Skip to main content

CWE archive

CWE-200 CVEs

Programmatic archive

10,464 CVEs tagged with CWE-200351 Critical, 2,035 High, 6,889 Medium, 1,185 Low, 4 Unrated.

CVE-2026-54659

Published Jul 28, 2026

Pagy is agnostic pagination in plain Ruby. From 43.0.0 until 43.5.6, Pagy::I18n.locale= in gem/lib/pagy/modules/i18n/i18n.rb stored locale values verbatim and later used them as <…

CVSS 6.9 · Medium
evidence mentions
4
Buzz score
21.1

CVE-2026-55403

Published Jul 28, 2026

datamodel-code-generator generates Python data models from schema definitions. Prior to 0.63.0, src/datamodel_code_generator/http.py get_body reuses Authorization, Cookie, and Pro…

CVSS 3.7 · Low
evidence mentions
3
Buzz score
18.9

CVE-2026-55390

Published Jul 28, 2026

datamodel-code-generator generates Python data models from schema definitions. From 0.59.0 until 0.62.0, XML Schema parsing in src/datamodel_code_generator/parser/xmlschema.py for…

CVSS 7.5 · High
evidence mentions
3
Buzz score
18.9

CVE-2026-55389

Published Jul 28, 2026

datamodel-code-generator generates Pydantic v2 models, dataclasses, TypedDict, and msgspec.Struct from OpenAPI, JSON Schema, GraphQL, Avro, Protobuf, and raw JSON, YAML, or CSV. P…

CVSS 7.5 · High
evidence mentions
3
Buzz score
18.9

CVE-2026-54605

Published Jul 28, 2026

OAuth is a Ruby wrapper for the OAuth 1.0 and 1.0a protocols, providing clients and servers. From 0.5.5 to 1.1.5, OAuth::Consumer#token_request parses the raw Location header of a…

CVSS 7.2 · High
evidence mentions
3
Buzz score
18.9

CVE-2026-54603

Published Jul 28, 2026

OAuth2 is a Ruby wrapper for the OAuth 2.0 and 2.1 authorization frameworks, including OpenID Connect (OIDC). From 0.4.0 to 2.0.21, a protocol-relative redirect Location returned…

CVSS 8.6 · High
evidence mentions
3
Buzz score
18.9

CVE-2026-8058

Published Jul 28, 2026

IBM OPENBMC FW1110.00 through FW1110.20, and FW1060.00 through FW1060.71 allows a user to supply a password with a resource dump request stores that password into the BMC audit lo…

CVSS 4.5 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-65881

Published Jul 28, 2026

Joomla Extension - joomdle.com - Insecure default configuration allows read/write user account access in Joomdle < 3.1.1 - The default configuration of the extension allowed read…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-18038

Published Jul 28, 2026

A flaw has been found in nextlevelbuilder GoClaw up to 3.13.2. Affected by this vulnerability is the function ExecTool.Execute of the file goclaw/internal/http/tools_invoke.go of…

CVSS 2.1 · Low
evidence mentions
7
Buzz score
27.3

CVE-2026-16773

Published Jul 28, 2026

The WPBot – AI ChatBot for Live Support, Lead Generation, AI Services plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 8.…

CVSS 5.3 · Medium
evidence mentions
6
Buzz score
26.0

CVE-2026-15012

Published Jul 28, 2026

The Demi – One Click Demo Import, WP Backup & Site Migration plugin for WordPress is vulnerable to Arbitrary Directory Copy in all versions up to, and including, 0.0.8 via the han…

CVSS 5.3 · Medium
evidence mentions
12
Buzz score
32.1

CVE-2026-51078

Published Jul 27, 2026

An issue in Dede CMS v.5.7.118 allows a remote attacker to obtain sensitive information via the str parameter of the file_manage_control.php component

CVSS 7.5 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-64755

Published Jul 27, 2026

An authorization issue was addressed with improved state management. This issue is fixed in iOS 26.6 and iPadOS 26.6. An app may be able to access sensitive user data.

CVSS 5.5 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-64744

Published Jul 27, 2026

An information leakage was addressed with additional validation. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to disclose…

CVSS 5.5 · Medium
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2026-64734

Published Jul 27, 2026

The issue was addressed with improved checks. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, visionOS 26.6, watchOS…

CVSS 5.5 · Medium
evidence mentions
6
Buzz score
24.5

CVE-2026-64710

Published Jul 27, 2026

A privacy issue was addressed by removing sensitive data. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to leak sensitive…

CVSS 5.5 · Medium
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2026-43800

Published Jul 27, 2026

An information disclosure issue was addressed by removing the vulnerable code. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, watchOS 26.6. An app m…

CVSS 5.5 · Medium
evidence mentions
4
Buzz score
21.1

CVE-2026-43797

Published Jul 27, 2026

This issue was addressed with improved checks. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6. An app may be able to access information about a user's contacts.

CVSS 5.5 · Medium
evidence mentions
2
Buzz score
16.0

CVE-2026-43782

Published Jul 27, 2026

This issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to access sensitive user data.

CVSS 5.5 · Medium
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2026-43759

Published Jul 27, 2026

An authorization issue was addressed with improved state management. This issue is fixed in macOS Tahoe 26.6, watchOS 26.6. An app may be able to access sensitive user data.

CVSS 5.5 · Medium
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort
Showing 1-25 of 10,464 CVEsPage 1 of 419