CWE-538
CVEs classified under CWE-538, newest first.
10 CVEsRSS
CVE-2026-57442Medium· 6.9PoCMCPVault is a lightweight Model Context Protocol server for safe access to files in an Obsidian vault
MCPVault is a lightweight Model Context Protocol server for safe access to files in an Obsidian vault. Prior to 0.11.5, PathFilter in src/pathfilter.ts uses root-anchored deny-list patterns, so nested .git, .obsidian, and node_modules pa…
CVE-2026-25827Low· 2.3An issue was discovered in Keyfactor SignServer before 7.6.0
An issue was discovered in Keyfactor SignServer before 7.6.0. A number of properties were identified to not have any restrictions to what path they can be set to by an admin user. Setting these properties to specific file paths can revea…
CVE-2026-80175Low· 3.3Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Insertion of Sensitive Information into Externally-Accessible File or Directory vulnerability
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Insertion of Sensitive Information into Externally-Accessible File or Directory vulnerability. A low privileged at…
CVE-2026-69507Medium· 5.7Insertion of sensitive information into externally-accessible file or directory in Microsoft Windows Search Component allows an authorized attacker to disclose information over a network.
Insertion of sensitive information into externally-accessible file or directory in Microsoft Windows Search Component allows an authorized attacker to disclose information over a network.
CVE-2026-15574High· 7.5A flaw was found in the vllm-orchestrator-gateway component
A flaw was found in the vllm-orchestrator-gateway component. The system's production binary logs all incoming authorization headers and full chat payloads, which may contain personally identifiable information (PII) and secrets, to persi…
CVE-2026-50565Medium· 4.9Fission builder pods auto-mount the fission-builder ServiceAccount token in the user-supplied builder container
Fission builder pods auto-mount the fission-builder ServiceAccount token in the user-supplied builder container
GHSA-9c83-rr99-vfwjMediumMCPVault: PathFilter restricted directories (.git/.obsidian/node_modules) only denied at vault root, not nested
MCPVault: PathFilter restricted directories (.git/.obsidian/node_modules) only denied at vault root, not nested
CVE-2019-25717Medium· 4.3Dräger Infinity Delta, Delta XL, and Kappa patient monitors contain an information disclosure vulnerability that allows unauthenticated network attackers to access log files over a network connection
Dräger Infinity Delta, Delta XL, and Kappa patient monitors contain an information disclosure vulnerability that allows unauthenticated network attackers to access log files over a network connection. Attackers can retrieve device intern…
CVE-2026-5434Medium· 5.9Honeywell Control Network Module (CNM) contains insertion of sensitive information into an unintended directory
Honeywell Control Network Module (CNM) contains insertion of sensitive information into an unintended directory. An attacker could exploit this vulnerability through probing system files, potentially resulting in unintended access to pro…
CVE-2026-27173High· 8.7JWT tokens that were used by workers in Kubernetes Executors have been exposed to users who had read only access to Kuberentes Pods
JWT tokens that were used by workers in Kubernetes Executors have been exposed to users who had read only access to Kuberentes Pods. This could allow users with just read-only access to perform actions that were only available to running…