VulnSea

CWE-200

CVEs classified under CWE-200, newest first.

824 CVEsRSS

CVE-2026-49988Medium
2mo ago

repomix: attach_packed_output can bypass file-read secret scanning for supported local files

repomix: attach_packed_output can bypass file-read secret scanning for supported local files

▾ Sunlitrepomix · repomixEPSS 0.18%via GHSA
GHSA-7m8x-qg2j-4m3vHigh· 8.1
3mo ago

Fission: MessageQueueTrigger scaler manager materializes Secret values into Deployment envvars and accepts arbitrary user PodSpec

Fission: MessageQueueTrigger scaler manager materializes Secret values into Deployment envvars and accepts arbitrary user PodSpec

▾ Twilightfission · github.com/fission/fissionvia GHSA
CVE-2026-49355Medium· 4.3
3mo ago

OpenProject is open-source, web-based project management software

OpenProject is open-source, web-based project management software. Prior to 17.4.0, `GET /api/v3/meetings/:meeting_id/agenda_items/:agenda_item_id` discloses private work package data from a linked work package that belongs to a private/…

▾ SunlitEPSS 0.29%via NVD
GHSA-q683-8468-r6h6Medium
3mo ago

WebauthnAuthenticator leaks sensitive HTTP headers through INFO-level logs

WebauthnAuthenticator leaks sensitive HTTP headers through INFO-level logs

▾ Sunlitweb-auth · web-auth/webauthn-symfony-bundlevia GHSA
CVE-2026-49288Medium· 4.3
3mo ago

Statamic CMS: Missing authorization on Control Panel fieldtype endpoints allows disclosure of restricted resources

Statamic CMS: Missing authorization on Control Panel fieldtype endpoints allows disclosure of restricted resources

▾ Sunlitstatamic · statamic/cmsEPSS 0.27%via GHSA
CVE-2026-49336Medium
3mo ago

@microsoft/kiota-http-fetchlibrary: Bearer token and Cookie leak across origin on redirect due to case-mismatched scrub in fetchRequestAdapter

@microsoft/kiota-http-fetchlibrary: Bearer token and Cookie leak across origin on redirect due to case-mismatched scrub in fetchRequestAdapter

▾ Sunlitmicrosoft · @microsoft/kiota-http-fetchlibraryEPSS 1.2%via GHSA
CVE-2026-50017Medium
3mo ago

pnpm binds unscoped user-level npm auth credentials to a repository-selected registry

pnpm binds unscoped user-level npm auth credentials to a repository-selected registry

▾ Sunlitpnpm · pnpmEPSS 0.44%via GHSA
CVE-2026-55180Medium· 6.5
3mo ago

pnpm: Repository config can expand victim environment secrets into registry requests before scripts run

pnpm: Repository config can expand victim environment secrets into registry requests before scripts run

▾ Sunlitpnpm · pnpmEPSS 0.37%via GHSA
GHSA-ww5p-j6cj-6mqqMedium
3mo ago

Nezha Dashboard: DDNS and Notification credential exposure via unredacted list API

Nezha Dashboard: DDNS and Notification credential exposure via unredacted list API

▾ Sunlitnezhahq · github.com/nezhahq/nezhavia GHSA
CVE-2026-44025High· 7.5
3mo ago

Fluentd is Vulnerable to Exposure of Sensitive Information via Monitor Agent API

Fluentd is Vulnerable to Exposure of Sensitive Information via Monitor Agent API

▾ Twilightfluentd · fluentdEPSS 0.47%via GHSA
CVE-2026-46406Medium
3mo ago

@anthropic-ai/claude-code has an Insecure Temporary File in /copy Command that Enables Response Disclosure and Symlink-Based File Write

@anthropic-ai/claude-code has an Insecure Temporary File in /copy Command that Enables Response Disclosure and Symlink-Based File Write

▾ Sunlitanthropic-ai · @anthropic-ai/claude-codeEPSS 0.15%via GHSA
CVE-2026-49219Medium· 5.5
3mo ago

ImageMagick: Policy Bypass can read disallowed files via symlink

ImageMagick: Policy Bypass can read disallowed files via symlink

▾ SunlitMagick · Magick.NET-Q16-AnyCPUEPSS 0.17%via GHSA
CVE-2026-12537High· 7.8⚖ disputed
3mo ago

Improper Neutralization used in an OS Command in the container launcher in Google Gemini CLI (versions prior to 0.39.1) and run-gemini-cli GitHub Action (versions prior to 0.1.22) on headless CI platforms allows an unprivileged attacker …

Improper Neutralization used in an OS Command in the container launcher in Google Gemini CLI (versions prior to 0.39.1) and run-gemini-cli GitHub Action (versions prior to 0.1.22) on headless CI platforms allows an unprivileged attacker …

▾ Twilightgoogle · gemini-cliEPSS 0.21%via NVD
CVE-2026-52815MediumPoC
3mo ago

Gogs Vulnerable to Unauthenticated Organization Teams Information Disclosure via API

Gogs Vulnerable to Unauthenticated Organization Teams Information Disclosure via API

▾ Twilightgogs · gogs.io/gogsEPSS 1.5%via GHSA
CVE-2026-54276Medium· 6.1
3mo ago

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, DigestAuthMiddleware can send an authentication response after following a cross-origin redirect. This likely requires an open redirect vuln…

▾ Sunlitaiohttp · aiohttpEPSS 0.31%via NVD
CVE-2026-55882High
3mo ago

Tilt: Unauthenticated pprof debug endpoints on the Tilt HUD server

Tilt: Unauthenticated pprof debug endpoints on the Tilt HUD server

▾ Twilighttilt-dev · github.com/tilt-dev/tiltEPSS 0.52%via GHSA
CVE-2026-49211Medium
3mo ago

symfony/ux-autocomplete: Information exposure via unescaped LIKE wildcards in EntitySearchUtil

symfony/ux-autocomplete: Information exposure via unescaped LIKE wildcards in EntitySearchUtil

▾ Sunlitsymfony · symfony/ux-autocompleteEPSS 0.53%via GHSA
CVE-2026-53725Medium
3mo ago

parse-server: Endpoints `/login` and `/verifyPassword` disclose MFA secrets and protected fields when `_User` get is denied

parse-server: Endpoints `/login` and `/verifyPassword` disclose MFA secrets and protected fields when `_User` get is denied

▾ Sunlitparse-server · parse-serverEPSS 0.43%via GHSA
CVE-2026-54317High· 7.6
3mo ago

Home Assistant: Konnected alarm-panel switch state and zone topology disclosed to unauthenticated actors on the LAN

Home Assistant: Konnected alarm-panel switch state and zone topology disclosed to unauthenticated actors on the LAN

▾ Twilighthomeassistant · homeassistantEPSS 0.31%via GHSA
CVE-2026-11769Medium
3mo ago

Grafana Operator: Privilege escalation from namespace admin to cluster admin via GrafanaDashboard jsonnetLib fileName

Grafana Operator: Privilege escalation from namespace admin to cluster admin via GrafanaDashboard jsonnetLib fileName

▾ Sunlitgrafana · github.com/grafana/grafana-operator/v5EPSS 0.36%via GHSA
GHSA-pr33-38xx-6r26Medium
3mo ago

http4k: BasicCookieStorage` (renamed `InsecureCookieStorage`) did not enforce RFC 6265 cookie scoping; new `DefaultCookieStorage` is now the default

http4k: BasicCookieStorage` (renamed `InsecureCookieStorage`) did not enforce RFC 6265 cookie scoping; new `DefaultCookieStorage` is now the default

▾ Sunlithttp4k · org.http4k:http4k-corevia GHSA
CVE-2026-55447Critical· 9.6
3mo ago

Langflow: BaseFileComponent-based nodes arbitrary file read with RCE exploit

Langflow: BaseFileComponent-based nodes arbitrary file read with RCE exploit

▾ Midnightlangflow · langflowEPSS 0.66%via GHSA
GHSA-97pr-9hgg-3p8rLow
3mo ago

parse-server: LiveQuery discloses object data to a subscriber across an ACL read-access change

parse-server: LiveQuery discloses object data to a subscriber across an ACL read-access change

▾ Sunlitparse-server · parse-servervia GHSA
GHSA-h4h3-3rfj-x6fqMedium· 4.3
3mo ago

SurrealDB: Indexed ORDER BY leaks the value ordering of a SELECT-restricted field

SurrealDB: Indexed ORDER BY leaks the value ordering of a SELECT-restricted field

▾ Sunlitsurrealdb · surrealdbvia GHSA
CVE-2026-47633High· 7.5
3mo ago

Microsoft Cost Management Information Disclosure Vulnerability

Exposure of sensitive information to an unauthorized actor in Cost Management Interactive Experiences allows an unauthorized attacker to disclose information over a network.

▾ TwilightMicrosoft · Microsoft Cost ManagementEPSS 1.0%via CVEORG
GHSA-22cj-m4wf-fv2cHigh· 7.5
3mo ago

PraisonAI Dynamic Context history and terminal tools read files outside configured storage via path traversal

PraisonAI Dynamic Context history and terminal tools read files outside configured storage via path traversal

▾ Twilightpraisonai · praisonaivia GHSA
GHSA-j7qx-p75m-wp7gHigh· 7.5
3mo ago

PraisonAI dynamic-context artifact tools read arbitrary host files outside artifact storage

PraisonAI dynamic-context artifact tools read arbitrary host files outside artifact storage

▾ Twilightpraisonai · praisonaivia GHSA
GHSA-892r-p3jq-jp24Critical· 9.8
3mo ago

PraisonAI: AgentOS remains unauthenticated after incomplete fix version and allows remote agent invocation

PraisonAI: AgentOS remains unauthenticated after incomplete fix version and allows remote agent invocation

▾ Midnightpraisonai · praisonaivia GHSA
GHSA-gcq3-mfvh-3x25High· 7.3
3mo ago

PraisonAI Code agent tools fail open without a workspace boundary

PraisonAI Code agent tools fail open without a workspace boundary

▾ Twilightpraisonai · praisonaivia GHSA
GHSA-jxcw-qp4h-6jfqHigh· 7.5
3mo ago

PraisonAI A2U incomplete authentication fix leaves current serve command unauthenticated by default

PraisonAI A2U incomplete authentication fix leaves current serve command unauthenticated by default

▾ Twilightpraisonai · praisonaivia GHSA
CWE-200 vulnerabilities (CVEs) — page 23 · VulnSea