Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

Filtering: Tag: cwe-200 Clear
ID Title
CVE-2026-54305 Information Disclosure in n8n (CVE-2026-54305)
vulnerability in n8n (CVE-2026-54305). Confidential information can be exposed externally. Exploitable via ``N8N_ENV_FEAT_DYNAMIC_CREDENTIALS``. Mitigation: upgrade to `2.25.7` or later.
CVE-2026-12117 Information Disclosure in devolutions (CVE-2026-12117)
vulnerability in devolutions (CVE-2026-12117). Risk of unauthorized operations or information disclosure.
CVE-2026-50019 Information Disclosure in yt-dlp (CVE-2026-50019)
vulnerability in yt-dlp (CVE-2026-50019). Confidential information can be exposed externally. Exploitable via ``curl``. Mitigation: upgrade to `2026.6.9` or later.
CVE-2026-12320 Information Disclosure in mozilla (CVE-2026-12320)
vulnerability in mozilla (CVE-2026-12320). Risk of unauthorized operations or information disclosure.
CVE-2026-12311 Information Disclosure in mozilla (CVE-2026-12311)
vulnerability in mozilla (CVE-2026-12311). Risk of unauthorized operations or information disclosure.
CVE-2026-49853 Information Disclosure in tornado (CVE-2026-49853)
vulnerability in tornado (CVE-2026-49853). Confidential information can be exposed externally. Exploitable via `Host header`. Mitigation: upgrade to `6.5.6` or later.
CVE-2026-50870 Information Disclosure in CVE-2026-50870 (CVE-2026-50870)
vulnerability in CVE-2026-50870 (CVE-2026-50870). Confidential information can be exposed externally.
CVE-2026-39007 Information Disclosure in CVE-2026-39007 (CVE-2026-39007)
vulnerability in CVE-2026-39007 (CVE-2026-39007). Confidential information can be exposed externally.
CVE-2026-54276 Information Disclosure in aiohttp (CVE-2026-54276)
vulnerability in aiohttp (CVE-2026-54276). Risk of unauthorized operations or information disclosure. Exploitable via ``DigestAuthMiddleware``. Mitigation: upgrade to `3.14.1` or later.
CVE-2026-54264 Information Disclosure in @angular/service-worker (CVE-2026-54264)
vulnerability in @angular/service-worker (CVE-2026-54264). Risk of unauthorized operations or information disclosure. Exploitable via ``Authorization``.
CVE-2026-53571 Path Traversal in vite (CVE-2026-53571)
path traversal in vite (CVE-2026-53571). Confidential information can be exposed externally. Exploitable via ``server.fs.deny``. Mitigation: upgrade to `6.4.3` or later.
CVE-2026-49356 Path Traversal in @babel/core (CVE-2026-49356)
path traversal in @babel/core (CVE-2026-49356). Risk of unauthorized operations or information disclosure. Exploitable via ``inputSourceMap``. Mitigation: upgrade to `7.29.6` or later.
CVE-2026-50184 Information Disclosure in @angular/service-worker (CVE-2026-50184)
vulnerability in @angular/service-worker (CVE-2026-50184). Risk of unauthorized operations or information disclosure. Exploitable via `Authorization header`.
CVE-2026-50169 Information Disclosure in @angular/service-worker (CVE-2026-50169)
vulnerability in @angular/service-worker (CVE-2026-50169). Risk of unauthorized operations or information disclosure. Exploitable via ``Request``. Mitigation: upgrade to `21.2.15` or later.
CVE-2026-8385 Information Disclosure in wordpress (CVE-2026-8385)
vulnerability in wordpress (CVE-2026-8385). Risk of unauthorized operations or information disclosure.
CVE-2026-12203 Information Disclosure in CVE-2026-12203 (CVE-2026-12203)
vulnerability in CVE-2026-12203 (CVE-2026-12203). Risk of unauthorized operations or information disclosure.
CVE-2026-54396 Information Disclosure in CVE-2026-54396 (CVE-2026-54396)
vulnerability in CVE-2026-54396 (CVE-2026-54396). Risk of unauthorized operations or information disclosure.
CVE-2026-47264 Information Disclosure in discourse (CVE-2026-47264)
vulnerability in discourse (CVE-2026-47264). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2026.1.4, 2026.3.1, 2026.4.1` or later.
CVE-2026-47263 Information Disclosure in discourse (CVE-2026-47263)
vulnerability in discourse (CVE-2026-47263). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2026.1.4, 2026.3.1, 2026.4.1` or later.
CVE-2026-45085 Information Disclosure in discourse (CVE-2026-45085)
vulnerability in discourse (CVE-2026-45085). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2026.1.4, 2026.3.1, 2026.4.1` or later.
CVE-2026-44786 Information Disclosure in discourse (CVE-2026-44786)
vulnerability in discourse (CVE-2026-44786). Confidential information can be exposed externally. Mitigation: upgrade to `2026.1.4, 2026.3.1, 2026.4.1` or later.
CVE-2026-44785 Information Disclosure in discourse (CVE-2026-44785)
vulnerability in discourse (CVE-2026-44785). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2026.1.4, 2026.3.1, 2026.4.1` or later.
CVE-2026-44784 Information Disclosure in discourse (CVE-2026-44784)
vulnerability in discourse (CVE-2026-44784). Confidential information can be exposed externally. Mitigation: upgrade to `2026.1.4, 2026.3.1, 2026.4.1` or later.
CVE-2026-44782 Information Disclosure in discourse (CVE-2026-44782)
vulnerability in discourse (CVE-2026-44782). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2026.1.4, 2026.3.1, 2026.4.1` or later.
CVE-2026-44780 Information Disclosure in discourse (CVE-2026-44780)
vulnerability in discourse (CVE-2026-44780). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2026.1.4, 2026.3.1, 2026.4.1` or later.
CVE-2026-44779 Information Disclosure in discourse (CVE-2026-44779)
vulnerability in discourse (CVE-2026-44779). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2026.1.4, 2026.3.1, 2026.4.1` or later.
CVE-2026-46371 Information Disclosure in github.com/fleetdm/fleet/v4 (CVE-2026-46371)
vulnerability in github.com/fleetdm/fleet/v4 (CVE-2026-46371). Confidential information can be exposed externally. Exploitable via `GET /api/v1/fleet/mdm/apple/commands`. Mitigation: upgrade to `4.84.2` or later.
CVE-2026-46370 SQL Injection in github.com/fleetdm/fleet/v4 (CVE-2026-46370)
SQL injection in github.com/fleetdm/fleet/v4 (CVE-2026-46370). Confidential information can be exposed externally. Exploitable via `GET /api/v1/fleet/labels/{id}/hosts`. Mitigation: upgrade to `4.84.2` or later.
CVE-2026-53725 Information Disclosure in parse-server (CVE-2026-53725)
vulnerability in parse-server (CVE-2026-53725). Risk of unauthorized operations or information disclosure. Exploitable via ``get``. Mitigation: upgrade to `9.9.1-alpha.5` or later.
CVE-2026-3433 Information Disclosure in github.com/mattermost/mattermost-server (CVE-2026-3433)
vulnerability in github.com/mattermost/mattermost-server (CVE-2026-3433). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `10.11.17` or later.
CVE-2026-6046 Information Disclosure in github.com/mattermost/mattermost-server (CVE-2026-6046)
vulnerability in github.com/mattermost/mattermost-server (CVE-2026-6046). Confidential information can be exposed externally. Mitigation: upgrade to `10.11.17` or later.
CVE-2026-50009 Information Disclosure in io.netty:netty-codec-classes-quic (CVE-2026-50009)
vulnerability in io.netty:netty-codec-classes-quic (CVE-2026-50009). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `4.2.15.Final` or later.
CVE-2026-44206 Information Disclosure in CVE-2026-44206 (CVE-2026-44206)
vulnerability in CVE-2026-44206 (CVE-2026-44206). Risk of unauthorized operations or information disclosure.
CVE-2026-47177 Information Disclosure in CVE-2026-47177 (CVE-2026-47177)
vulnerability in CVE-2026-47177 (CVE-2026-47177). Risk of unauthorized operations or information disclosure.
CVE-2026-47176 Information Disclosure in CVE-2026-47176 (CVE-2026-47176)
vulnerability in CVE-2026-47176 (CVE-2026-47176). Risk of unauthorized operations or information disclosure.
CVE-2026-48050 Information Disclosure in github.com/basekick-labs/arc (CVE-2026-48050)
vulnerability in github.com/basekick-labs/arc (CVE-2026-48050). Risk of unauthorized operations or information disclosure. Exploitable via ``PublicPrefixes``. Mitigation: upgrade to `0.0.0-20260520170331-32a4091fb949` or later.
CVE-2026-48007 Information Disclosure in @element-hq/element-call-embedded (CVE-2026-48007)
vulnerability in @element-hq/element-call-embedded (CVE-2026-48007). Risk of unauthorized operations or information disclosure. Exploitable via ``posthog``. Mitigation: upgrade to `0.19.4` or later.
CVE-2026-53912 Information Disclosure in CVE-2026-53912 (CVE-2026-53912)
vulnerability in CVE-2026-53912 (CVE-2026-53912). Risk of unauthorized operations or information disclosure.
CVE-2026-49219 Information Disclosure in Magick.NET-Q16-AnyCPU (CVE-2026-49219)
vulnerability in Magick.NET-Q16-AnyCPU (CVE-2026-49219). Confidential information can be exposed externally. Mitigation: upgrade to `14.14.0` or later.
CVE-2026-47751 OS Command Injection in anthropics/claude-code-action (CVE-2026-47751)
OS command injection in anthropics/claude-code-action (CVE-2026-47751). Risk of unauthorized operations or information disclosure. Exploitable via ``enableAllProjectMcpServers``. Mitigation: upgrade to `1.0.74` or later.
CVE-2026-48855 Information Disclosure in erlang (CVE-2026-48855)
vulnerability in erlang (CVE-2026-48855). Confidential information can be exposed externally.
CVE-2026-49397 Information Disclosure in github.com/nezhahq/nezha (CVE-2026-49397)
vulnerability in github.com/nezhahq/nezha (CVE-2026-49397). Risk of unauthorized operations or information disclosure. Exploitable via `GET /api/v1/service`. Mitigation: upgrade to `2.0.14` or later.
CVE-2026-45329 ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.5.4 and 6.0, several ESP-TEE secure-service wrappers in esp_secure_services.c and esp_secure_services_iram.c vali...
ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.5.4 and 6.0, several ESP-TEE secure-service wrappers in esp_secure_services.c and esp_secure_services_iram.c validated only some of the caller-supplied pointer arguments, leaving input pointer arguments unchecked....
CVE-2026-36719 Information Disclosure in CVE-2026-36719 (CVE-2026-36719)
vulnerability in CVE-2026-36719 (CVE-2026-36719). Confidential information can be exposed externally.
CVE-2026-42973 Information Disclosure in microsoft (CVE-2026-42973)
vulnerability in microsoft (CVE-2026-42973). Confidential information can be exposed externally.
CVE-2026-42971 Information Disclosure in microsoft (CVE-2026-42971)
vulnerability in microsoft (CVE-2026-42971). Confidential information can be exposed externally.
CVE-2026-42972 Information Disclosure in microsoft (CVE-2026-42972)
vulnerability in microsoft (CVE-2026-42972). Confidential information can be exposed externally.
CVE-2026-42970 Information Disclosure in microsoft (CVE-2026-42970)
vulnerability in microsoft (CVE-2026-42970). Confidential information can be exposed externally.
CVE-2026-42907 Information Disclosure in microsoft (CVE-2026-42907)
vulnerability in microsoft (CVE-2026-42907). Confidential information can be exposed externally.
CVE-2026-42906 Information Disclosure in microsoft (CVE-2026-42906)
vulnerability in microsoft (CVE-2026-42906). Confidential information can be exposed externally.

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →