VulnSea

CWE-212

CVEs classified under CWE-212, newest first.

19 CVEsRSS

CVE-2026-90860High· 7.1
yesterday

The Canva Mobile App for HarmonyOS before v1.15.1 did not restrict the headers returned to an external origin running in a privileged WebView

The Canva Mobile App for HarmonyOS before v1.15.1 did not restrict the headers returned to an external origin running in a privileged WebView. A threat actor with control of the WebView could access a user’s session.

TwilightCanva · CanvaEPSS 0.18%via NVD
CVE-2026-67071Medium· 6.5
5d ago

HCL DevOps Deploy / HCL Launch is susceptible to an information disclosure vulnerability when processing redacted property values

HCL DevOps Deploy / HCL Launch is susceptible to an information disclosure vulnerability when processing redacted property values. If a deployment is configured with a secure property that starts with certain non-ASCII characters, the re…

SunlitHCLSoftware · HCL DevOps Deploy / HCL LaunchEPSS 0.22%via NVD
CVE-2026-64684Medium· 6.8
6d ago

RMCP is an official Rust SDK for the Model Context Protocol

RMCP is an official Rust SDK for the Model Context Protocol. Prior to 2.1.0, the rmcp crate's StreamableHttpClientTransport in crates/rmcp/src/transport/common/reqwest/streamable_http_client.rs builds its default_http_client with reqwest…

Sunlitmodelcontextprotocol · rust-sdkEPSS 0.40%via NVD
CVE-2026-73440Medium· 4.2
6d ago

On affected platforms running Arista EOS with Simple Network Management Protocol (SNMP) configured, SNMPv3 local or remote user credentials may be exposed as a one-way hashed, localized key value within the device's running and sanitized…

On affected platforms running Arista EOS with Simple Network Management Protocol (SNMP) configured, SNMPv3 local or remote user credentials may be exposed as a one-way hashed, localized key value within the device's running and sanitized…

SunlitArista Networks · EOSEPSS 0.26%via NVD
CVE-2026-86740Low· 3.8
1w ago

Snipe-IT before 8.7.0 fails to check the return value of Storage::delete() in UploadedFilesController::destroy() and Api\\UploadedFilesController::destroy(), allowing deletion requests to report success while files remain on disk

Snipe-IT before 8.7.0 fails to check the return value of Storage::delete() in UploadedFilesController::destroy() and Api\\UploadedFilesController::destroy(), allowing deletion requests to report success while files remain on disk. Admini…

Sunlitsnipeitapp · snipe-itEPSS 0.21%via NVD
CVE-2026-82069Low· 2.7
2w ago

A security issue in MongoDB Server's query statistics serialization on the router allows users with monitoring privileges to access unredacted search query text from other users' operations

A security issue in MongoDB Server's query statistics serialization on the router allows users with monitoring privileges to access unredacted search query text from other users' operations. An improper conditional check in the serializa…

Sunlitmongodb · mongodbEPSS 0.30%via NVD
CVE-2026-78658Medium· 6.5
2w ago

IBM UCD - IBM UrbanCode Deploy 7.2 through 7.2.3.25, and 7.3 through 7.3.2.20 and IBM UCD - IBM DevOps Deploy 8.0 through 8.0.1.15, 8.1 through 8.1.2.8, and 8.2 through 8.2.2.1 IBM DevOps Deploy / IBM UrbanCode Deploy (UCD) is susceptibl…

IBM UCD - IBM UrbanCode Deploy 7.2 through 7.2.3.25, and 7.3 through 7.3.2.20 and IBM UCD - IBM DevOps Deploy 8.0 through 8.0.1.15, 8.1 through 8.1.2.8, and 8.2 through 8.2.2.1 IBM DevOps Deploy / IBM UrbanCode Deploy (UCD) is susceptibl…

SunlitIBM · UCD - IBM UrbanCode DeployEPSS 0.27%via NVD
CVE-2026-85094High· 8.8
2w ago

The Canva Android App before 2.376.0 did not restrict the headers returned to an external origin running in a privileged WebView

The Canva Android App before 2.376.0 did not restrict the headers returned to an external origin running in a privileged WebView. A threat actor with control of the WebView could access a user’s session.

TwilightEPSS 0.23%via NVD
CVE-2026-53604High· 7.1
2w ago

nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN

nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN. Prior to version 0.3.8, the web handler renderMobileBundle passes the real *pki.CAResolver directly into mobilebundle.Build. Inside Build, resolver.LoadByID decrypts t…

Twilightforgekeep · nebula-meshEPSS 0.12%via NVD
CVE-2026-62900Medium· 5.9
1mo ago

.NET Information Disclosure Vulnerability

Improper removal of sensitive information before storage or transfer in .NET allows an unauthorized attacker to disclose information over a network.

SunlitMicrosoft · .NET 10.0EPSS 0.55%via CVEORG
GHSA-h95v-h523-3mw8Medium· 5.9
2mo ago

Guzzle: URI fragments disclosed in redirect Referer headers

Guzzle: URI fragments disclosed in redirect Referer headers

Sunlitguzzlehttp · guzzlehttp/guzzlevia GHSA
CVE-2026-16104Medium· 4.3
2mo ago

A flaw was found in the authentication configuration endpoint of the keycloak-services component, which is the core engine for Red Hat Build of Keycloak identity and access management

A flaw was found in the authentication configuration endpoint of the keycloak-services component, which is the core engine for Red Hat Build of Keycloak identity and access management. The issue occurs because the system fails to mask se…

Sunlitredhat · build_of_keycloakEPSS 0.26%via NVD
CVE-2026-54171Medium· 6.5
2mo ago

excon: Excon: Information disclosure via unstripped sensitive headers during redirects (CVE-2026-54171)

A flaw was found in Excon, a Ruby HTTP client library. The RedirectFollower middleware, responsible for handling redirects, failed to remove sensitive header information when a request was redirected to a new target. This oversight could l…

SunlitRed Hat · Red Hat 3scale API Management Platform 2EPSS 0.43%via CSAF
CVE-2026-45737Medium· 6.3
2mo ago

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. From 3.2.0 until 3.2.12, 3.3.10, and 3.4.2, Argo CD ServerSideDiff can expose Kubernetes Secret values embedded in the kubectl.kubernetes.io/last-applied-configura…

Sunlitargoproj · argo_cdEPSS 0.52%via NVD
CVE-2026-9079Critical· 9.8PoC⚖ disputed
2mo ago

libcurl had a flaw that when instructed to clear proxy authentication credentials which made it not do so, leaving the old credentials around to get used for subsequent transfers that should not know nor use them.

libcurl had a flaw that when instructed to clear proxy authentication credentials which made it not do so, leaving the old credentials around to get used for subsequent transfers that should not know nor use them.

Abyssalhaxx · curlEPSS 0.58%via NVD
CVE-2026-40895High· 7.5
5mo ago

follow-redirects is an open source, drop-in replacement for Node's `http` and `https` modules that automatically follows redirects

follow-redirects is an open source, drop-in replacement for Node's `http` and `https` modules that automatically follows redirects. Prior to 1.16.0, when an HTTP request follows a cross-domain redirect (301/302/307/308), follow-redirects…

Twilightfollow-redirects_project · follow-redirectsEPSS 0.49%via NVD
CVE-2026-39937None
5mo ago

Improper removal of sensitive information before storage or transfer vulnerability in The Wikimedia Foundation Mediawiki - CentralAuth Extension allows Resource Leak Exposure. The issue has been remediated on the `master` branch, and in …

Improper removal of sensitive information before storage or transfer vulnerability in The Wikimedia Foundation Mediawiki - CentralAuth Extension allows Resource Leak Exposure. The issue has been remediated on the `master` branch, and in …

SunlitEPSS 0.26%via NVD
CVE-2026-34214High· 7.7
5mo ago

Trino is a distributed SQL query engine for big data analytics

Trino is a distributed SQL query engine for big data analytics. From version 439 to before version 480, Iceberg connector REST catalog static credentials (access key) or vended credentials (temporary access key) are accessible to users t…

Twilighttrino · trinoEPSS 0.20%via NVD
CVE-2021-31780High· 7.5
5y ago

In app/Model/MispObject.php in MISP 2.4.141, an incorrect sharing group association could lead to information disclosure on an event edit

In app/Model/MispObject.php in MISP 2.4.141, an incorrect sharing group association could lead to information disclosure on an event edit. When an object has a sharing group associated with an event edit, the sharing group object is igno…

Twilightmisp-project · mispEPSS 1.0%via NVD
CWE-212 vulnerabilities (CVEs) · VulnSea