VulnSea

CWE-200

CVEs classified under CWE-200, newest first.

824 CVEsRSS

CVE-2026-42972Medium· 5.5
3mo ago

Windows Hyper-V Information Disclosure Vulnerability

Exposure of sensitive information to an unauthorized actor in Windows Hyper-V allows an authorized attacker to disclose information locally.

▾ SunlitMicrosoft · Windows 10 Version 1607EPSS 0.48%via CVEORG
CVE-2026-42971Medium· 5.5
3mo ago

Windows Push Notification Information Disclosure Vulnerability

Exposure of sensitive information to an unauthorized actor in Windows Push Notifications allows an authorized attacker to disclose information locally.

▾ SunlitMicrosoft · Windows 10 Version 1607EPSS 0.48%via CVEORG
CVE-2026-42973Medium· 5.5
3mo ago

Windows Push Notification Information Disclosure Vulnerability

Exposure of sensitive information to an unauthorized actor in Windows Push Notifications allows an authorized attacker to disclose information locally.

▾ SunlitMicrosoft · Windows 10 Version 1607EPSS 0.48%via CVEORG
CVE-2026-42970Medium· 5.5
3mo ago

Windows Push Notification Information Disclosure Vulnerability

Exposure of sensitive information to an unauthorized actor in Windows Push Notifications allows an authorized attacker to disclose information locally.

▾ SunlitMicrosoft · Windows 10 Version 1607EPSS 0.48%via CVEORG
CVE-2026-47655Medium· 6.5
3mo ago

Microsoft Graph Information Disclosure Vulnerability

Exposure of sensitive information to an unauthorized actor in Microsoft Graph allows an authorized attacker to disclose information over a network.

▾ SunlitMicrosoft · Microsoft GraphEPSS 1.00%via CVEORG
CVE-2026-45286Medium· 4.3
3mo ago

Nextcloud is an open source content collaboration platform

Nextcloud is an open source content collaboration platform. From versions 5.5.13 to before 5.5.17, and 6.2.0 to before 6.2.3, an authenticated user can enumerate users on the same Nextcloud instance by using the Calendar app's endpoint f…

▾ Sunlitnextcloud · calendarEPSS 0.46%via NVD
CVE-2026-7526Medium· 4.3
4mo ago

The PDF Embedder plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.9.3 via the enqueue_block_assets

The PDF Embedder plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.9.3 via the enqueue_block_assets. This makes it possible for authenticated attackers, with contributor-level ac…

▾ SunlitEPSS 0.41%via NVD
CVE-2026-8706Medium· 6.5
4mo ago

Firefox for iOS hosted Reader mode on an unauthenticated local web server, allowing another application on the same device to request arbitrary URLs and receive the response rendered with the signed-in user's cookies

Firefox for iOS hosted Reader mode on an unauthenticated local web server, allowing another application on the same device to request arbitrary URLs and receive the response rendered with the signed-in user's cookies. This vulnerability …

▾ Sunlitmozilla · firefoxEPSS 0.23%via NVD
CVE-2026-8967High· 7.5
4mo ago

Information disclosure in the Graphics: WebGPU component

Information disclosure in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 151 and Thunderbird 151.

▾ Twilightmozilla · firefoxEPSS 0.43%via NVD
CVE-2026-8966High· 7.5
4mo ago

Information disclosure in the IP Protection component

Information disclosure in the IP Protection component. This vulnerability was fixed in Firefox 151 and Thunderbird 151.

▾ Twilightmozilla · firefoxEPSS 0.43%via NVD
CVE-2026-8965High· 7.5
4mo ago

Information disclosure in the DOM: Security component

Information disclosure in the DOM: Security component. This vulnerability was fixed in Firefox 151 and Thunderbird 151.

▾ Twilightmozilla · firefoxEPSS 0.43%via NVD
CVE-2026-6429Medium· 5.3
4mo ago

When asked to both use a `.netrc` file for credentials and to follow HTTP redirects, libcurl could leak the password used for the first host to the followed-to host under certain circumstances.

When asked to both use a `.netrc` file for credentials and to follow HTTP redirects, libcurl could leak the password used for the first host to the followed-to host under certain circumstances.

▾ Sunlithaxx · curlEPSS 0.51%via NVD
CVE-2026-41954Medium· 4.9
4mo ago

Sensitive information disclosure vulnerability exists in the undisclosed iControl REST endpoint and TMOS Shell (tmsh) command which may allow an authenticated attacker with resource administrator role privileges to view sensitive informa…

Sensitive information disclosure vulnerability exists in the undisclosed iControl REST endpoint and TMOS Shell (tmsh) command which may allow an authenticated attacker with resource administrator role privileges to view sensitive informa…

▾ SunlitEPSS 0.40%via NVD
CVE-2026-44431Medium· 5.3PoC
4mo ago

urllib3 is an HTTP client library for Python

urllib3 is an HTTP client library for Python. From 1.23 to before 2.7.0, cross-origin redirects followed from the low-level API via ProxyManager.connection_from_url().urlopen(..., assert_same_host=False) still forward these sensitive hea…

▾ TwilightRed Hat · Red Hat Enterprise Linux AppStream (v. 8)EPSS 0.34%via NVD
CVE-2026-28958Medium· 5.5
4mo ago

This issue was addressed with improved data protection

This issue was addressed with improved data protection. This issue is fixed in Safari 26.5, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, visionOS 26.5. An app may be able to access sensitive user data.

▾ Sunlitapple · ipadosEPSS 0.16%via NVD
CVE-2025-31976Medium· 4.8
4mo ago

HCL BigFix Service Management (SM) is vulnerable to insufficiently protected credentials for a short duration while communicating with a backend, internal application which could allow an attacker to potentially misuse them, if exfiltrat…

HCL BigFix Service Management (SM) is vulnerable to insufficiently protected credentials for a short duration while communicating with a backend, internal application which could allow an attacker to potentially misuse them, if exfiltrat…

▾ Sunlithcltech · bigfix_service_managementEPSS 0.16%via NVD
CVE-2026-42151High· 7.5
4mo ago

Prometheus is an open-source monitoring system and time series database

Prometheus is an open-source monitoring system and time series database. Prior to versions 3.5.3 and 3.11.3, the client_secret field in the Azure AD remote write OAuth configuration (storage/remote/azuread) was typed as string instead of…

▾ Twilightprometheus · prometheusEPSS 0.41%via NVD
CVE-2026-21515Critical· 9.9
5mo ago

Azure IoT Central Elevation of Privilege Vulnerability

Exposure of sensitive information to an unauthorized actor in Azure IOT Central allows an authorized attacker to elevate privileges over a network.

▾ MidnightMicrosoft · Azure IOT CentralEPSS 0.70%via CVEORG
CVE-2026-22016High· 7.5PoC
5mo ago

Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JAXP)

Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JAXP). Supported versions that are affected are Oracle Java SE: 8u481, 8u481-b50, 8u481-perf, 11.0.30, …

▾ Midnightoracle · jreEPSS 0.70%via NVD
CVE-2026-21999Medium· 5.3
5mo ago

Vulnerability in the XML Database component of Oracle Database Server

Vulnerability in the XML Database component of Oracle Database Server. Supported versions that are affected are 23.4.0-23.26.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromi…

▾ Sunlitoracle · xml_databaseEPSS 0.24%via NVD
CVE-2026-40895High· 7.5
5mo ago

follow-redirects is an open source, drop-in replacement for Node's `http` and `https` modules that automatically follows redirects

follow-redirects is an open source, drop-in replacement for Node's `http` and `https` modules that automatically follows redirects. Prior to 1.16.0, when an HTTP request follows a cross-domain redirect (301/302/307/308), follow-redirects…

▾ Twilightfollow-redirects_project · follow-redirectsEPSS 0.82%via NVD
CVE-2026-22051Medium· 4.3
5mo ago

StorageGRID (formerly StorageGRID Webscale) versions prior to 11.9.0.13 and 12.0.0.6 are susceptible to a Information Disclosure vulnerability

StorageGRID (formerly StorageGRID Webscale) versions prior to 11.9.0.13 and 12.0.0.6 are susceptible to a Information Disclosure vulnerability. Successful exploit could allow an authenticated attacker with low privileges to run arbitrary…

▾ Sunlitnetapp · storagegridEPSS 0.18%via NVD
CVE-2026-6492Medium· 5.3
5mo ago

A vulnerability was detected in arnobt78 Hotel Booking Management System up to f8922d0e0f6ac1cc761974c7616f44c2bbc04bea

A vulnerability was detected in arnobt78 Hotel Booking Management System up to f8922d0e0f6ac1cc761974c7616f44c2bbc04bea. The impacted element is an unknown function of the file /api/health/detailed of the component Health Check Endpoint.…

▾ SunlitEPSS 0.53%via NVD
CVE-2026-40293High· 7.5
5mo ago

OpenFGA: github.com/openfga/openfga: OpenFGA: Information disclosure of preshared API key via playground endpoint (CVE-2026-40293)

A flaw was found in OpenFGA, an authorization/permission engine. When OpenFGA is configured to use preshared-key authentication and the built-in playground is enabled and accessible beyond localhost or trusted networks, a remote attacker c…

▾ TwilightRed Hat · Multicluster Global Hub 1.7.3EPSS 0.50%via CSAF
CVE-2026-32081Medium· 5.5
5mo ago

Package Catalog Information Disclosure Vulnerability

Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.

▾ SunlitMicrosoft · Windows 10 Version 1607EPSS 0.48%via CVEORG
CVE-2026-32085Medium· 5.5
5mo ago

Remote Procedure Call Information Disclosure Vulnerability

Exposure of sensitive information to an unauthorized actor in Windows Remote Procedure Call allows an authorized attacker to disclose information locally.

▾ SunlitMicrosoft · Windows 10 Version 1607EPSS 0.48%via CVEORG
CVE-2026-32084Medium· 5.5
5mo ago

Windows Print Spooler Information Disclosure Vulnerability

Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.

▾ SunlitMicrosoft · Windows 10 Version 1607EPSS 0.48%via CVEORG
CVE-2026-32079Medium· 5.5
5mo ago

Web Account Manager Information Disclosure Vulnerability

Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.

▾ SunlitMicrosoft · Windows 10 Version 1607EPSS 0.48%via CVEORG
CVE-2026-32151Medium· 6.5
5mo ago

Windows Shell Information Disclosure Vulnerability

Exposure of sensitive information to an unauthorized actor in Windows Shell allows an authorized attacker to disclose information over a network.

▾ SunlitMicrosoft · Windows 10 Version 1607EPSS 1.00%via CVEORG
CVE-2026-33829Medium· 4.3PoC
5mo ago

Windows Snipping Tool Spoofing Vulnerability

Exposure of sensitive information to an unauthorized actor in Windows Snipping Tool allows an unauthorized attacker to perform spoofing over a network.

▾ TwilightMicrosoft · Windows 10 Version 1607EPSS 2.0%via CVEORG
CWE-200 vulnerabilities (CVEs) — page 25 · VulnSea