Skip to main content

CWE archive

CWE-212 CVEs

Programmatic archive

119 CVEs tagged with CWE-2124 Critical, 38 High, 60 Medium, 17 Low, 0 Unrated.

CVE-2024-5300

Published Jul 21, 2026

An access control bypass and information disclosure vulnerability exists in the base AppArmor security profile configuration of Canonical snapd. The abstraction rules located in /…

CVSS 5.6 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-15811

Published Jul 21, 2026

A vulnerability was found in kronosnet's (version <=1.34) cryptographic configuration management. The framework does not correctly zero-out or wipe sensitive memory segments after…

CVSS 5.8 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2026-45737

Published Jul 15, 2026

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. From 3.2.0 until 3.2.12, 3.3.10, and 3.4.2, Argo CD ServerSideDiff can expose Kubernetes Secret values em…

CVSS 6.3 · Medium
evidence mentions
8
Buzz score
27.0
Vendor/product tagsBeta · best-effort

CVE-2026-54421

Published Jun 14, 2026

In OpenStack Ironic before 37.0.1, when applying a PATCH to update fields in volume properties the user is authorized for, Ironic can return unredacted sensitive information (such…

CVSS 6.8 · Medium
evidence mentions
3
Buzz score
25.4

CVE-2026-46657

Published Jun 8, 2026

Bludit is a content management system. Versions prior to 3.22.0 have a vulnerability in the user management logic that allows deactivated accounts to maintain access via persisten…

CVSS 7.1 · High
evidence mentions
2
Buzz score
16.0

CVE-2026-36178

Published Jun 4, 2026

The factory reset functionality in GNCC GP5 v7.1.76 fails to clear sensitive cryptographic material in the JFFS2 configuration partition, possibly allowing attackers to recover an…

CVSS 4.6 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-45046

Published May 27, 2026

Gryph provides a security layer for AI coding agents. Prior to 0.7.0, Gryph implements logging levels that determine what content is logged to a local sqlite database. The README…

CVSS 5.5 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-27892

Published May 18, 2026

FacturaScripts is an open source accounting and invoicing software. In versions prior to 2026, the Library module stores and serves uploaded images byte-for-byte, without strippin…

CVSS 6.5 · Medium
evidence mentions
2
Buzz score
16.0

CVE-2026-42186

Published May 14, 2026

OpenBao is an open source identity-based secrets management system. Prior to 2.5.3, when OpenBao's initial namespace deletion fails, subsequent retries fail to properly remove all…

CVSS 2.3 · Low
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2026-42880

Published May 7, 2026

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. From versions 3.2.0 to before 3.2.11 and 3.3.0 to before 3.3.9, there is a missing authorization and data…

CVSS 9.6 · Critical
evidence mentions
7
Buzz score
33.8
Vendor/product tagsBeta · best-effort

CVE-2026-43528

Published May 5, 2026

OpenClaw before 2026.4.14 contains a redaction bypass vulnerability that allows authenticated gateway clients to receive unredacted secrets through sourceConfig and runtimeConfig…

CVSS 7.1 · High
evidence mentions
3
Buzz score
20.4
Vendor/product tagsBeta · best-effort

CVE-2026-43824

Published May 2, 2026

In Argo CD 3.2.0 before 3.2.11 and 3.3.0 before 3.3.9, ServerSideDiff allows reading cleartext Kubernetes Secret data.

CVSS 7.7 · High
evidence mentions
4
Buzz score
29.1

CVE-2026-40895

Published Apr 21, 2026

follow-redirects is an open source, drop-in replacement for Node's `http` and `https` modules that automatically follows redirects. Prior to 1.16.0, when an HTTP request follows a…

CVSS 6.9 · Medium
evidence mentions
42
Buzz score
43.0
Vendor/product tagsBeta · best-effort

CVE-2026-20928

Published Apr 14, 2026

Improper removal of sensitive information before storage or transfer in Windows Recovery Environment Agent allows an unauthorized attacker to bypass a security feature with a phys…

CVSS 4.6 · Medium
evidence mentions
2
Buzz score
17.5

CVE-2026-39937

Published Apr 7, 2026

Improper removal of sensitive information before storage or transfer vulnerability in The Wikimedia Foundation Mediawiki - CentralAuth Extension allows Resource Leak Exposure. The…

CVSS 8.8 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-34214

Published Mar 31, 2026

Trino is a distributed SQL query engine for big data analytics. From version 439 to before version 480, Iceberg connector REST catalog static credentials (access key) or vended cr…

CVSS 7.7 · High
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-32891

Published Mar 20, 2026

Anchorr is a Discord bot for requesting movies and TV shows and receiving notifications when items are added to a media server. Versions 1.4.1 and below contain a stored XSS vulne…

CVSS 9.0 · Critical
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-1182

Published Mar 12, 2026

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 8.14 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2 that could have allowed an authenticated…

CVSS 4.3 · Medium
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2026-1732

Published Mar 11, 2026

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.6 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2 that could have allowed an authenticated…

CVSS 4.3 · Medium
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort

CVE-2026-27640

Published Feb 25, 2026

tfplan2md is software for converting Terraform plan JSON files into human-readable Markdown reports. Prior to version 1.26.1, a bug in tfplan2md affected several distinct renderin…

CVSS 8.5 · High
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2025-8860

Published Feb 18, 2026

A flaw was found in QEMU in the uefi-vars virtual device. When the guest writes to register UEFI_VARS_REG_BUFFER_SIZE, the .write callback `uefi_vars_write` is invoked. The functi…

CVSS 3.3 · Low

CVE-2025-61643

Published Feb 3, 2026

Vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/recentchanges/RecentChangeRCFeedNotifier.Php. This issue affects Med…

CVSS 2.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-59955

Published Jan 5, 2026

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Coolify versions prior to and including v4.0.0-beta.420.8 have an information d…

CVSS 5.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-68131

Published Dec 31, 2025

cbor2 provides encoding and decoding for the Concise Binary Object Representation (CBOR) serialization format. Starting in version 3.0.0 and prior to version 5.8.0, whhen a CBORDe…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 119 CVEsPage 1 of 5