VulnSea

CWE-200

CVEs classified under CWE-200, newest first.

823 CVEsRSS

CVE-2026-41186High· 7.5
2mo ago

When Calico's shared debug server is enabled (disabled by default), the Calico kube-controllers and Goldmane components bind their Go pprof debug listener to 0.0.0.0 without authentication

When Calico's shared debug server is enabled (disabled by default), the Calico kube-controllers and Goldmane components bind their Go pprof debug listener to 0.0.0.0 without authentication. Any pod with network reachability to the listen…

▾ Twilighttigera · calicoEPSS 0.67%via NVD
CVE-2026-67435Medium
2mo ago

linuxfabrik-lib: fetch() forwards credential headers across a cross-origin redirect

linuxfabrik-lib: fetch() forwards credential headers across a cross-origin redirect

▾ Sunlitlinuxfabrik-lib · linuxfabrik-libEPSS 0.50%via GHSA
CVE-2026-55651High· 7.1
2mo ago

Easy!Appointments Vulnerable to Appointments Takeover via Excessive Data Exposure

Easy!Appointments Vulnerable to Appointments Takeover via Excessive Data Exposure

▾ Twilightalextselegidis · alextselegidis/easyappointmentsEPSS 0.32%via GHSA
CVE-2026-52837Medium
2mo ago

Easy!Appointments has unauthenticated customer PII disclosure on booking reschedule page

Easy!Appointments has unauthenticated customer PII disclosure on booking reschedule page

▾ Sunlitalextselegidis · alextselegidis/easyappointmentsEPSS 0.56%via GHSA
CVE-2026-54660High· 7.4
2mo ago

swagger-typescript-api vulnerable to authorization-token exfiltration via spec `$ref`

swagger-typescript-api vulnerable to authorization-token exfiltration via spec `$ref`

▾ Twilightswagger-typescript-api · swagger-typescript-apiEPSS 0.44%via GHSA
CVE-2026-55389High· 7.5
2mo ago

datamodel-code-generator vulnerable to arbitrary local file read via JSON-Schema `$ref` (`file://` and `../` traversal), bypassing `--no-…

datamodel-code-generator vulnerable to arbitrary local file read via JSON-Schema `$ref` (`file://` and `../` traversal), bypassing `--no-allow-remote-refs`

▾ Twilightdatamodel-code-generator · datamodel-code-generatorEPSS 0.55%via OSV
CVE-2026-54659Medium
2mo ago

Pagy I18n locale option is not validated before being used in a file path

Pagy I18n locale option is not validated before being used in a file path

▾ Sunlitpagy · pagyEPSS 0.54%via GHSA
CVE-2026-52888Medium· 6.8
2mo ago

NocoBase: Sensitive Data Exposure via SQL Blacklist Bypass

NocoBase: Sensitive Data Exposure via SQL Blacklist Bypass

▾ Sunlitnocobase · @nocobase/plugin-collection-sqlEPSS 0.47%via GHSA
CVE-2026-55390High· 7.5
2mo ago

datamodel-code-generator vulnerable to arbitrary local file read via XSD `schemaLocation` (`xs:include`/`xs:import`) path traversal, with no remote-ref gate

datamodel-code-generator vulnerable to arbitrary local file read via XSD `schemaLocation` (`xs:include`/`xs:import`) path traversal, with no remote-ref gate

▾ Twilightdatamodel-code-generator · datamodel-code-generatorEPSS 0.53%via GHSA
CVE-2026-55403Low· 3.7
2mo ago

datamodel-code-generator: Authorization / request headers leaked to cross-origin redirect target when fetching remote schemas

datamodel-code-generator: Authorization / request headers leaked to cross-origin redirect target when fetching remote schemas

▾ Sunlitdatamodel-code-generator · datamodel-code-generatorEPSS 0.34%via OSV
CVE-2026-54605High· 7.2
2mo ago

OAuth is a Ruby wrapper for the OAuth 1.0 and 1.0a protocols, providing clients and servers

OAuth is a Ruby wrapper for the OAuth 1.0 and 1.0a protocols, providing clients and servers. From 0.5.5 to 1.1.5, OAuth::Consumer#token_request parses the raw Location header of a 300 to 399 redirect returned by the OAuth server and foll…

▾ Twilightoauth · oauthEPSS 0.19%via NVD
CVE-2026-54603High· 8.6
2mo ago

OAuth2 is a Ruby wrapper for the OAuth 2.0 and 2.1 authorization frameworks, including OpenID Connect (OIDC)

OAuth2 is a Ruby wrapper for the OAuth 2.0 and 2.1 authorization frameworks, including OpenID Connect (OIDC). From 0.4.0 to 2.0.21, a protocol-relative redirect Location returned to OAuth2::Client#request overrides the request authority,…

▾ Twilightoauth2 · oauth2EPSS 0.59%via NVD
CVE-2026-45623High· 7.5
2mo ago

postcss: PostCSS: Information disclosure and denial of service via crafted CSS input (CVE-2026-45623)

A flaw was found in PostCSS, a tool that processes CSS files. An attacker who provides specially crafted CSS input containing a malicious source map comment can cause the system to read arbitrary files from the local filesystem. This can l…

▾ TwilightRed Hat · Red Hat OpenShift AI 3.4EPSS 0.61%via CSAF
CVE-2026-17457Medium· 4.3
2mo ago

A vulnerability has been found in mf-yang openclaw-cn up to 0.2.1

A vulnerability has been found in mf-yang openclaw-cn up to 0.2.1. Affected by this issue is the function assertBrowserNavigationAllowed of the file src/browser/navigation-guard.ts of the component Scheme Handler. Such manipulation of th…

▾ SunlitEPSS 0.42%via NVD
CVE-2026-49159Medium· 6.5
2mo ago

Microsoft Graph Information Disclosure Vulnerability

Exposure of sensitive information to an unauthorized actor in Microsoft Graph allows an authorized attacker to disclose information over a network.

▾ SunlitMicrosoft · Microsoft GraphEPSS 1.00%via CVEORG
CVE-2026-17048Medium· 5.5
2mo ago

A flaw was found in the Keycloak Admin REST API, which is used to manage security realms and clients

A flaw was found in the Keycloak Admin REST API, which is used to manage security realms and clients. The issue occurs when the system processes requests for rotated client secrets that are stored in a secure vault. Due to improper bound…

▾ Sunlitredhat · build_of_keycloakEPSS 0.42%via NVD
GHSA-94p4-4cq8-9g67High· 7.5
2mo ago

GitPython: Environment-variable exfiltration via Repo.create_remote() / Remote.add() URL (incomplete fix of GHSA-rwj8-pgh3-r573)

GitPython: Environment-variable exfiltration via Repo.create_remote() / Remote.add() URL (incomplete fix of GHSA-rwj8-pgh3-r573)

▾ TwilightGitPython · GitPythonvia GHSA
GHSA-f45q-w629-wr25Medium
2mo ago

Hubuum client library (Rust): Authenticated requests may escape the configured base path through redirects

Hubuum client library (Rust): Authenticated requests may escape the configured base path through redirects

▾ Sunlithubuum_client · hubuum_clientvia GHSA
GHSA-p6ph-3jx2-3337Medium· 4.3
2mo ago

OpenList: Search metadata/count disclosure via Non-Separator-Aware Path Check in Bleve Search

OpenList: Search metadata/count disclosure via Non-Separator-Aware Path Check in Bleve Search

▾ SunlitOpenListTeam · github.com/OpenListTeam/OpenList/v4via GHSA
GHSA-q53c-4prm-w95qMedium
2mo ago

Shescape: Home-directory disclosure in assignment context on Unix with Dash

Shescape: Home-directory disclosure in assignment context on Unix with Dash

▾ Sunlitshescape · shescapevia GHSA
GHSA-fcrw-f7gg-6g9fMedium· 4.9
2mo ago

Budibase: SSO OAuth2 Token Leakage via User Metadata Endpoints to Power-Role Users

Budibase: SSO OAuth2 Token Leakage via User Metadata Endpoints to Power-Role Users

▾ Sunlitbudibase · @budibase/servervia GHSA
GHSA-mqhr-6j6h-74p5Critical
2mo ago

Budibase: Unauthenticated REST Datasource Credential Theft via Cross-Origin Auth Leak

Budibase: Unauthenticated REST Datasource Credential Theft via Cross-Origin Auth Leak

▾ Midnightbudibase · @budibase/servervia GHSA
GHSA-hr66-5mqr-8mpxHigh· 7.5
2mo ago

Budibase: Unauthenticated user information disclosure via public tenant user lookup endpoint

Budibase: Unauthenticated user information disclosure via public tenant user lookup endpoint

▾ Twilightbudibase · @budibase/servervia GHSA
GHSA-gh4h-34gr-87r7Medium· 5.7
2mo ago

Budibase: OAuth2 Token Disclosure via Automation Test Results Broadcast to Other Builders

Budibase: OAuth2 Token Disclosure via Automation Test Results Broadcast to Other Builders

▾ Sunlitbudibase · @budibase/servervia GHSA
CVE-2026-59222Medium
2mo ago

Open WebUI: /api/v1/channels/{id}/members exposes full user model including sensitive credentials

Open WebUI: /api/v1/channels/{id}/members exposes full user model including sensitive credentials

▾ Sunlitopen-webui · open-webuiEPSS 0.46%via GHSA
CVE-2026-54673High
2mo ago

electron-updater: Cross-origin redirect leaks `PRIVATE-TOKEN` and mixed-case `Authorization` credentials in `builder-util-runtime`

electron-updater: Cross-origin redirect leaks `PRIVATE-TOKEN` and mixed-case `Authorization` credentials in `builder-util-runtime`

▾ Twilightbuilder-util-runtime · builder-util-runtimeEPSS 0.41%via GHSA
CVE-2026-53467Medium· 5.3
2mo ago

ImageMagick: Information Disclosure in MNG decoder because allocated memory is left unchanged

ImageMagick: Information Disclosure in MNG decoder because allocated memory is left unchanged

▾ SunlitMagick · Magick.NET-Q16-AnyCPUEPSS 0.33%via GHSA
GHSA-2x35-3fw4-9jr4High
2mo ago

n8n: Send Email Node Arbitrary File Read and SSRF via Nodemailer Content-Object Type Confusion

n8n: Send Email Node Arbitrary File Read and SSRF via Nodemailer Content-Object Type Confusion

▾ Twilightn8n · n8nvia GHSA
CVE-2026-59209High
2mo ago

n8n: Shared Credential Header Leak via HTTP Request Pagination Expression

n8n: Shared Credential Header Leak via HTTP Request Pagination Expression

▾ Twilightn8n · n8nEPSS 0.40%via GHSA
CVE-2026-60812Medium· 6.5
2mo ago

Vulnerability in the Oracle Supply Chain Trading Connector product of Oracle E-Business Suite (component: Collaboration History)

Vulnerability in the Oracle Supply Chain Trading Connector product of Oracle E-Business Suite (component: Collaboration History). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privi…

▾ Sunlitoracle · e-business_suiteEPSS 0.39%via NVD
CWE-200 vulnerabilities (CVEs) — page 18 · VulnSea