CWE-200
CVEs classified under CWE-200, newest first.
814 CVEsRSS
GHSA-2223-f22x-24cqMedium· 4.9Winter: Local File Inclusion through =include directives in JavaScript asset compilation
Winter: Local File Inclusion through =include directives in JavaScript asset compilation
CVE-2026-50192MediumKerberos Agent is an open source video (surveillance) management agent
Kerberos Agent is an open source video (surveillance) management agent. Prior to version 3.6.26, the Kerberos Hub upload path sends the agent's Hub credentials in the custom `X-Kerberos-Hub-PrivateKey` and `X-Kerberos-Hub-PublicKey` requ…
CVE-2026-53452Medium· 5.3Ground Station is a browser-based suite for satellite tracking, SDR reception, hardware control, and telemetry decoding
Ground Station is a browser-based suite for satellite tracking, SDR reception, hardware control, and telemetry decoding. Prior to version 0.4.13, the unauthenticated configure-sdr Socket.IO command accepts a recordingPath for the sigmf-p…
CVE-2026-76647High· 8.8Leantime JSON-RPC API through version 3.9.0 contains a missing authorization vulnerability in the JSON-RPC dispatcher in app/Domain/Api/Controllers/Jsonrpc.php
Leantime JSON-RPC API through version 3.9.0 contains a missing authorization vulnerability in the JSON-RPC dispatcher in app/Domain/Api/Controllers/Jsonrpc.php. The dispatcher does not enforce authorization before invoking service-layer …
CVE-2026-61842Medium· 6.5Grav is a file-based Web platform
Grav is a file-based Web platform. Prior to 2.0.2, the Grav Twig content sandbox permits grav.offsetGet('config') to return the raw configuration object and permits json_encode, print_r, yaml_encode, and string filters to serialize that …
GHSA-cc2g-gq8c-r332High· 7.5grok-faf-mcp has an arbitrary local file read via unconfined `path` argument in FAF tools
grok-faf-mcp has an arbitrary local file read via unconfined `path` argument in FAF tools
GHSA-j4r7-8ph4-43g3High· 7.5faf-mcp has an arbitrary local file read/write via unconfined `path` argument in FAF tools
faf-mcp has an arbitrary local file read/write via unconfined `path` argument in FAF tools
GHSA-rr55-jp92-8wp2High· 7.5claude-faf-mcp has an arbitrary local file read/write via unconfined `path` argument in FAF tools
claude-faf-mcp has an arbitrary local file read/write via unconfined `path` argument in FAF tools
GHSA-p77j-g7h5-r2vwHighGeoLens's authorization and cache-scope flaws disclose private dataset data and metadata to unauthorized users (fixed in 1.2.4)
GeoLens's authorization and cache-scope flaws disclose private dataset data and metadata to unauthorized users (fixed in 1.2.4)
CVE-2026-55088Medium· 6.8Etherpad is a real-time collaborative editor
Etherpad is a real-time collaborative editor. From 2.6.0 until 3.1.0, Etherpad's src/node/hooks/express/tokenTransfer.ts uses POST /tokenTransfer to store an author token for transfer between browsers and exposes it through GET /tokenTra…
CVE-2026-69189High· 7.6Hoppscotch is an open source API development ecosystem
Hoppscotch is an open source API development ecosystem. Prior to 2026.6.0, the team, teamMembers.user, RESTHistory, GQLHistory, currentRESTSession, currentGQLSession, environments, globalEnvironments, and settings GraphQL paths expose an…
CVE-2026-53959Medium· 6.5PoC4gaBoards is a boards system for realtime project management
4gaBoards is a boards system for realtime project management. Prior to 3.3.9, 4gaBoards allows any authenticated user to enumerate account information for every user through GET /api/users and retrieve arbitrary accounts through GET /api…
CVE-2026-52481High· 7.5An issue in SJRC F11 SJ-GPS-PRO firmware build 2019-09-17 allows a remote attacker to obtain sensitive information via the tcp_actions() function
An issue in SJRC F11 SJ-GPS-PRO firmware build 2019-09-17 allows a remote attacker to obtain sensitive information via the tcp_actions() function
CVE-2026-75859High· 7.5CodeWhale versions before 0.8.64 fail to validate file paths in the project config instructions field, allowing attackers to read arbitrary files on the victim's system
CodeWhale versions before 0.8.64 fail to validate file paths in the project config instructions field, allowing attackers to read arbitrary files on the victim's system. A malicious .codewhale/config.toml file in a cloned repository can …
CVE-2026-75915High· 7.5CodeWhale versions before 0.8.64 contain an environment variable exposure vulnerability in the js_execution tool that fails to scrub parent process environment variables before spawning Node.js
CodeWhale versions before 0.8.64 contain an environment variable exposure vulnerability in the js_execution tool that fails to scrub parent process environment variables before spawning Node.js. Attackers can craft malicious JavaScript c…
CVE-2026-75912High· 7.4CodeWhale versions before 0.8.64 contain an argument injection vulnerability in the git_blame tool that allows attackers to read arbitrary files by injecting git options into the unvalidated rev parameter
CodeWhale versions before 0.8.64 contain an argument injection vulnerability in the git_blame tool that allows attackers to read arbitrary files by injecting git options into the unvalidated rev parameter. Attackers can supply rev values…
CVE-2026-70990Medium· 6.8Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Content Acquisition System)
Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Content Acquisition System). The supported version that is affected is 11.4.0. Difficult to exploit vulnerab…
CVE-2026-70975Medium· 6.5Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security)
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with n…
CVE-2026-70974Medium· 5.3Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security)
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows low privileged attacker with…
CVE-2026-70943High· 8.1Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security)
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with …
CVE-2026-70942High· 7.7Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security)
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with n…
CVE-2026-70917Medium· 4.0Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security)
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with …
CVE-2026-70916Medium· 4.0Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security)
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with …
CVE-2026-70911Medium· 5.3Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security)
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with …
CVE-2026-60969High· 7.7Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core)
Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacke…
CVE-2026-60853Low· 3.7Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server)
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 3.2.20. Difficult to exploit vulnerability allows unauthenticated attacker with network acce…
CVE-2026-60415High· 8.1Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core)
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Difficult to exploit vulnerability allows un…
CVE-2026-60414High· 7.8Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: Outside In Core)
Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: Outside In Core). The supported version that is affected is 8.5.8. Easily exploitable vulnerability allows unauthenticated attacker with …
CVE-2026-60413High· 7.8Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: Outside In Core)
Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: Outside In Core). The supported version that is affected is 8.5.8. Easily exploitable vulnerability allows unauthenticated attacker with …
CVE-2026-74948Medium· 6.5Information disclosure in the Graphics component
Information disclosure in the Graphics component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.