CWE-200
CVEs classified under CWE-200, newest first.
824 CVEsRSS
CVE-2026-53923High· 7.5vLLM: GGUF dequantize kernel int truncation exposes uninitialized GPU memory in multi-tenant serving
vLLM: GGUF dequantize kernel int truncation exposes uninitialized GPU memory in multi-tenant serving
CVE-2026-53840High· 7.1OpenClaw: MCP Streamable HTTP redirects could forward configured custom headers to another origin
OpenClaw: MCP Streamable HTTP redirects could forward configured custom headers to another origin
CVE-2026-54316MediumPoCClaude Code: Out-of-Band Data Exfiltration via Pre-Approved HuggingFace Domain in WebFetch
Claude Code: Out-of-Band Data Exfiltration via Pre-Approved HuggingFace Domain in WebFetch
CVE-2026-47340Medium· 6.5Apache DolphinScheduler: An incorrect authorization vulnerability allows authenticated users to access alert instances associated with alert groups they do not have permission to access.
Apache DolphinScheduler: An incorrect authorization vulnerability allows authenticated users to access alert instances associated with alert groups they do not have permission to access.
CVE-2026-55450Critical· 9.3PoCLangflow: Unauthenticated file upload leads to DoS (space exhaustion) and information leak
Langflow: Unauthenticated file upload leads to DoS (space exhaustion) and information leak
CVE-2026-50019Medium· 6.1yt-dlp: File Downloader cookie leak with curl
yt-dlp: File Downloader cookie leak with curl
GHSA-f989-c77f-r2cqHigh· 8.2Crawl4AI: LLM credential exfiltration in Docker server via request base_url and env: token resolution
Crawl4AI: LLM credential exfiltration in Docker server via request base_url and env: token resolution
CVE-2026-54305High· 9.9n8n: Cross-Tenant Credential Takeover via Dynamic Credentials EE Endpoints
n8n: Cross-Tenant Credential Takeover via Dynamic Credentials EE Endpoints
CVE-2026-54304High· 7.7n8n: SecurityScorecard Node Leaks API Token to User-Controlled Host
n8n: SecurityScorecard Node Leaks API Token to User-Controlled Host
CVE-2026-50169MediumAngular Service Worker Policy-Bypass & Credential-Stripping Vulnerabilities
Angular Service Worker Policy-Bypass & Credential-Stripping Vulnerabilities
CVE-2026-50184Medium@angular/service-worker: Request Credential & Cache Policy Stripping
@angular/service-worker: Request Credential & Cache Policy Stripping
CVE-2026-49356Low· 3.2@babel/core: Arbitrary File Read via sourceMappingURL Comment
@babel/core: Arbitrary File Read via sourceMappingURL Comment
CVE-2026-53571HighPoCvite: `server.fs.deny` bypass on Windows alternate paths
vite: `server.fs.deny` bypass on Windows alternate paths
CVE-2026-54264High@angular/service-worker: Sensitive Header Leakage on Cross-Origin Redirects in Angular Service Worker
@angular/service-worker: Sensitive Header Leakage on Cross-Origin Redirects in Angular Service Worker
GHSA-pw6j-qg29-8w7fMedium· 5.9Tornado: CurlAsyncHTTPClient leaks per-request credentials on handle reuse
Tornado: CurlAsyncHTTPClient leaks per-request credentials on handle reuse
CVE-2026-50009Medium· 4.8Netty: QUIC stateless reset token material exposed through header-visible connection IDs
Netty: QUIC stateless reset token material exposed through header-visible connection IDs
GHSA-rq7w-g337-39qqLowNuxt: Dev server discloses project absolute path and persistent workspace UUID via `/.well-known/appspecific/com.chrome.devtools.json`
Nuxt: Dev server discloses project absolute path and persistent workspace UUID via `/.well-known/appspecific/com.chrome.devtools.json`
CVE-2026-45536Medium· 4.0netty-transport-native-epoll: netty-transport-native-kqueue: Netty: Denial of Service due to file descriptor leak in SCM_RIGHTS message han…
A flaw was found in Netty, a network application framework. A local attacker could exploit a vulnerability in the `netty_unix_socket_recvFd` function when handling `SCM_RIGHTS` messages in `Epoll` or `KQueue DomainSocketChannel` with `Doma…
CVE-2026-47351MediumTYPO3 CMS: Broken Access Control in Media Module
TYPO3 CMS: Broken Access Control in Media Module
CVE-2026-49742HighTYPO3 CMS has Broken Access Control in its Media Module
TYPO3 CMS has Broken Access Control in its Media Module
CVE-2026-44486High· 7.5PoCAxios is a promise based HTTP client for the browser and Node.js
Axios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16.0, Axios’ Node.js HTTP adapter can leak proxy credentials to a redirect target in affected versions. When a request is sent through an authenticat…
CVE-2026-48022Medium· 6.5@hapi/wreck: Sensitive credential headers leak across cross-port and cross-scheme redirects
@hapi/wreck: Sensitive credential headers leak across cross-port and cross-scheme redirects
CVE-2026-48855Medium· 6.5⚖ disputedExposure of Sensitive Information to an Unauthorized Actor vulnerability in Erlang OTP ssh (ssh_sftpd module) allows File Discovery. The SSH_FXP_READLINK handler in ssh_sftpd sends the raw result of file:read_link/2 to the client withou…
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Erlang OTP ssh (ssh_sftpd module) allows File Discovery. The SSH_FXP_READLINK handler in ssh_sftpd sends the raw result of file:read_link/2 to the client withou…
CVE-2026-49397Medium· 5.3Nezha's private services (`EnableShowInService: false`) are enumerable via per-server endpoints, leaking name and timing data
Nezha's private services (`EnableShowInService: false`) are enumerable via per-server endpoints, leaking name and timing data
CVE-2026-47751MediumClaude Code Action: Malicious MCP Server Configuration in PRs Enables Remote Code Execution and Secret Exfiltration
Claude Code Action: Malicious MCP Server Configuration in PRs Enables Remote Code Execution and Secret Exfiltration
CVE-2026-50508Medium· 6.5Windows NTLM Spoofing Vulnerability
Exposure of sensitive information to an unauthorized actor in Windows NTLM allows an unauthorized attacker to perform spoofing over a network.
CVE-2026-45594Medium· 5.5Windows Application Identity (AppID) Information Disclosure Vulnerability
Exposure of sensitive information to an unauthorized actor in Windows Application Identity (AppID) Subsystem allows an authorized attacker to disclose information locally.
CVE-2026-47284Medium· 6.5Visual Studio Code Information Disclosure Vulnerability
Exposure of sensitive information to an unauthorized actor in Visual Studio Code allows an unauthorized attacker to disclose information over a network.
CVE-2026-42906Medium· 5.5Windows Shell Information Disclosure Vulnerability
Exposure of sensitive information to an unauthorized actor in Windows Shell allows an authorized attacker to disclose information locally.
CVE-2026-42907Medium· 6.5Windows Shell Information Disclosure Vulnerability
Exposure of sensitive information to an unauthorized actor in Windows Shell allows an authorized attacker to disclose information over a network.