VulnSea

CWE-200

CVEs classified under CWE-200, newest first.

824 CVEsRSS

CVE-2026-53923High· 7.5
3mo ago

vLLM: GGUF dequantize kernel int truncation exposes uninitialized GPU memory in multi-tenant serving

vLLM: GGUF dequantize kernel int truncation exposes uninitialized GPU memory in multi-tenant serving

▾ Twilightvllm · vllmEPSS 0.48%via OSV
CVE-2026-53840High· 7.1
3mo ago

OpenClaw: MCP Streamable HTTP redirects could forward configured custom headers to another origin

OpenClaw: MCP Streamable HTTP redirects could forward configured custom headers to another origin

▾ Twilightopenclaw · openclawEPSS 0.31%via GHSA
CVE-2026-54316MediumPoC
3mo ago

Claude Code: Out-of-Band Data Exfiltration via Pre-Approved HuggingFace Domain in WebFetch

Claude Code: Out-of-Band Data Exfiltration via Pre-Approved HuggingFace Domain in WebFetch

▾ Twilightanthropic-ai · @anthropic-ai/claude-codeEPSS 0.52%via GHSA
CVE-2026-47340Medium· 6.5
3mo ago

Apache DolphinScheduler: An incorrect authorization vulnerability allows authenticated users to access alert instances associated with alert groups they do not have permission to access.

Apache DolphinScheduler: An incorrect authorization vulnerability allows authenticated users to access alert instances associated with alert groups they do not have permission to access.

▾ Sunlitapache · org.apache.dolphinscheduler:dolphinscheduler-apiEPSS 0.55%via GHSA
CVE-2026-55450Critical· 9.3PoC
3mo ago

Langflow: Unauthenticated file upload leads to DoS (space exhaustion) and information leak

Langflow: Unauthenticated file upload leads to DoS (space exhaustion) and information leak

▾ Abyssallangflow · langflowEPSS 1.2%via GHSA
CVE-2026-50019Medium· 6.1
3mo ago

yt-dlp: File Downloader cookie leak with curl

yt-dlp: File Downloader cookie leak with curl

▾ Sunlityt-dlp · yt-dlpEPSS 0.32%via GHSA
GHSA-f989-c77f-r2cqHigh· 8.2
3mo ago

Crawl4AI: LLM credential exfiltration in Docker server via request base_url and env: token resolution

Crawl4AI: LLM credential exfiltration in Docker server via request base_url and env: token resolution

▾ Twilightcrawl4ai · crawl4aivia GHSA
CVE-2026-54305High· 9.9
3mo ago

n8n: Cross-Tenant Credential Takeover via Dynamic Credentials EE Endpoints

n8n: Cross-Tenant Credential Takeover via Dynamic Credentials EE Endpoints

▾ Twilightn8n · n8nEPSS 0.37%via GHSA
CVE-2026-54304High· 7.7
3mo ago

n8n: SecurityScorecard Node Leaks API Token to User-Controlled Host

n8n: SecurityScorecard Node Leaks API Token to User-Controlled Host

▾ Twilightn8n · n8nEPSS 0.38%via GHSA
CVE-2026-50169Medium
3mo ago

Angular Service Worker Policy-Bypass & Credential-Stripping Vulnerabilities

Angular Service Worker Policy-Bypass & Credential-Stripping Vulnerabilities

▾ Sunlitangular · @angular/service-workerEPSS 0.23%via GHSA
CVE-2026-50184Medium
3mo ago

@angular/service-worker: Request Credential & Cache Policy Stripping

@angular/service-worker: Request Credential & Cache Policy Stripping

▾ Sunlitangular · @angular/service-workerEPSS 0.21%via GHSA
CVE-2026-49356Low· 3.2
3mo ago

@babel/core: Arbitrary File Read via sourceMappingURL Comment

@babel/core: Arbitrary File Read via sourceMappingURL Comment

▾ Sunlitbabel · @babel/coreEPSS 0.15%via GHSA
CVE-2026-53571HighPoC
3mo ago

vite: `server.fs.deny` bypass on Windows alternate paths

vite: `server.fs.deny` bypass on Windows alternate paths

▾ Midnightvite · viteEPSS 0.58%via GHSA
CVE-2026-54264High
3mo ago

@angular/service-worker: Sensitive Header Leakage on Cross-Origin Redirects in Angular Service Worker

@angular/service-worker: Sensitive Header Leakage on Cross-Origin Redirects in Angular Service Worker

▾ Twilightangular · @angular/service-workerEPSS 0.39%via GHSA
GHSA-pw6j-qg29-8w7fMedium· 5.9
3mo ago

Tornado: CurlAsyncHTTPClient leaks per-request credentials on handle reuse

Tornado: CurlAsyncHTTPClient leaks per-request credentials on handle reuse

▾ Sunlittornado · tornadovia OSV
CVE-2026-50009Medium· 4.8
3mo ago

Netty: QUIC stateless reset token material exposed through header-visible connection IDs

Netty: QUIC stateless reset token material exposed through header-visible connection IDs

▾ Sunlitnetty · io.netty:netty-codec-classes-quicEPSS 0.32%via GHSA
GHSA-rq7w-g337-39qqLow
3mo ago

Nuxt: Dev server discloses project absolute path and persistent workspace UUID via `/.well-known/appspecific/com.chrome.devtools.json`

Nuxt: Dev server discloses project absolute path and persistent workspace UUID via `/.well-known/appspecific/com.chrome.devtools.json`

▾ Sunlitnuxt · nuxtvia GHSA
CVE-2026-45536Medium· 4.0
3mo ago

netty-transport-native-epoll: netty-transport-native-kqueue: Netty: Denial of Service due to file descriptor leak in SCM_RIGHTS message han…

A flaw was found in Netty, a network application framework. A local attacker could exploit a vulnerability in the `netty_unix_socket_recvFd` function when handling `SCM_RIGHTS` messages in `Epoll` or `KQueue DomainSocketChannel` with `Doma…

▾ SunlitRed Hat · Red Hat OpenShift AI (RHOAI)EPSS 0.19%via CSAF
CVE-2026-47351Medium
3mo ago

TYPO3 CMS: Broken Access Control in Media Module

TYPO3 CMS: Broken Access Control in Media Module

▾ Sunlittypo3 · typo3/cms-coreEPSS 0.41%via GHSA
CVE-2026-49742High
3mo ago

TYPO3 CMS has Broken Access Control in its Media Module

TYPO3 CMS has Broken Access Control in its Media Module

▾ Twilighttypo3 · typo3/cms-coreEPSS 0.46%via GHSA
CVE-2026-44486High· 7.5PoC
3mo ago

Axios is a promise based HTTP client for the browser and Node.js

Axios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16.0, Axios’ Node.js HTTP adapter can leak proxy credentials to a redirect target in affected versions. When a request is sent through an authenticat…

▾ Midnightaxios · axiosEPSS 0.76%via NVD
CVE-2026-48022Medium· 6.5
3mo ago

@hapi/wreck: Sensitive credential headers leak across cross-port and cross-scheme redirects

@hapi/wreck: Sensitive credential headers leak across cross-port and cross-scheme redirects

▾ Sunlithapi · @hapi/wreckEPSS 0.18%via GHSA
CVE-2026-48855Medium· 6.5⚖ disputed
3mo ago

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Erlang OTP ssh (ssh_sftpd module) allows File Discovery. The SSH_FXP_READLINK handler in ssh_sftpd sends the raw result of file:read_link/2 to the client withou…

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Erlang OTP ssh (ssh_sftpd module) allows File Discovery. The SSH_FXP_READLINK handler in ssh_sftpd sends the raw result of file:read_link/2 to the client withou…

▾ Sunliterlang · erlang/otpEPSS 0.53%via NVD
CVE-2026-49397Medium· 5.3
3mo ago

Nezha's private services (`EnableShowInService: false`) are enumerable via per-server endpoints, leaking name and timing data

Nezha's private services (`EnableShowInService: false`) are enumerable via per-server endpoints, leaking name and timing data

▾ Sunlitnezhahq · github.com/nezhahq/nezhaEPSS 0.34%via GHSA
CVE-2026-47751Medium
3mo ago

Claude Code Action: Malicious MCP Server Configuration in PRs Enables Remote Code Execution and Secret Exfiltration

Claude Code Action: Malicious MCP Server Configuration in PRs Enables Remote Code Execution and Secret Exfiltration

▾ Sunlitanthropics · anthropics/claude-code-actionEPSS 0.77%via GHSA
CVE-2026-50508Medium· 6.5
3mo ago

Windows NTLM Spoofing Vulnerability

Exposure of sensitive information to an unauthorized actor in Windows NTLM allows an unauthorized attacker to perform spoofing over a network.

▾ SunlitMicrosoft · Windows 10 Version 1607EPSS 0.92%via CVEORG
CVE-2026-45594Medium· 5.5
3mo ago

Windows Application Identity (AppID) Information Disclosure Vulnerability

Exposure of sensitive information to an unauthorized actor in Windows Application Identity (AppID) Subsystem allows an authorized attacker to disclose information locally.

▾ SunlitMicrosoft · Windows 10 Version 1607EPSS 0.48%via CVEORG
CVE-2026-47284Medium· 6.5
3mo ago

Visual Studio Code Information Disclosure Vulnerability

Exposure of sensitive information to an unauthorized actor in Visual Studio Code allows an unauthorized attacker to disclose information over a network.

▾ SunlitMicrosoft · Visual Studio CodeEPSS 0.92%via CVEORG
CVE-2026-42906Medium· 5.5
3mo ago

Windows Shell Information Disclosure Vulnerability

Exposure of sensitive information to an unauthorized actor in Windows Shell allows an authorized attacker to disclose information locally.

▾ SunlitMicrosoft · Windows 10 Version 21H2EPSS 0.48%via CVEORG
CVE-2026-42907Medium· 6.5
3mo ago

Windows Shell Information Disclosure Vulnerability

Exposure of sensitive information to an unauthorized actor in Windows Shell allows an authorized attacker to disclose information over a network.

▾ SunlitMicrosoft · Windows 10 Version 1809EPSS 1.00%via CVEORG
CWE-200 vulnerabilities (CVEs) — page 24 · VulnSea