VulnSea

CWE-202

CVEs classified under CWE-202, newest first.

3 CVEsRSS

CVE-2026-40533Medium· 5.3
3d ago

An exposure of sensitive information through data queries vulnerability in Desktop API in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote attackers to obtain non-sensitive information.

An exposure of sensitive information through data queries vulnerability in Desktop API in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote attackers to obtain non-sensitive information.

SunlitSynology · DiskStation Manager (DSM)EPSS 0.29%via NVD
CVE-2026-77883Medium· 4.9
1w ago

Exposure of sensitive information through data queries vulnerability in Apache Syncope. An administrator with adequate entitlements for Derived Schemas can create a malicious JEXL expression which allows any administrator with sufficien…

Exposure of sensitive information through data queries vulnerability in Apache Syncope. An administrator with adequate entitlements for Derived Schemas can create a malicious JEXL expression which allows any administrator with sufficien…

SunlitApache Software Foundation · org.apache.syncope.core:syncope-core-provisioning-apiEPSS 0.38%via NVD
CVE-2026-70473High· 8.5
1mo ago

Flowise is a drag-and-drop user interface for building customized large language model (LLM) flows

Flowise is a drag-and-drop user interface for building customized large language model (LLM) flows. Prior to 3.1.3, Flowise GET /api/v1/upsert-history returns the entire server-wide upsert history instead of being scoped to the requestin…

Twilightflowiseai · flowiseEPSS 0.29%via NVD
CWE-202 vulnerabilities (CVEs) · VulnSea