CWE-200
CVEs classified under CWE-200, newest first.
823 CVEsRSS
CVE-2026-41186High· 7.5When Calico's shared debug server is enabled (disabled by default), the Calico kube-controllers and Goldmane components bind their Go pprof debug listener to 0.0.0.0 without authentication
When Calico's shared debug server is enabled (disabled by default), the Calico kube-controllers and Goldmane components bind their Go pprof debug listener to 0.0.0.0 without authentication. Any pod with network reachability to the listen…
CVE-2026-67435Mediumlinuxfabrik-lib: fetch() forwards credential headers across a cross-origin redirect
linuxfabrik-lib: fetch() forwards credential headers across a cross-origin redirect
CVE-2026-55651High· 7.1Easy!Appointments Vulnerable to Appointments Takeover via Excessive Data Exposure
Easy!Appointments Vulnerable to Appointments Takeover via Excessive Data Exposure
CVE-2026-52837MediumEasy!Appointments has unauthenticated customer PII disclosure on booking reschedule page
Easy!Appointments has unauthenticated customer PII disclosure on booking reschedule page
CVE-2026-54660High· 7.4swagger-typescript-api vulnerable to authorization-token exfiltration via spec `$ref`
swagger-typescript-api vulnerable to authorization-token exfiltration via spec `$ref`
CVE-2026-55389High· 7.5datamodel-code-generator vulnerable to arbitrary local file read via JSON-Schema `$ref` (`file://` and `../` traversal), bypassing `--no-…
datamodel-code-generator vulnerable to arbitrary local file read via JSON-Schema `$ref` (`file://` and `../` traversal), bypassing `--no-allow-remote-refs`
CVE-2026-54659MediumPagy I18n locale option is not validated before being used in a file path
Pagy I18n locale option is not validated before being used in a file path
CVE-2026-52888Medium· 6.8NocoBase: Sensitive Data Exposure via SQL Blacklist Bypass
NocoBase: Sensitive Data Exposure via SQL Blacklist Bypass
CVE-2026-55390High· 7.5datamodel-code-generator vulnerable to arbitrary local file read via XSD `schemaLocation` (`xs:include`/`xs:import`) path traversal, with no remote-ref gate
datamodel-code-generator vulnerable to arbitrary local file read via XSD `schemaLocation` (`xs:include`/`xs:import`) path traversal, with no remote-ref gate
CVE-2026-55403Low· 3.7datamodel-code-generator: Authorization / request headers leaked to cross-origin redirect target when fetching remote schemas
datamodel-code-generator: Authorization / request headers leaked to cross-origin redirect target when fetching remote schemas
CVE-2026-54605High· 7.2OAuth is a Ruby wrapper for the OAuth 1.0 and 1.0a protocols, providing clients and servers
OAuth is a Ruby wrapper for the OAuth 1.0 and 1.0a protocols, providing clients and servers. From 0.5.5 to 1.1.5, OAuth::Consumer#token_request parses the raw Location header of a 300 to 399 redirect returned by the OAuth server and foll…
CVE-2026-54603High· 8.6OAuth2 is a Ruby wrapper for the OAuth 2.0 and 2.1 authorization frameworks, including OpenID Connect (OIDC)
OAuth2 is a Ruby wrapper for the OAuth 2.0 and 2.1 authorization frameworks, including OpenID Connect (OIDC). From 0.4.0 to 2.0.21, a protocol-relative redirect Location returned to OAuth2::Client#request overrides the request authority,…
CVE-2026-45623High· 7.5postcss: PostCSS: Information disclosure and denial of service via crafted CSS input (CVE-2026-45623)
A flaw was found in PostCSS, a tool that processes CSS files. An attacker who provides specially crafted CSS input containing a malicious source map comment can cause the system to read arbitrary files from the local filesystem. This can l…
CVE-2026-17457Medium· 4.3A vulnerability has been found in mf-yang openclaw-cn up to 0.2.1
A vulnerability has been found in mf-yang openclaw-cn up to 0.2.1. Affected by this issue is the function assertBrowserNavigationAllowed of the file src/browser/navigation-guard.ts of the component Scheme Handler. Such manipulation of th…
CVE-2026-49159Medium· 6.5Microsoft Graph Information Disclosure Vulnerability
Exposure of sensitive information to an unauthorized actor in Microsoft Graph allows an authorized attacker to disclose information over a network.
CVE-2026-17048Medium· 5.5A flaw was found in the Keycloak Admin REST API, which is used to manage security realms and clients
A flaw was found in the Keycloak Admin REST API, which is used to manage security realms and clients. The issue occurs when the system processes requests for rotated client secrets that are stored in a secure vault. Due to improper bound…
GHSA-94p4-4cq8-9g67High· 7.5GitPython: Environment-variable exfiltration via Repo.create_remote() / Remote.add() URL (incomplete fix of GHSA-rwj8-pgh3-r573)
GitPython: Environment-variable exfiltration via Repo.create_remote() / Remote.add() URL (incomplete fix of GHSA-rwj8-pgh3-r573)
GHSA-f45q-w629-wr25MediumHubuum client library (Rust): Authenticated requests may escape the configured base path through redirects
Hubuum client library (Rust): Authenticated requests may escape the configured base path through redirects
GHSA-p6ph-3jx2-3337Medium· 4.3OpenList: Search metadata/count disclosure via Non-Separator-Aware Path Check in Bleve Search
OpenList: Search metadata/count disclosure via Non-Separator-Aware Path Check in Bleve Search
GHSA-q53c-4prm-w95qMediumShescape: Home-directory disclosure in assignment context on Unix with Dash
Shescape: Home-directory disclosure in assignment context on Unix with Dash
GHSA-fcrw-f7gg-6g9fMedium· 4.9Budibase: SSO OAuth2 Token Leakage via User Metadata Endpoints to Power-Role Users
Budibase: SSO OAuth2 Token Leakage via User Metadata Endpoints to Power-Role Users
GHSA-mqhr-6j6h-74p5CriticalBudibase: Unauthenticated REST Datasource Credential Theft via Cross-Origin Auth Leak
Budibase: Unauthenticated REST Datasource Credential Theft via Cross-Origin Auth Leak
GHSA-hr66-5mqr-8mpxHigh· 7.5Budibase: Unauthenticated user information disclosure via public tenant user lookup endpoint
Budibase: Unauthenticated user information disclosure via public tenant user lookup endpoint
GHSA-gh4h-34gr-87r7Medium· 5.7Budibase: OAuth2 Token Disclosure via Automation Test Results Broadcast to Other Builders
Budibase: OAuth2 Token Disclosure via Automation Test Results Broadcast to Other Builders
CVE-2026-59222MediumOpen WebUI: /api/v1/channels/{id}/members exposes full user model including sensitive credentials
Open WebUI: /api/v1/channels/{id}/members exposes full user model including sensitive credentials
CVE-2026-54673Highelectron-updater: Cross-origin redirect leaks `PRIVATE-TOKEN` and mixed-case `Authorization` credentials in `builder-util-runtime`
electron-updater: Cross-origin redirect leaks `PRIVATE-TOKEN` and mixed-case `Authorization` credentials in `builder-util-runtime`
CVE-2026-53467Medium· 5.3ImageMagick: Information Disclosure in MNG decoder because allocated memory is left unchanged
ImageMagick: Information Disclosure in MNG decoder because allocated memory is left unchanged
GHSA-2x35-3fw4-9jr4Highn8n: Send Email Node Arbitrary File Read and SSRF via Nodemailer Content-Object Type Confusion
n8n: Send Email Node Arbitrary File Read and SSRF via Nodemailer Content-Object Type Confusion
CVE-2026-59209Highn8n: Shared Credential Header Leak via HTTP Request Pagination Expression
n8n: Shared Credential Header Leak via HTTP Request Pagination Expression
CVE-2026-60812Medium· 6.5Vulnerability in the Oracle Supply Chain Trading Connector product of Oracle E-Business Suite (component: Collaboration History)
Vulnerability in the Oracle Supply Chain Trading Connector product of Oracle E-Business Suite (component: Collaboration History). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privi…