VulnSea

CWE-200

CVEs classified under CWE-200, newest first.

676 CVEsRSS

CVE-2026-54649Low· 2.1
4d ago

punchin-email is a Cloudflare Email Worker that provides two-way role aliases while relaying mail to a private inbox

punchin-email is a Cloudflare Email Worker that provides two-way role aliases while relaying mail to a private inbox. Prior to 1.5.0, handleInbound delivers inbound alias mail with message.forward(), which silently drops the added Reply-…

SunlitPunchIn-App · punchin-emailEPSS 0.47%via NVD
CVE-2026-92927Medium· 5.3PoC
4d ago

A vulnerability was found in SourceCodester Drug Recommendation System 1.0

A vulnerability was found in SourceCodester Drug Recommendation System 1.0. This issue affects some unknown processing of the file /db/drug_recommendor.sql. Performing a manipulation results in information disclosure. The attack is possi…

TwilightSourceCodester · Drug Recommendation SystemEPSS 0.32%via NVD
CVE-2026-69088High· 8.1
4d ago

Grav: Incomplete callable validation in blueprint dynamic fields allows arbitrary static method invocation and file disclosure

Grav: Incomplete callable validation in blueprint dynamic fields allows arbitrary static method invocation and file disclosure

Twilightgetgrav · getgrav/gravEPSS 0.23%via GHSA
CVE-2026-85717Medium· 6.8
4d ago

The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses

The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 2.14.5 to 2.16.0 and from 3.0.9 to 3.0.11, a client configured with a client-wide Realm and redire…

SunlitAsyncHttpClient · async-http-clientEPSS 0.33%via NVD
CVE-2026-75523Medium· 5.9
4d ago

Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applications

Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applications. Prior to 4.3.0, the Steeltoe.Management.Endpoint /actuator/httpexchanges endpoint passes recorded request URIs t…

SunlitSteeltoe · Steeltoe.Management.EndpointEPSS 0.29%via NVD
CVE-2026-69197High· 8.7
4d ago

Umbraco is an ASP.NET CMS

Umbraco is an ASP.NET CMS. Prior to 13.15.1, 17.5.3, and 18.0.2, the Content Delivery API applies member and Public Access checks to the directly requested node but not to referenced nodes serialized through Content Picker or Multi-Node …

Twilightumbraco · Umbraco-CMSEPSS 0.38%via NVD
CVE-2026-80356High· 7.3
4d ago

Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Exposure of Sensitive Information to an Unauthorized Actor vulnerability

Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Exposure of Sensitive Information to an Unauthorized Actor vulnerability. A low privileged attacker with local access could potentially exploit this vulnerabil…

TwilightDell · OpenManage Server Administrator Managed Node (Patch) for WindowsEPSS 0.14%via NVD
CVE-2026-63461Medium· 5.3
4d ago

Vendure is an open-source headless commerce platform

Vendure is an open-source headless commerce platform. Prior to 3.6.5, the public Shop API products, collections, and facets queries combine mandatory visibility guards with caller-supplied filters using the caller-controlled filterOperat…

Sunlitvendurehq · vendureEPSS 0.32%via NVD
CVE-2026-92960Critical· 10.0PoC
4d ago

vm2 before 3.11.6 fails to restrict access to os and dns builtins under the builtin: ['*'] configuration, allowing sandbox code to read host process identity and network topology

vm2 before 3.11.6 fails to restrict access to os and dns builtins under the builtin: ['*'] configuration, allowing sandbox code to read host process identity and network topology. Attackers can invoke dns.setServers() to hijack the host …

Abyssalpatriksimek · vm2EPSS 0.43%via NVD
CVE-2026-92947Critical· 10.0PoC
4d ago

vm2 before 3.11.7 exposes Node's shared Buffer pool to sandboxed code, allowing disclosure of host memory used by Buffer.from, Buffer.concat, and related allocations

vm2 before 3.11.7 exposes Node's shared Buffer pool to sandboxed code, allowing disclosure of host memory used by Buffer.from, Buffer.concat, and related allocations. Sandboxed code can read and write to host-realm buffers by acquiring A…

Abyssalpatriksimek · vm2EPSS 0.43%via NVD
CVE-2026-92933Medium· 5.8PoC
4d ago

vm2 is a sandbox for running untrusted Node.js code

vm2 is a sandbox for running untrusted Node.js code. In versions <= 3.11.7, NodeVM exposes the host `util` module to the sandbox as an unfiltered shallow copy (`Object.assign({}, util)` in `defaultBuiltinLoaderUtil`), and the deprecated …

Twilightpatriksimek · vm2EPSS 0.27%via NVD
CVE-2026-92916High· 7.5
4d ago

Grav is a flat-file CMS

Grav is a flat-file CMS. In Grav 1.7.0 through 1.7.53.2 and 2.0.0 through 2.0.21, when the debugger is enabled (system.debugger.enabled: true, which is not the default), the Clockwork profiler endpoint is exposed without authentication: …

Twilightgetgrav · gravEPSS 0.35%via NVD
CVE-2026-92917High· 7.5PoC
4d ago

Grav is a flat-file CMS

Grav is a flat-file CMS. In versions 2.0.0-rc.1 through 2.0.21, the Twig content sandbox fails to restrict the dump and serialize filters (print_r, vardump, json_encode, yaml_encode, string): GravExtension::assertSandboxDumpSafe() determ…

Midnightgetgrav · gravEPSS 0.33%via NVD
CVE-2026-44940Medium· 5.7
4d ago

The rancher-extension-stackstate extension in SUSE Observability exposes service tokens in plain configuration or insecure locations rather than managing them securely

The rancher-extension-stackstate extension in SUSE Observability exposes service tokens in plain configuration or insecure locations rather than managing them securely. An attacker with minimal access could obtain the token to gain unaut…

SunlitSUSE · rancher-extension-stackstateEPSS 0.13%via NVD
CVE-2026-86446Low· 3.7
4d ago

The LearnPress WordPress plugin before 4.4.7 does not restrict the correctness flags it returns when a quiz answer is checked, allowing unauthenticated attackers to obtain the correct answer to every option of a question, along with the…

The LearnPress WordPress plugin before 4.4.7 does not restrict the correctness flags it returns when a quiz answer is checked, allowing unauthenticated attackers to obtain the correct answer to every option of a question, along with the…

SunlitEPSS 0.18%via NVD
CVE-2026-87836Low· 2.7
4d ago

The Comments Import & Export WordPress plugin before 2.5.4 does not restrict its comment export to users able to moderate comments, nor scope the export to content owned by the requesting user, allowing users with the Author role and abo…

The Comments Import & Export WordPress plugin before 2.5.4 does not restrict its comment export to users able to moderate comments, nor scope the export to content owned by the requesting user, allowing users with the Author role and abo…

SunlitEPSS 0.19%via NVD
CVE-2026-54617Critical· 9.8
4d ago

GravitLauncher is an open-source Minecraft launcher based on sashok724's v3

GravitLauncher is an open-source Minecraft launcher based on sashok724's v3. Prior to 5.7.12, an unauthenticated remote actor can send a raw HTTP request target without a leading slash to the default LaunchServer file server on port 9274…

MidnightGravitLauncher · LauncherEPSS 0.68%via NVD
CVE-2026-64684Medium· 6.8
5d ago

RMCP is an official Rust SDK for the Model Context Protocol

RMCP is an official Rust SDK for the Model Context Protocol. Prior to 2.1.0, the rmcp crate's StreamableHttpClientTransport in crates/rmcp/src/transport/common/reqwest/streamable_http_client.rs builds its default_http_client with reqwest…

Sunlitmodelcontextprotocol · rust-sdkEPSS 0.40%via NVD
CVE-2026-92594High· 7.5
5d ago

Craft CMS 5.0.0-RC1 through versions before 5.11.0 incorrectly authorize the GraphQL draftCreator and revisionCreator fields: instead of requiring the user-data scope enforced by Gql::canQueryUsers() (usergroups.*:read), these fields are…

Craft CMS 5.0.0-RC1 through versions before 5.11.0 incorrectly authorize the GraphQL draftCreator and revisionCreator fields: instead of requiring the user-data scope enforced by Gql::canQueryUsers() (usergroups.*:read), these fields are…

Twilightcraftcms · cmsEPSS 0.26%via NVD
CVE-2026-61588Medium· 6.5
5d ago

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, when a Django `Model` instance is assigned to a public view attribute, djust serialized it to the clie…

Sunlitdjust-org · djustEPSS 0.30%via NVD
CVE-2026-92770Medium· 6.5PoC
5d ago

Harbor through 2.15.2 fails to properly restrict the q query parameter filtering on scanner registration access credentials

Harbor through 2.15.2 fails to properly restrict the q query parameter filtering on scanner registration access credentials. Project administrators can exploit fuzzy filtering on the AccessCredential column to recover the scanner adapter…

Twilightgoharbor · harborEPSS 0.33%via NVD
CVE-2026-92811Medium· 6.5PoC
5d ago

browserless versions 1.44.0 through 2.56.7 fail to enforce file protocol restrictions in Playwright websocket endpoints, allowing authenticated token holders to read arbitrary files

browserless versions 1.44.0 through 2.56.7 fail to enforce file protocol restrictions in Playwright websocket endpoints, allowing authenticated token holders to read arbitrary files. Attackers can navigate Playwright-driven browsers to f…

Twilightbrowserless · browserlessEPSS 0.26%via NVD
CVE-2026-81870Low· 2.0PoC
5d ago

OpenTelemetry-Go is the Go implementation of OpenTelemetry

OpenTelemetry-Go is the Go implementation of OpenTelemetry. From version 1.5.0 to 1.44.0, sdk/trace.NewTracerProvider emits a TracerProvider created internal Info-level diagnostic event whose MarshalLog implementations recursively includ…

Twilightopen-telemetry · opentelemetry-goEPSS 0.19%via NVD
CVE-2026-87076Medium· 6.5
5d ago

Tanium addressed an information disclosure vulnerability in Discover.

Tanium addressed an information disclosure vulnerability in Discover.

SunlitTanium · DiscoverEPSS 0.36%via NVD
CVE-2026-20360High· 8.8
5d ago

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Nexus Dashboard engineering team has conducted a comprehensive internal security review

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Nexus Dashboard engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that…

TwilightCisco · Cisco Nexus DashboardEPSS 0.32%via NVD
CVE-2026-76825High· 8.4
5d ago

RestrictedPython is a tool that helps define a subset of the Python language for accepting program input in a trusted environment

RestrictedPython is a tool that helps define a subset of the Python language for accepting program input in a trusted environment. Prior to 8.4, RestrictedPython could allow a sandbox escape when a custom import policy or globals exposed…

Twilightzopefoundation · RestrictedPythonEPSS 0.57%via NVD
CVE-2026-92357Medium· 4.3
5d ago

A vulnerability was identified in a2ui-project a2ui 0.8/0.9/1.0

A vulnerability was identified in a2ui-project a2ui 0.8/0.9/1.0. Impacted is an unknown function of the file model-processor.ts of the component Model Processor. The manipulation of the argument current[segment] leads to information disc…

Sunlita2ui-project · a2uiEPSS 0.30%via NVD
CVE-2026-87907Medium· 5.3
5d ago

The Rox Appointment Booking WordPress plugin before 1.2.8 does not perform any authorization check on the endpoints that return booking service and category records, allowing unauthenticated attackers to read the private internal notes …

The Rox Appointment Booking WordPress plugin before 1.2.8 does not perform any authorization check on the endpoints that return booking service and category records, allowing unauthenticated attackers to read the private internal notes …

SunlitEPSS 0.27%via NVD
CVE-2026-87896Medium· 5.3
5d ago

The Rox Appointment Booking WordPress plugin before 1.2.8 does not perform any authorization check on the endpoint that returns booking agent (staff) records, allowing unauthenticated attackers to read staff email addresses, phone numbe…

The Rox Appointment Booking WordPress plugin before 1.2.8 does not perform any authorization check on the endpoint that returns booking agent (staff) records, allowing unauthenticated attackers to read staff email addresses, phone numbe…

SunlitEPSS 0.27%via NVD
CVE-2026-87854Medium· 5.3
5d ago

The Subscriptions for WooCommerce WordPress plugin before 2.0.3 does not correctly validate the shared secret protecting one of its REST endpoints, allowing unauthenticated users to retrieve the store's full list of subscriptions, includ…

The Subscriptions for WooCommerce WordPress plugin before 2.0.3 does not correctly validate the shared secret protecting one of its REST endpoints, allowing unauthenticated users to retrieve the store's full list of subscriptions, includ…

SunlitEPSS 0.27%via NVD
CWE-200 vulnerabilities (CVEs) — page 2 · VulnSea