VulnSea

CWE-200

CVEs classified under CWE-200, newest first.

824 CVEsRSS

CVE-2026-25125Medium· 4.9
5mo ago

October is a Content Management System (CMS) and web platform

October is a Content Management System (CMS) and web platform. Versions prior to 3.7.14 and 4.1.10 contain a server-side information disclosure vulnerability in the INI settings parser. Because PHP's parse_ini_string() function supports …

▾ Sunlitoctobercms · octoberEPSS 0.33%via NVD
CVE-2026-39363High· 7.5PoC
5mo ago

Vite is a frontend tooling framework for JavaScript

Vite is a frontend tooling framework for JavaScript. From 6.0.0 to before 6.4.2, 7.3.2, and 8.0.5, if it is possible to connect to the Vite dev server’s WebSocket without an Origin header, an attacker can invoke fetchModule via the custo…

▾ Midnightvitejs · viteEPSS 2.6%via NVD
CVE-2026-27949Low· 2.0
5mo ago

Plane is an an open-source project management tool

Plane is an an open-source project management tool. Prior to 1.3.0, a vulnerability was identified in Plane's authentication flow where a user's email address is included as a query parameter in the URL during error handling (e.g., when …

▾ Sunlitplane · planeEPSS 0.29%via NVD
CVE-2026-27481Medium· 5.3
5mo ago

Discourse is an open-source discussion platform

Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to before 2026.2.2, and 2026.3.0-latest to before 2026.3.0, an authorization bypass vulnerability allows unauthenticated o…

▾ Sunlitdiscourse · discourseEPSS 0.39%via NVD
CVE-2026-35038Medium· 6.5
6mo ago

Signal K Server is a server application that runs on a central hub in a boat

Signal K Server is a server application that runs on a central hub in a boat. Prior to version 2.24.0, there is an arbitrary prototype read vulnerability via `from` field bypass. This vulnerability allows a low-privileged authenticated u…

▾ Sunlitsignalk · signal_k_serverEPSS 0.41%via NVD
CVE-2026-32618Medium· 4.3
6mo ago

Discourse is an open-source discussion platform

Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to before 2026.2.2, and 2026.3.0-latest to before 2026.3.0, there is possible channel membership inference from chat user …

▾ Sunlitdiscourse · discourseEPSS 0.34%via NVD
CVE-2026-32143Medium· 6.5
6mo ago

Discourse is an open-source discussion platform

Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to before 2026.2.2, and 2026.3.0-latest to before 2026.3.0, moderators could export CSV data for admin-restricted reports,…

▾ Sunlitdiscourse · discourseEPSS 0.40%via NVD
CVE-2026-56341High· 7.5
6mo ago

AVideo: Unauthenticated Access to Payment Log DataTables Endpoints Exposes Transaction Data, PayPal Tokens, and User Financial Records

AVideo: Unauthenticated Access to Payment Log DataTables Endpoints Exposes Transaction Data, PayPal Tokens, and User Financial Records

▾ Twilightwwbn · wwbn/avideoEPSS 0.46%via GHSA
CVE-2026-31837High· 7.5
6mo ago

Istio is an open platform to connect, manage, and secure microservices

Istio is an open platform to connect, manage, and secure microservices. Prior to 1.29.1, 1.28.5, and 1.27.8, a user of Istio is impacted if the JWKS resolver becomes unavailable or the fetch fails, exposing hardcoded defaults regardless …

▾ Twilightistio · istioEPSS 0.68%via NVD
CVE-2026-20623Medium· 5.5
7mo ago

A permissions issue was addressed by removing the vulnerable code

A permissions issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia 15.7.4, macOS Tahoe 26.3. An app may be able to access protected user data.

▾ Sunlitapple · macosEPSS 0.14%via NVD
CVE-2026-1669High· 7.5
7mo ago

Arbitrary file read in the model loading mechanism (HDF5 integration) in Keras versions 3.0.0 through 3.13.1 on all supported platforms allows a remote attacker to read local files and disclose sensitive information via a crafted .keras …

Arbitrary file read in the model loading mechanism (HDF5 integration) in Keras versions 3.0.0 through 3.13.1 on all supported platforms allows a remote attacker to read local files and disclose sensitive information via a crafted .keras …

▾ Twilightkeras · kerasEPSS 0.31%via NVD
CVE-2025-68686Medium· 5.9CISA KEV
7mo ago

An Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE-200] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.1, FortiOS 7.4.0 through 7.4.6, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all…

An Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE-200] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.1, FortiOS 7.4.0 through 7.4.6, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all…

▾ Midnightfortinet · fortiosEPSS 30%via NVD
CVE-2026-20862Medium· 5.5
8mo ago

Exposure of sensitive information to an unauthorized actor in Windows Management Services allows an authorized attacker to disclose information locally.

Exposure of sensitive information to an unauthorized actor in Windows Management Services allows an authorized attacker to disclose information locally.

▾ Sunlitmicrosoft · windows_10_1809EPSS 0.65%via NVD
CVE-2026-20847Medium· 6.5
8mo ago

Exposure of sensitive information to an unauthorized actor in Windows Shell allows an authorized attacker to perform spoofing over a network.

Exposure of sensitive information to an unauthorized actor in Windows Shell allows an authorized attacker to perform spoofing over a network.

▾ Sunlitmicrosoft · windows_10_1607EPSS 1.4%via NVD
CVE-2026-20827Medium· 5.5
8mo ago

Exposure of sensitive information to an unauthorized actor in Tablet Windows User Interface (TWINUI) Subsystem allows an authorized attacker to disclose information locally.

Exposure of sensitive information to an unauthorized actor in Tablet Windows User Interface (TWINUI) Subsystem allows an authorized attacker to disclose information locally.

▾ Sunlitmicrosoft · windows_10_1607EPSS 0.67%via NVD
CVE-2026-20823Medium· 5.5
8mo ago

Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.

Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.

▾ Sunlitmicrosoft · windows_10_1607EPSS 0.67%via NVD
CVE-2026-20821Medium· 6.2
8mo ago

Exposure of sensitive information to an unauthorized actor in Windows Remote Procedure Call allows an unauthorized attacker to disclose information locally.

Exposure of sensitive information to an unauthorized actor in Windows Remote Procedure Call allows an unauthorized attacker to disclose information locally.

▾ Sunlitmicrosoft · windows_10_1607EPSS 0.71%via NVD
CVE-2026-20805Medium· 5.5CISA KEV0dayPoC
8mo ago

Exposure of sensitive information to an unauthorized actor in Desktop Windows Manager allows an authorized attacker to disclose information locally.

Exposure of sensitive information to an unauthorized actor in Desktop Windows Manager allows an authorized attacker to disclose information locally.

▾ Midnightmicrosoft · windows_10_1607EPSS 7.2%via NVD
CVE-2025-46283Medium· 5.5
9mo ago

A logic issue was addressed with improved validation

A logic issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.2. An app may be able to access sensitive user data.

▾ Sunlitapple · macosEPSS 0.19%via NVD
CVE-2025-43473Medium· 5.5
9mo ago

This issue was addressed with improved state management

This issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.1. An app may be able to access sensitive user data.

▾ Sunlitapple · macosEPSS 0.20%via NVD
CVE-2025-66623High· 7.4
9mo ago

Strimzi provides a way to run an Apache Kafka cluster on Kubernetes or OpenShift in various deployment configurations

Strimzi provides a way to run an Apache Kafka cluster on Kubernetes or OpenShift in various deployment configurations. From 0.47.0 and prior to 0.49.1, in some situations, Strimzi creates an incorrect Kubernetes Role which grants the Apa…

▾ Twilightlinuxfoundation · strimziEPSS 0.17%via NVD
CVE-2025-13494Medium· 5.3
9mo ago

The SSP Debug plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.0.0

The SSP Debug plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.0.0. This is due to the plugin storing PHP error logs in a predictable, web-accessible location (wp-content/upload…

▾ SunlitEPSS 0.29%via NVD
CVE-2025-41015High· 7.5
10mo ago

User Enumeration Vulnerability in TCMAN GIM v11 version 20250304

User Enumeration Vulnerability in TCMAN GIM v11 version 20250304. This vulnerability allows an unauthenticated attacker to determine whether a user exists on the system. The vulnerability is exploitable through the 'pda:username' paramet…

▾ Twilighttcman · gimEPSS 0.30%via NVD
CVE-2025-41014High· 7.5
10mo ago

User Enumeration Vulnerability in TCMAN GIM v11 version 20250304

User Enumeration Vulnerability in TCMAN GIM v11 version 20250304. This vulnerability allows an unauthenticated attacker to determine whether a user exists on the system. The vulnerability is exploitable through the 'pda:username' paramet…

▾ Twilighttcman · gimEPSS 0.30%via NVD
CVE-2025-66304Medium· 6.2
10mo ago

Grav is a file-based Web platform

Grav is a file-based Web platform. Prior to 1.8.0-beta.27, users with read access on the user account management section of the admin panel can view the password hashes of all users, including the admin user. This exposure can potentiall…

▾ Sunlitgetgrav · gravEPSS 0.41%via NVD
CVE-2025-13804Medium· 4.3
10mo ago

A security flaw has been discovered in nutzam NutzBoot up to 2.6.0-SNAPSHOT

A security flaw has been discovered in nutzam NutzBoot up to 2.6.0-SNAPSHOT. The impacted element is an unknown function of the file nutzboot-demo/nutzboot-demo-simple/nutzboot-demo-simple-web3j/src/main/java/io/nutz/demo/simple/module/E…

▾ SunlitEPSS 0.26%via NVD
CVE-2025-13785Medium· 4.3
10mo ago

A security vulnerability has been detected in yungifez Skuul School Management System up to 2.6.5

A security vulnerability has been detected in yungifez Skuul School Management System up to 2.6.5. This issue affects some unknown processing of the file /user/profile of the component Image Handler. Such manipulation leads to informatio…

▾ Sunlityungifez · skuulEPSS 0.37%via NVD
CVE-2025-52669Medium· 4.3
10mo ago

Insecure design policies in the user management system of Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes non-admin users to have access to the contact name and email address of other users on the system.

Insecure design policies in the user management system of Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes non-admin users to have access to the contact name and email address of other users on the system.

▾ Sunlitrevive-adserver · revive_adserverEPSS 0.29%via NVD
CVE-2025-63891High· 7.5
10mo ago

Information Disclosure in web-accessible backup file in SourceCodester Simple Online Book Store System allows a remote unauthenticated attacker to disclose full database contents (including schema and credential hashes) via an unauthenti…

Information Disclosure in web-accessible backup file in SourceCodester Simple Online Book Store System allows a remote unauthenticated attacker to disclose full database contents (including schema and credential hashes) via an unauthenti…

▾ Twilightoretnom23 · simple_online_book_store_systemEPSS 0.45%via NVD
CVE-2025-43460Medium· 4.6
10mo ago

A logic issue was addressed with improved checks

A logic issue was addressed with improved checks. This issue is fixed in iOS 26.1 and iPadOS 26.1. An attacker with physical access to a locked device may be able to view sensitive user information.

▾ Sunlitapple · ipadosEPSS 0.23%via NVD
CWE-200 vulnerabilities (CVEs) — page 26 · VulnSea