Skip to main content

CWE archive

CWE-200 CVEs

Programmatic archive

10,383 CVEs tagged with CWE-200349 Critical, 2,013 High, 6,846 Medium, 1,169 Low, 6 Unrated.

CVE-2026-47177

Published Jun 11, 2026

Quest Bot is an opensource modern Discord Bot built for moderation, utilities and support. Prior to version 1.0.4, a user who can configure bot settings can set the ticket transcr…

CVSS 5.7 · Medium
evidence mentions
2
Buzz score
16.0

CVE-2026-47176

Published Jun 11, 2026

Quest Bot is an opensource modern Discord Bot built for moderation, utilities and support. Prior to version 1.0.4, a user who can configure bot settings can enable logging and cho…

CVSS 5.7 · Medium
evidence mentions
2
Buzz score
16.0

CVE-2026-44486

Published Jun 11, 2026

Axios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16.0, Axios’ Node.js HTTP adapter can leak proxy credentials to a redirect target in affect…

CVSS 7.5 · High
evidence mentions
41
Buzz score
43.0
Vendor/product tagsBeta · best-effort

CVE-2026-53912

Published Jun 11, 2026

Cerebrate before version 1.37 exposed credential material from self-registration requests. The self-registration workflow stored the registrant’s hashed password in the inbox mess…

CVSS 5.1 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-49219

Published Jun 10, 2026

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-48 and 7.1.2-24, an incorrect parsing of the filename can r…

CVSS 5.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-47165

Published Jun 10, 2026

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-48 and 7.1.2-23, the distributed pixel cache was originally…

CVSS 4.1 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-48855

Published Jun 10, 2026

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Erlang OTP ssh (ssh_sftpd module) allows File Discovery. The SSH_FXP_READLINK handler in ssh_sftpd sen…

CVSS 2.3 · Low
evidence mentions
5
Buzz score
30.9
Vendor/product tagsBeta · best-effort

CVE-2026-45329

Published Jun 10, 2026

ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.5.4 and 6.0, several ESP-TEE secure-service wrappers in esp_secure_services.c and esp_secure…

CVSS 7.1 · High
evidence mentions
4
Buzz score
21.1
Vendor/product tagsBeta · best-effort

CVE-2026-36719

Published Jun 9, 2026

An information disclosure vulnerability in the /api/v1/user/info endpoint of AgentChat v2.3.0 allows unauthenticated attackers to obtain sensitive information, including SHA256 pa…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-47284

Published Jun 9, 2026

Exposure of sensitive information to an unauthorized actor in Visual Studio Code allows an unauthorized attacker to disclose information over a network.

CVSS 6.5 · Medium
evidence mentions
3
Buzz score
21.9
Vendor/product tagsBeta · best-effort

CVE-2026-45594

Published Jun 9, 2026

Exposure of sensitive information to an unauthorized actor in Windows Application Identity (AppID) Subsystem allows an authorized attacker to disclose information locally.

CVSS 5.5 · Medium
evidence mentions
3
Buzz score
21.9

CVE-2026-42973

Published Jun 9, 2026

Exposure of sensitive information to an unauthorized actor in Windows Push Notifications allows an authorized attacker to disclose information locally.

CVSS 5.5 · Medium
evidence mentions
4
Buzz score
25.6

CVE-2026-42971

Published Jun 9, 2026

Exposure of sensitive information to an unauthorized actor in Windows Push Notifications allows an authorized attacker to disclose information locally.

CVSS 5.5 · Medium
evidence mentions
4
Buzz score
25.6

CVE-2026-42907

Published Jun 9, 2026

Exposure of sensitive information to an unauthorized actor in Windows Shell allows an authorized attacker to disclose information over a network.

CVSS 6.5 · Medium
evidence mentions
3
Buzz score
21.9

CVE-2026-0411

Published Jun 9, 2026

An information disclosure vulnerability in the NETGEAR Orbi satellites (RBR/RBE/RBS Series) could allow a user connected to your network to gain administrator access to the Orbi r…

CVSS 4.2 · Medium
evidence mentions
6
Buzz score
29.5

CVE-2026-49742

Published Jun 9, 2026

Backend users with file download permissions were able to download files from the fallback storage of the file abstraction layer (FAL) via the Media Module. Since the fallback sto…

CVSS 7.1 · High
evidence mentions
3
Buzz score
23.9

CVE-2026-47351

Published Jun 9, 2026

Backend users were able to insert arbitrary records and files into the TYPO3 clipboard without proper read permission checks, which allowed users to gather information about recor…

CVSS 5.3 · Medium
evidence mentions
3
Buzz score
23.9

CVE-2026-7542

Published Jun 9, 2026

The Slider Revolution plugin for WordPress is vulnerable to Sensitive Information Disclosure in versions 7.0 to 7.0.10. This is due to three compounding design flaws: (1) the plug…

CVSS 6.5 · Medium
evidence mentions
3
Buzz score
28.9

CVE-2026-34905

Published Jun 9, 2026

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. The unlisted question feature did not…

CVSS 6.5 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-41980

Published Jun 9, 2026

Permission control vulnerability in the file preview module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

CVSS 5.5 · Medium
evidence mentions
3
Buzz score
18.9

CVE-2026-46443

Published Jun 8, 2026

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, when credentials are fetched with a credentialName filter paramete…

CVSS 7.0 · High
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort
Showing 326-350 of 10,383 CVEsPage 14 of 416