CWE-523
CVEs classified under CWE-523, newest first.
3 CVEsRSS
CVE-2026-54784High· 7.4CoreWCF: SPNEGO SecurityContextToken proof key wrapped without confidentiality
CoreWCF: SPNEGO SecurityContextToken proof key wrapped without confidentiality
▾ TwilightCoreWCF · CoreWCF.PrimitivesEPSS 0.27%via GHSA
CVE-2025-64309High· 7.4The affected product discloses device telemetry, configuration, and sensitive information via WebSocket traffic to unauthenticated users when they connect to a specific URL
The affected product discloses device telemetry, configuration, and sensitive information via WebSocket traffic to unauthenticated users when they connect to a specific URL. The unauthenticated URL can be discovered through basic network…
▾ TwilightEPSS 0.21%via NVD
CVE-2025-64308Medium· 6.5The Brightpick Mission Control web application exposes hardcoded credentials in its client-side JavaScript bundle to Brightpick AI's documentation portal.
The Brightpick Mission Control web application exposes hardcoded credentials in its client-side JavaScript bundle to Brightpick AI's documentation portal.
▾ SunlitEPSS 0.21%via NVD