Skip to main content

CWE archive

CWE-200 CVEs

Programmatic archive

10,661 CVEs tagged with CWE-200366 Critical, 2,099 High, 6,992 Medium, 1,199 Low, 5 Unrated.

CVE-2026-21579

Published Jul 21, 2026

This High severity Information Disclosure vulnerability was introduced in versions 7.17.0, 7.19.0, 8.5.0, 8.9.0, 9.0.1, 9.1.0, 9.2.0, 10.0.2, 10.1.0, and 10.2.0 of Confluence Data…

CVSS 8.2 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2026-47395

Published Jul 21, 2026

PraisonAI is a multi-agent teams system. Prior to version 4.6.40 of PraisonAI, corresponding to version 1.6.40 of praisonaiagents, PraisonAI's direct-prompt CLI automatically expa…

CVSS 5.5 · Medium
evidence mentions
3
Buzz score
18.9

CVE-2026-47394

Published Jul 21, 2026

PraisonAI is a multi-agent teams system. Prior to version 4.6.40, the fix for GHSA-9mqq-jqxf-grvw / CVE-2026-44336 is incomplete. The original advisory description named four vuln…

CVSS 8.7 · High
evidence mentions
3
Buzz score
18.9

CVE-2026-56584

Published Jul 21, 2026

HCL IEM was affected with the Information disclosure nginx server. It may enable attackers to identify outdated software versions and target known vulnerabilities or publicly avai…

CVSS 3.7 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-16405

Published Jul 21, 2026

Information disclosure in the Networking: WebSockets component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.

CVSS 7.5 · High
evidence mentions
5
Buzz score
27.9
Vendor/product tagsBeta · best-effort

CVE-2026-16391

Published Jul 21, 2026

Information disclosure in the Storage: IndexedDB component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.

CVSS 7.5 · High
evidence mentions
5
Buzz score
27.9
Vendor/product tagsBeta · best-effort

CVE-2026-16374

Published Jul 21, 2026

Information disclosure in the Framework component in DevTools. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.

CVSS 7.5 · High
evidence mentions
5
Buzz score
27.9
Vendor/product tagsBeta · best-effort

CVE-2026-16373

Published Jul 21, 2026

Information disclosure in the Privacy component in Firefox for Android. This vulnerability was fixed in Firefox 153.

CVSS 7.5 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-16354

Published Jul 21, 2026

Information disclosure in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 1…

CVSS 7.5 · High
evidence mentions
6
Buzz score
29.5
Vendor/product tagsBeta · best-effort

CVE-2026-65009

Published Jul 21, 2026

OpenRemote versions before 1.26.2 contain an information disclosure vulnerability in the SyslogResource REST endpoint that fails to filter operational logs by realm. Attackers wit…

CVSS 5.3 · Medium
evidence mentions
2
Buzz score
17.5

CVE-2026-44231

Published Jul 20, 2026

RT is an open source, enterprise-grade issue and ticket tracking system. Versions prior to 5.0.10, 6.0.0 and above, prior to 6.0.3 contain an information disclosure and privilege…

CVSS 9.1 · Critical
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-60031

Published Jul 20, 2026

Joomla Extension - themexpert.com - Information disclosure in Quix Page Builder < 6.2.1 - The Joomla extension Quix Page Builder Pro is vulnerable to an information disclosure. Ra…

CVSS 6.9 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-51027

Published Jul 20, 2026

An issue in FileThingie v.2.5.7 allows a remote attacker to obtain sensitive information via the ft2.php component.

CVSS 9.9 · Critical
evidence mentions
2
Buzz score
16.0

CVE-2026-46410

Published Jul 20, 2026

FileBrowser Quantum is a free, self-hosted, web-based file manager. Versions prior to 1.3.2-stable and 1.4.1-beta may leak some sensitive info, such as source and path. Versions 1…

CVSS 8.7 · High
evidence mentions
2
Buzz score
16.0

CVE-2026-63746

Published Jul 20, 2026

SurrealDB versions before 3.1.0 fail to enforce table SELECT permissions when traversing graph edges or back-references. Authenticated users can read records from any table reacha…

CVSS 7.1 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2026-8825

Published Jul 20, 2026

The Elementor Website Builder WordPress plugin before 4.1.4 does not properly check user permissions before returning post data through one of its REST endpoints, allowing authen…

CVSS 4.9 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2026-16201

Published Jul 19, 2026

A vulnerability was found in zevorn rt-claw up to 0.2.0. Affected is the function claw_net_get/claw_net_post of the file claw/services/tools/net.c of the component http_request. T…

CVSS 5.5 · Medium
evidence mentions
6
Buzz score
26.0

CVE-2026-44979

Published Jul 17, 2026

@hapi/wreck is an HTTP client utility. Prior to 18.1.1, when @hapi/wreck follows a 3xx redirect to a different hostname, only the Authorization and Cookie headers are stripped, an…

CVSS 6.3 · Medium
evidence mentions
4
Buzz score
21.1

CVE-2026-52203

Published Jul 17, 2026

An issue in MCMS v.6.1.1 allows a remote attacker to obtain sensitive information via the source parameter.

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-48009

Published Jul 17, 2026

Shopware is an open commerce platform. Prior to 6.6.10.18 and 6.7.10.1, a low-privilege admin user with user_recovery:read ACL can take over any admin account by triggering POST /…

CVSS 6.8 · Medium
evidence mentions
6
Buzz score
24.5

CVE-2026-49211

Published Jul 17, 2026

Symfony UX is a JavaScript ecosystem for Symfony. From 2.2.0 until 2.36.0 and 3.1.0, Symfony\UX\Autocomplete\Doctrine\EntitySearchUtil::addSearchClause() builds the LIKE expressio…

CVSS 6.9 · Medium
evidence mentions
4
Buzz score
21.1
Vendor/product tagsBeta · best-effort

CVE-2026-16108

Published Jul 17, 2026

A flaw was found in the default-groups REST endpoint and realm representation of Keycloak. This component is responsible for managing groups that are automatically assigned to new…

CVSS 4.3 · Medium
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort
Showing 351-375 of 10,661 CVEsPage 15 of 427