VulnSea

CWE-200

CVEs classified under CWE-200, newest first.

823 CVEsRSS

CVE-2026-50431Medium· 5.5
2mo ago

Windows Quality of Service (QoS) Packet Scheduler Information Disclosure Vulnerability

Windows Quality of Service (QoS) Packet Scheduler Information Disclosure Vulnerability

▾ SunlitMicrosoft · Windows 10 Version 1607EPSS 0.48%via CVEORG
CVE-2026-50429High· 8.2
2mo ago

Windows Kernel Information Disclosure Vulnerability

Out-of-bounds read in Windows Kernel allows an unauthorized attacker to disclose information over a network.

▾ TwilightMicrosoft · Windows 10 Version 1607EPSS 1.1%via CVEORG
CVE-2026-50415Medium· 5.3
2mo ago

Windows Media Information Disclosure Vulnerability

Exposure of sensitive information to an unauthorized actor in Windows Media allows an unauthorized attacker to disclose information over a network.

▾ SunlitMicrosoft · Windows 10 Version 1809EPSS 0.86%via CVEORG
CVE-2026-50394Medium· 5.5
2mo ago

Windows Media Information Disclosure Vulnerability

Exposure of sensitive information to an unauthorized actor in Windows Media allows an authorized attacker to disclose information locally.

▾ SunlitMicrosoft · Windows 10 Version 1607EPSS 0.48%via CVEORG
CVE-2026-50483Medium· 5.5
2mo ago

Windows Graphics Component Information Disclosure Vulnerability

Exposure of sensitive information to an unauthorized actor in Microsoft Graphics Component allows an authorized attacker to disclose information locally.

▾ SunlitMicrosoft · Windows 11 Version 24H2EPSS 0.48%via CVEORG
CVE-2026-50681Medium· 5.5
2mo ago

Windows Secure Channel Information Disclosure Vulnerability

Exposure of sensitive information to an unauthorized actor in Windows Cryptographic Services allows an authorized attacker to disclose information locally.

▾ SunlitMicrosoft · Windows 10 Version 1607EPSS 0.48%via CVEORG
CVE-2026-56184Medium· 5.5
2mo ago

Win32k Information Disclosure Vulnerability

Exposure of sensitive information to an unauthorized actor in Windows Win32K allows an authorized attacker to disclose information locally.

▾ SunlitMicrosoft · Windows 10 Version 21H2EPSS 0.48%via CVEORG
CVE-2026-57095Medium· 6.2
2mo ago

Win32k Elevation of Privilege Vulnerability

Exposure of sensitive information to an unauthorized actor in Windows Win32K allows an unauthorized attacker to elevate privileges locally.

▾ SunlitMicrosoft · Windows 10 Version 1607EPSS 0.49%via CVEORG
CVE-2026-57102High· 8.8
2mo ago

Visual Studio Code Security Feature Bypass Vulnerability

Inclusion of functionality from untrusted control sphere in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.

▾ TwilightMicrosoft · Visual Studio CodeEPSS 0.82%via CVEORG
CVE-2026-10051Medium· 5.3
2mo ago

jetty: Eclipse Jetty: Information disclosure due to retained HTTP/1.1 trailers across connections (CVE-2026-10051)

A flaw was found in Eclipse Jetty. This vulnerability allows a remote attacker to cause the server to retain HTTP/1.1 request trailers from a prior connection. Consequently, subsequent requests made over the same connection may unintention…

▾ SunlitRed Hat · Red Hat Satellite 6.17 for RHEL 9EPSS 0.30%via CSAF
CVE-2026-47282Medium· 6.5
2mo ago

Insufficiently protected credentials in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to disclose information over a network.

Insufficiently protected credentials in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to disclose information over a network.

▾ Sunlitmicrosoft · visual_studio_codeEPSS 0.87%via NVD
CVE-2026-41087Medium· 5.5
2mo ago

Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.

Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.

▾ Sunlitmicrosoft · windows_10_1607EPSS 0.48%via NVD
CVE-2026-34349Medium· 5.5
2mo ago

Exposure of sensitive information to an unauthorized actor in Windows Media allows an authorized attacker to disclose information locally.

Exposure of sensitive information to an unauthorized actor in Windows Media allows an authorized attacker to disclose information locally.

▾ Sunlitmicrosoft · windows_10_1809EPSS 0.48%via NVD
CVE-2026-34328Medium· 5.5
2mo ago

Exposure of sensitive information to an unauthorized actor in Windows Audio Service allows an authorized attacker to disclose information locally.

Exposure of sensitive information to an unauthorized actor in Windows Audio Service allows an authorized attacker to disclose information locally.

▾ Sunlitmicrosoft · windows_10_1809EPSS 0.48%via NVD
CVE-2026-33842Medium· 5.5
2mo ago

Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.

Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.

▾ Sunlitmicrosoft · windows_10_1607EPSS 0.48%via NVD
GHSA-q3v2-xj35-9grxMedium· 4.9
2mo ago

Umbraco.AI discloses sensitive application configuration values

Umbraco.AI discloses sensitive application configuration values

▾ SunlitUmbraco · Umbraco.AIvia GHSA
CVE-2026-55608Medium· 4.2
2mo ago

n8n-MCP: Incorrect authorization can expose default-scope workflow version backups in multi-tenant HTTP mode

n8n-MCP: Incorrect authorization can expose default-scope workflow version backups in multi-tenant HTTP mode

▾ Sunlitn8n-mcp · n8n-mcpEPSS 0.28%via GHSA
CVE-2026-49853High· 7.7
2mo ago

tornado: Tornado: Information disclosure via improper handling of credentials during HTTP redirects (CVE-2026-49853)

A flaw was found in Tornado's SimpleAsyncHTTPClient. When following a redirect to a different origin, the client improperly retains and forwards sensitive authentication credentials, such as Authorization headers, to the new, potentially u…

▾ TwilightRed Hat · Red Hat Enterprise Linux AppStream (v. 10)EPSS 0.45%via CSAF
CVE-2026-15530Medium· 5.3
2mo ago

A flaw has been found in WuzhiCMS up to 4.1.0

A flaw has been found in WuzhiCMS up to 4.1.0. Affected by this vulnerability is the function config/listimage of the file /index.php?m=attachment&f=index&v=upload of the component Attachment API. Executing a manipulation can lead to inf…

▾ SunlitEPSS 0.53%via NVD
CVE-2026-56336Medium· 5.3PoC
2mo ago

Capgo before 12.128.2 contains an information disclosure vulnerability in the unauthenticated /private/sso/check-domain endpoint that returns internal org_id and provider_id values

Capgo before 12.128.2 contains an information disclosure vulnerability in the unauthenticated /private/sso/check-domain endpoint that returns internal org_id and provider_id values. Attackers can enumerate email domains to build mappings…

▾ TwilightCapgo · CapgoEPSS 0.34%via NVD
CVE-2026-56259High· 8.2
2mo ago

Crawl4AI before 0.8.8 contains credential exfiltration vulnerabilities in the Docker API server that allow attackers to redirect LLM API calls to attacker-controlled endpoints and read arbitrary environment variables

Crawl4AI before 0.8.8 contains credential exfiltration vulnerabilities in the Docker API server that allow attackers to redirect LLM API calls to attacker-controlled endpoints and read arbitrary environment variables. Attackers can explo…

▾ TwilightCrawl4AI · Crawl4AIEPSS 0.43%via NVD
CVE-2026-56238High· 7.5
2mo ago

Capgo before 12.128.2 contains an information disclosure vulnerability in the Supabase PostgREST global_stats endpoint that allows unauthenticated attackers to read sensitive financial and operational metrics using only the public apikey…

Capgo before 12.128.2 contains an information disclosure vulnerability in the Supabase PostgREST global_stats endpoint that allows unauthenticated attackers to read sensitive financial and operational metrics using only the public apikey…

▾ TwilightEPSS 0.56%via NVD
CVE-2026-61454Medium· 5.3
2mo ago

The Grav Admin2 plugin (getgrav/grav-plugin-admin2) before 2.0.4 embeds a global JavaScript variable window.__GRAV_CONFIG__ in the Admin2 SPA bootstrap page at /grav/admin (and its subroutes)

The Grav Admin2 plugin (getgrav/grav-plugin-admin2) before 2.0.4 embeds a global JavaScript variable window.__GRAV_CONFIG__ in the Admin2 SPA bootstrap page at /grav/admin (and its subroutes). This object is returned in every unauthentic…

▾ SunlitEPSS 0.36%via NVD
CVE-2026-61426High· 8.6
2mo ago

PraisonAI before 1.7.3 contains an insecure default configuration that binds to all interfaces with no API key requirement and wildcard CORS

PraisonAI before 1.7.3 contains an insecure default configuration that binds to all interfaces with no API key requirement and wildcard CORS. Unauthenticated attackers can call GET /api/agents to read agent instructions and system prompt…

▾ TwilightEPSS 0.48%via NVD
CVE-2026-56303High· 7.5
2mo ago

Capgo before 12.128.2 contains an information disclosure vulnerability in the find_apikey_by_value PostgreSQL function marked SECURITY DEFINER and executable by the anon role

Capgo before 12.128.2 contains an information disclosure vulnerability in the find_apikey_by_value PostgreSQL function marked SECURITY DEFINER and executable by the anon role. Unauthenticated attackers can call this function via the /res…

▾ TwilightEPSS 0.46%via NVD
CVE-2026-6801Medium· 5.3
2mo ago

The Context Blog theme for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.3.5 via the context_blog_modal_popup

The Context Blog theme for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.3.5 via the context_blog_modal_popup. This makes it possible for unauthenticated attackers to extract the conten…

▾ SunlitEPSS 0.36%via NVD
CVE-2026-10865Medium· 5.3
2mo ago

The Cost Calculator Builder plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.0.11 via the (template body)

The Cost Calculator Builder plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.0.11 via the (template body). This makes it possible for unauthenticated attackers to extract the pl…

▾ SunlitEPSS 0.58%via NVD
CVE-2026-7544Medium· 4.3
2mo ago

The Mux Video Uploader plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.1.4 via the muxvideo_enqueue_settings_script

The Mux Video Uploader plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.1.4 via the muxvideo_enqueue_settings_script. This makes it possible for authenticated attackers, with su…

▾ SunlitEPSS 0.41%via NVD
CVE-2026-12426Medium· 5.3
2mo ago

The Members – Membership & User Role Editor Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.2.22 via the members_filter_protected_posts_for_rest

The Members – Membership & User Role Editor Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.2.22 via the members_filter_protected_posts_for_rest. This makes it possible …

▾ SunlitEPSS 0.47%via NVD
CVE-2026-57474Medium· 5.3
2mo ago

Deloitte AI Assist for Customer disclosed some configuration information through public-facing API endpoints that accepted unauthenticated requests

Deloitte AI Assist for Customer disclosed some configuration information through public-facing API endpoints that accepted unauthenticated requests. This information could reduce an attacker’s reconnaissance effort. On 2026-03-25, AI Ass…

▾ Sunlitdeloitte · ai_assist_for_customerEPSS 0.51%via NVD
CWE-200 vulnerabilities (CVEs) — page 21 · VulnSea