Skip to main content

CWE archive

CWE-200 CVEs

Programmatic archive

10,350 CVEs tagged with CWE-200345 Critical, 2,000 High, 6,835 Medium, 1,163 Low, 7 Unrated.

CVE-2026-36719

Published Jun 9, 2026

An information disclosure vulnerability in the /api/v1/user/info endpoint of AgentChat v2.3.0 allows unauthenticated attackers to obtain sensitive information, including SHA256 pa…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-47284

Published Jun 9, 2026

Exposure of sensitive information to an unauthorized actor in Visual Studio Code allows an unauthorized attacker to disclose information over a network.

CVSS 6.5 · Medium
evidence mentions
3
Buzz score
21.9
Vendor/product tagsBeta · best-effort

CVE-2026-45594

Published Jun 9, 2026

Exposure of sensitive information to an unauthorized actor in Windows Application Identity (AppID) Subsystem allows an authorized attacker to disclose information locally.

CVSS 5.5 · Medium
evidence mentions
3
Buzz score
21.9

CVE-2026-42973

Published Jun 9, 2026

Exposure of sensitive information to an unauthorized actor in Windows Push Notifications allows an authorized attacker to disclose information locally.

CVSS 5.5 · Medium
evidence mentions
4
Buzz score
25.6

CVE-2026-42971

Published Jun 9, 2026

Exposure of sensitive information to an unauthorized actor in Windows Push Notifications allows an authorized attacker to disclose information locally.

CVSS 5.5 · Medium
evidence mentions
4
Buzz score
25.6

CVE-2026-42907

Published Jun 9, 2026

Exposure of sensitive information to an unauthorized actor in Windows Shell allows an authorized attacker to disclose information over a network.

CVSS 6.5 · Medium
evidence mentions
3
Buzz score
21.9

CVE-2026-0411

Published Jun 9, 2026

An information disclosure vulnerability in the NETGEAR Orbi satellites (RBR/RBE/RBS Series) could allow a user connected to your network to gain administrator access to the Orbi r…

CVSS 4.2 · Medium
evidence mentions
6
Buzz score
29.5

CVE-2026-49742

Published Jun 9, 2026

Backend users with file download permissions were able to download files from the fallback storage of the file abstraction layer (FAL) via the Media Module. Since the fallback sto…

CVSS 7.1 · High
evidence mentions
3
Buzz score
23.9

CVE-2026-47351

Published Jun 9, 2026

Backend users were able to insert arbitrary records and files into the TYPO3 clipboard without proper read permission checks, which allowed users to gather information about recor…

CVSS 5.3 · Medium
evidence mentions
3
Buzz score
23.9

CVE-2026-7542

Published Jun 9, 2026

The Slider Revolution plugin for WordPress is vulnerable to Sensitive Information Disclosure in versions 7.0 to 7.0.10. This is due to three compounding design flaws: (1) the plug…

CVSS 6.5 · Medium
evidence mentions
3
Buzz score
28.9

CVE-2026-34905

Published Jun 9, 2026

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. The unlisted question feature did not…

CVSS 6.5 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-41980

Published Jun 9, 2026

Permission control vulnerability in the file preview module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

CVSS 5.5 · Medium
evidence mentions
3
Buzz score
18.9

CVE-2026-46443

Published Jun 8, 2026

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, when credentials are fetched with a credentialName filter paramete…

CVSS 7.0 · High
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-11464

Published Jun 7, 2026

A vulnerability was identified in JeecgBoot up to 3.9.2. Affected by this vulnerability is the function queryPageList of the file src\main\java\org\jeecg\modules\system\controller…

CVSS 1.3 · Low
evidence mentions
7
Buzz score
27.3

CVE-2026-11459

Published Jun 7, 2026

A security vulnerability has been detected in SecureAge CatchPulse up to 10.9.3. Impacted is an unknown function in the library saappctl.sys of the component IOCTL Handler. The ma…

CVSS 1.9 · Low
evidence mentions
6
Buzz score
31.0

CVE-2026-11458

Published Jun 7, 2026

A weakness has been identified in erzhongxmu JeeWMS up to 141740afb2ba14d441c82a833d0a418d07ca2d69. This issue affects some unknown processing of the file /base-boot/actuator of t…

CVSS 5.5 · Medium
evidence mentions
5
Buzz score
24.4

CVE-2026-11431

Published Jun 5, 2026

A path traversal vulnerability exists in the Projects Service download endpoint shared by Altium Enterprise Server and Altium 365. An authenticated user can supply a crafted path…

CVSS 8.3 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-11424

Published Jun 5, 2026

A server-side request forgery (SSRF) vulnerability exists in a GraphQL service component shared by Altium Enterprise Server and Altium 365. An authenticated user can submit a requ…

CVSS 8.3 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-45300

Published Jun 5, 2026

The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. Versions on the 2.x branch prior to 2.15.0 an…

CVSS 7.4 · High
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2026-46395

Published Jun 5, 2026

HAX CMS helps manage microsite universe with PHP or NodeJs backends. Prior to version 26.0.0, the `hmacBase64()` function in the HAXcms Node.js backend contains two critical crypt…

CVSS 9.3 · Critical
evidence mentions
1
Buzz score
11.9
Showing 301-325 of 10,350 CVEsPage 13 of 414