VulnSea

CWE-200

CVEs classified under CWE-200, newest first.

814 CVEsRSS

CVE-2026-90538Medium· 5.3PoC
2w ago

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a missing authorization vulnerability in playlistsFromUser.json.php that allows unauthenticated attackers to read private playlists by requesting another user's…

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a missing authorization vulnerability in playlistsFromUser.json.php that allows unauthenticated attackers to read private playlists by requesting another user's…

▾ TwilightWWBN · AVideoEPSS 0.36%via NVD
CVE-2026-90536Medium· 5.3
2w ago

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to authorize access to the adsInfo API endpoint, allowing unauthenticated attackers to retrieve password-protected video owner identifiers

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to authorize access to the adsInfo API endpoint, allowing unauthenticated attackers to retrieve password-protected video owner identifiers. Attackers can call the …

▾ SunlitWWBN · AVideoEPSS 0.41%via NVD
CVE-2026-17585Medium· 5.3
2w ago

The Royal Addons for Elementor – Addons and Templates Kit for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.7.1066 via the 'wpr_keyword' parameter

The Royal Addons for Elementor – Addons and Templates Kit for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.7.1066 via the 'wpr_keyword' parameter. This makes it po…

▾ Sunlitwproyal · Royal Addons for Elementor – Addons and Templates Kit for ElementorEPSS 0.32%via NVD
CVE-2026-90550Medium· 5.3PoC
2w ago

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to check user authorization in the PlayerSkins mediaSession.json.php endpoint before returning video metadata

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to check user authorization in the PlayerSkins mediaSession.json.php endpoint before returning video metadata. Unauthenticated attackers can request the endpoint w…

▾ TwilightWWBN · AVideoEPSS 0.41%via NVD
CVE-2026-90549Medium· 5.3
2w ago

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to properly authorize access to the videosAndroid.json.php endpoint, allowing unauthenticated guests to list password-protected videos with sensitive owner informa…

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to properly authorize access to the videosAndroid.json.php endpoint, allowing unauthenticated guests to list password-protected videos with sensitive owner informa…

▾ SunlitWWBN · AVideoEPSS 0.34%via NVD
CVE-2026-90548Medium· 5.3PoC
2w ago

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate user permissions in the ImageGallery list.json.php endpoint, allowing unauthenticated access to list gallery files

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate user permissions in the ImageGallery list.json.php endpoint, allowing unauthenticated access to list gallery files. Attackers can retrieve filenames an…

▾ TwilightWWBN · AVideoEPSS 0.40%via NVD
CVE-2026-90541Medium· 5.3
2w ago

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to require authentication in the plugin/TopMenu/menus.json.php endpoint, allowing unauthenticated attackers to retrieve all menu data

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to require authentication in the plugin/TopMenu/menus.json.php endpoint, allowing unauthenticated attackers to retrieve all menu data. Attackers can send GET reque…

▾ SunlitWWBN · AVideoEPSS 0.41%via NVD
CVE-2026-87916Medium· 5.3
2w ago

The WPBot WordPress plugin before 8.6.0 does not perform any capability or nonce check on the AJAX action that lists stored chat sessions, allowing unauthenticated attackers to retrieve the name, email address and phone number of every …

The WPBot WordPress plugin before 8.6.0 does not perform any capability or nonce check on the AJAX action that lists stored chat sessions, allowing unauthenticated attackers to retrieve the name, email address and phone number of every …

▾ SunlitEPSS 0.34%via NVD
CVE-2026-87842High· 7.5
2w ago

The Zonify WordPress plugin before 1.0.5 does not perform any capability or authentication check before returning the site's stored account login token, allowing unauthenticated attackers to retrieve it and authenticate to the site owne…

The Zonify WordPress plugin before 1.0.5 does not perform any capability or authentication check before returning the site's stored account login token, allowing unauthenticated attackers to retrieve it and authenticate to the site owne…

▾ TwilightEPSS 0.50%via NVD
CVE-2026-78152Medium· 5.3
2w ago

The SureRank SEO WordPress plugin before 1.10.1 does not exclude users' registered account email addresses from the structured data it outputs on public pages by default, allowing unauthenticated visitors to obtain the email address of …

The SureRank SEO WordPress plugin before 1.10.1 does not exclude users' registered account email addresses from the structured data it outputs on public pages by default, allowing unauthenticated visitors to obtain the email address of …

▾ SunlitEPSS 0.33%via NVD
CVE-2026-49462Medium· 5.3
2w ago

NL Portal Backend Libraries provide backend components for Dutch government portals that interact with residents, customers, suppliers, and partner organizations

NL Portal Backend Libraries provide backend components for Dutch government portals that interact with residents, customers, suppliers, and partner organizations. In versions up to and including 3.0.0, deployments using the shipped defau…

▾ Sunlitnl-portal · nl.nl-portal:appEPSS 0.40%via NVD
CVE-2026-50025Medium· 6.9
2w ago

Mousehole is a background service to update a seedbox IP for MAM and web app to manage it

Mousehole is a background service to update a seedbox IP for MAM and web app to manage it. Prior to version 0.4.05, Mousehole's HTTP/WebSocket management boundary is reachable without application-layer authentication or browser/LAN prove…

▾ Sunlitt-mart · mouseholeEPSS 0.26%via NVD
CVE-2026-89298Medium· 4.9
2w ago

A flaw was found in the Dynamic Client Registration service of Keycloak, an open-source identity and access management solution

A flaw was found in the Dynamic Client Registration service of Keycloak, an open-source identity and access management solution. The issue occurs when a user with the view-clients role accesses the client registration endpoint to retriev…

▾ SunlitRed Hat · keycloak/rhbk-openshift-rhel9EPSS 0.41%via NVD
CVE-2026-14562Medium· 5.3
2w ago

The teddy-bear-customize-addon WordPress plugin through 1.0.5 does not perform any authorization or ownership checks before returning WooCommerce order metadata and the URLs of customer-uploaded attachments, allowing unauthenticated atta…

The teddy-bear-customize-addon WordPress plugin through 1.0.5 does not perform any authorization or ownership checks before returning WooCommerce order metadata and the URLs of customer-uploaded attachments, allowing unauthenticated atta…

▾ SunlitEPSS 0.21%via NVD
CVE-2026-89248Medium· 5.3PoC
2w ago

AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 is missing an authentication/authorization check in plugin/WebRTC/status.json.php

AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 is missing an authentication/authorization check in plugin/WebRTC/status.json.php. When the WebRTC plugin is present, any unauthenticated remote user can request /plugin/WebR…

▾ TwilightWWBN · AVideoEPSS 0.50%via NVD
CVE-2026-49463Medium· 6.5
2w ago

NL Portal: Missing per-user authorization on document and decision GraphQL queries in nl-portal-backend-libraries

NL Portal Backend Libraries provide backend components for Dutch government portals that interact with residents, customers, suppliers, and partner organizations. The `nl.nl-portal:documenten-api` package through version 3.0.0 and the `n…

▾ Sunlitnl-portal · nl.nl-portal:besluitenEPSS 0.34%via CVEORG
CVE-2026-88013Low· 3.7PoC
2w ago

rclone is a command-line program to sync files and directories to and from different cloud storage providers

rclone is a command-line program to sync files and directories to and from different cloud storage providers. From 1.49.0 until 1.75.1, the HTTP backend attaches headers configured through --http-headers or headers= to requests in backen…

▾ Twilightrclone · rcloneEPSS 0.19%via NVD
CVE-2026-88059Medium· 4.0
2w ago

Angular: Information Leak via `HttpTransferCache` Bypass When Using `withRequestsMadeViaParent`

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 20.3.28, 21.2.20, and 22.1.1, Angular's @angular/common HttpTransferCache can cache an authentic…

▾ Sunlitangular · angularEPSS 0.48%via CVEORG
CVE-2026-88874High· 7.5PoC
2w ago

AVideo through revision c3edcc274c389816d434acadac07ee78eaf330c1 (master, 2026-08-23) does not enforce the Live stream password check on the stats endpoint or on the HLS origin

AVideo through revision c3edcc274c389816d434acadac07ee78eaf330c1 (master, 2026-08-23) does not enforce the Live stream password check on the stats endpoint or on the HLS origin. Live::_getStats() (plugin/Live/Live.php) returns a password…

▾ MidnightWWBN · AVideoEPSS 0.55%via NVD
CVE-2026-88893High· 7.5
2w ago

OpenPanel share lookup procedures fail to validate access controls and return password hashes and protected report definitions to unauthenticated callers

OpenPanel share lookup procedures fail to validate access controls and return password hashes and protected report definitions to unauthenticated callers. Attackers with a share link can retrieve argon2id password hashes and full report …

▾ TwilightOpenpanel-dev · openpanelEPSS 0.43%via NVD
CVE-2026-88876High· 7.5PoC
2w ago

AVideo through revision c3edcc274c389816d434acadac07ee78eaf330c1 contains a missing authorization vulnerability in plugin/PlayerSkins/seo.php that allows unauthenticated attackers to access password-protected video sources by calling get…

AVideo through revision c3edcc274c389816d434acadac07ee78eaf330c1 contains a missing authorization vulnerability in plugin/PlayerSkins/seo.php that allows unauthenticated attackers to access password-protected video sources by calling get…

▾ MidnightWWBN · AVideoEPSS 0.44%via NVD
CVE-2026-19439High· 7.5
2w ago

The Ultimate Gift Cards for WooCommerce WordPress plugin before 3.2.10 does not have any authorisation check when displaying gift card details, allowing unauthenticated users to retrieve the gift cards attached to arbitrary orders and di…

The Ultimate Gift Cards for WooCommerce WordPress plugin before 3.2.10 does not have any authorisation check when displaying gift card details, allowing unauthenticated users to retrieve the gift cards attached to arbitrary orders and di…

▾ TwilightEPSS 0.26%via NVD
CVE-2026-0305Medium· 4.3
2w ago

An information disclosure vulnerability in the Palo Alto Networks Prisma® Access Agent on Linux enables a local user to access sensitive configuration data and credentials. The Prisma Access Agent on macOS, Windows, iOS, Android and C…

An information disclosure vulnerability in the Palo Alto Networks Prisma® Access Agent on Linux enables a local user to access sensitive configuration data and credentials. The Prisma Access Agent on macOS, Windows, iOS, Android and C…

▾ SunlitPalo Alto Networks · Prisma Access AgentEPSS 0.10%via NVD
CVE-2026-87810Medium· 5.3PoC
2w ago

Siyuan before v3.8.2 Information Disclosure via fullTextSearchBlock

Siyuan before v3.8.2 contains an information disclosure vulnerability in the POST /api/search/fullTextSearchBlock endpoint that filters private blocks from results but returns unfiltered match counts. Unauthenticated publish-mode readers…

▾ Twilightsiyuan-note · siyuanEPSS 0.34%via CVEORG
CVE-2026-87820Medium· 5.3PoC
2w ago

CyberPanel versions 2.4.3 through 2.4.5 expose unauthenticated AI Scanner debugging endpoints that disclose administrator usernames, API-key prefixes, scan identifiers, target domains, and account metadata

CyberPanel versions 2.4.3 through 2.4.5 expose unauthenticated AI Scanner debugging endpoints that disclose administrator usernames, API-key prefixes, scan identifiers, target domains, and account metadata. Unauthenticated attackers can …

▾ Twilightusmannasir · cyberpanelEPSS 0.87%via NVD
CVE-2026-87035Medium· 4.3
2w ago

Tanium addressed an information disclosure vulnerability in Comply.

Tanium addressed an information disclosure vulnerability in Comply.

▾ Sunlittanium · complyEPSS 0.30%via NVD
CVE-2026-87032Medium· 4.3
2w ago

Tanium addressed an information disclosure vulnerability in Tanium Server.

Tanium addressed an information disclosure vulnerability in Tanium Server.

▾ SunlitTanium · Tanium ServerEPSS 0.29%via NVD
CVE-2026-87017Medium· 4.3
2w ago

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.7.0 until 0.11.1, the built-in knowledge search tool passed the caller's readable knowledge identifiers through a metadata filter, but the searc…

▾ Sunlitopenwebui · open_webuiEPSS 0.37%via NVD
CVE-2026-86767Medium· 5.0
2w ago

Snipe-IT versions before 8.7.0 fail to apply company scope filtering to the GET /hardware/requested endpoint when Full Multiple Company Support is enabled, allowing authenticated users with assets.view permission to read pending asset re…

Snipe-IT versions before 8.7.0 fail to apply company scope filtering to the GET /hardware/requested endpoint when Full Multiple Company Support is enabled, allowing authenticated users with assets.view permission to read pending asset re…

▾ Sunlitsnipeitapp · snipe-itEPSS 0.33%via NVD
CVE-2026-79323High· 7.5
2w ago

Information disclosure in the blogComments GraphQL query in Magefan Blog GraphQL for Magento 2 (magefan/module-blog-graph-ql) through 2.2.1 allows remote unauthenticated attackers to obtain blog commenter email addresses and internal cus…

Information disclosure in the blogComments GraphQL query in Magefan Blog GraphQL for Magento 2 (magefan/module-blog-graph-ql) through 2.2.1 allows remote unauthenticated attackers to obtain blog commenter email addresses and internal cus…

▾ Twilightmageplaza · magefan_blogEPSS 0.56%via NVD
CWE-200 vulnerabilities (CVEs) — page 9 · VulnSea