VulnSea

CWE-200

CVEs classified under CWE-200, newest first.

823 CVEsRSS

CVE-2026-59155None
2mo ago

Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool

Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. Prior to 2.2.5, the GET /api/v1/ddns and GET /api/v1/notification endpoints return full resource objects including plaintext third-party API …

▾ SunlitEPSS 0.48%via NVD
CVE-2026-57219NonePoC
2mo ago

RabbitMQ is a messaging and streaming broker

RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.20, 4.1.11, and 4.2.6, the obsolete GET /api/auth endpoint can disclose the OAuth 2 client secret on RabbitMQ installations configured with management.oauth_client_secre…

▾ TwilightEPSS 2.8%via NVD
CVE-2026-55664Medium· 4.3
2mo ago

Grist is spreadsheet software using Python as its formula language

Grist is spreadsheet software using Python as its formula language. Prior to 1.7.15, the GET /forms endpoint read table and column metadata without applying the document's access rules and did not check that the requested section was act…

▾ SunlitEPSS 0.33%via NVD
GHSA-g936-7jqj-mwv8Critical· 9.0
2mo ago

TSDProxy: Internal proxy auth token forwarded to backend services enables management API escalation

TSDProxy: Internal proxy auth token forwarded to backend services enables management API escalation

▾ Midnightalmeidapaulopt · github.com/almeidapaulopt/tsdproxyvia GHSA
CVE-2026-59216High· 7.7
2mo ago

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.10.0, get_event_call delivered execute:python and execute:tool Socket.IO events to a client-supplied session_id after checking only that the…

▾ Twilightopenwebui · open_webuiEPSS 0.45%via NVD
CVE-2026-48828Medium· 6.5
2mo ago

The Bulk Variables API in Apache Airflow called the redactor without passing the variable's key, so the key-based `should_hide_value_for_key` check (which triggers on secret-suffixed key names like `*_password` / `*_token` / `*_secret`) …

The Bulk Variables API in Apache Airflow called the redactor without passing the variable's key, so the key-based `should_hide_value_for_key` check (which triggers on secret-suffixed key names like `*_password` / `*_token` / `*_secret`) …

▾ Sunlitapache · airflowEPSS 0.66%via NVD
CVE-2026-49487Medium· 6.5
2mo ago

In Apache Airflow before 3.3.0, the REST API task-instance detail and list endpoints returned a deferred task's trigger kwargs without masking

In Apache Airflow before 3.3.0, the REST API task-instance detail and list endpoints returned a deferred task's trigger kwargs without masking. When a deferred operator passed a secret (for example a provider API key) into its trigger, a…

▾ Sunlitapache · airflowEPSS 0.66%via NVD
CVE-2026-48892Medium· 6.5
2mo ago

The Config API in Apache Airflow surfaced per-key secrets-backend overrides (environment variables like `AIRFLOW__SECRETS__BACKEND_KWARG__SECRET_ID` and `AIRFLOW__WORKERS__SECRETS_BACKEND_KWARG__SECRET_ID`) as synthetic config options wh…

The Config API in Apache Airflow surfaced per-key secrets-backend overrides (environment variables like `AIRFLOW__SECRETS__BACKEND_KWARG__SECRET_ID` and `AIRFLOW__WORKERS__SECRETS_BACKEND_KWARG__SECRET_ID`) as synthetic config options wh…

▾ Sunlitapache · airflowEPSS 0.66%via NVD
CVE-2026-48891Medium· 4.3
2mo ago

A bug in Apache Airflow's `/ui/dependencies` scheduling graph endpoint applied the caller's readable-Dag filter to the top-level serialized Dag key but still emitted referenced Dag IDs through the `dep.source` and `dep.target` fields of …

A bug in Apache Airflow's `/ui/dependencies` scheduling graph endpoint applied the caller's readable-Dag filter to the top-level serialized Dag key but still emitted referenced Dag IDs through the `dep.source` and `dep.target` fields of …

▾ Sunlitapache · airflowEPSS 0.64%via NVD
GHSA-vjc7-jrh9-9j86Critical· 10.0
2mo ago

9router has unauthenticated CRUD on /api/providers and Full API Key Leak via /api/usage/stats

9router has unauthenticated CRUD on /api/providers and Full API Key Leak via /api/usage/stats

▾ Midnight9router · 9routervia GHSA
CVE-2026-55792Medium
2mo ago

Craft CMS: Sensitive File Disclosure / Server-Side File Read

Craft CMS: Sensitive File Disclosure / Server-Side File Read

▾ Sunlitcraftcms · craftcms/cmsEPSS 0.40%via GHSA
CVE-2026-55500Critical· 9.9
2mo ago

9routers has Exposure of Sensitive Information and Unprotected Database Import/Export, Allowing Complete Credential Theft and Database Takeover

9routers has Exposure of Sensitive Information and Unprotected Database Import/Export, Allowing Complete Credential Theft and Database Takeover

▾ Midnight9router · 9routerEPSS 0.69%via GHSA
GHSA-x76w-8c62-48mgMedium
2mo ago

Craft CMS: Authenticated "assets/preview-thumb" discloses signed fallback transform preview link to CP users without asset-view permission

Craft CMS: Authenticated "assets/preview-thumb" discloses signed fallback transform preview link to CP users without asset-view permission

▾ Sunlitcraftcms · craftcms/cmsvia GHSA
CVE-2026-56646Medium· 6.5
2mo ago

Exposure of sensitive information to an unauthorized actor in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

Exposure of sensitive information to an unauthorized actor in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

▾ SunlitMicrosoft · Microsoft Edge (Chromium-based)EPSS 0.92%via NVD
CVE-2026-25038None
2mo ago

Gitea 1.26.2 allows unauthorized users to access labels of private organizations.

Gitea 1.26.2 allows unauthorized users to access labels of private organizations.

▾ SunlitEPSS 0.48%via NVD
CVE-2026-24451None
2mo ago

Gitea 1.26.2 allows fork synchronization to continue after a parent repository changes from public to private, exposing data to a fork that should no longer be authorized.

Gitea 1.26.2 allows fork synchronization to continue after a parent repository changes from public to private, exposing data to a fork that should no longer be authorized.

▾ SunlitEPSS 0.48%via NVD
CVE-2026-14611Medium· 4.3
2mo ago

A vulnerability has been found in DeepMyst Mysti up to 0.4.0

A vulnerability has been found in DeepMyst Mysti up to 0.4.0. The affected element is the function initProjectMemory of the file src/managers/MemoryManager.ts of the component Per-Project Auto-Memory Handler. Such manipulation of the arg…

▾ SunlitEPSS 0.43%via NVD
CVE-2026-10055High· 8.5
2mo ago

In Eclipse Theia since version 1.26.0, the backend /services/request-service RPC accepts an attacker-controlled URL from any client connected to the standard /services messaging endpoint, performs the HTTP request server-side, and return…

In Eclipse Theia since version 1.26.0, the backend /services/request-service RPC accepts an attacker-controlled URL from any client connected to the standard /services messaging endpoint, performs the HTTP request server-side, and return…

▾ TwilightEPSS 0.40%via NVD
CVE-2026-9546High· 7.5PoC
2mo ago

A vulnerability in libcurl caused the HTTP `Referer:` header to persist even when explicitly cleared

A vulnerability in libcurl caused the HTTP `Referer:` header to persist even when explicitly cleared. While the documentation states that passing NULL to `CURLOPT_REFERER` suppresses the header, the option failed to clear the internal st…

▾ Midnighthaxx · curlEPSS 0.65%via NVD
CVE-2026-9545High· 7.5PoC
2mo ago

In this scenario, libcurl first uses a proper HTTP/3 server for the initial transfers, and when it makes a second transfer to the same site it has been replaced by the attacker's impostor machine - without a valid certificate. When libc…

In this scenario, libcurl first uses a proper HTTP/3 server for the initial transfers, and when it makes a second transfer to the same site it has been replaced by the attacker's impostor machine - without a valid certificate. When libc…

▾ Midnighthaxx · curlEPSS 0.41%via NVD
GHSA-gj2h-2fpw-fhv9Medium
2mo ago

@nuxt/ui: UAuthForm / UForm SSR markup omits `method`, leaking credentials via GET if submitted before hydration

@nuxt/ui: UAuthForm / UForm SSR markup omits `method`, leaking credentials via GET if submitted before hydration

▾ Sunlitnuxt · @nuxt/uivia GHSA
CVE-2026-50200High· 7.5
2mo ago

Steeltoe's env sanitizer misses connection strings — leaks embedded DB passwords

Steeltoe's env sanitizer misses connection strings — leaks embedded DB passwords

▾ TwilightSteeltoe · Steeltoe.Management.EndpointEPSS 0.31%via GHSA
GHSA-mr9h-45p9-fg8hMedium· 4.3
2mo ago

Froxlor: Authenticated customers can read other customers' allowed sender aliases

Froxlor: Authenticated customers can read other customers' allowed sender aliases

▾ Sunlitfroxlor · froxlor/froxlorvia GHSA
CVE-2026-53815High· 6.5
2mo ago

OpenClaw: Message read actions could skip channel allowlist checks

OpenClaw: Message read actions could skip channel allowlist checks

▾ Twilightopenclaw · openclawEPSS 0.36%via GHSA
CVE-2026-53814High· 8.4
2mo ago

OpenClaw: Hook-triggered CLI runs could receive owner MCP tool authority

OpenClaw: Hook-triggered CLI runs could receive owner MCP tool authority

▾ Twilightopenclaw · openclawEPSS 0.39%via GHSA
GHSA-mhq8-78pj-5j79High· 7.1
2mo ago

OpenClaw's POSIX node system.run safe-bin allowlist could be widened by shell expansion

OpenClaw's POSIX node system.run safe-bin allowlist could be widened by shell expansion

▾ Twilightopenclaw · openclawvia GHSA
GHSA-vh4v-2xq2-g5cgMedium
2mo ago

ORAS Go forwards registry credentials across registry redirects

ORAS Go forwards registry credentials across registry redirects

▾ Sunlitoras-go · oras.land/oras-go/v2via GHSA
GHSA-9c3v-684m-579cMedium· 6.5
2mo ago

OpenClaw MCP SSE redirects could forward Authorization headers

OpenClaw MCP SSE redirects could forward Authorization headers

▾ Sunlitopenclaw · openclawvia GHSA
GHSA-vjjx-rfw4-rmfcMedium· 6.5
2mo ago

SurrealDB: Graph traversal bypasses table SELECT permissions

SurrealDB: Graph traversal bypasses table SELECT permissions

▾ Sunlitsurrealdb · surrealdbvia GHSA
CVE-2026-49988Medium
2mo ago

repomix: attach_packed_output can bypass file-read secret scanning for supported local files

repomix: attach_packed_output can bypass file-read secret scanning for supported local files

▾ Sunlitrepomix · repomixEPSS 0.18%via GHSA
CWE-200 vulnerabilities (CVEs) — page 22 · VulnSea