VulnSea

CWE-200

CVEs classified under CWE-200, newest first.

814 CVEsRSS

CVE-2026-74945Medium· 6.5PoC
1mo ago

Information disclosure in the Graphics: Text component

Information disclosure in the Graphics: Text component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.

▾ TwilightRed Hat · Red Hat Enterprise Linux AppStream (v. 10)EPSS 0.44%via NVD
CVE-2026-74934High· 7.5
1mo ago

Site isolation issue in the Graphics: CanvasWebGL component

Site isolation issue in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.

▾ TwilightRed Hat · Red Hat Enterprise Linux AppStream (v. 10)EPSS 0.21%via NVD
CVE-2026-62988Critical· 9.0
1mo ago

Froxlor is open source server administration software

Froxlor is open source server administration software. From 2.3.7 until 2.3.8, the Customers.get, Customers.listing, Admins.get, Admins.listing, Ftps.get, and Ftps.listing API commands in lib/Froxlor/Api/Commands/Customers.php, lib/Froxl…

▾ Midnightfroxlor · froxlor/froxlorEPSS 0.63%via NVD
CVE-2026-63640Medium· 4.3
1mo ago

MagicMirror² is an open source modular smart mirror platform

MagicMirror² is an open source modular smart mirror platform. Prior to 2.37.0, when hideConfigSecrets is enabled, the catch-all socket dispatcher in js/node_helper.js passes every inbound object payload through replaceSecretPlaceholder i…

▾ Sunlitmagicmirror · magicmirrorEPSS 0.30%via NVD
CVE-2026-62684Low· 2.7
1mo ago

File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory

File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.63.17, the Link storage struct is serialized directly by sharePostHandler, shareListHandl…

▾ Sunlitfilebrowser · github.com/filebrowser/filebrowser/v2EPSS 0.43%via NVD
CVE-2026-71424Critical· 9.6
1mo ago

Onyx is an open-source AI platform

Onyx is an open-source AI platform. Prior to 3.1.10, 3.2.14, and 4.0.0, Onyx's GET /api/mcp/servers and GET /api/mcp/servers/persona/{persona_id} endpoints expose another user's OAuth Authorization header because OnyxTokenStorage.set_tok…

▾ MidnightEPSS 0.49%via NVD
CVE-2026-64778Medium· 6.5
1mo ago

The issue was addressed with improved checks

The issue was addressed with improved checks. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, tvOS 27, visionOS 27, watchOS 27. Visiting a maliciously crafted websit…

▾ Sunlitapple · safariEPSS 0.34%via NVD
CVE-2026-64760Medium· 5.5
1mo ago

An information leakage was addressed with additional validation

An information leakage was addressed with additional validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 27 and iPadOS 27, macOS Golden Gate 27, tvOS 27, visionOS 27, watchOS 27. An app may be able to leak sensitive ke…

▾ Sunlitapple · ipadosEPSS 0.16%via NVD
CVE-2026-57485High· 8.5
1mo ago

Stirling-PDF is a locally hosted web application that facilitates various operations on PDF files

Stirling-PDF is a locally hosted web application that facilitates various operations on PDF files. Prior to 2.9.0, the /api/v1/pipeline/handleData endpoint in app/core/src/main/java/stirling/software/SPDF/controller/api/pipeline/Pipeline…

▾ TwilightEPSS 0.42%via NVD
CVE-2026-68520Medium· 5.3
1mo ago

Glances is an open-source system cross-platform monitoring tool

Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.6, as_dict_secure() in glances/config.py checks only option names and exposes public_username and credentials embedded in public_api values through unauthentic…

▾ Sunlitglances · glancesEPSS 0.40%via NVD
GHSA-m5w8-4gq2-6f8xCritical· 10.0
1mo ago

vm2: NodeVM `builtin: ['*']` exposes `os` and `dns` — process-wide observability reads AND writes that hijack the host (sibling class of GHSA-9g8x-92q2-p28f)

vm2: NodeVM `builtin: ['*']` exposes `os` and `dns` — process-wide observability reads AND writes that hijack the host (sibling class of GHSA-9g8x-92q2-p28f)

▾ Midnightvm2 · vm2via GHSA
CVE-2026-64859Critical· 9.1
1mo ago

New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system

New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to 1.0.0-rc.7, the admin user list and user lookup APIs, including GET /api/user/, return User.AccessToken as access_token bec…

▾ MidnightQuantumNous · github.com/QuantumNous/new-apiEPSS 0.63%via NVD
CVE-2026-73047Medium· 6.2
1mo ago

siyuan versions <= 3.7.3 (fixed in v3.7.4) contain a server-side template injection vulnerability in the attribute-view Template calculation feature (introduced in v3.7.0-beta.1)

siyuan versions <= 3.7.3 (fixed in v3.7.4) contain a server-side template injection vulnerability in the attribute-view Template calculation feature (introduced in v3.7.0-beta.1). The feature's template engine uses Sprig's unmodified fun…

▾ SunlitEPSS 0.19%via NVD
CVE-2026-72834Medium· 4.3
1mo ago

filebrowser before 2.63.19 contains a permission bypass in the /api/resources endpoint

filebrowser before 2.63.19 contains a permission bypass in the /api/resources endpoint. The checksum (?checksum=) branch of resourceGetHandler reads the entire file to compute a digest and returns it without performing a Perm.Download ch…

▾ SunlitEPSS 0.39%via NVD
CVE-2026-73304Medium· 4.9
1mo ago

Budibase is an open-source low-code platform

Budibase is an open-source low-code platform. Prior to 3.39.25, GET /api/users/metadata and GET /api/users/metadata/:id returned user objects processed by packages/server/src/utilities/global.ts without removing oauth2.accessToken or oau…

▾ SunlitEPSS 0.48%via NVD
CVE-2026-72670High· 7.7
1mo ago

A lower privileged user who holds only the privilege to read agent policies can read the entire configuration of a configured Fleet proxy

A lower privileged user who holds only the privilege to read agent policies can read the entire configuration of a configured Fleet proxy. This would normally require the Fleet privilege to read settings.The proxy configuration possibly …

▾ Twilightelastic · kibanaEPSS 0.48%via NVD
CVE-2026-73604Medium· 6.5
1mo ago

Flowise before 3.1.3 contains an incomplete credential redaction vulnerability in the GET /api/v1/credentials/:id endpoint that returns decrypted secrets in plaintext

Flowise before 3.1.3 contains an incomplete credential redaction vulnerability in the GET /api/v1/credentials/:id endpoint that returns decrypted secrets in plaintext. Authenticated users with credentials:view permission can retrieve sen…

▾ Sunlitflowiseai · flowiseEPSS 0.41%via NVD
CVE-2026-65017Medium· 6.5
1mo ago

Apache Airflow's Config API did not mask team-scoped sensitive configuration values in multi-team deployments

Apache Airflow's Config API did not mask team-scoped sensitive configuration values in multi-team deployments. When an administrator has enabled multi-team mode and exposed the Config API, an authenticated Viewer holding only configurati…

▾ Sunlitapache · airflowEPSS 0.70%via NVD
CVE-2026-73411None
1mo ago

Shescape is a simple shell escape library for JavaScript

Shescape is a simple shell escape library for JavaScript. Prior to 2.1.14 and 3.0.1, getEscapeFunction in src/internal/unix/dash.js fails to escape ~ after : or = when applications use the escape or escapeAll APIs on Unix with shell set …

▾ SunlitEPSS 0.59%via NVD
CVE-2026-47234Medium· 4.4
1mo ago

Admidio is an open-source user management solution

Admidio is an open-source user management solution. Prior to version 5.0.10, when debug logging is enabled, `Session::setCookie()` logs full cookie values and `Session::start()` logs the current session ID. In a real Admidio deployment t…

▾ SunlitEPSS 0.17%via NVD
CVE-2026-73406High· 7.5
1mo ago

Budibase is an open-source low-code platform

Budibase is an open-source low-code platform. Prior to 3.39.32, GET /api/global/users/tenant/:id was listed in PUBLIC_ENDPOINTS in packages/worker/src/api/index.ts, and tenantUserLookup returned a full PlatformUser document. An unauthent…

▾ TwilightEPSS 0.51%via NVD
CVE-2026-54183Medium· 4.3
1mo ago

Apache Airflow's secrets masker hides values stored under sensitive key names when they are displayed in the UI

Apache Airflow's secrets masker hides values stored under sensitive key names when they are displayed in the UI. The masker's recursion-depth limit did not descend into values nested inside a list, tuple, or set beyond that limit, so an …

▾ Sunlitapache · airflowEPSS 0.64%via NVD
CVE-2026-73308Medium· 5.7
1mo ago

Budibase is an open-source low-code platform

Budibase is an open-source low-code platform. Prior to 3.39.25, packages/server/src/api/controllers/automation.ts returned automation test results containing trigger.outputs.user.oauth2, broadcast BuilderSocketEvent.AutomationTestProgres…

▾ SunlitEPSS 0.41%via NVD
CVE-2026-72744Medium· 6.2PoC
1mo ago

Nuxt versions >= 4.4.7 and < 4.5.1, and >= 3.21.7 and < 3.21.10, contain an information disclosure vulnerability in the development server's Chrome DevTools workspace endpoint (GET /.well-known/appspecific/com.chrome.devtools.json)

Nuxt versions >= 4.4.7 and < 4.5.1, and >= 3.21.7 and < 3.21.10, contain an information disclosure vulnerability in the development server's Chrome DevTools workspace endpoint (GET /.well-known/appspecific/com.chrome.devtools.json). The …

▾ TwilightEPSS 0.18%via NVD
CVE-2026-73230None
1mo ago

Ente provides end-to-end encrypted cloud services and security tools

Ente provides end-to-end encrypted cloud services and security tools. Prior to 2026.07.28, Ente 2of3 card format version 1 stored the secret byte length and 32-bit FNV-1a checksum in cleartext on every card, allowing someone with one car…

▾ SunlitEPSS 0.16%via NVD
CVE-2026-73246High· 7.5
1mo ago

Kestra is an open-source, event-driven orchestration platform

Kestra is an open-source, event-driven orchestration platform. Prior to 2.0.0-rc6, Kestra's worker/src/main/java/io/kestra/worker/endpoint/WorkerEndpoint.java serves GET /worker without authentication and serializes the complete live Tas…

▾ TwilightEPSS 0.60%via NVD
CVE-2026-73082None
1mo ago

Activepieces is an open source AI workflow automation platform

Activepieces is an open source AI workflow automation platform. Prior to 0.82.0, the POST /api/v1/projects/:projectId/mcp-server/validate-agent-mcp-tool endpoint makes an outbound HTTP or SSE request to a user-supplied serverUrl without …

▾ SunlitEPSS 0.43%via NVD
CVE-2026-48771High· 8.2
1mo ago

ishankportfolio is a portfolio website

ishankportfolio is a portfolio website. Prior to version 1.0.1, contact form submissions could potentially be exposed due to improperly secured client-side database configuration and insufficient access control policies. Applications usi…

▾ TwilightEPSS 0.35%via NVD
CVE-2026-48767High· 7.6
1mo ago

TypeBot is a chatbot builder tool

TypeBot is a chatbot builder tool. Versions prior to 3.17.0 allow a low-privilege guest member of a workspace to obtain a live Google Sheets OAuth access token for that workspace by calling the Google Sheets helper `getAccessToken`. The …

▾ TwilightEPSS 0.43%via NVD
CVE-2026-48766High· 7.6
1mo ago

TypeBot is a chatbot builder tool

TypeBot is a chatbot builder tool. Versions prior to 3.17.0 allow a low-privilege guest member of a workspace to exfiltrate stored OpenAI-compatible API keys by invoking the OpenAI model-listing helper with an attacker-controlled `baseUr…

▾ TwilightEPSS 0.43%via NVD
CWE-200 vulnerabilities (CVEs) — page 15 · VulnSea