VulnSea

CWE-359

CVEs classified under CWE-359, newest first.

24 CVEsRSS

CVE-2026-54565Medium· 4.7
5d ago

rhwp is an HWP viewer and editor implemented in Rust and WebAssembly

rhwp is an HWP viewer and editor implemented in Rust and WebAssembly. Prior to rhwp 0.7.15 and rhwp Chrome and Firefox extension 0.2.4, the browser extensions use an all-URLs host permission to detect HWP and HWPX links on visited pages,…

Sunlitedwardkim · rhwpEPSS 0.13%via NVD
CVE-2026-61588Medium· 6.5
6d ago

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, when a Django `Model` instance is assigned to a public view attribute, djust serialized it to the clie…

Sunlitdjust-org · djustEPSS 0.30%via NVD
CVE-2026-92565Medium· 5.3
6d ago

Rallly before 4.15.0 contains an information disclosure vulnerability in the polls.get tRPC procedure that returns scheduled-event invitee names and email addresses to unauthenticated callers

Rallly before 4.15.0 contains an information disclosure vulnerability in the polls.get tRPC procedure that returns scheduled-event invitee names and email addresses to unauthenticated callers. Attackers can access a poll's urlId from pub…

Sunlitlukevella · ralllyEPSS 0.36%via NVD
CVE-2026-76855Medium· 6.5
1w ago

Netcore NR255-V version 1.5.130703 contains a sensitive information disclosure vulnerability in the audit endpoints handled by l7_web_auth_log_dump_cgi.c, audit_get_cgi.c, and mod_dispatch_auth/plan.json

Netcore NR255-V version 1.5.130703 contains a sensitive information disclosure vulnerability in the audit endpoints handled by l7_web_auth_log_dump_cgi.c, audit_get_cgi.c, and mod_dispatch_auth/plan.json. Attackers can query these audit …

SunlitNetcore · NR255-VEPSS 0.38%via NVD
CVE-2026-28938High· 7.5
1w ago

A privacy issue was addressed by moving sensitive data

A privacy issue was addressed by moving sensitive data. This issue is fixed in iOS 26.6 and iPadOS 26.6. An app may be able to fingerprint the user.

Twilightapple · ipadosEPSS 0.29%via NVD
CVE-2026-64753Medium· 6.5
1w ago

A permissions issue was addressed by removing the vulnerable code

A permissions issue was addressed by removing the vulnerable code. This issue is fixed in Safari 27, iOS 27 and iPadOS 27, macOS Golden Gate 27, tvOS 27, visionOS 27, watchOS 27. Processing maliciously crafted web content may disclose se…

Sunlitapple · safariEPSS 0.29%via NVD
CVE-2026-28836Medium· 6.1
1w ago

A correctness issue was addressed with improved checks

A correctness issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.8.8. An attacker with physical access may be able to silently persist an Apple Account on an erased device.

Sunlitapple · macosEPSS 0.18%via NVD
CVE-2026-84606High· 7.5
1w ago

A privacy issue was addressed with improved handling of identifiers

A privacy issue was addressed with improved handling of identifiers. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, visionOS 27. An app may be able to identify a user across reinstalls.

Twilightapple · ipadosEPSS 0.30%via NVD
CVE-2026-86904High· 7.5
1w ago

A privacy issue was addressed with improved state management

A privacy issue was addressed with improved state management. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, watchOS 27. An app may be able to track users across apps and websites without permission.

Twilightapple · ipadosEPSS 0.25%via NVD
CVE-2026-88875Medium· 4.3
1w ago

AVideo through revision c3edcc274c389816d434acadac07ee78eaf330c1 (master, 2026-08-23) incompletely sanitizes sensitive user fields in the APIName=video response

AVideo through revision c3edcc274c389816d434acadac07ee78eaf330c1 (master, 2026-08-23) incompletely sanitizes sensitive user fields in the APIName=video response. Video rows include columns joined from the video owner's user record, and A…

SunlitWWBN · AVideoEPSS 0.22%via NVD
CVE-2026-73008Medium· 5.5
2w ago

Exposure of private personal information to an unauthorized actor in Windows Biometric Service allows an authorized attacker to disclose information locally.

Exposure of private personal information to an unauthorized actor in Windows Biometric Service allows an authorized attacker to disclose information locally.

Sunlitmicrosoft · windows_10_1607EPSS 0.46%via NVD
CVE-2026-69351Medium· 5.5
2w ago

Exposure of private personal information to an unauthorized actor in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to disclose information locally.

Exposure of private personal information to an unauthorized actor in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to disclose information locally.

Sunlitmicrosoft · windows_10_1607EPSS 0.46%via NVD
CVE-2026-53497Medium· 5.3PoC
1mo ago

CrossWatch (CW) is a synchronization engine

CrossWatch (CW) is a synchronization engine. Prior to version 0.9.21, GET /api/app-auth/status is accessible without authentication and returns the other_sessions array, which exposes metadata of all active sessions — including originati…

Twilightcenodude · CrossWatchEPSS 0.29%via NVD
CVE-2026-48048High· 7.5
1mo ago

XWiki Platform is a generic wiki platform

XWiki Platform is a generic wiki platform. XWiki discovered that the patch for GHSA-5cf8-vrr8-8hjm was insufficient. Starting with version 6.2.1 and prior to versions 18.0.0RC1, 17.10.13, 17.4.9 and 16.10.17, with slightly modified param…

TwilightEPSS 0.36%via NVD
CVE-2026-55496Medium· 4.3
1mo ago

Cloudreve is a self-hosted file management and sharing system

Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, GET /api/v4/user/search calls SearchActive without adding a StatusActive predicate and serializes matches at RedactLevelUser, allowing any logged-in user to …

Sunlitcloudreve · github.com/cloudreve/Cloudreve/v4EPSS 0.26%via NVD
CVE-2026-58510Medium· 4.3
2mo ago

Gitea: GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private

Gitea: GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private

Sunlitgitea · code.gitea.io/giteaEPSS 0.21%via GHSA
CVE-2026-56171High· 7.1
2mo ago

Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability

Exposure of private personal information to an unauthorized actor in Windows RDP allows an unauthorized attacker to disclose information over a network.

TwilightMicrosoft · Remote Desktop Web ClientEPSS 0.66%via CVEORG
CVE-2026-50657Medium· 4.7PoC
2mo ago

Microsoft Defender for Endpoint for Mac Information Disclosure Vulnerability

Exposure of private personal information to an unauthorized actor in Microsoft Defender allows an authorized attacker to disclose information locally.

TwilightMicrosoft · Microsoft Defender for Endpoint for MacEPSS 0.40%via CVEORG
CVE-2026-58296High· 7.1
2mo ago

Microsoft Edge for Android Information Disclosure Vulnerability

Exposure of private personal information to an unauthorized actor in Microsoft Edge for Android allows an unauthorized attacker to disclose information over a network.

TwilightMicrosoft · Microsoft Edge (Chromium-based)EPSS 0.54%via CVEORG
CVE-2026-58297High· 7.1
2mo ago

Microsoft Edge for Android Information Disclosure Vulnerability

Exposure of private personal information to an unauthorized actor in Microsoft Edge for Android allows an unauthorized attacker to disclose information over a network.

TwilightMicrosoft · Microsoft Edge (Chromium-based)EPSS 0.54%via CVEORG
CVE-2019-25762High· 7.5
3mo ago

Joomla! Component JoomProject 1.1.3.2 contains an information disclosure vulnerability that allows unauthenticated attackers to access sensitive user data by exploiting the projects endpoint

Joomla! Component JoomProject 1.1.3.2 contains an information disclosure vulnerability that allows unauthenticated attackers to access sensitive user data by exploiting the projects endpoint. Attackers can send requests to index.php with…

Twilightjoomboost · joomprojectEPSS 0.63%via NVD
CVE-2026-54264High
3mo ago

@angular/service-worker: Sensitive Header Leakage on Cross-Origin Redirects in Angular Service Worker

@angular/service-worker: Sensitive Header Leakage on Cross-Origin Redirects in Angular Service Worker

Twilightangular · @angular/service-workerEPSS 0.39%via GHSA
CVE-2026-20834Medium· 4.6
8mo ago

Absolute path traversal in Windows Shell allows an unauthorized attacker to perform spoofing with a physical attack.

Absolute path traversal in Windows Shell allows an unauthorized attacker to perform spoofing with a physical attack.

Sunlitmicrosoft · windows_10_1607EPSS 0.75%via NVD
CVE-2025-65857High· 7.5PoC
9mo ago

An issue was discovered in Xiongmai XM530 IP cameras on firmware V5.00.R02.000807D8.10010.346624.S.ONVIF 21.06

An issue was discovered in Xiongmai XM530 IP cameras on firmware V5.00.R02.000807D8.10010.346624.S.ONVIF 21.06. The GetStreamUri exposes RTSP URIs containing hardcoded credentials enabling direct unauthorized video stream access.

Midnightxiongmaitech · xm530v200_x6-weq_8m_firmwareEPSS 0.43%via NVD
CWE-359 vulnerabilities (CVEs) · VulnSea