VulnSea

CWE-201

CVEs classified under CWE-201, newest first.

82 CVEsRSS

GHSA-wrr4-782v-jhwhLow
3mo ago

neotoma has tenant isolation gap in relationship query endpoints

neotoma has tenant isolation gap in relationship query endpoints

▾ Sunlitneotoma · neotomavia GHSA
CVE-2026-45049High· 8.3
3mo ago

OpenAM Unauthenticated Session Hijacking via Information Exposure in CDCServlet

OpenAM Unauthenticated Session Hijacking via Information Exposure in CDCServlet

▾ Twilightopenidentityplatform · org.openidentityplatform.openam:openam-federationvia GHSA
CVE-2026-22551Medium
3mo ago

[Eclipse Theia] Data Exfiltration via Markdown Image Rendering in AI Chat

[Eclipse Theia] Data Exfiltration via Markdown Image Rendering in AI Chat

▾ Sunlittheia · @theia/ai-chat-uiEPSS 0.31%via GHSA
CVE-2026-44486High· 7.5PoC
3mo ago

Axios is a promise based HTTP client for the browser and Node.js

Axios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16.0, Axios’ Node.js HTTP adapter can leak proxy credentials to a redirect target in affected versions. When a request is sent through an authenticat…

▾ Midnightaxios · axiosEPSS 0.76%via NVD
CVE-2026-44487High· 7.5PoC
3mo ago

Axios is a promise based HTTP client for the browser and Node.js

Axios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16.0, Axios’s Node.js HTTP adapter may forward a Proxy-Authorization header to a redirected origin during specific proxy-to-direct redirect flows. Th…

▾ Midnightaxios · axiosEPSS 0.76%via NVD
CVE-2026-10101Medium· 6.3
4mo ago

ACM/MCE assisted-service writes raw referenced pull-secret contents into `InfraEnv.status.conditions[].message` when pull-secret validation fails

ACM/MCE assisted-service writes raw referenced pull-secret contents into `InfraEnv.status.conditions[].message` when pull-secret validation fails. A namespace principal with the stock `view` ClusterRole cannot directly read Secrets, but …

▾ SunlitEPSS 0.18%via NVD
CVE-2026-7168Medium· 5.3PoC
4mo ago

Successfully using libcurl to do a transfer over a specific HTTP proxy (`proxyA`) with **Digest** authentication and then changing the proxy host to a second one (`proxyB`) for a second transfer, reusing the same handle, makes libcurl wr…

Successfully using libcurl to do a transfer over a specific HTTP proxy (`proxyA`) with **Digest** authentication and then changing the proxy host to a second one (`proxyB`) for a second transfer, reusing the same handle, makes libcurl wr…

▾ Twilighthaxx · curlEPSS 0.59%via NVD
CVE-2026-6429Medium· 5.3
4mo ago

When asked to both use a `.netrc` file for credentials and to follow HTTP redirects, libcurl could leak the password used for the first host to the followed-to host under certain circumstances.

When asked to both use a `.netrc` file for credentials and to follow HTTP redirects, libcurl could leak the password used for the first host to the followed-to host under certain circumstances.

▾ Sunlithaxx · curlEPSS 0.51%via NVD
CVE-2026-6253Medium· 5.9PoC
4mo ago

curl might erroneously pass on credentials for a first proxy to a second proxy. This can happen when the following conditions are true: 1

curl might erroneously pass on credentials for a first proxy to a second proxy. This can happen when the following conditions are true: 1. curl is setup to use specific different proxies for different URL schemes 2. the first proxy nee…

▾ Twilighthaxx · curlEPSS 0.75%via NVD
CVE-2026-44431Medium· 5.3
4mo ago

urllib3 is an HTTP client library for Python

urllib3 is an HTTP client library for Python. From 1.23 to before 2.7.0, cross-origin redirects followed from the low-level API via ProxyManager.connection_from_url().urlopen(..., assert_same_host=False) still forward these sensitive hea…

▾ SunlitRed Hat · Red Hat Enterprise Linux AppStream (v. 8)EPSS 0.34%via NVD
CVE-2025-31978Medium· 4.6
4mo ago

HCL BigFix Service Management (SM) does not adequately sanitize or safely render spreadsheet files (CSV, XLS, XLSX) before processing or distributing them

HCL BigFix Service Management (SM) does not adequately sanitize or safely render spreadsheet files (CSV, XLS, XLSX) before processing or distributing them. An attacker could populate data fields which, when saved to a CSV file, may attem…

▾ Sunlithcltech · bigfix_service_managementEPSS 0.14%via NVD
CVE-2026-42997High· 7.7
4mo ago

An issue was discovered in idrac in OpenStack Ironic before 35.0.1

An issue was discovered in idrac in OpenStack Ironic before 35.0.1. During import, a user invoking molds can request authorization to be sent to a remote endpoint. The credential forwarded is a time-limited Keystone token (which provides…

▾ Twilightopenstack · ironicEPSS 0.54%via NVD
CVE-2026-40293High· 7.5
5mo ago

OpenFGA: github.com/openfga/openfga: OpenFGA: Information disclosure of preshared API key via playground endpoint (CVE-2026-40293)

A flaw was found in OpenFGA, an authorization/permission engine. When OpenFGA is configured to use preshared-key authentication and the built-in playground is enabled and accessible beyond localhost or trusted networks, a remote attacker c…

▾ TwilightRed Hat · Multicluster Global Hub 1.7.3EPSS 0.50%via CSAF
CVE-2025-41118Critical· 9.1
5mo ago

Pyroscope is an open-source continuous profiling database

Pyroscope is an open-source continuous profiling database. The database supports various storage backends, including Tencent Cloud Object Storage (COS). If the database is configured to use Tencent COS as the storage backend, an attacke…

▾ Midnightgrafana · pyroscopeEPSS 0.41%via NVD
CVE-2026-20151High· 7.3
5mo ago

A vulnerability in the web interface of Cisco Smart Software Manager On-Prem (SSM On-Prem) could allow an authenticated, remote attacker to elevate privileges on an affected system. This vulnerability is due to the improper transmissi…

A vulnerability in the web interface of Cisco Smart Software Manager On-Prem (SSM On-Prem) could allow an authenticated, remote attacker to elevate privileges on an affected system. This vulnerability is due to the improper transmissi…

▾ Twilightcisco · smart_software_manager_on-premEPSS 0.27%via NVD
CVE-2026-32829High· 7.5
6mo ago

lz4_flex is a pure Rust implementation of LZ4 compression/decompression

lz4_flex is a pure Rust implementation of LZ4 compression/decompression. In versions 0.11.5 and below, and 0.12.0, decompressing invalid LZ4 data can leak sensitive information from uninitialized memory or from previous decompression op…

▾ Twilightpseitz · lz4_flexEPSS 0.69%via NVD
CVE-2026-3783Medium· 5.3PoC
6mo ago

When an OAuth2 bearer token is used for an HTTP(S) transfer, and that transfer performs a redirect to a second URL, curl could leak that token to the second hostname under some circumstances. If the hostname that the first request is re…

When an OAuth2 bearer token is used for an HTTP(S) transfer, and that transfer performs a redirect to a second URL, curl could leak that token to the second hostname under some circumstances. If the hostname that the first request is re…

▾ Twilighthaxx · curlEPSS 0.51%via NVD
CVE-2026-1694Medium· 4.3
7mo ago

HTTP headers are added by the default configuration of IIS and ASP.net, and are not removed at the deployment phase of the webservices used by the WebVue, WebScheduler, TouchVue and SnapVue features of PcVue in version 12.0.0 through 16.…

HTTP headers are added by the default configuration of IIS and ASP.net, and are not removed at the deployment phase of the webservices used by the WebVue, WebScheduler, TouchVue and SnapVue features of PcVue in version 12.0.0 through 16.…

▾ Sunlitarcinfo · pcvueEPSS 0.17%via NVD
CVE-2025-7708Medium· 6.8
7mo ago

Insertion of Sensitive Information Into Sent Data vulnerability in Atlas Educational Software Industry Ltd

Insertion of Sensitive Information Into Sent Data vulnerability in Atlas Educational Software Industry Ltd. Co. K12net allows Communication Channel Manipulation. This issue affects k12net: through 26072025.

▾ SunlitEPSS 0.26%via NVD
CVE-2025-66566None
9mo ago

yawkat LZ4 Java provides LZ4 compression for Java

yawkat LZ4 Java provides LZ4 compression for Java. Insufficient clearing of the output buffer in Java-based decompressor implementations in lz4-java 1.10.0 and earlier allows remote attackers to read previous buffer contents via crafted …

▾ SunlitEPSS 0.60%via NVD
CVE-2025-58098High· 8.3PoC
9mo ago

Apache HTTP Server 2.4.65 and earlier with Server Side Includes (SSI) enabled and mod_cgid (but not mod_cgi) passes the shell-escaped query string to #exec cmd="..." directives. This issue affects Apache HTTP Server before 2.4.66. User…

Apache HTTP Server 2.4.65 and earlier with Server Side Includes (SSI) enabled and mod_cgid (but not mod_cgi) passes the shell-escaped query string to #exec cmd="..." directives. This issue affects Apache HTTP Server before 2.4.66. User…

▾ Midnightapache · http_serverEPSS 1.4%via NVD
CVE-2025-66304Medium· 6.2
10mo ago

Grav is a file-based Web platform

Grav is a file-based Web platform. Prior to 1.8.0-beta.27, users with read access on the user account management section of the admin panel can view the password hashes of all users, including the admin user. This exposure can potentiall…

▾ Sunlitgetgrav · gravEPSS 0.41%via NVD
CWE-201 vulnerabilities (CVEs) — page 3 · VulnSea