VulnSea

CWE-201

CVEs classified under CWE-201, newest first.

74 CVEsRSS

CVE-2026-54649Low· 2.1
5d ago

punchin-email is a Cloudflare Email Worker that provides two-way role aliases while relaying mail to a private inbox

punchin-email is a Cloudflare Email Worker that provides two-way role aliases while relaying mail to a private inbox. Prior to 1.5.0, handleInbound delivers inbound alias mail with message.forward(), which silently drops the added Reply-…

SunlitPunchIn-App · punchin-emailEPSS 0.47%via NVD
CVE-2026-82837Medium· 5.3
1w ago

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.1.0 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that certain conditions could have allowed an authenticated user to access sensitive credentials …

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.1.0 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that certain conditions could have allowed an authenticated user to access sensitive credentials …

SunlitGitLab · GitLabEPSS 0.48%via NVD
CVE-2026-92044High· 7.5
1w ago

Information disclosure in the Networking: HTTP component

Information disclosure in the Networking: HTTP component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.

TwilightMozilla · FirefoxEPSS 0.15%via NVD
CVE-2026-92070Low· 3.4
1w ago

Information disclosure in the Networking component

Information disclosure in the Networking component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.

SunlitMozilla · FirefoxEPSS 0.14%via NVD
CVE-2026-91198Medium· 5.3
1w ago

GrowthBook through 5.0.1 returns unredacted fact table definitions including raw warehouse SQL in payloads served by unauthenticated public report and experiment endpoints

GrowthBook through 5.0.1 returns unredacted fact table definitions including raw warehouse SQL in payloads served by unauthenticated public report and experiment endpoints. Attackers with knowledge of a publicly shared report or experime…

Sunlitgrowthbook · growthbookEPSS 0.24%via NVD
CVE-2026-78336High· 7.5
1w ago

Insertion of sensitive information into sent data vulnerability in Apache Syncope. Any authenticated user can query for the list of available OIDC providers configured for SSO with Console and Enduser

Insertion of sensitive information into sent data vulnerability in Apache Syncope. Any authenticated user can query for the list of available OIDC providers configured for SSO with Console and Enduser. The returned payload contains al…

TwilightApache Software Foundation · org.apache.syncope.ext.oidcc4ui:syncope-ext-oidcc4ui-logicEPSS 0.41%via NVD
CVE-2026-89642High· 7.0
1w ago

kernel: cifs: call pagecache_isize_extended() in cifs_setsize() when extending (CVE-2026-89642)

A flaw was found in the Linux kernel's Common Internet File System (CIFS) implementation. When a client extends a file, the `cifs_setsize()` function fails to properly zero out the newly extended portion of the page cache. This oversight c…

TwilightRed Hat · Red Hat Enterprise Linux 9EPSS 0.15%via CSAF
CVE-2026-89481High· 7.0
1w ago

kernel: nvme-tcp: fix host memory disclosure on R2T for a read command (CVE-2026-89481)

A flaw was found in the Linux kernel's NVMe (Non-Volatile Memory Express) over TCP (nvme-tcp) component. A malicious NVMe controller can exploit this vulnerability by sending a Ready to Transfer (R2T) command for a read request. The host s…

TwilightRed Hat · Red Hat Enterprise Linux 9EPSS 0.41%via CSAF
CVE-2026-89765Medium· 5.5
1w ago

kernel: timers/itimer: Zero-init old itimerval before copy to userspace (CVE-2026-89765)

A flaw was found in the Linux kernel's `timers/itimer` component. On native sparc64 systems, the `struct __kernel_old_timeval` contains uninitialized padding bytes. When `put_itimerval()` copies this structure to userspace, these padding b…

SunlitRed Hat · Red Hat Enterprise Linux 9EPSS 0.20%via CSAF
CVE-2026-89332Medium· 5.5
1w ago

Inclusion of functionality from an untrusted control sphere in the Kiro Powers feature in Amazon Kiro IDE before version 0.8.135 might allow remote unauthenticated actors to obtain sensitive information from a developer workstation

Inclusion of functionality from an untrusted control sphere in the Kiro Powers feature in Amazon Kiro IDE before version 0.8.135 might allow remote unauthenticated actors to obtain sensitive information from a developer workstation. Craf…

Sunlitamazon · kiro_ideEPSS 0.17%via NVD
CVE-2026-62088Medium· 5.3
1w ago

WordPress ElasticPress plugin <= 5.3.4 - Sensitive Data Exposure vulnerability

Insertion of Sensitive Information Into Sent Data vulnerability in 10up ElasticPress allows Retrieve Embedded Sensitive Data. This issue affects ElasticPress: from n/a through 5.3.4.

Sunlit10up · elasticpressEPSS 0.20%via CVEORG
CVE-2026-90461Medium· 6.3
1w ago

OpenStack Ironic through 38.0.0 may send a username and password to an unexpected remote host when Image Service is configured for HTTP(S) Basic Authentication.

OpenStack Ironic through 38.0.0 may send a username and password to an unexpected remote host when Image Service is configured for HTTP(S) Basic Authentication.

SunlitOpenStack · IronicEPSS 0.21%via NVD
CVE-2026-78303Medium· 6.9
1w ago

Joomla Extension - joomshaper.com - Unvalidated Email Destination & Form Manipulation in Booking Requests in SP Property < 4.1.4 - Booking inquiries previously relied on client-submitted hidden fields for recipient routing, allowing pote…

Joomla Extension - joomshaper.com - Unvalidated Email Destination & Form Manipulation in Booking Requests in SP Property < 4.1.4 - Booking inquiries previously relied on client-submitted hidden fields for recipient routing, allowing pote…

Sunlitjoomshaper.com · SP Property extension for JoomlaEPSS 0.25%via NVD
CVE-2026-81804High· 7.5
1w ago

WordPress ZHBackup – Backup, Restore & Migration plugin <= 2.4.2 - Sensitive Data Exposure vulnerability

Unauthenticated Sensitive Data Exposure in ZHBackup – Backup, Restore &amp; Migration <= 2.4.2 versions.

TwilightZain Hassan · zhbackupEPSS 0.24%via CVEORG
CVE-2026-78374Medium· 6.9
1w ago

Joomla Extension - joomlart.com - Open mail relay via contact AJAX endpoint in T4 Page Builder extension < 2.3.0

Joomla Extension - joomlart.com - Open mail relay via contact AJAX endpoint in T4 Page Builder extension < 2.3.0 - The front-end JSON editor endpoint exposes an action called contact that requires no authentication, no CSRF token, no cap…

Sunlitjoomlart.com · T4 Page Builder extension for JoomlaEPSS 0.31%via CVEORG
CVE-2026-87015Medium· 6.8PoC
1w ago

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.6.27 until 0.11.1, backend/open_webui/utils/tools.py captured a cookie jar from the enclosing connection loop instead of binding it to each exte…

Twilightopenwebui · open_webuiEPSS 0.29%via NVD
CVE-2026-65812Medium· 6.8
2w ago

Insertion of sensitive information into sent data in Microsoft Teams for Android allows an authorized attacker to disclose information over a network.

Insertion of sensitive information into sent data in Microsoft Teams for Android allows an authorized attacker to disclose information over a network.

SunlitMicrosoft · Microsoft Teams for AndroidEPSS 0.49%via NVD
CVE-2026-86505Low· 3.3
2w ago

In JetBrains IntelliJ IDEA before 2026.2.2 missing project-trust check leaked project metadata to JetBrains Marketplace

In JetBrains IntelliJ IDEA before 2026.2.2 missing project-trust check leaked project metadata to JetBrains Marketplace

SunlitJetBrains · IntelliJ IDEAEPSS 0.11%via NVD
CVE-2026-86497Medium· 6.8
2w ago

In JetBrains YouTrack before 2026.2.18769 changing a mailbox host without re-authentication allowed a project administrator to exfiltrate stored mailbox credentials

In JetBrains YouTrack before 2026.2.18769 changing a mailbox host without re-authentication allowed a project administrator to exfiltrate stored mailbox credentials

SunlitJetBrains · YouTrackEPSS 0.30%via NVD
CVE-2026-82209High· 8.2PoC⚖ disputed
2w ago

When libpsl support is enabled, libcurl fails to enforce the Public Suffix List boundary check when processing a `Set-Cookie` header where the `Domain` attribute explicitly matches an origin host that is itself a public suffix (e.g., `Do…

When libpsl support is enabled, libcurl fails to enforce the Public Suffix List boundary check when processing a `Set-Cookie` header where the `Domain` attribute explicitly matches an origin host that is itself a public suffix (e.g., `Do…

Midnighthaxx · curlEPSS 0.54%via NVD
CVE-2026-80255High· 7.5PoC
2w ago

A `Set-Cookie:` header using tab (horizontal tab, ASCII code 9) instead of space (ascii code 32) immediately before the `Secure` attribute causes curl to store the cookie without its Secure flag

A `Set-Cookie:` header using tab (horizontal tab, ASCII code 9) instead of space (ascii code 32) immediately before the `Secure` attribute causes curl to store the cookie without its Secure flag. The cookie might then wrongfully be sent …

Midnighthaxx · curlEPSS 0.68%via NVD
CVE-2026-81162Medium· 5.3
2w ago

Insertion of Sensitive Information Into Sent Data vulnerability in Drupal DXPR Builder: The Best Editing (AI) Experience for Drupal allows Forceful Browsing

Insertion of Sensitive Information Into Sent Data vulnerability in Drupal DXPR Builder: The Best Editing (AI) Experience for Drupal allows Forceful Browsing. This issue affects DXPR Builder: The Best Editing (AI) Experience for Drupal ve…

Sunlitdxpr_builder_project · dxpr_builderEPSS 0.33%via NVD
CVE-2026-77123None
2w ago

Nexus Repository 3 contains a sensitive information disclosure vulnerability in the capability read API

Nexus Repository 3 contains a sensitive information disclosure vulnerability in the capability read API. An account holding the nexus:capabilities:read privilege can retrieve the plaintext shared secret configured on a webhook capability…

SunlitEPSS 0.27%via NVD
GHSA-vx52-2968-3vc6High· 7.4
3w ago

pnpm: Environment secrets exfiltrated via env-placeholder expansion in proxy settings read from an untrusted pnpm-workspace.yaml

pnpm: Environment secrets exfiltrated via env-placeholder expansion in proxy settings read from an untrusted pnpm-workspace.yaml

Twilightpnpm · pnpmvia GHSA
CVE-2026-55553High· 7.5
4w ago

urllib is an HTTP client for Node.js that supports authentication, redirects, timeouts, and other request features

urllib is an HTTP client for Node.js that supports authentication, redirects, timeouts, and other request features. Prior to 4.9.1 and 2.44.1, urllib follows redirects through followRedirect but reuses caller-supplied options across orig…

Twilighturllib · urllibEPSS 0.37%via NVD
CVE-2026-59809Medium· 4.9
1mo ago

SiYuan before v3.8.0 interpolates secret placeholders into the destination URL parameter of the http_request MCP tool, allowing attackers to exfiltrate stored secrets

SiYuan before v3.8.0 interpolates secret placeholders into the destination URL parameter of the http_request MCP tool, allowing attackers to exfiltrate stored secrets. An MCP client can craft a request with an attacker-controlled URL con…

SunlitEPSS 0.24%via NVD
CVE-2026-63481Medium
1mo ago

Hurl is a command line tool that runs and tests HTTP requests defined in plain text files

Hurl is a command line tool that runs and tests HTTP requests defined in plain text files. In version 8.0.1 and earlier, the redirect handling in packages/hurl/src/http/client.rs strips Authorization and Cookie headers and basic-auth cre…

Sunlithurl · hurlEPSS 0.47%via NVD
CVE-2026-74945Medium· 6.5PoC
1mo ago

Information disclosure in the Graphics: Text component

Information disclosure in the Graphics: Text component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.

TwilightRed Hat · Red Hat Enterprise Linux AppStream (v. 10)EPSS 0.43%via NVD
CVE-2026-47717High· 7.5PoC
1mo ago

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. In fuxa-server version 1.3.0, the GET /api/project endpoint exposes sensitive project configuration data to guest-context requests even when secureEnabled is enabl…

MidnightEPSS 1.4%via NVD
CVE-2026-16637Medium· 6.5
1mo ago

OPeNDAP Hyrax allows SSRF and credential disclosure via unvalidated HTTP redirects that bypass the AllowedHosts allowlist and leak Earthdata headers (User-Id, Echo-Token) to attacker-controlled endpoints.

OPeNDAP Hyrax allows SSRF and credential disclosure via unvalidated HTTP redirects that bypass the AllowedHosts allowlist and leak Earthdata headers (User-Id, Echo-Token) to attacker-controlled endpoints.

SunlitEPSS 0.40%via NVD
CWE-201 vulnerabilities (CVEs) · VulnSea