VulnSea

CWE-200

CVEs classified under CWE-200, newest first.

814 CVEsRSS

CVE-2026-18887Medium· 6.5
3w ago

IBM i 7.6, 7.5, 7.4, and 7.3 could allow an authenticated attacker to obtain sensitive information in PASE

IBM i 7.6, 7.5, 7.4, and 7.3 could allow an authenticated attacker to obtain sensitive information in PASE. An attacker could exploit this vulnerability to access information about process they shouldn't be permitted to access.

▾ Sunlitibm · iEPSS 0.28%via NVD
CVE-2026-85517Medium· 5.3
3w ago

A flaw has been found in code-projects Vehicle Management System 1.0

A flaw has been found in code-projects Vehicle Management System 1.0. The impacted element is an unknown function of the file /vehicle_management.sql of the component SQL Database Backup File Handler. Executing a manipulation can lead to…

▾ SunlitEPSS 0.53%via NVD
CVE-2026-81270High· 7.5
3w ago

Apache Allura: exposure of non-public information via search. This issue affects Apache Allura: through 1.20.0. Users are recommended to upgrade to version 1.21.0, which fixes the issue.

Apache Allura: exposure of non-public information via search. This issue affects Apache Allura: through 1.20.0. Users are recommended to upgrade to version 1.21.0, which fixes the issue.

▾ TwilightEPSS 0.43%via NVD
CVE-2026-44506High· 8.2
3w ago

Medplum is a developer platform that enables development of healthcare apps

Medplum is a developer platform that enables development of healthcare apps. In Medplum versions 4.1.10 through 5.1.6, the /oauth2/register endpoint could return the client_secret of preconfigured OAuth clients defined via the defaultOAu…

▾ TwilightEPSS 0.35%via NVD
CVE-2026-85157Medium· 5.3
3w ago

WWBN AVideo contains a broken access control vulnerability in the unauthenticated feed/index.php endpoint that disables per-video visibility checks when a program_id parameter is supplied

WWBN AVideo contains a broken access control vulnerability in the unauthenticated feed/index.php endpoint that disables per-video visibility checks when a program_id parameter is supplied. Attackers can enumerate playlist identifiers and…

▾ SunlitEPSS 0.34%via NVD
CVE-2026-85156Medium· 5.3
3w ago

WWBN AVideo fails to properly validate access controls on the public channel page, allowing unauthenticated visitors to view unlisted and group-restricted videos through hardcoded visibility flags and an undefined property

WWBN AVideo fails to properly validate access controls on the public channel page, allowing unauthenticated visitors to view unlisted and group-restricted videos through hardcoded visibility flags and an undefined property. Attackers can…

▾ SunlitEPSS 0.34%via NVD
CVE-2026-72804High· 8.6
3w ago

SiYuan: Graph endpoints omit the publish-password tier: anonymous readers receive block-level content of password-protected documents

SiYuan: Graph endpoints omit the publish-password tier: anonymous readers receive block-level content of password-protected documents

▾ Twilightsiyuan-note · github.com/siyuan-note/siyuan/kernelEPSS 0.43%via GHSA
CVE-2026-50554Medium· 5.3
3w ago

Note Mark is an open-source note-taking application

Note Mark is an open-source note-taking application. Prior to version 0.19.5, GET /api/books/{bookID}/notes is an unauthenticated endpoint that accepts a "deleted" query parameter. When the request is ?deleted=true, the service runs the …

▾ Sunlitenchant97 · github.com/enchant97/note-mark/backendEPSS 0.42%via NVD
CVE-2026-84658Medium· 4.3
3w ago

Jenkins Script Security Plugin 1412.v7737b_3405f86 and earlier uses the `@DataBoundConstructor` annotation on a constructor that loads script approval configuration, allowing attackers able to submit certain forms to read that configurat…

Jenkins Script Security Plugin 1412.v7737b_3405f86 and earlier uses the `@DataBoundConstructor` annotation on a constructor that loads script approval configuration, allowing attackers able to submit certain forms to read that configurat…

▾ Sunlitjenkins · script_securityEPSS 0.31%via NVD
CVE-2026-53682Medium· 5.3
3w ago

An unauthenticated client can query the Security Domain hosts inventory via GET /ca/rest/securityDomain/hosts and receive a structured response enumerating internal PKI/CA hosts and roles (security domain topology and participating subsy…

An unauthenticated client can query the Security Domain hosts inventory via GET /ca/rest/securityDomain/hosts and receive a structured response enumerating internal PKI/CA hosts and roles (security domain topology and participating subsy…

▾ SunlitRed Hat · pki-coreEPSS 0.21%via NVD
CVE-2026-84481None
3w ago

WWBN AVideo through 30.0 contains an information disclosure vulnerability in the MobileManager plugin getConfiguration endpoint that returns sensitive configuration data to unauthenticated visitors

WWBN AVideo through 30.0 contains an information disclosure vulnerability in the MobileManager plugin getConfiguration endpoint that returns sensitive configuration data to unauthenticated visitors. Attackers can send an unauthenticated …

▾ SunlitEPSS 0.45%via NVD
CVE-2026-84195High· 7.7
3w ago

Kyverno before 1.16.4 automatically attaches the admission controller's ServiceAccount token to outbound HTTP requests in apiCall service mode without explicit authorization headers

Kyverno before 1.16.4 automatically attaches the admission controller's ServiceAccount token to outbound HTTP requests in apiCall service mode without explicit authorization headers. Attackers can exfiltrate the token by directing apiCal…

▾ Twilightkyverno · github.com/kyverno/kyvernoEPSS 0.39%via NVD
CVE-2026-53507None
3w ago

oasdiff-action is a GitHub Action that detects breaking changes in OpenAPI specs and post a review on every pull request

oasdiff-action is a GitHub Action that detects breaking changes in OpenAPI specs and post a review on every pull request. Before version 0.0.51, the oasdiff actions resolved external $refs in the OpenAPI spec by default (allow-external-r…

▾ SunlitEPSS 0.50%via NVD
CVE-2026-53553High· 7.7
3w ago

Goploy is an open-source automation deployment system

Goploy is an open-source automation deployment system. Prior to version 1.18.0, a severe path traversal vulnerability exists in its backend API endpoints, specifically /deploy/fileDiff (File Compare), when handling file paths provided by…

▾ Twilightzhenorzz · github.com/zhenorzz/goployEPSS 0.46%via NVD
CVE-2026-81322None
4w ago

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in ash-project ash_cloak allows anyone with access to logs, error trackers, or crash reports, or anyone who can trigger a validation error, to recover the plaintext…

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in ash-project ash_cloak allows anyone with access to logs, error trackers, or crash reports, or anyone who can trigger a validation error, to recover the plaintext…

▾ SunlitEPSS 0.12%via NVD
CVE-2026-82657High· 7.5
4w ago

Admidio before 5.0.12 fails to enforce login-only module restrictions in RSS feed endpoints for forum and announcements modules

Admidio before 5.0.12 fails to enforce login-only module restrictions in RSS feed endpoints for forum and announcements modules. Unauthenticated attackers can retrieve forum topics and announcements by sending GET requests to rss/forum.p…

▾ TwilightEPSS 0.45%via NVD
CVE-2026-82651Medium· 4.9
4w ago

SiYuan before v3.8.1 does not apply the IsForbiddenAbsPath guard (introduced in GHSA-c8r8-95hg-mp34) to the /history/*path and /repo/diff/*path endpoints in kernel/server/serve.go

SiYuan before v3.8.1 does not apply the IsForbiddenAbsPath guard (introduced in GHSA-c8r8-95hg-mp34) to the /history/*path and /repo/diff/*path endpoints in kernel/server/serve.go. These routes require admin authentication but construct …

▾ SunlitEPSS 0.48%via NVD
CVE-2026-82548Medium· 5.3
4w ago

A vulnerability was determined in Linux Foundation Magma 1.9.0

A vulnerability was determined in Linux Foundation Magma 1.9.0. The impacted element is an unknown function of the component InitialUEMessage Handler. This manipulation causes information disclosure. The attack may be initiated remotely.…

▾ SunlitEPSS 0.53%via NVD
CVE-2026-77007High· 7.5
4w ago

The HEL Online Classroom: AI-powered Online Classrooms WordPress plugin through 1.0.3 does not perform any authorisation check on one of its REST API routes, allowing unauthenticated users to retrieve its stored settings, including the s…

The HEL Online Classroom: AI-powered Online Classrooms WordPress plugin through 1.0.3 does not perform any authorisation check on one of its REST API routes, allowing unauthenticated users to retrieve its stored settings, including the s…

▾ TwilightEPSS 0.43%via NVD
CVE-2026-82306Medium· 6.5
1mo ago

StarRocks through 4.0.13 contains an information disclosure vulnerability in the query_detail endpoint that returns unfiltered query history for all users

StarRocks through 4.0.13 contains an information disclosure vulnerability in the query_detail endpoint that returns unfiltered query history for all users. Authenticated attackers with low privileges can access full SQL text, execution p…

▾ SunlitStarRocks · starrocksEPSS 0.55%via NVD
CVE-2026-61802Medium· 6.5
1mo ago

Wazuh is an open-source security platform providing unified XDR and SIEM protection for endpoints and cloud workloads

Wazuh is an open-source security platform providing unified XDR and SIEM protection for endpoints and cloud workloads. In versions 4.14.0 through 4.14.6, a low-privilege API user can read the cleartext cluster key from a configuration en…

▾ Sunlitwazuh · wazuhEPSS 0.70%via NVD
CVE-2026-61783Medium· 6.5
1mo ago

Wazuh is an open-source security platform providing unified XDR and SIEM protection for endpoints and cloud workloads

Wazuh is an open-source security platform providing unified XDR and SIEM protection for endpoints and cloud workloads. In versions 4.14.0 through 4.14.6, an authenticated low-privilege user can read the cluster secret from the manager co…

▾ Sunlitwazuh · wazuhEPSS 0.41%via NVD
CVE-2026-81732None
1mo ago

WWBN AVideo through version 30.0 fails to enforce authentication on the report4.json.php and report4.1.json.php endpoints, allowing unauthenticated access to user registration statistics

WWBN AVideo through version 30.0 fails to enforce authentication on the report4.json.php and report4.1.json.php endpoints, allowing unauthenticated access to user registration statistics. Attackers can send GET requests to these endpoint…

▾ SunlitEPSS 0.56%via NVD
CVE-2026-55406Medium
1mo ago

Buffa has a Use-After-Free in OwnedView via Unsound 'static Lifetime Promotion in Deref

Buffa has a Use-After-Free in OwnedView via Unsound 'static Lifetime Promotion in Deref

▾ Sunlitbuffa · buffaEPSS 0.19%via GHSA
CVE-2026-55485High· 8.8
1mo ago

piccolo-admin has a privilege escalation issue - admin to superuser via session-token disclosure in GET /api/tables/sessions/.

piccolo-admin has a privilege escalation issue - admin to superuser via session-token disclosure in GET /api/tables/sessions/.

▾ Twilightpiccolo-admin · piccolo-adminEPSS 0.56%via OSV
CVE-2026-81101Medium· 6.5
1mo ago

The configure command accepted any endpoint URL and stored it beside the user's access token

The configure command accepted any endpoint URL and stored it beside the user's access token. ConfigureCommand.execute in src/cli.ts persisted the value given to its endpoint option into the user profile without passing it through create…

▾ SunlitEPSS 0.45%via NVD
CVE-2026-81679High· 7.7
1mo ago

OpenRemote versions before 1.28.0 contain a cross-realm information disclosure vulnerability in the Notification REST API that allows per-realm tenant administrators to read all tenants' sent notifications including message bodies

OpenRemote versions before 1.28.0 contain a cross-realm information disclosure vulnerability in the Notification REST API that allows per-realm tenant administrators to read all tenants' sent notifications including message bodies. Attac…

▾ TwilightEPSS 0.39%via NVD
CVE-2026-77438High· 7.5
1mo ago

Trilium is an open-source hierarchical note-taking application

Trilium is an open-source hierarchical note-taking application. In versions up to and including 0.103.0, the public share-search endpoint does not enforce the per-note shareCredentials and shareHiddenFromTree controls, allowing an unauth…

▾ TwilightEPSS 0.41%via NVD
CVE-2026-77507Medium· 5.3
1mo ago

Weblate is a web-based continuous localization platform used to manage software translations

Weblate is a web-based continuous localization platform used to manage software translations. In versions prior to 2026.8, Weblate's object-scoped RSS feeds do not apply the permission checks used elsewhere, allowing unauthorized users t…

▾ SunlitEPSS 0.40%via NVD
CVE-2026-62249Medium· 4.3
1mo ago

Weblate is a web-based continuous localization platform used to manage software translations

Weblate is a web-based continuous localization platform used to manage software translations. In versions prior to 2026.7, an authenticated user with access to a project can retrieve the change history of restricted components in that pr…

▾ SunlitEPSS 0.30%via NVD
CWE-200 vulnerabilities (CVEs) — page 12 · VulnSea