CWE-200
CVEs classified under CWE-200, newest first.
823 CVEsRSS
CVE-2026-58442Medium· 6.5Gitea: Repository migration SSRF via multi-answer DNS allow-list bypass
Gitea: Repository migration SSRF via multi-answer DNS allow-list bypass
CVE-2026-50105Medium· 4.3Gitea: RSS/Atom feed handlers bypass API-token scope & public-only confinement (incomplete fix of #37698)
Gitea: RSS/Atom feed handlers bypass API-token scope & public-only confinement (incomplete fix of #37698)
CVE-2026-58417MediumGitea: REST API exposes organization membership of private organizations to public
Gitea: REST API exposes organization membership of private organizations to public
CVE-2026-58434LowGitea: Private Repository Metadata Remains Accessible After Access Revocation
Gitea: Private Repository Metadata Remains Accessible After Access Revocation
CVE-2026-55982MediumGitea: OIDC userinfo Endpoint Returns Identity Claims Without Enforcing API Token Scopes
Gitea: OIDC userinfo Endpoint Returns Identity Claims Without Enforcing API Token Scopes
CVE-2026-44231Critical· 9.1RT is an open source, enterprise-grade issue and ticket tracking system
RT is an open source, enterprise-grade issue and ticket tracking system. Versions prior to 5.0.10, 6.0.0 and above, prior to 6.0.3 contain an information disclosure and privilege escalation vulnerability in the REST 2.0 API. A privileged…
GHSA-94pj-82f3-465wMedium· 5.3Guzzle: Proxy-Authorization headers can be sent to origin servers
Guzzle: Proxy-Authorization headers can be sent to origin servers
GHSA-gcfj-64vw-6mp9HighAxios Node HTTP adapter can use an inherited proxy after interceptor config cloning
Axios Node HTTP adapter can use an inherited proxy after interceptor config cloning
CVE-2026-16201Medium· 5.3A vulnerability was found in zevorn rt-claw up to 0.2.0
A vulnerability was found in zevorn rt-claw up to 0.2.0. Affected is the function claw_net_get/claw_net_post of the file claw/services/tools/net.c of the component http_request. The manipulation results in information disclosure. The att…
CVE-2026-16108Medium· 4.3A flaw was found in the default-groups REST endpoint and realm representation of Keycloak
A flaw was found in the default-groups REST endpoint and realm representation of Keycloak. This component is responsible for managing groups that are automatically assigned to new users within a realm. The issue allows a delegated admini…
CVE-2026-44979None@hapi/wreck is an HTTP client utility
@hapi/wreck is an HTTP client utility. Prior to 18.1.1, when @hapi/wreck follows a 3xx redirect to a different hostname, only the Authorization and Cookie headers are stripped, and the standard credential header Proxy-Authorization is fo…
CVE-2026-53598High· 7.5Prompty: Arbitrary file read via file reference expansion
Prompty: Arbitrary file read via file reference expansion
CVE-2026-35145Low· 3.1HCL DFXAnalytics is affected by a Missing HTTP Strict-Transport-Security Header vulnerability
HCL DFXAnalytics is affected by a Missing HTTP Strict-Transport-Security Header vulnerability. The application fails to implement the HTTP Strict Transport Security (HSTS) policy within its responses, which could allow a remote attacker …
GHSA-x8mg-6r4p-87pfHighArcadeDB has cross-database IDOR: /ts/*, /batch/*, Prometheus and Grafana handlers bypass authorization
ArcadeDB has cross-database IDOR: /ts/*, /batch/*, Prometheus and Grafana handlers bypass authorization
CVE-2026-45737Medium· 6.3Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes
Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. From 3.2.0 until 3.2.12, 3.3.10, and 3.4.2, Argo CD ServerSideDiff can expose Kubernetes Secret values embedded in the kubectl.kubernetes.io/last-applied-configura…
CVE-2026-50697High· 7.8Windows Common Log File System Driver Elevation of Privilege Vulnerability
Exposure of sensitive information to an unauthorized actor in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.
CVE-2026-50350Medium· 5.5Windows Trusted Runtime Interface Driver Information Disclosure Vulnerability
Exposure of sensitive information to an unauthorized actor in Windows Trusted Runtime Interface Driver allows an authorized attacker to disclose information locally.
CVE-2026-49807Medium· 6.2Windows DirectX Information Disclosure Vulnerability
Exposure of sensitive information to an unauthorized actor in Windows DirectX allows an unauthorized attacker to disclose information locally.
CVE-2026-50419Low· 3.3Windows Kernel Information Disclosure Vulnerability
Exposure of sensitive information to an unauthorized actor in Windows Kernel allows an authorized attacker to disclose information locally.
CVE-2026-50434Medium· 5.5Windows Push Notification Information Disclosure Vulnerability
Exposure of sensitive information to an unauthorized actor in Windows Push Notifications allows an authorized attacker to disclose information locally.
CVE-2026-50430Medium· 5.5Windows Push Notification Information Disclosure Vulnerability
Exposure of sensitive information to an unauthorized actor in Windows Push Notifications allows an authorized attacker to disclose information locally.
CVE-2026-50339Medium· 5.5Windows Push Notification Information Disclosure Vulnerability
Exposure of sensitive information to an unauthorized actor in Windows Push Notifications allows an authorized attacker to disclose information locally.
CVE-2026-50416Low· 3.3PoCWin32k Information Disclosure Vulnerability
Exposure of sensitive information to an unauthorized actor in Windows Win32K allows an authorized attacker to disclose information locally.
CVE-2026-50352Medium· 5.5Windows Cryptographic Services Information Disclosure Vulnerability
Exposure of sensitive information to an unauthorized actor in Windows Cryptographic Services allows an authorized attacker to disclose information locally.
CVE-2026-50334Medium· 5.5Windows Push Notification Information Disclosure Vulnerability
Exposure of sensitive information to an unauthorized actor in Windows Notification allows an authorized attacker to disclose information locally.
CVE-2026-50473Medium· 5.5Windows File Explorer Information Disclosure Vulnerability
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.
CVE-2026-50456Medium· 5.5Windows File Explorer Information Disclosure Vulnerability
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.
CVE-2026-50442Medium· 5.5Windows File Explorer Information Disclosure Vulnerability
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.
CVE-2026-50409Medium· 5.5Windows Overlay Filter Information Disclosure Vulnerability
Exposure of sensitive information to an unauthorized actor in Windows Overlay Filter allows an authorized attacker to disclose information locally.
CVE-2026-50389Medium· 5.5Windows File Explorer Information Disclosure Vulnerability
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.