VulnSea

CWE-538

CVEs classified under CWE-538, newest first.

10 CVEsRSS

CVE-2026-57442Medium· 6.9PoC
1w ago

MCPVault is a lightweight Model Context Protocol server for safe access to files in an Obsidian vault

MCPVault is a lightweight Model Context Protocol server for safe access to files in an Obsidian vault. Prior to 0.11.5, PathFilter in src/pathfilter.ts uses root-anchored deny-list patterns, so nested .git, .obsidian, and node_modules pa…

Twilightbitbonsai · mcpvaultEPSS 0.17%via NVD
CVE-2026-25827Low· 2.3
1w ago

An issue was discovered in Keyfactor SignServer before 7.6.0

An issue was discovered in Keyfactor SignServer before 7.6.0. A number of properties were identified to not have any restrictions to what path they can be set to by an admin user. Setting these properties to specific file paths can revea…

SunlitEPSS 0.12%via NVD
CVE-2026-80175Low· 3.3
1w ago

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Insertion of Sensitive Information into Externally-Accessible File or Directory vulnerability

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Insertion of Sensitive Information into Externally-Accessible File or Directory vulnerability. A low privileged at…

SunlitDell · Secure Connect Gateway 5.0 - ApplicationEPSS 0.10%via CVEORG
CVE-2026-69507Medium· 5.7
2w ago

Insertion of sensitive information into externally-accessible file or directory in Microsoft Windows Search Component allows an authorized attacker to disclose information over a network.

Insertion of sensitive information into externally-accessible file or directory in Microsoft Windows Search Component allows an authorized attacker to disclose information over a network.

Sunlitmicrosoft · windows_11_23h2EPSS 0.84%via NVD
CVE-2026-15574High· 7.5
2mo ago

A flaw was found in the vllm-orchestrator-gateway component

A flaw was found in the vllm-orchestrator-gateway component. The system's production binary logs all incoming authorization headers and full chat payloads, which may contain personally identifiable information (PII) and secrets, to persi…

TwilightEPSS 0.44%via NVD
CVE-2026-50565Medium· 4.9
2mo ago

Fission builder pods auto-mount the fission-builder ServiceAccount token in the user-supplied builder container

Fission builder pods auto-mount the fission-builder ServiceAccount token in the user-supplied builder container

Sunlitfission · github.com/fission/fissionEPSS 0.26%via GHSA
GHSA-9c83-rr99-vfwjMedium
3mo ago

MCPVault: PathFilter restricted directories (.git/.obsidian/node_modules) only denied at vault root, not nested

MCPVault: PathFilter restricted directories (.git/.obsidian/node_modules) only denied at vault root, not nested

Sunlitbitbonsai · @bitbonsai/mcpvaultvia GHSA
CVE-2019-25717Medium· 4.3
3mo ago

Dräger Infinity Delta, Delta XL, and Kappa patient monitors contain an information disclosure vulnerability that allows unauthenticated network attackers to access log files over a network connection

Dräger Infinity Delta, Delta XL, and Kappa patient monitors contain an information disclosure vulnerability that allows unauthenticated network attackers to access log files over a network connection. Attackers can retrieve device intern…

Sunlitdraeger · infinity_delta_firmwareEPSS 0.20%via NVD
CVE-2026-5434Medium· 5.9
4mo ago

Honeywell Control Network Module (CNM) contains insertion of sensitive information into an unintended directory

Honeywell Control Network Module (CNM) contains insertion of sensitive information into an unintended directory. An attacker could exploit this vulnerability through probing system files, potentially resulting in unintended access to pro…

SunlitEPSS 0.21%via NVD
CVE-2026-27173High· 8.7
4mo ago

JWT tokens that were used by workers in Kubernetes Executors have been exposed to users who had read only access to Kuberentes Pods

JWT tokens that were used by workers in Kubernetes Executors have been exposed to users who had read only access to Kuberentes Pods. This could allow users with just read-only access to perform actions that were only available to running…

Twilightapache · airflow_cncf_kubernetesEPSS 0.16%via NVD
CWE-538 vulnerabilities (CVEs) · VulnSea