VulnSea

CWE-203

CVEs classified under CWE-203, newest first.

41 CVEsRSS

CVE-2026-91725Medium· 5.3
6d ago

Observable discrepancy in CSS in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to leak sensitive information via a crafted HTML page

Observable discrepancy in CSS in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to leak sensitive information via a crafted HTML page. (Chromium security severity: Medium)

Sunlitgoogle · chromeEPSS 0.24%via NVD
CVE-2026-91714Medium· 5.3
6d ago

Observable discrepancy in Fonts in Google Chrome prior to 153.0.8010.47 allowed a remote attacker leveraging social engineering to leak sensitive information via a crafted HTML page

Observable discrepancy in Fonts in Google Chrome prior to 153.0.8010.47 allowed a remote attacker leveraging social engineering to leak sensitive information via a crafted HTML page. (Chromium security severity: Medium)

Sunlitgoogle · chromeEPSS 0.24%via NVD
CVE-2026-56888Medium· 6.2
6d ago

In multiple locations, there is a possible permission bypass due to side channel information disclosure

In multiple locations, there is a possible permission bypass due to side channel information disclosure. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for …

Sunlitgoogle · androidEPSS 0.08%via NVD
CVE-2025-5802Medium· 5.3
6d ago

The self-registration flow accepts user-supplied input for usernames without adequately preventing the disclosure of username existence

The self-registration flow accepts user-supplied input for usernames without adequately preventing the disclosure of username existence. When a user attempts to register with an existing username, the system responds with an error messag…

SunlitWSO2 · WSO2 API ManagerEPSS 0.25%via NVD
CVE-2025-13166Low· 3.7
6d ago

The SMS OTP flow fails to adequately handle error messages, allowing an attacker to infer the existence of registered user accounts based on the responses received during the OTP initiation process. This weakness can be exploited by an …

The SMS OTP flow fails to adequately handle error messages, allowing an attacker to infer the existence of registered user accounts based on the responses received during the OTP initiation process. This weakness can be exploited by an …

SunlitWSO2 · WSO2 Identity ServerEPSS 0.22%via NVD
CVE-2026-59341Medium· 4.2PoC
6d ago

A security vulnerability exists in the Sealed Secrets controller's unauthenticated POST endpoints

A security vulnerability exists in the Sealed Secrets controller's unauthenticated POST endpoints. By submitting a modified payload containing custom Go template logic in spec.template.data, an attacker with internal network access can a…

TwilightBitnami · sealed-secretsEPSS 0.31%via NVD
CVE-2026-87478Medium· 6.5
1w ago

Observable discrepancy in Autofill in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to obtain sensitive information via a crafted HTML page

Observable discrepancy in Autofill in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)

Sunlitgoogle · chromeEPSS 0.35%via NVD
CVE-2026-87539Low· 3.1
1w ago

Observable discrepancy in Network in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to obtain cross-origin data via a crafted HTML page

Observable discrepancy in Network in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

Sunlitgoogle · chromeEPSS 0.21%via NVD
CVE-2026-87516Medium· 4.3⚖ disputed
1w ago

Observable discrepancy in Navigation in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to leak cross-origin data via a crafted HTML page

Observable discrepancy in Navigation in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

Sunlitgoogle · chromeEPSS 0.24%via NVD
CVE-2026-87518Medium· 5.3
1w ago

Observable discrepancy in Safebrowsing in Google Chrome on on iOS prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially obtain sensitive information via a crafted HTML page

Observable discrepancy in Safebrowsing in Google Chrome on on iOS prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially obtain sensitive information via a crafted HTML page. (Chromium se…

Sunlitgoogle · chromeEPSS 0.26%via NVD
CVE-2026-87623Medium· 6.5⚖ disputed
1w ago

Observable discrepancy in DOM in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page

Observable discrepancy in DOM in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)

Sunlitgoogle · chromeEPSS 0.24%via NVD
CVE-2026-87566Medium· 5.3
1w ago

Observable discrepancy in Layout in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to leak sensitive information via a crafted HTML page

Observable discrepancy in Layout in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to leak sensitive information via a crafted HTML page. (Chromium security severity: Medium)

Sunlitgoogle · chromeEPSS 0.22%via NVD
CVE-2026-87620Medium· 6.5⚖ disputed
1w ago

Observable discrepancy in SVG in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to obtain sensitive information via a crafted HTML page

Observable discrepancy in SVG in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Low)

Sunlitgoogle · chromeEPSS 0.24%via NVD
CVE-2026-87619Medium· 4.3
1w ago

Observable discrepancy in Prefetch in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to leak cross-origin data via a crafted HTML page

Observable discrepancy in Prefetch in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)

Sunlitgoogle · chromeEPSS 0.19%via NVD
CVE-2026-87459Medium· 6.5
1w ago

Observable discrepancy in Select in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to obtain sensitive information via a crafted HTML page

Observable discrepancy in Select in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Low)

Sunlitgoogle · chromeEPSS 0.25%via NVD
CVE-2026-53933Medium· 6.9
1w ago

Maravel, a PHP framework oriented towards dependency injection, prior to version 10.73.1 has a side-channel information disclosure issue

Maravel, a PHP framework oriented towards dependency injection, prior to version 10.73.1 has a side-channel information disclosure issue. When a route was compiled with dynamic placeholders (e.g., `/api/v1/users/{id}`), the raw string pl…

Sunlitmacropay-solutions · maravel-frameworkEPSS 0.32%via NVD
CVE-2026-55227Medium· 4.3
3w ago

Private Weblate projects vulnerable to observable object existence disclosure via globally scoped object lookups

Private Weblate projects vulnerable to observable object existence disclosure via globally scoped object lookups

Sunlitweblate · weblateEPSS 0.19%via OSV
CVE-2026-78949Low· 2.9
3w ago

Observable discrepancy in CustomTabs in Google Chrome on on Android prior to 152.0.7977.65 allowed a local attacker to obtain cross-origin data via a co-installed app

Observable discrepancy in CustomTabs in Google Chrome on on Android prior to 152.0.7977.65 allowed a local attacker to obtain cross-origin data via a co-installed app. (Chromium security severity: Medium)

SunlitGoogle · ChromeEPSS 0.10%via CVEORG
CVE-2026-78936Low· 2.9
3w ago

Observable discrepancy in CustomTabs in Google Chrome on on Android prior to 152.0.7977.65 allowed a local attacker to obtain cross-origin data via a co-installed app

Observable discrepancy in CustomTabs in Google Chrome on on Android prior to 152.0.7977.65 allowed a local attacker to obtain cross-origin data via a co-installed app. (Chromium security severity: Medium)

SunlitGoogle · ChromeEPSS 0.11%via CVEORG
CVE-2026-72699Medium· 5.3
3w ago

The Grav Login plugin (getgrav/grav-plugin-login) before 3.9.1 is vulnerable to email address enumeration

The Grav Login plugin (getgrav/grav-plugin-login) before 3.9.1 is vulnerable to email address enumeration. The register() method in classes/Login.php throws a distinct exception (EMAIL_NOT_AVAILABLE) when a submitted email address alread…

SunlitEPSS 0.21%via NVD
GHSA-8fxq-53rx-ph5fLow· 3.7
1mo ago

Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison

Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison

Sunlitcoder · github.com/coder/coder/v2via GHSA
CVE-2026-73409None
1mo ago

Budibase is an open-source low-code platform

Budibase is an open-source low-code platform. Prior to 3.40.1, packages/server/src/integrations/mongodb.ts passed builder-controlled tlsCertificateKeyFile and tlsCAFile values directly to MongoClient on Budibase Cloud. A builder could su…

SunlitEPSS 0.24%via NVD
CVE-2026-59640None
1mo ago

In Bouncy Castle for Java before 1.85, OpenPGP CFB quick-check oracle active on symmetric/session-key paths

In Bouncy Castle for Java before 1.85, OpenPGP CFB quick-check oracle active on symmetric/session-key paths. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpg-fips 1.0…

SunlitEPSS 0.22%via NVD
CVE-2026-55555Low
2mo ago

Dompdf: File existence oracle via font-face stylesheet declaration

Dompdf: File existence oracle via font-face stylesheet declaration

Sunlitdompdf · dompdf/dompdfEPSS 0.35%via GHSA
CVE-2026-58445Low· 2.7
2mo ago

Gitea: Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API

Gitea: Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API

Sunlitgitea · code.gitea.io/giteaEPSS 0.23%via GHSA
CVE-2026-56296Medium· 5.3
2mo ago

Cap-go before 12.128.2 contains an information disclosure vulnerability in the public.transfer_app RPC function that returns distinct error messages for existing versus non-existing app IDs

Cap-go before 12.128.2 contains an information disclosure vulnerability in the public.transfer_app RPC function that returns distinct error messages for existing versus non-existing app IDs. Unauthenticated attackers can enumerate valid …

SunlitEPSS 0.36%via NVD
CVE-2026-58503None
2mo ago

Frappe is a full-stack web application framework

Frappe is a full-stack web application framework. Prior to 16.16.0 and 15.106.0, user enumeration could be performed via the reset_password endpoint. This issue is fixed in versions 16.16.0 and 15.106.0.

SunlitEPSS 0.59%via NVD
CVE-2026-44332Medium· 5.3
2mo ago

GoFiber Vulnerable to Username Enumeration via Timing Oracle in BasicAuth Default Authorizer

GoFiber Vulnerable to Username Enumeration via Timing Oracle in BasicAuth Default Authorizer

Sunlitgofiber · github.com/gofiber/fiber/v3EPSS 0.52%via GHSA
CVE-2023-54357High· 7.5
3mo ago

Joomla com_booking component 2.4.9 contains an information disclosure vulnerability that allows unauthenticated attackers to enumerate user accounts by exploiting the getUserData function in the customer controller

Joomla com_booking component 2.4.9 contains an information disclosure vulnerability that allows unauthenticated attackers to enumerate user accounts by exploiting the getUserData function in the customer controller. Attackers can send GE…

Twilightartio · book_it!EPSS 0.49%via NVD
CVE-2026-8242Low· 3.7
4mo ago

A vulnerability was found in Industrial Application Software IAS Canias ERP 8.03

A vulnerability was found in Industrial Application Software IAS Canias ERP 8.03. The impacted element is the function doAction of the component Login RMI Interface. Performing a manipulation results in observable response discrepancy. T…

SunlitEPSS 0.29%via NVD
CWE-203 vulnerabilities (CVEs) · VulnSea