VulnSea

CWE-200

CVEs classified under CWE-200, newest first.

824 CVEsRSS

CVE-2025-40646Medium· 5.4
12mo ago

Exposure of sensitive information in Viday

Exposure of sensitive information in Viday. This vulnerability could allow an attacker to obtain sensitive information about customers by intercepting HTTP requests and searching for the JWT containing sensitive user information in the J…

▾ Sunlitenergycrm · energy_crmEPSS 0.18%via NVD
CVE-2025-10222Low· 3.3
1y ago

Exposure of Sensitive Information to an Unauthorized Actor (CWE-200) in the diagnostic dump component in AxxonSoft Axxon One VMS (C-Werk) 2.0.0 through 2.0.1 on Windows allows a local attacker to obtain licensing-related information such…

Exposure of Sensitive Information to an Unauthorized Actor (CWE-200) in the diagnostic dump component in AxxonSoft Axxon One VMS (C-Werk) 2.0.0 through 2.0.1 on Windows allows a local attacker to obtain licensing-related information such…

▾ Sunlitaxxonsoft · axxon_oneEPSS 0.12%via NVD
CVE-2025-51643Low· 2.4PoC
1y ago

Meitrack T366G-L GPS Tracker devices contain an SPI flash chip (Winbond 25Q64JVSIQ) that is accessible without authentication or tamper protection

Meitrack T366G-L GPS Tracker devices contain an SPI flash chip (Winbond 25Q64JVSIQ) that is accessible without authentication or tamper protection. An attacker with physical access to the device can use a standard SPI programmer to extra…

▾ Twilightmeitrack · t366l-g_firmwareEPSS 0.26%via NVD
CVE-2025-8852Medium· 4.3
1y ago

A vulnerability was identified in WuKongOpenSource WukongCRM 11.0

A vulnerability was identified in WuKongOpenSource WukongCRM 11.0. This affects an unknown part of the file /adminFile/upload of the component API Response Handler. The manipulation leads to information exposure through error message. It…

▾ Sunlit5kcrm · wukong_crmEPSS 0.36%via NVD
CVE-2025-30758Medium· 5.3
1y ago

Vulnerability in the Siebel CRM End User product of Oracle Siebel CRM (component: User Interface)

Vulnerability in the Siebel CRM End User product of Oracle Siebel CRM (component: User Interface). Supported versions that are affected are 25.0-25.5. Easily exploitable vulnerability allows unauthenticated attacker with network access …

▾ Sunlitoracle · siebel_crmEPSS 0.30%via NVD
CVE-2025-23173High· 7.5
1y ago

The Versa Director SD-WAN orchestration platform provides direct web-based access to uCPE virtual machines through the Director GUI

The Versa Director SD-WAN orchestration platform provides direct web-based access to uCPE virtual machines through the Director GUI. By default, the websockify service is exposed on port 6080 and accessible from the internet. This exposu…

▾ Twilightversa-networks · versa_directorEPSS 0.62%via NVD
CVE-2025-49177Medium· 6.1
1y ago

A flaw was found in the XFIXES extension

A flaw was found in the XFIXES extension. The XFixesSetClientDisconnectMode handler does not validate the request length, allowing a client to read unintended memory from previous requests.

▾ SunlitEPSS 0.43%via NVD
CVE-2025-6199Low· 3.3
1y ago

A flaw was found in the GIF parser of GdkPixbuf’s LZW decoder

A flaw was found in the GIF parser of GdkPixbuf’s LZW decoder. When an invalid symbol is encountered during decompression, the decoder sets the reported output size to the full buffer length rather than the actual number of written bytes…

▾ Sunlitgnome · gdkpixbufEPSS 0.20%via NVD
CVE-2025-25250Medium· 4.3
1y ago

An Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE-200] vulnerability in Fortinet FortiOS 7.6.0, FortiOS 7.4.0 through 7.4.7, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions, For…

An Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE-200] vulnerability in Fortinet FortiOS 7.6.0, FortiOS 7.4.0 through 7.4.7, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions, For…

▾ Sunlitfortinet · fortisaseEPSS 0.54%via NVD
CVE-2025-4526Medium· 4.3
1y ago

A vulnerability was identified in Dígitro NGC Explorer up to 3.48.21

A vulnerability was identified in Dígitro NGC Explorer up to 3.48.21. The affected element is an unknown function of the component Configuration Page. Such manipulation leads to missing password field masking. It is possible to launch th…

▾ Sunlitdigitro · ngc_explorerEPSS 0.29%via NVD
CVE-2025-2842Medium· 4.3
1y ago

A flaw was found in the Tempo Operator

A flaw was found in the Tempo Operator. When the Jaeger UI Monitor Tab functionality is enabled in a Tempo instance managed by the Tempo Operator, the Operator creates a ClusterRoleBinding for the Service Account of the Tempo instance to…

▾ SunlitRed Hat · tempo-operatorEPSS 0.38%via NVD
CVE-2025-2786Medium· 4.3
1y ago

A flaw was found in Tempo Operator, where it creates a ServiceAccount, ClusterRole, and ClusterRoleBinding when a user deploys a TempoStack or TempoMonolithic instance

A flaw was found in Tempo Operator, where it creates a ServiceAccount, ClusterRole, and ClusterRoleBinding when a user deploys a TempoStack or TempoMonolithic instance. This flaw allows a user with full access to their namespace to extra…

▾ SunlitRed Hat · tempo-operatorEPSS 0.36%via NVD
CVE-2025-22866Medium· 5.3
1y ago

crypto/internal/nistec: golang: Timing sidechannel for P-256 on ppc64le in crypto/internal/nistec (CVE-2025-22866)

A flaw was found in the Golang crypto/internal/nistec package. Due to the usage of a variable time instruction in the assembly implementation of an internal function, a small number of bits of secret scalars are leaked on the ppc64le archi…

▾ SunlitRed Hat · Red Hat Enterprise Linux AppStream E4S (v.8.8)EPSS 0.29%via CSAF
CVE-2024-50312Medium· 5.3
1y ago

A vulnerability was found in GraphQL due to improper access controls on the GraphQL introspection query

A vulnerability was found in GraphQL due to improper access controls on the GraphQL introspection query. This flaw allows unauthorized users to retrieve a comprehensive list of available queries and mutations. Exposure to this flaw incre…

▾ Sunlitredhat · openshift_container_platformEPSS 0.56%via NVD
CVE-2024-39896High· 7.5
2y ago

Directus Allows Single Sign-On User Enumeration

Directus Allows Single Sign-On User Enumeration

▾ Twilightdirectus · directusEPSS 0.51%via GHSA
CVE-2024-37325High· 8.1
2y ago

Azure Science Virtual Machine (DSVM) Elevation of Privilege Vulnerability

Azure Science Virtual Machine (DSVM) Elevation of Privilege Vulnerability

▾ Twilightmicrosoft · azure_data_science_virtual_machineEPSS 1.1%via NVD
CVE-2024-35263Medium· 5.7
2y ago

Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability

Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability

▾ Sunlitmicrosoft · dynamics_365EPSS 1.7%via NVD
CVE-2024-30096Medium· 5.5
2y ago

Windows Cryptographic Services Information Disclosure Vulnerability

Windows Cryptographic Services Information Disclosure Vulnerability

▾ Sunlitmicrosoft · windows_10_1809EPSS 0.95%via NVD
CVE-2024-24919High· 8.6CISA KEVPoC
2y ago

Potentially allowing an attacker to read certain information on Check Point Security Gateways once connected to the internet and enabled with remote Access VPN or Mobile Access Software Blades

Potentially allowing an attacker to read certain information on Check Point Security Gateways once connected to the internet and enabled with remote Access VPN or Mobile Access Software Blades. A Security fix that mitigates this vulnerab…

▾ Abyssalcheckpoint · cloudguard_network_securityEPSS 100%via NVD
CVE-2024-1139High· 7.7
2y ago

A credentials leak vulnerability was found in the cluster monitoring operator in OCP

A credentials leak vulnerability was found in the cluster monitoring operator in OCP. This issue may allow a remote attacker who has basic login credentials to check the pod manifest to discover a repository pull secret.

▾ TwilightEPSS 0.89%via NVD
CVE-2024-1979Low· 3.5
2y ago

A vulnerability was found in Quarkus

A vulnerability was found in Quarkus. In certain conditions related to the CI process, git credentials could be inadvertently published, which could put the git repository at risk.

▾ SunlitEPSS 0.60%via NVD
CVE-2024-21626High· 8.6PoC
2y ago

runc is a CLI tool for spawning and running containers on Linux according to the OCI specification

runc is a CLI tool for spawning and running containers on Linux according to the OCI specification. In runc 1.1.11 and earlier, due to an internal file descriptor leak, an attacker could cause a newly-spawned container process (from runc…

▾ Midnightlinuxfoundation · runcEPSS 18%via NVD
CVE-2023-6393Medium· 5.3
2y ago

A flaw was found in the Quarkus Cache Runtime

A flaw was found in the Quarkus Cache Runtime. When request processing utilizes a Uni cached using @CacheResult and the cached Uni reuses the initial "completion" context, the processing switches to the cached Uni instead of the request …

▾ Sunlitredhat · build_of_quarkusEPSS 0.63%via NVD
CVE-2023-4061Medium· 6.5
2y ago

A flaw was found in wildfly-core

A flaw was found in wildfly-core. A management user could use the resolve-expression in the HAL Interface to read possible sensitive information from the Wildfly system. This issue could allow a malicious user to access the system and ob…

▾ Sunlitredhat · jboss_enterprise_application_platformEPSS 0.83%via NVD
CVE-2023-25500Low· 3.5
3y ago

Possible information disclosure in Vaadin 10.0.0 to 10.0.23, 11.0.0 to 14.10.1, 15.0.0 to 22.0.28, 23.0.0 to 23.3.13, 24.0.0 to 24.0.6, 24.1.0.alpha1 to 24.1.0.rc2, resulting in potential information disclosure of class and method names …

Possible information disclosure in Vaadin 10.0.0 to 10.0.23, 11.0.0 to 14.10.1, 15.0.0 to 22.0.28, 23.0.0 to 23.3.13, 24.0.0 to 24.0.6, 24.1.0.alpha1 to 24.1.0.rc2, resulting in potential information disclosure of class and method names …

▾ Sunlitvaadin · vaadinEPSS 0.51%via NVD
CVE-2023-25499Medium· 5.7
3y ago

When adding non-visible components to the UI in server side, content is sent to the browser in Vaadin 10.0.0 through 10.0.22, 11.0.0 through 14.10.0, 15.0.0 through 22.0.28, 23.0.0 through 23.3.12, 24.0.0 through 24.0.5 and 24.1.0.alpha1…

When adding non-visible components to the UI in server side, content is sent to the browser in Vaadin 10.0.0 through 10.0.22, 11.0.0 through 14.10.0, 15.0.0 through 22.0.28, 23.0.0 through 23.3.12, 24.0.0 through 24.0.5 and 24.1.0.alpha1…

▾ Sunlitvaadin · vaadinEPSS 0.58%via NVD
CVE-2023-28841Medium· 6.8
3y ago

Moby is an open source container framework developed by Docker Inc

Moby is an open source container framework developed by Docker Inc. that is distributed as Docker, Mirantis Container Runtime, and various other downstream projects/products. The Moby daemon component (`dockerd`), which is developed as m…

▾ Sunlitmobyproject · mobyEPSS 0.69%via NVD
CVE-2022-31746Medium· 6.5
3y ago

Internal URLs are protected by a secret UUID key, which could have been leaked to web page through the Referrer header

Internal URLs are protected by a secret UUID key, which could have been leaked to web page through the Referrer header. This vulnerability affects Firefox for iOS < 102.

▾ Sunlitmozilla · firefox_mobileEPSS 0.41%via NVD
CVE-2022-34659Medium· 5.3
4y ago

A vulnerability has been identified in Simcenter STAR-CCM+ (All versions only if the Power-on-Demand public license server is used)

A vulnerability has been identified in Simcenter STAR-CCM+ (All versions only if the Power-on-Demand public license server is used). Affected applications expose user, host and display name of users, when the public license server is use…

▾ Sunlitsiemens · simcenter_star-ccm+_viewerEPSS 0.62%via NVD
CVE-2022-29567Medium· 5.7
4y ago

The default configuration of a TreeGrid component uses Object::toString as a key on the client-side and server communication in Vaadin 14.8.5 through 14.8.9, 22.0.6 through 22.0.14, 23.0.0.beta2 through 23.0.8 and 23.1.0.alpha1 through 2…

The default configuration of a TreeGrid component uses Object::toString as a key on the client-side and server communication in Vaadin 14.8.5 through 14.8.9, 22.0.6 through 22.0.14, 23.0.0.beta2 through 23.0.8 and 23.1.0.alpha1 through 2…

▾ Sunlitvaadin · vaadinEPSS 0.99%via NVD
CWE-200 vulnerabilities (CVEs) — page 27 · VulnSea