Skip to main content

CWE archive

CWE-202 CVEs

Programmatic archive

35 CVEs tagged with CWE-2020 Critical, 15 High, 18 Medium, 2 Low, 0 Unrated.

CVE-2026-42797

Published May 25, 2026

Exposure of Sensitive Information Through Data Queries vulnerability in Apache Syncope. An administrator with adequate entitlements for Derived Schemas can create a malicious JEX…

CVSS 4.9 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-40245

Published Apr 16, 2026

Free5GC is an open-source Linux Foundation project for 5th generation (5G) mobile core networks. Versions 4.2.1 and below contain an information disclosure vulnerability in the UD…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-30778

Published Apr 15, 2026

The SkyWalking OAP /debugging/config/dump endpoint may leak sensitive configuration information of MySQL/PostgreSQL. This issue affects Apache SkyWalking: from 9.7.0 through 10.3…

CVSS 7.5 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-33530

Published Mar 26, 2026

InvenTree is an Open Source Inventory Management System. Prior to version 1.2.6, certain API endpoints associated with bulk data operations can be hijacked to exfiltrate sensitive…

CVSS 7.7 · High
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-3546

Published Mar 21, 2026

The e-shot form builder plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.0.2. The eshot_form_builder_get_account_data()…

CVSS 5.3 · Medium
evidence mentions
5
Buzz score
24.4

CVE-2026-25050

Published Jan 30, 2026

Vendure is an open-source headless commerce platform. Prior to version 3.5.3, the `NativeAuthenticationStrategy.authenticate()` method is vulnerable to a timing attack that allows…

CVSS 2.7 · Low
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2025-68456

Published Jan 5, 2026

Craft is a platform for creating digital experiences. In versions 5.0.0-RC1 through 5.8.20 and 3.0.0 through 4.16.16, unauthenticated users can trigger database backup operations…

CVSS 7.0 · High
Vendor/product tagsBeta · best-effort

CVE-2025-64528

Published Dec 30, 2025

Discourse is an open source discussion platform. Prior to versions 3.5.3, 2025.11.1, and 2025.12.0, an attacker who knows part of a username can find the user and their full name…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-69200

Published Dec 29, 2025

phpMyFAQ is an open source FAQ web application. In versions prior to 4.0.16, an unauthenticated remote attacker can trigger generation of a configuration backup ZIP via `POST /api…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-64504

Published Nov 10, 2025

Langfuse is an open source large language model engineering platform. Starting in version 2.70.0 and prior to versions 2.95.11 and 3.124.1, in certain project membership APIs, the…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-59352

Published Sep 17, 2025

Dragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.1.0, the gRPC API and HTTP APIs allow peers to send requests that force the recip…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-36575

Published Jun 10, 2025

Dell Wyse Management Suite, versions prior to WMS 5.2, contain an Exposure of Sensitive Information Through Data Queries vulnerability. An unauthenticated attacker with remote acc…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-29981

Published Apr 2, 2025

Dell Wyse Management Suite, versions prior to WMS 5.1, contains an Exposure of Sensitive Information Through Data Queries vulnerability. An unauthenticated attacker with remote ac…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-25205

Published Feb 12, 2025

Audiobookshelf is a self-hosted audiobook and podcast server. Starting in version 2.17.0 and prior to version 2.19.1, a flaw in the authentication bypass logic allows unauthentica…

CVSS 8.2 · High
evidence mentions
6
Buzz score
29.5
Vendor/product tagsBeta · best-effort

CVE-2024-6400

Published Oct 4, 2024

Cleartext Storage of Sensitive Information, Exposure of Sensitive Information Through Data Queries vulnerability in Finrota Netahsilat allows Retrieve Embedded Sensitive Data, Aut…

CVSS 8.2 · High
Vendor/product tagsBeta · best-effort

CVE-2024-1287

Published Jul 30, 2024

The pmpro-member-directory WordPress plugin before 1.2.6 does not prevent users with at least the contributor role from leaking other users' sensitive information, including passw…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-2088

Published May 22, 2024

The NextScripts: Social Networks Auto-Poster plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.4.3 via the 'nxs_getExpSe…

CVSS 8.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-7072

Published Mar 12, 2024

The Post Grid Combo – 36+ Gutenberg Blocks plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.2.68 via the 'get_posts' RE…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-1625

Published Sep 24, 2023

An information leak was discovered in OpenStack heat. This issue could allow a remote, authenticated attacker to use the 'stack show' command to reveal parameters which are suppos…

CVSS 7.4 · High
Vendor/product tagsBeta · best-effort

CVE-2023-20215

Published Aug 3, 2023

A vulnerability in the scanning engines of Cisco AsyncOS Software for Cisco Secure Web Appliance could allow an unauthenticated, remote attacker to bypass a configured rule, allow…

CVSS 5.8 · Medium
Showing 1-25 of 35 CVEsPage 1 of 2