Skip to main content

CWE archive

CWE-200 CVEs

Programmatic archive

10,347 CVEs tagged with CWE-200345 Critical, 2,000 High, 6,835 Medium, 1,163 Low, 4 Unrated.

CVE-2026-12385

Published Jul 13, 2026

The Smart Slider 3 plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.5.1.37 via the 'keyword' parameter. This makes it p…

CVSS 4.3 · Medium
evidence mentions
7
Buzz score
30.8

CVE-2026-15530

Published Jul 13, 2026

A flaw has been found in WuzhiCMS up to 4.1.0. Affected by this vulnerability is the function config/listimage of the file /index.php?m=attachment&f=index&v=upload of the componen…

CVSS 5.5 · Medium
evidence mentions
6
Buzz score
26.0

CVE-2026-56336

Published Jul 12, 2026

Capgo before 12.128.2 contains an information disclosure vulnerability in the unauthenticated /private/sso/check-domain endpoint that returns internal org_id and provider_id value…

CVSS 6.9 · Medium
evidence mentions
2
Buzz score
17.5

CVE-2026-56259

Published Jul 12, 2026

Crawl4AI before 0.8.8 contains credential exfiltration vulnerabilities in the Docker API server that allow attackers to redirect LLM API calls to attacker-controlled endpoints and…

CVSS 8.8 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2026-56238

Published Jul 12, 2026

Capgo before 12.128.2 contains an information disclosure vulnerability in the Supabase PostgREST global_stats endpoint that allows unauthenticated attackers to read sensitive fina…

CVSS 8.7 · High
evidence mentions
2
Buzz score
17.5

CVE-2026-61454

Published Jul 11, 2026

The Grav Admin2 plugin (getgrav/grav-plugin-admin2) before 2.0.4 embeds a global JavaScript variable window.__GRAV_CONFIG__ in the Admin2 SPA bootstrap page at /grav/admin (and it…

CVSS 8.7 · High
evidence mentions
2
Buzz score
17.5

CVE-2026-61426

Published Jul 11, 2026

PraisonAI before 1.7.3 contains an insecure default configuration that binds to all interfaces with no API key requirement and wildcard CORS. Unauthenticated attackers can call GE…

CVSS 8.8 · High
evidence mentions
2
Buzz score
17.5

CVE-2026-56303

Published Jul 11, 2026

Capgo before 12.128.2 contains an information disclosure vulnerability in the find_apikey_by_value PostgreSQL function marked SECURITY DEFINER and executable by the anon role. Una…

CVSS 8.7 · High
evidence mentions
2
Buzz score
17.5

CVE-2026-6801

Published Jul 11, 2026

The Context Blog theme for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.3.5 via the context_blog_modal_popup. This makes it po…

CVSS 5.3 · Medium
evidence mentions
3
Buzz score
28.9

CVE-2026-10865

Published Jul 11, 2026

The Cost Calculator Builder plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.0.11 via the (template body). This makes i…

CVSS 5.3 · Medium
evidence mentions
11
Buzz score
39.9

CVE-2026-7544

Published Jul 11, 2026

The Mux Video Uploader plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.1.4 via the muxvideo_enqueue_settings_script. T…

CVSS 4.3 · Medium
evidence mentions
7
Buzz score
35.8

CVE-2026-12426

Published Jul 11, 2026

The Members – Membership & User Role Editor Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.2.22 via the member…

CVSS 5.3 · Medium
evidence mentions
7
Buzz score
35.8

CVE-2026-59155

Published Jul 10, 2026

Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. Prior to 2.2.5, the GET /api/v1/ddns and GET /api/v1/notification endpoints return…

CVSS 6.9 · Medium
evidence mentions
3
Buzz score
18.9

CVE-2026-55882

Published Jul 10, 2026

Tilt defines dev environments as code for microservice apps on Kubernetes. From 0.19.5 through 0.37.3, the Tilt HUD server mounts Go net/http/pprof handlers under /debug with no a…

CVSS 8.3 · High
evidence mentions
4
Buzz score
21.1

CVE-2026-57219

Published Jul 10, 2026

RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.20, 4.1.11, and 4.2.6, the obsolete GET /api/auth endpoint can disclose the OAuth 2 client secret on RabbitMQ i…

CVSS 8.7 · High
evidence mentions
9
Buzz score
39.5
Vendor/product tagsBeta · best-effort

CVE-2026-55664

Published Jul 10, 2026

Grist is spreadsheet software using Python as its formula language. Prior to 1.7.15, the GET /forms endpoint read table and column metadata without applying the document's access…

CVSS 4.3 · Medium
evidence mentions
3
Buzz score
18.9

CVE-2026-57474

Published Jul 10, 2026

Deloitte AI Assist for Customer disclosed some configuration information through public-facing API endpoints that accepted unauthenticated requests. This information could reduce…

CVSS 6.9 · Medium
evidence mentions
4
Buzz score
31.1
Vendor/product tagsBeta · best-effort

CVE-2026-59180

Published Jul 10, 2026

Apprise is an open source library which allows you to send a notification to almost all of the most popular notification services available. Prior to 1.11.0, Apprise HTTP-based no…

CVSS 3.1 · Low
evidence mentions
4
Buzz score
21.1

CVE-2026-55500

Published Jul 10, 2026

9Router is an AI router & token saver. Prior to 0.4.80, the /api/settings/database endpoint allows full database export (containing all credentials, API keys, OAuth tokens, and se…

CVSS 9.9 · Critical
evidence mentions
3
Buzz score
18.9

CVE-2026-57994

Published Jul 10, 2026

phpMyFAQ before 4.1.5 applies inconsistent active=yes and publication-date filtering across its public FAQ API endpoints, allowing unauthenticated attackers to retrieve inactive (…

CVSS 6.9 · Medium
evidence mentions
2
Buzz score
17.5

CVE-2026-15329

Published Jul 10, 2026

A vulnerability was found in zhayujie CowAgent up to 2.1.0. This issue affects the function BrowserTool._do_navigate of the file agent/tools/browser/browser_tool.py of the compone…

CVSS 2.1 · Low
evidence mentions
7
Buzz score
27.3

CVE-2026-59828

Published Jul 9, 2026

Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, post revisions that should be hidden from regular users could be leaked throu…

CVSS 5.3 · Medium
evidence mentions
9
Buzz score
28.0
Vendor/product tagsBeta · best-effort

CVE-2026-49256

Published Jul 9, 2026

Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, restricted tag and tag-group names attached to publicly readable categories a…

CVSS 6.3 · Medium
evidence mentions
5
Buzz score
22.9
Vendor/product tagsBeta · best-effort

CVE-2026-45788

Published Jul 9, 2026

Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, secure uploads could be exposed by pull_hotlinked_images when an attacker kne…

CVSS 6.3 · Medium
evidence mentions
9
Buzz score
28.0
Vendor/product tagsBeta · best-effort

CVE-2026-45780

Published Jul 9, 2026

Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, EventSerializer could expose invited group names, sample invitees, and attend…

CVSS 5.3 · Medium
evidence mentions
9
Buzz score
28.0
Vendor/product tagsBeta · best-effort
Showing 126-150 of 10,347 CVEsPage 6 of 414