VulnSea

CWE-200

CVEs classified under CWE-200, newest first.

814 CVEsRSS

CVE-2026-54123Medium· 5.5
1mo ago

Microsoft Defender for Endpoint for Mac Information Disclosure Vulnerability

Exposure of sensitive information to an unauthorized actor in Microsoft Defender for Endpoint allows an authorized attacker to disclose information locally.

▾ SunlitMicrosoft · Microsoft Defender for Endpoint for MacEPSS 0.48%via CVEORG
CVE-2026-66301Medium· 6.5
1mo ago

Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability

Exposure of sensitive information to an unauthorized actor in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to disclose information over a network.

▾ SunlitMicrosoft · Microsoft Dynamics 365 (on-premises) version 9.1EPSS 1.00%via CVEORG
CVE-2026-73229Medium· 4.3
1mo ago

Django REST framework is a powerful and flexible toolkit for building Web APIs

Django REST framework is a powerful and flexible toolkit for building Web APIs. Prior to 3.17.2, Django REST Framework's rest_framework/renderers.py AdminRenderer.render() uses override_method() to simulate GET and directly invokes view.…

▾ Sunlitdjangorestframework · djangorestframeworkEPSS 0.37%via NVD
GHSA-4jjw-pwvw-q6w3Medium· 6.2
1mo ago

Duplicate Advisory: Nuxt dev server discloses project root and workspace UUID via the Chrome DevTools workspace endpoint

Duplicate Advisory: Nuxt dev server discloses project root and workspace UUID via the Chrome DevTools workspace endpoint

▾ Sunlitnuxt · nuxtvia GHSA
CVE-2026-61924Medium· 6.5
1mo ago

Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.

Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.

▾ Sunlitmicrosoft · windows_10_1607EPSS 0.92%via NVD
CVE-2026-61921Medium· 6.5
1mo ago

Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.

Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.

▾ Sunlitmicrosoft · windows_10_1607EPSS 0.92%via NVD
CVE-2026-61918Medium· 6.5
1mo ago

Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.

Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.

▾ Sunlitmicrosoft · windows_10_1607EPSS 0.92%via NVD
CVE-2026-59130Medium· 5.6
1mo ago

No cwe for this issue in AMD Zen allows an authorized attacker to disclose information locally.

No cwe for this issue in AMD Zen allows an authorized attacker to disclose information locally.

▾ Sunlitmicrosoft · windows_10_1607EPSS 0.37%via NVD
CVE-2026-65769Medium· 6.5
1mo ago

Exposure of sensitive information to an unauthorized actor in Microsoft Teams Mobile allows an unauthorized attacker to disclose information over a network.

Exposure of sensitive information to an unauthorized actor in Microsoft Teams Mobile allows an unauthorized attacker to disclose information over a network.

▾ Sunlitmicrosoft · teamsEPSS 0.92%via NVD
CVE-2026-72915High· 7.5
1mo ago

Mastodon is a free, open-source social network server based on ActivityPub

Mastodon is a free, open-source social network server based on ActivityPub. From 4.6.0-beta.1 until 4.6.4 and 4.7.0-beta.1, any logged-in local user could use the show action in app/controllers/admin/collections_controller.rb to access p…

▾ TwilightEPSS 0.48%via NVD
CVE-2026-72873Medium· 6.5
1mo ago

Dokploy is a free, self-hostable Platform as a Service (PaaS)

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, application.one in apps/dokploy/server/api/routers/application.ts returns provider relations loaded by findApplicationById in packages/server/src/services/a…

▾ SunlitEPSS 0.45%via NVD
CVE-2026-72726Medium· 6.5
1mo ago

Discourse is an open-source discussion platform

Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, an authenticated user could eavesdrop on private AI bot conversations through the AI bot reply stream. The issue is fixed in 2026.1.6, …

▾ SunlitEPSS 0.45%via NVD
CVE-2026-19357Medium· 5.3
1mo ago

A security flaw has been discovered in MingSoft MCMS up to 3.0.6

A security flaw has been discovered in MingSoft MCMS up to 3.0.6. Affected is an unknown function of the file /mdiy/form/get of the component ms-mdiy. The manipulation results in information disclosure. It is possible to launch the attac…

▾ SunlitEPSS 0.48%via NVD
CVE-2026-19356Medium· 5.3
1mo ago

A vulnerability was identified in MingSoft MCMS up to 3.0.6

A vulnerability was identified in MingSoft MCMS up to 3.0.6. This impacts an unknown function of the file /mdiy/form/data/list of the component ms-mdiy. The manipulation leads to information disclosure. It is possible to initiate the att…

▾ SunlitEPSS 0.48%via NVD
CVE-2026-76217Medium· 6.5
1mo ago

GitPython: Arbitrary file read via --pathspec-from-file in IndexFile.remove() and Head.checkout()

GitPython: Arbitrary file read via --pathspec-from-file in IndexFile.remove() and Head.checkout()

▾ Sunlitgitpython · gitpythonEPSS 0.41%via OSV
CVE-2026-71849Low· 3.7
1mo ago

Hono is a Web application framework that provides support for any JavaScript runtime

Hono is a Web application framework that provides support for any JavaScript runtime. From 4.7.0 to 4.12.33, the Proxy Helper proxy() function in hono/proxy does not remove response headers named by the origin's Connection header. Per RF…

▾ Sunlithono · honoEPSS 0.36%via NVD
GHSA-7c4v-fwgw-9rf7Medium
1mo ago

Nuxt dev server discloses project root and workspace UUID via the Chrome DevTools workspace endpoint

Nuxt dev server discloses project root and workspace UUID via the Chrome DevTools workspace endpoint

▾ Sunlitnuxt · nuxtvia GHSA
GHSA-hh9p-6wh2-4mfcMedium· 6.5
1mo ago

GitPython: Arbitrary file read via --pathspec-from-file in IndexFile.remove() and Head.checkout()

GitPython: Arbitrary file read via --pathspec-from-file in IndexFile.remove() and Head.checkout()

▾ SunlitGitPython · GitPythonvia GHSA
CVE-2026-48007High
1mo ago

Element Call is a native Matrix video conferencing application

Element Call is a native Matrix video conferencing application. Versions 0.5.17 through 0.19.3 report analytics data to a PostHog server, when configured to by a `posthog` key in config.json or by the `posthogApiHost` and `posthogApiKey`…

▾ Twilightelement-hq · @element-hq/element-call-embeddedEPSS 0.25%via NVD
CVE-2026-48080High· 8.0
1mo ago

OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform

OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.2, the `GET /api/tenants/{id}` endpoint returns the full tenant record to any authenticated `TENANT_ADMIN` o…

▾ TwilightEPSS 0.47%via NVD
CVE-2026-48078Medium· 5.3
1mo ago

OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform

OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.5, the unauthenticated `/api/tenants/{id}/schedule` endpoint returns every non-archived channel for a tenant…

▾ SunlitEPSS 0.34%via NVD
CVE-2026-71433Medium· 5.3
1mo ago

LangGraph Checkpoint Postgres and SQLite Checkpoint are the Postgres and SQLite implementations of LangGraph's checkpoint saver

LangGraph Checkpoint Postgres and SQLite Checkpoint are the Postgres and SQLite implementations of LangGraph's checkpoint saver. Prior to 3.1.1, the langgraph-checkpoint-postgres and langgraph-checkpoint-sqlite packages persisted hierarc…

▾ Sunlitlanggraph-checkpoint-postgres · langgraph-checkpoint-postgresEPSS 0.36%via NVD
CVE-2026-64664Medium· 4.3
1mo ago

Statamic is a Laravel and Git powered content management system (CMS)

Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.1 and 6.24.0, an authenticated Control Panel user could use an endpoint intended for the user creation wizard to determine if a given email address belo…

▾ Sunlitstatamic · statamic/cmsEPSS 0.34%via NVD
CVE-2026-45378High· 7.5
1mo ago

Decidim is a participatory democracy framework

Decidim is a participatory democracy framework. Prior to 0.30.9, from 0.31.0 before 0.31.5, and in 0.32.0.rc1 before 0.32.0.rc2, the identity-document verification admin UI embeds verification_attachment blobs through reusable signed Act…

▾ Twilightdecidim-verifications · decidim-verificationsEPSS 0.42%via NVD
GHSA-8mxv-9xhp-86h4Medium· 5.3
1mo ago

rclone: S3 Redirect Sanitization Omits IBM IAM Bearer Tokens and SSE-C Keys

rclone: S3 Redirect Sanitization Omits IBM IAM Bearer Tokens and SSE-C Keys

▾ Sunlitrclone · github.com/rclone/rclonevia GHSA
CVE-2026-53949Medium· 5.3
1mo ago

Ghost Content API filter bypass reveals private fields

Ghost Content API filter bypass reveals private fields

▾ Sunlitghost · ghostEPSS 0.36%via GHSA
CVE-2026-70491Medium· 6.5
1mo ago

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. In 0.10.2 and earlier, the GET /api/v1/tools/, GET /api/v1/tools/list, and GET /api/v1/tools/id/{id} endpoints in backend/open_webui/routers/tools.py r…

▾ Sunlitopenwebui · open_webuiEPSS 0.48%via NVD
CVE-2026-70590Medium· 4.8
1mo ago

Ghost is a Node.js content management system

Ghost is a Node.js content management system. Prior to 6.54.1, any staff-level user was able to leak the hashed passwords of other staff users through the Ghost Admin API. An offline password-guessing attack against the hashes could lead…

▾ Sunlitghost · ghostEPSS 0.32%via NVD
CVE-2026-70478Critical· 10.0
1mo ago

Flowise is a drag & drop user interface to build a customized large language model flow

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the POST /api/v1/oauth2-credential/refresh/:credentialId endpoint is included in WHITELIST_URLS and requires no authentication. The …

▾ Midnightflowiseai · flowiseEPSS 0.61%via NVD
CVE-2026-70473High· 8.5
1mo ago

Flowise is a drag-and-drop user interface for building customized large language model (LLM) flows

Flowise is a drag-and-drop user interface for building customized large language model (LLM) flows. Prior to 3.1.3, Flowise GET /api/v1/upsert-history returns the entire server-wide upsert history instead of being scoped to the requestin…

▾ Twilightflowiseai · flowiseEPSS 0.45%via NVD
CWE-200 vulnerabilities (CVEs) — page 16 · VulnSea