VulnSea

CWE-200

CVEs classified under CWE-200, newest first.

814 CVEsRSS

CVE-2026-54553Medium· 5.4
1mo ago

Starlette-Admin's unvalidated `order_by` parameter allows ordering by hidden columns (info-exposure oracle) and HTTP 500 DoS

Starlette-Admin's unvalidated `order_by` parameter allows ordering by hidden columns (info-exposure oracle) and HTTP 500 DoS

▾ Sunlitstarlette-admin · starlette-adminEPSS 0.45%via OSV
CVE-2026-48786Medium· 6.5
1mo ago

Fleet is an open-source device management platform built on osquery

Fleet is an open-source device management platform built on osquery. In versions prior to 4.87.0, the target search endpoint (POST /api/latest/fleet/targets) returned unmasked team enroll secrets and full team configuration, including cr…

▾ Sunlitfleetdm · github.com/fleetdm/fleet/v4EPSS 0.44%via NVD
CVE-2026-46370Medium· 6.5
1mo ago

Fleet is an open-source device management platform built on osquery

Fleet is an open-source device management platform built on osquery. In versions up to and including 4.84.1, the labels host-listing endpoint (GET /api/v1/fleet/labels/{id}/hosts) allowed an authenticated user with the lowest-privilege O…

▾ Sunlitfleetdm · github.com/fleetdm/fleet/v4EPSS 0.37%via NVD
CVE-2026-46371Medium· 6.5
1mo ago

Fleet is an open-source device management platform built on osquery

Fleet is an open-source device management platform built on osquery. In versions up to and including 4.84.1, the Apple MDM commands listing endpoint (GET /api/v1/fleet/mdm/apple/commands) allowed an authenticated user with the lowest-pri…

▾ Sunlitfleetdm · github.com/fleetdm/fleet/v4EPSS 0.37%via NVD
GHSA-mw85-cjh9-8hp7High· 6.5
1mo ago

Duplicate Advisory: Grav: The system, site, and theme Twig variables bypass the content sandbox entirely and are never covered by config_denied_paths

Duplicate Advisory: Grav: The system, site, and theme Twig variables bypass the content sandbox entirely and are never covered by config_denied_paths

▾ Twilightgetgrav · getgrav/gravvia GHSA
CVE-2026-79146Medium· 5.5
1mo ago

Information leak in CustomTabs in Google Chrome on on Android prior to 152.0.7977.65 allowed a local attacker to obtain cross-origin data via a co-installed app

Information leak in CustomTabs in Google Chrome on on Android prior to 152.0.7977.65 allowed a local attacker to obtain cross-origin data via a co-installed app. (Chromium security severity: Medium)

▾ SunlitGoogle · ChromeEPSS 0.12%via CVEORG
CVE-2026-79776Medium· 5.3PoC⚖ disputed
1mo ago

rclone before 1.75.0 mounts the pprof debug handler as its own router route, bypassing the fail-closed authentication rule in the main handler

rclone before 1.75.0 mounts the pprof debug handler as its own router route, bypassing the fail-closed authentication rule in the main handler. Attackers can access the /debug/pprof/cmdline endpoint unauthenticated to retrieve the full p…

▾ Twilightrclone · rcloneEPSS 0.43%via NVD
CVE-2026-62865None
1mo ago

Typebot is an open-source chatbot builder

Typebot is an open-source chatbot builder. In self-hosted versions prior to 3.18.0, the server-side Send Email integration block allows arbitrary reading of local files on the server. The block builds Nodemailer attachments from a typebo…

▾ SunlitEPSS 0.32%via NVD
CVE-2026-62986Medium· 4.3
1mo ago

OpenEXR is the reference implementation and specification for the EXR image file format, widely used in the motion picture industry

OpenEXR is the reference implementation and specification for the EXR image file format, widely used in the motion picture industry. In versions 3.3.0 through 3.3.12 and 3.4.0 through 3.4.13, the PyOpenEXR Python bindings return stale he…

▾ SunlitEPSS 0.38%via NVD
CVE-2026-78679Medium· 6.5
1mo ago

GitPython before 3.1.59 contains an arbitrary file read vulnerability in TagReference.create() where a positional reference parameter bypasses the unsafe option guard

GitPython before 3.1.59 contains an arbitrary file read vulnerability in TagReference.create() where a positional reference parameter bypasses the unsafe option guard. Attackers can supply a reference value like --file=<path> to read arb…

▾ SunlitRed Hat · Red Hat OpenShift AI (RHOAI)EPSS 0.26%via NVD
CVE-2026-78678Medium· 6.5
1mo ago

gitpython: GitPython: Arbitrary file read via Repo.blame() (CVE-2026-78678)

A flaw was found in GitPython. An incomplete denylist in the `unsafe_git_revision_options` guard omits `--contents` and `-S` options. This allows an attacker to read arbitrary files by passing these options to the `Repo.blame()` function. …

▾ SunlitRed Hat · Red Hat OpenShift AI (RHOAI)EPSS 0.41%via CSAF
CVE-2026-79780Medium· 5.3
1mo ago

rclone before v1.75.0 fails to sanitize IBM IAM bearer tokens and SSE-C encryption keys during S3 redirect callbacks, allowing credentials to be preserved across scheme or host changes

rclone before v1.75.0 fails to sanitize IBM IAM bearer tokens and SSE-C encryption keys during S3 redirect callbacks, allowing credentials to be preserved across scheme or host changes. Attackers observing network traffic from a trusted …

▾ Sunlitrclone · github.com/rclone/rcloneEPSS 0.13%via NVD
GHSA-mf8r-wm2w-f8c5Medium· 5.3
1mo ago

phpMyFAQ public FAQ APIs expose inactive FAQ content

phpMyFAQ public FAQ APIs expose inactive FAQ content

▾ Sunlitthorsten · thorsten/phpmyfaqvia GHSA
CVE-2026-55553High· 7.5
1mo ago

urllib is an HTTP client for Node.js that supports authentication, redirects, timeouts, and other request features

urllib is an HTTP client for Node.js that supports authentication, redirects, timeouts, and other request features. Prior to 4.9.1 and 2.44.1, urllib follows redirects through followRedirect but reuses caller-supplied options across orig…

▾ Twilighturllib · urllibEPSS 0.66%via NVD
CVE-2026-59256High· 7.5
1mo ago

WWBN AVideo through commit 9c39d8c8 contains an authorization bypass vulnerability where getToken() creates tokens without binding to user identity or purpose, and plugin/Gallery/view/sections.php issues valid tokens to unauthenticated v…

WWBN AVideo through commit 9c39d8c8 contains an authorization bypass vulnerability where getToken() creates tokens without binding to user identity or purpose, and plugin/Gallery/view/sections.php issues valid tokens to unauthenticated v…

▾ TwilightEPSS 0.46%via NVD
CVE-2026-56380Medium· 5.3
1mo ago

AVideo through commit 9c39d8c8 contains an information exposure vulnerability in feed/index.php that allows unauthenticated attackers to retrieve channel owner email addresses by supplying a public channel name parameter

AVideo through commit 9c39d8c8 contains an information exposure vulnerability in feed/index.php that allows unauthenticated attackers to retrieve channel owner email addresses by supplying a public channel name parameter. Attackers can e…

▾ SunlitEPSS 0.36%via NVD
CVE-2026-62960High· 7.4
1mo ago

Git for Windows is the Windows port of Git

Git for Windows is the Windows port of Git. Prior to 2.55.0.windows.4, a malicious remote Git server can advertise a bundle URI that reaches transport_get_remote_bundle_uri(), fetch_bundle_uri_internal(), and copy_uri_to_file() in bundle…

▾ TwilightEPSS 0.46%via NVD
CVE-2026-71862High· 7.5
1mo ago

Checkmate is an open-source, self-hosted tool designed to track and monitor server hardware, uptime, response times, and incidents in real-time with beautiful visualizations

Checkmate is an open-source, self-hosted tool designed to track and monitor server hardware, uptime, response times, and incidents in real-time with beautiful visualizations. From 3.3.0 until 3.9.2, enabling the global showURL setting ca…

▾ TwilightEPSS 0.48%via NVD
CVE-2026-30866High· 7.5
1mo ago

Combodo iTop is a web based IT service management tool

Combodo iTop is a web based IT service management tool. Prior to 3.2.3, unauthenticated users can access uploaded sensitive via sniffed url. This issue has been fixed in version 3.2.3.

▾ TwilightCombodo · iTopEPSS 0.46%via NVD
CVE-2026-53497Medium· 5.3PoC
1mo ago

CrossWatch (CW) is a synchronization engine

CrossWatch (CW) is a synchronization engine. Prior to version 0.9.21, GET /api/app-auth/status is accessible without authentication and returns the other_sessions array, which exposes metadata of all active sessions — including originati…

▾ Twilightcenodude · CrossWatchEPSS 0.40%via NVD
CVE-2026-62316High· 8.8PoC
1mo ago

Microsoft UFO open-source framework for intelligent automation across devices and platforms

Microsoft UFO open-source framework for intelligent automation across devices and platforms. Prior to 3.0.8, ufo/client/mcp/http_servers/linux_mcp_server.py binds a FastMCP streamable HTTP server to localhost:8010 but does not validate t…

▾ Midnightmicrosoft · UFOEPSS 0.51%via NVD
CVE-2026-69225Medium· 5.9
1mo ago

There is an information disclosure vulnerability in Esri Portal for ArcGIS versions 11.5 through 12.0 and earlier that may allow a remote, unauthenticated attacker to reflect sensitive information in a http response body.

There is an information disclosure vulnerability in Esri Portal for ArcGIS versions 11.5 through 12.0 and earlier that may allow a remote, unauthenticated attacker to reflect sensitive information in a http response body.

▾ Sunlitesri · portal_for_arcgisEPSS 0.46%via NVD
CVE-2026-69224Medium· 5.9
1mo ago

There is an information disclosure vulnerability in Esri Portal for ArcGIS versions 12.0 and earlier that may under difficult to reproduce circumstances allow a remote, unauthenticated attacker to reflect sensitive information in a http …

There is an information disclosure vulnerability in Esri Portal for ArcGIS versions 12.0 and earlier that may under difficult to reproduce circumstances allow a remote, unauthenticated attacker to reflect sensitive information in a http …

▾ Sunlitesri · portal_for_arcgisEPSS 0.46%via NVD
CVE-2026-34948High· 7.7
1mo ago

Combodo iTop is a web based IT service management tool

Combodo iTop is a web based IT service management tool. Prior to 3.2.3, only classes present in the SELECT clause are protected by the silos access check in OQL. This issue has been fixed in version 3.2.3.

▾ TwilightEPSS 0.39%via NVD
CVE-2026-27463Medium· 5.3
1mo ago

Combodo iTop is a web based IT service management tool

Combodo iTop is a web based IT service management tool. Prior to 3.2.3, the HTML title attribute of the logo in the login page contains the complete iTop version. This issue has been fixed in version 3.2.3.

▾ SunlitEPSS 0.34%via NVD
CVE-2026-47735High
1mo ago

Arc is an open, SQL-native time-series database for telemetry

Arc is an open, SQL-native time-series database for telemetry. Prior to version 26.06.1, Arc's user-SQL validator (`internal/api/query.go:ValidateSQLRequest`) blocked only `read_parquet(` and `arc_partition_agg(` via regex denylist. The …

▾ Twilightbasekick-labs · github.com/basekick-labs/arcEPSS 0.43%via NVD
CVE-2026-48050High· 8.2
1mo ago

Arc is an open, SQL-native time-series database for telemetry

Arc is an open, SQL-native time-series database for telemetry. Versions prior to 26.06.1 register Go's `net/http/pprof` handlers at `/debug/pprof/*` via `app.Use(pprof.New())` in `internal/api/server.go`, and `/debug/pprof` is added to `…

▾ TwilightRed Hat · Red Hat Edge Manager 1EPSS 0.64%via NVD
CVE-2026-53586Medium· 6.5
1mo ago

libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing to build Git functionality into your application

libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing to build Git functionality into your application. Prior to 1.8.6 and 1.9.5, the built-in HTTP transport in src/libgi…

▾ SunlitEPSS 0.48%via NVD
CVE-2026-67448Medium· 6.5
1mo ago

Mailpit is an email testing tool and API for developers

Mailpit is an email testing tool and API for developers. From 1.29.0 until 1.30.6, Mailpit's server/server.go origin middleware checks the raw RequestURI for the /api/ prefix while Go's ServeMux routes using the percent-decoded URL path,…

▾ Sunlitaxllent · github.com/axllent/mailpitEPSS 0.22%via NVD
CVE-2026-61798High· 8.1
1mo ago

netty-incubator-codec-ohttp: BoringSSL HPKE private key bytes exposed through toString() and exception messages

netty-incubator-codec-ohttp: BoringSSL HPKE private key bytes exposed through toString() and exception messages

▾ Twilightnetty · io.netty.incubator:netty-incubator-codec-ohttp-hpke-classes-boringsslvia GHSA
CWE-200 vulnerabilities (CVEs) — page 13 · VulnSea