Skip to main content

CWE archive

CWE-200 CVEs

Programmatic archive

10,350 CVEs tagged with CWE-200345 Critical, 2,000 High, 6,835 Medium, 1,163 Low, 7 Unrated.

CVE-2026-49256

Published Jul 9, 2026

Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, restricted tag and tag-group names attached to publicly readable categories a…

CVSS 6.3 · Medium
evidence mentions
5
Buzz score
22.9
Vendor/product tagsBeta · best-effort

CVE-2026-45788

Published Jul 9, 2026

Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, secure uploads could be exposed by pull_hotlinked_images when an attacker kne…

CVSS 6.3 · Medium
evidence mentions
9
Buzz score
28.0
Vendor/product tagsBeta · best-effort

CVE-2026-45780

Published Jul 9, 2026

Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, EventSerializer could expose invited group names, sample invitees, and attend…

CVSS 5.3 · Medium
evidence mentions
9
Buzz score
28.0
Vendor/product tagsBeta · best-effort

CVE-2025-63579

Published Jul 9, 2026

Unauthorized use of Kyocera printers, allows all information stored in the Kyocera address book to be exported. The security measure that encrypts incoming data ian be bypassed wi…

CVSS 7.5 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-59720

Published Jul 9, 2026

Hoppscotch is an open source API development ecosystem. Prior to 2026.6.0, mock server creation in mock-server.service.ts does not persist the isPublic input field while schema.pr…

CVSS 7.5 · High
evidence mentions
4
Buzz score
21.1

CVE-2026-59222

Published Jul 9, 2026

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.7.0 before 0.10.0, GET /api/v1/channels//members returned full UserModelResponse objec…

CVSS 6.0 · Medium
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2026-59216

Published Jul 9, 2026

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.10.0, get_event_call delivered execute:python and execute:tool Socket.IO events to…

CVSS 7.7 · High
evidence mentions
4
Buzz score
21.1
Vendor/product tagsBeta · best-effort

CVE-2026-59209

Published Jul 9, 2026

n8n is an open source workflow automation platform. Prior to 1.123.61, 2.27.4, and, 2.28.1, an authenticated member with use-only editor access to a shared workflow could read cre…

CVSS 7.1 · High
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2026-57481

Published Jul 8, 2026

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.9.1-alpha.13 and 8.6.83, a LiveQuery subscriber could receive ob…

CVSS 2.3 · Low
evidence mentions
7
Buzz score
25.8

CVE-2026-15044

Published Jul 8, 2026

A flaw was found in the TrustyAI Service Operator. When deploying services like gorch or NemoGuardrails, if a specific security setting is not enabled, these services can expose t…

CVSS 6.3 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2026-56298

Published Jul 8, 2026

Capgo before 12.128.2 fails to strip EXIF metadata from images uploaded via the app information endpoint, exposing sensitive geolocation data. Attackers can upload images containi…

CVSS 5.3 · Medium
evidence mentions
2
Buzz score
17.5

CVE-2026-56284

Published Jul 8, 2026

Capgo (Cap-go/capgo) before 12.128.2 contains an information disclosure vulnerability in the Supabase PostgREST RPC function public.get_total_metrics(org_id), which is callable by…

CVSS 6.9 · Medium
evidence mentions
2
Buzz score
17.5

CVE-2026-56226

Published Jul 8, 2026

Capgo (Cap-go/capgo) before 12.128.2 exposes the Supabase PostgREST RPC function public.get_orgs_v6(userid uuid), which is SECURITY DEFINER and granted to the anon role, allowing…

CVSS 8.7 · High
evidence mentions
2
Buzz score
17.5

CVE-2026-44877

Published Jul 7, 2026

An unauthenticated remote disclosure vulnerability has been identified in HPE Networking Instant On 1830, 1930, and 1960 Switches. Successful exploitation of this vulnerability co…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-49487

Published Jul 7, 2026

In Apache Airflow before 3.3.0, the REST API task-instance detail and list endpoints returned a deferred task's trigger kwargs without masking. When a deferred operator passed a s…

CVSS 6.5 · Medium
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort

CVE-2026-48892

Published Jul 7, 2026

The Config API in Apache Airflow surfaced per-key secrets-backend overrides (environment variables like `AIRFLOW__SECRETS__BACKEND_KWARG__SECRET_ID` and `AIRFLOW__WORKERS__SECRETS…

CVSS 6.5 · Medium
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort

CVE-2026-48891

Published Jul 7, 2026

A bug in Apache Airflow's `/ui/dependencies` scheduling graph endpoint applied the caller's readable-Dag filter to the top-level serialized Dag key but still emitted referenced Da…

CVSS 4.3 · Medium
evidence mentions
3
Buzz score
28.9
Vendor/product tagsBeta · best-effort

CVE-2026-48828

Published Jul 7, 2026

The Bulk Variables API in Apache Airflow called the redactor without passing the variable's key, so the key-based `should_hide_value_for_key` check (which triggers on secret-suffi…

CVSS 6.5 · Medium
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort

CVE-2026-53647

Published Jul 7, 2026

FOSSBilling is a free, open-source billing and client management system. In versions 0.5.3 through 0.7.2, the Guest `serviceapikey/get_info` API endpoint is accessible without aut…

CVSS 6.9 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-53643

Published Jul 6, 2026

FOSSBilling is a free, open-source billing and client management system. Versions prior to 0.8.0 allow low-privileged staff accounts to perform unauthorized actions via admin API…

CVSS 8.7 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-53640

Published Jul 6, 2026

FOSSBilling is a free, open-source billing and client management system. Prior to version 0.8.0, low-privileged staff accounts may read sensitive data via admin API endpoints that…

CVSS 2.3 · Low
evidence mentions
1
Buzz score
11.9

CVE-2026-14898

Published Jul 6, 2026

The OpenAI Codex desktop app for macOS rendered remote images from Markdown in model responses. An attacker who could place an indirect prompt injection in content processed by Co…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-55994

Published Jul 6, 2026

Improper Input Validation, Exposure of Sensitive Information to an Unauthorized Actor, Server-Side Request Forgery (SSRF) vulnerability in Apache Camel in Iggy component. The cam…

CVSS 7.5 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-55993

Published Jul 6, 2026

Improper Input Validation, Exposure of Sensitive Information to an Unauthorized Actor, Server-Side Request Forgery (SSRF) vulnerability in Apache Camel in Atmosphere Websocket Com…

CVSS 7.5 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-46726

Published Jul 6, 2026

Improper Input Validation, Exposure of Sensitive Information to an Unauthorized Actor, Server-Side Request Forgery (SSRF) vulnerability in Apache Camel in Vertx Websocket componen…

CVSS 7.5 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort
Showing 151-175 of 10,350 CVEsPage 7 of 414