VulnSea

CWE-522

CVEs classified under CWE-522, newest first.

134 CVEsRSS

CVE-2026-71494Medium
1mo ago

Infracost provides cloud cost intelligence for engineers, AI coding agents, and CI/CD

Infracost provides cloud cost intelligence for engineers, AI coding agents, and CI/CD. Prior to 0.10.45, internal/hcl/remote_variables_loader.go and related Terraform Cloud, remote-plan, and Terragrunt registry request paths can attach a…

Sunlitinfracost · github.com/infracost/infracostEPSS 0.37%via NVD
CVE-2026-55765High· 8.5
1mo ago

CloudNativePG is a platform designed to manage PostgreSQL databases within Kubernetes environments

CloudNativePG is a platform designed to manage PostgreSQL databases within Kubernetes environments. Prior to 1.28.4 and 1.29.2, CloudNativePG embedded cleartext role passwords in `ALTER ROLE` and `CREATE ROLE` statements generated by Set…

TwilightEPSS 0.29%via NVD
CVE-2026-53586Medium· 6.5
1mo ago

libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing to build Git functionality into your application

libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing to build Git functionality into your application. Prior to 1.8.6 and 1.9.5, the built-in HTTP transport in src/libgi…

SunlitEPSS 0.28%via NVD
CVE-2026-50192Medium
1mo ago

Kerberos Agent is an open source video (surveillance) management agent

Kerberos Agent is an open source video (surveillance) management agent. Prior to version 3.6.26, the Kerberos Hub upload path sends the agent's Hub credentials in the custom `X-Kerberos-Hub-PrivateKey` and `X-Kerberos-Hub-PublicKey` requ…

Sunlitkerberos-io · github.com/kerberos-io/agent/machineryEPSS 0.32%via NVD
CVE-2026-53456None
1mo ago

Blueprint Studio is a VS Code-like file editor for Home Assistant configuration files

Blueprint Studio is a VS Code-like file editor for Home Assistant configuration files. Prior to 2.5.2, Blueprint Studio terminal SSH key authentication in custom_components/blueprint_studio/backend/terminal_manager.py wrote SSH private-k…

SunlitEPSS 0.19%via NVD
CVE-2026-23922Medium· 4.9
1mo ago

The email media OAuth field 'Client secret' cannot be read after saving, but a Super Admin can leak it by setting a malicious 'Token endpoint'

The email media OAuth field 'Client secret' cannot be read after saving, but a Super Admin can leak it by setting a malicious 'Token endpoint'. Changes were made to reset the client secret upon changing the token endpoint.

Sunlitzabbix · zabbixEPSS 0.27%via NVD
CVE-2026-53454None
1mo ago

Blueprint Studio is a VS Code-like file editor for Home Assistant configuration files

Blueprint Studio is a VS Code-like file editor for Home Assistant configuration files. Prior to 2.5.2, Blueprint Studio configured Git's credential.helper store when saving Git credentials, causing Git credential-store to persist usernam…

SunlitEPSS 0.34%via NVD
CVE-2026-62684Low· 2.7
1mo ago

File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory

File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.63.17, the Link storage struct is serialized directly by sharePostHandler, shareListHandl…

Sunlitfilebrowser · github.com/filebrowser/filebrowser/v2EPSS 0.39%via NVD
CVE-2026-57485High· 8.5
1mo ago

Stirling-PDF is a locally hosted web application that facilitates various operations on PDF files

Stirling-PDF is a locally hosted web application that facilitates various operations on PDF files. Prior to 2.9.0, the /api/v1/pipeline/handleData endpoint in app/core/src/main/java/stirling/software/SPDF/controller/api/pipeline/Pipeline…

TwilightEPSS 0.31%via NVD
CVE-2026-0289Medium· 6.5⚖ disputed
1mo ago

A security bypass vulnerability in the Account Protection feature of Palo Alto Networks Prisma® Browser enables a user to bypass intended security controls.

A security bypass vulnerability in the Account Protection feature of Palo Alto Networks Prisma® Browser enables a user to bypass intended security controls.

Sunlitpaloaltonetworks · prisma_browserEPSS 0.22%via NVD
CVE-2026-0290Medium· 5.5⚖ disputed
1mo ago

An information disclosure vulnerability in the Account Protection feature of Palo Alto Networks Prisma® Browser enables a local attacker to view sensitive data.

An information disclosure vulnerability in the Account Protection feature of Palo Alto Networks Prisma® Browser enables a local attacker to view sensitive data.

Sunlitpaloaltonetworks · prisma_browserEPSS 0.13%via NVD
CVE-2026-72801High· 7.5
1mo ago

SiYuan versions before v3.7.4 disclose encrypted-notebook key-derivation material and wrapped data keys through unauthenticated endpoints in publish mode

SiYuan versions before v3.7.4 disclose encrypted-notebook key-derivation material and wrapped data keys through unauthenticated endpoints in publish mode. Attackers can retrieve Argon2id salt, cost parameters, password verifiers, and wra…

TwilightEPSS 0.24%via NVD
CVE-2026-72793High· 8.6
1mo ago

SiYuan versions before v3.7.4 fail to mask sensitive configuration fields in the /api/system/getConf endpoint, allowing anonymous or publish-reader users to obtain the session-cookie signing key, OS username via pandoc path, and encrypte…

SiYuan versions before v3.7.4 fail to mask sensitive configuration fields in the /api/system/getConf endpoint, allowing anonymous or publish-reader users to obtain the session-cookie signing key, OS username via pandoc path, and encrypte…

TwilightEPSS 0.24%via NVD
CVE-2026-49349Medium· 6.8
1mo ago

regclient is a Docker and OCI Registry Client in Go

regclient is a Docker and OCI Registry Client in Go. Prior to version 0.11.5, credentials for a registry may be inadvertently leaked to external servers. A prerequisite for this attack is a malicious registry server, a malicious blob sto…

Sunlitregclient · github.com/regclient/regclientEPSS 0.22%via NVD
CVE-2026-62882Medium· 4.3
1mo ago

Microsoft Outlook Spoofing Vulnerability

Insufficiently protected credentials in Microsoft Office Outlook allows an unauthorized attacker to perform spoofing over a network.

SunlitMicrosoft · Microsoft 365 Apps for EnterpriseEPSS 0.62%via CVEORG
CVE-2026-62839Medium· 6.5
1mo ago

Microsoft SharePoint Server Spoofing Vulnerability

Insufficiently protected credentials in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

SunlitMicrosoft · Microsoft SharePoint Enterprise Server 2016EPSS 0.63%via CVEORG
CVE-2026-71577Medium· 6.3
1mo ago

A flaw was found in multicluster-global-hub

A flaw was found in multicluster-global-hub. During a ManagedClusterMigration, the system incorrectly grants all managed hubs read access to a shared communication topic. This allows a compromised managed hub to intercept and collect sen…

SunlitRed Hat · multicluster-globalhub/multicluster-globalhub-rhel9-operatorEPSS 0.19%via NVD
CVE-2026-47662None
1mo ago

Pathling is a set of tools that make it easier to use FHIR and clinical terminology within health data analytics

Pathling is a set of tools that make it easier to use FHIR and clinical terminology within health data analytics. Prior to version 2.0.0 of Pathling Server, Pathling's typed CRUD/search/batch FHIR surface allows an authenticated caller w…

SunlitEPSS 0.30%via NVD
CVE-2026-47660None
1mo ago

Pathling is a set of tools that make it easier to use FHIR and clinical terminology within health data analytics

Pathling is a set of tools that make it easier to use FHIR and clinical terminology within health data analytics. Prior to version 2.0.0 of Pathling Server, Pathling's bulk-submit operation allows an allowed submitter to supply an explic…

SunlitEPSS 0.31%via NVD
CVE-2026-48039Critical· 9.1
1mo ago

Meta Ads MCP is a Model Context Protocol (MCP) server that lets AI assistants run Meta Ads

Meta Ads MCP is a Model Context Protocol (MCP) server that lets AI assistants run Meta Ads. Prior to version 1.0.109, `AuthInjectionMiddleware.dispatch()` at `http_auth_integration.py:272` unconditionally forwards unauthenticated Streama…

Midnightmeta-ads-mcp · meta-ads-mcpEPSS 0.43%via NVD
GHSA-8mxv-9xhp-86h4Medium· 5.3
1mo ago

rclone: S3 Redirect Sanitization Omits IBM IAM Bearer Tokens and SSE-C Keys

rclone: S3 Redirect Sanitization Omits IBM IAM Bearer Tokens and SSE-C Keys

Sunlitrclone · github.com/rclone/rclonevia GHSA
GHSA-h4mf-4v27-hggjMedium· 5.3
1mo ago

rclone: WebDAV Credentials Survive a Same-Host HTTPS-to-HTTP Redirect

rclone: WebDAV Credentials Survive a Same-Host HTTPS-to-HTTP Redirect

Sunlitrclone · github.com/rclone/rclonevia GHSA
GHSA-gx4c-2hqx-cw2rLow· 3.1
1mo ago

rclone: S3 backend does not strip X-Amz-Security-Token on a same-host HTTPS->HTTP redirect

rclone: S3 backend does not strip X-Amz-Security-Token on a same-host HTTPS->HTTP redirect

Sunlitrclone · github.com/rclone/rclonevia GHSA
CVE-2026-17349Critical· 9.6
1mo ago

/misc/workspace/adhoc_connect_server, part of the Workspaces feature introduced in pgAdmin 4 9.0, when passed the id of an existing server, clones that server via Server.clone(), which copies every column from the source row, including u…

/misc/workspace/adhoc_connect_server, part of the Workspaces feature introduced in pgAdmin 4 9.0, when passed the id of an existing server, clones that server via Server.clone(), which copies every column from the source row, including u…

MidnightEPSS 0.31%via NVD
CVE-2026-52855Critical· 9.9
1mo ago

Wings is the server control plane for Pterodactyl, a free, open-source game server management panel

Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to 1.12.3, {{config.}} placeholders in egg configuration-file templates allow a low-privileged user to read {{config.token}}, {{co…

Midnightpterodactyl · github.com/pterodactyl/wingsEPSS 0.29%via NVD
CVE-2026-67427High· 8.6
1mo ago

Flyto2 Core: ${env.VAR} interpolation reads any env secret despite env.get being denylisted

Flyto2 Core: ${env.VAR} interpolation reads any env secret despite env.get being denylisted

Twilightflyto-core · flyto-coreEPSS 0.36%via GHSA
CVE-2026-67425High· 8.6
1mo ago

Flyto2 Core: LLM/API keys leak to an attacker-controlled base_url

Flyto2 Core: LLM/API keys leak to an attacker-controlled base_url

Twilightflyto-core · flyto-coreEPSS 0.32%via GHSA
CVE-2026-67426Critical· 9.3
1mo ago

Flyto2 Core: Unauthenticated flyto-verification /run: callback_url SSRF and internal runner-secret exfiltration

Flyto2 Core: Unauthenticated flyto-verification /run: callback_url SSRF and internal runner-secret exfiltration

Midnightflyto-core · flyto-coreEPSS 0.31%via GHSA
CVE-2026-54660High· 7.4
1mo ago

swagger-typescript-api vulnerable to authorization-token exfiltration via spec `$ref`

swagger-typescript-api vulnerable to authorization-token exfiltration via spec `$ref`

Twilightswagger-typescript-api · swagger-typescript-apiEPSS 0.24%via GHSA
CVE-2026-54422Medium· 5.5
1mo ago

In OpenStack Ironic Python Agent through 11.5.0, a malicious bootc container, when deployed using ironic-python-agent, may be able to extract the credentials used to download it.

In OpenStack Ironic Python Agent through 11.5.0, a malicious bootc container, when deployed using ironic-python-agent, may be able to extract the credentials used to download it.

SunlitEPSS 0.12%via NVD
CWE-522 vulnerabilities (CVEs) — page 3 · VulnSea