AVideoEPSS 0.44%via NVD
CVE-2026-84926Low· 2.7
3w ago

The EmbedPress WordPress plugin before 4.6.4 does not correctly restrict access to one of its Google Reviews REST routes to administrators, allowing any authenticated user with contributor-level access or above to read the site administ…

The EmbedPress WordPress plugin before 4.6.4 does not correctly restrict access to one of its Google Reviews REST routes to administrators, allowing any authenticated user with contributor-level access or above to read the site administ…

▾ SunlitEPSS 0.32%via NVD
CVE-2026-84745Low· 2.7
3w ago

The Events Calendar WordPress plugin before 6.17.3.1 does not restrict non-public content to the users entitled to read it on its public REST archives, allowing users with a low-privilege role such as contributor to read the full content…

The Events Calendar WordPress plugin before 6.17.3.1 does not restrict non-public content to the users entitled to read it on its public REST archives, allowing users with a low-privilege role such as contributor to read the full content…

▾ SunlitEPSS 0.32%via NVD
CVE-2026-81348Low· 3.7
3w ago

The My Private Site WordPress plugin before 4.2.3 does not apply its site-privacy access control to certain unauthenticated front-end read surfaces, allowing unauthenticated users to view post content, comments and post URLs from a site…

The My Private Site WordPress plugin before 4.2.3 does not apply its site-privacy access control to certain unauthenticated front-end read surfaces, allowing unauthenticated users to view post content, comments and post URLs from a site…

▾ SunlitEPSS 0.28%via NVD
CVE-2026-78149Medium· 5.3
3w ago

The Smart Post WordPress plugin before 4.0.8 does not check whether a post is password protected before returning its content and its stored password through an unauthenticated AJAX action, allowing unauthenticated users to read protect…

The Smart Post WordPress plugin before 4.0.8 does not check whether a post is password protected before returning its content and its stored password through an unauthenticated AJAX action, allowing unauthenticated users to read protect…

▾ SunlitEPSS 0.34%via NVD
CVE-2026-19858High· 7.5
3w ago

The JetFormBuilder — Dynamic Blocks Form Builder WordPress plugin before 3.6.5.2 does not perform authorisation checks when resolving request-derived data during page rendering, allowing unauthenticated users to read arbitrary user, post…

The JetFormBuilder — Dynamic Blocks Form Builder WordPress plugin before 3.6.5.2 does not perform authorisation checks when resolving request-derived data during page rendering, allowing unauthenticated users to read arbitrary user, post…

▾ TwilightEPSS 0.32%via NVD
CVE-2026-75162Medium· 6.5
3w ago

An information disclosure vulnerability in the opcua-configuration method of /cgi-bin/wwwugw.cgi in MBS-Solutions X-Serie Gateway firmware V6_00_05 allows any remote authenticated user, including users with the low-privileged Standard ro…

An information disclosure vulnerability in the opcua-configuration method of /cgi-bin/wwwugw.cgi in MBS-Solutions X-Serie Gateway firmware V6_00_05 allows any remote authenticated user, including users with the low-privileged Standard ro…

▾ SunlitEPSS 0.65%via NVD
CVE-2026-75163Medium· 6.5
3w ago

An information disclosure vulnerability in the ugw-deviceinfo method of /cgi-bin/wwwugw.cgi in MBS-Solutions X-Serie Gateway firmware V6_00_05 returns detailed system version fields (operatingsystem, gatewayversion) to any authenticated …

An information disclosure vulnerability in the ugw-deviceinfo method of /cgi-bin/wwwugw.cgi in MBS-Solutions X-Serie Gateway firmware V6_00_05 returns detailed system version fields (operatingsystem, gatewayversion) to any authenticated …

▾ SunlitEPSS 0.45%via NVD
CVE-2026-85588Medium· 5.3
3w ago

phpMyFAQ versions before 4.1.8 include live TOTP shared secrets in plaintext within user data export ZIP files

phpMyFAQ versions before 4.1.8 include live TOTP shared secrets in plaintext within user data export ZIP files. Attackers obtaining exported archives can extract the TOTP seed and generate valid one-time codes to bypass two-factor authen…

▾ Sunlitthorsten · phpMyFAQEPSS 0.53%via NVD
CVE-2026-84146Medium· 5.3
3w ago

The Xpro Addons — 140+ Widgets for Elementor WordPress plugin before 1.7.8 does not perform any capability or post-status check before rendering a WooCommerce product summary from a supplied product identifier, allowing unauthenticated v…

The Xpro Addons — 140+ Widgets for Elementor WordPress plugin before 1.7.8 does not perform any capability or post-status check before rendering a WooCommerce product summary from a supplied product identifier, allowing unauthenticated v…

▾ SunlitEPSS 0.33%via NVD
CVE-2026-79631Medium· 5.3
3w ago

The WPFunnels WordPress plugin before 3.13.0 does not restrict access to the log files it writes to a predictable location under the public uploads directory, allowing unauthenticated users to download customer order details and opt-in …

The WPFunnels WordPress plugin before 3.13.0 does not restrict access to the log files it writes to a predictable location under the public uploads directory, allowing unauthenticated users to download customer order details and opt-in …

▾ SunlitEPSS 0.34%via NVD
CVE-2026-17517Medium· 5.3
3w ago

The Content Views WordPress plugin before 4.5.1.2 does not check whether the user requesting a view is allowed to read the posts it returns, allowing unauthenticated attackers to obtain the title and content of non-public posts, such as…

The Content Views WordPress plugin before 4.5.1.2 does not check whether the user requesting a view is allowed to read the posts it returns, allowing unauthenticated attackers to obtain the title and content of non-public posts, such as…

▾ SunlitEPSS 0.21%via NVD
CVE-2026-84933Medium· 6.5
3w ago

undici's cache interceptor does not handle the Set-Cookie response header anywhere in its cache path, so it neither refuses to store nor strips that header

undici's cache interceptor does not handle the Set-Cookie response header anywhere in its cache path, so it neither refuses to store nor strips that header. In shared cache mode, which is the default, an otherwise cacheable response that…

▾ Sunlitnodejs · undiciEPSS 0.34%via NVD
CVE-2026-71626High· 7.5PoC
3w ago

An issue in Invoice Ninja v5.13.24 allows a remote attacker to obtain sensitive information via the StoreWebhookRequest.php, UpdateWebhookRequest.php, and WebhookSingle.php components

An issue in Invoice Ninja v5.13.24 allows a remote attacker to obtain sensitive information via the StoreWebhookRequest.php, UpdateWebhookRequest.php, and WebhookSingle.php components

▾ MidnightEPSS 0.53%via NVD
CVE-2026-18486High· 8.8
3w ago

IBM ContextForge MCP Gateway <= v1.0.7 MCP Context Forge could allow a remote authenticated attacker to obtain sensitive credentials and escalate privileges due to improper validation of jq filters.

IBM ContextForge MCP Gateway <= v1.0.7 MCP Context Forge could allow a remote authenticated attacker to obtain sensitive credentials and escalate privileges due to improper validation of jq filters.

▾ Twilightibm · contextforgeEPSS 0.33%via NVD
CVE-2026-19300High· 7.5
3w ago

IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote attacker to obtain sensitive information due to incomplete scrubbing of sensitive credential fields.

IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote attacker to obtain sensitive information due to incomplete scrubbing of sensitive credential fields.

▾ Twilightlangflow · langflowEPSS 0.38%via NVD
CWE-200 vulnerabilities (CVEs) — page 11 · VulnSea