Threats Tagged 'cwe-200'
View all threats tagged with 'cwe-200'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-200'
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-53923: CWE-681: Incorrect Conversion between Numeric Types in vllm-project vllmCVE-2026-53923 0 vLLM versions from 0.5.5 up to but not including 0.23.1rc0 contain a vulnerability where integer truncation in the GGUF dequantize CUDA kernels causes partial tensor processing. This results in uninitialized portions of output tensors retaining residual GPU memory data, potentially exposing data from other users in multi-tenant inference environments. The issue is fixed starting with version 0.23.1rc0. Join the discussion | CVE Database V5 | 06/22/2026, 21:55:42 UTC Added: 06/22/2026, 22:39:45 UTC |
CVE-2026-54276: CWE-200: Exposure of Sensitive Information to an Unauthorized Actor in aio-libs aiohttpCVE-2026-54276 0 AIOHTTP versions prior to 3.14.1 contain a vulnerability in DigestAuthMiddleware where an authentication response can be sent after following a cross-origin redirect. This may expose sensitive information such as user credentials if an attacker exploits an open redirect on the target domain. The vulnerability is fixed in version 3.14.1. Join the discussion | CVE Database V5 | 06/22/2026, 16:36:23 UTC Added: 06/22/2026, 17:39:39 UTC |
CVE-2026-53571: CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in vitejs viteCVE-2026-53571 0 Vite is a frontend tooling framework for JavaScript. Prior to 8.0.16, 7.3.5, and 6.4.3, the contents of files that are specified by server.fs.deny can be returned to the browser on Windows. Vite’s dev server denies direct access to sensitive files through server.fs.deny, including entries such as .env, .env.*, and *.{crt,pem}. However, on Windows, the deny logic does not correctly normalize NTFS ADS path forms before access checks are applied. Because of this, requests such as /.env::$DATA?raw are treated as allowed paths, while Windows resolves them to the original file's default data stream. Similar to that, Windows allows accessing a file using a different name with the 8.3 short name compatibility feature. Vite did not reject accessing files via them. This vulnerability is fixed in 8.0.16, 7.3.5, and 6.4.3. Join the discussion | CVE Database V5 | 06/22/2026, 16:10:58 UTC Added: 06/22/2026, 17:39:39 UTC |
CVE-2026-7167: CWE-200 Exposure of Sensitive Information to an Unauthorized Actor in Gaudire Assassin gameCVE-2026-7167 0 The vulnerability arises when the system fails to properly validate the 'email' field during the authentication process, allowing unverified or fake email addresses to be accepted. This lack of validation enables the creation of user accounts with fake email addresses, facilitating the mass creation of fraudulent accounts. Successful exploitation of this vulnerability could allow an authenticated attacker to carry out various attacks, such as mass spam distribution, system abuse, or bypassing user controls, thereby compromising the security and integrity of the system. Join the discussion | CVE Database V5 | 06/22/2026, 12:50:35 UTC Added: 06/22/2026, 13:54:18 UTC |
CVE-2026-7166: CWE-200 Exposure of Sensitive Information to an Unauthorized Actor in Gaudire Assassin gameCVE-2026-7166 0 Vulnerability involving the exposure of sensitive data provided without adequate protection. The API exposes email and phone number data from the ‘email’ and ‘telefon’ fields. This vulnerability is also present in the local database, as it contains accessible sensitive information such as data on minors and municipal users. Successful exploitation of this vulnerability could allow an unauthenticated remote attacker to gain access to sensitive information and data. Join the discussion | CVE Database V5 | 06/22/2026, 12:47:47 UTC Added: 06/22/2026, 13:54:18 UTC |
CVE-2026-49336: CWE-178: Improper Handling of Case Sensitivity in microsoft kiota-typescriptCVE-2026-49336 0 @microsoft/kiota-http-fetchlibrary provides TypeScript libraries for Kiota-generated API clients. In versions 1.0.0-preview.97 through 1.0.0-preview.101, `@microsoft/kiota-http-fetchlibrary`'s `RedirectHandler` is documented as stripping `Authorization` and `Cookie` from cross-origin redirect targets, but the default `scrubSensitiveHeaders` callback in `RedirectHandlerOptions` uses case-sensitive property deletion (`delete headers.Authorization`, `delete headers.Cookie`) on a headers object that `FetchRequestAdapter.getRequestFromRequestInformation` has already lower-cased. The delete therefore targets keys that do not exist, the scrub is a no-op, and any Bearer token or Cookie attached by a kiota-generated SDK is forwarded to an attacker-controlled host across a 30x redirect. This is reachable in the default middleware chain (`MiddlewareFactory.getDefaultMiddlewares`) with no custom configuration, and applies to every kiota-generated TypeScript SDK that uses `BaseBearerTokenAuthenticationProvider` or any other authentication provider that sets the `Authorization` request header. Version 1.0.0-preview.102 patches the issue. Join the discussion | CVE Database V5 | 06/19/2026, 18:19:03 UTC Added: 06/19/2026, 18:37:16 UTC |
CVE-2026-49288: CWE-200: Exposure of Sensitive Information to an Unauthorized Actor in statamic cmsCVE-2026-49288 0 Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.73.23 and 6.20.0, an authenticated Control Panel user could view metadata and content for resources they don't have permission to view, including entries, assets, users, roles, groups, and other configured resources. Depending on the resource, this could expose titles, custom field values, entry content, asset metadata, and the existence of users, roles, and groups. No data could be modified. This has been fixed in 5.73.23 and 6.20.0. Join the discussion | CVE Database V5 | 06/19/2026, 18:11:53 UTC Added: 06/19/2026, 18:37:16 UTC |
CVE-2026-12620: CWE-200 in Microchip GridTime 3000CVE-2026-12620 0 The GridTime 3000 GNSS Time Server leaks the access token in the URL parameters of some endpoints. This issue affects GridTime 3000: from 1.0r0.03 through 1.1r0.0. Join the discussion | CVE Database V5 | 06/19/2026, 15:59:07 UTC Added: 06/19/2026, 16:20:40 UTC |
CVE-2026-47633: CWE-200: Exposure of Sensitive Information to an Unauthorized Actor in Microsoft Microsoft Cost ManagementCVE-2026-47633 0 Exposure of sensitive information to an unauthorized actor in Cost Management Interactive Experiences allows an unauthorized attacker to disclose information over a network. Join the discussion | CVE Database V5 | 06/18/2026, 21:37:36 UTC Added: 06/18/2026, 22:06:01 UTC |
CVE-2026-12111: CWE-200 Exposure of Sensitive Information to an Unauthorized Actor in codepeople Appointment Booking CalendarCVE-2026-12111 0 The Appointment Booking Calendar plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 1.4.01. This is due to insufficient authorization and missing per-calendar ownership checks in the cpabc_appointments_calendar_load2() function, which is reachable via the cpabc_calendar_load2=1 query parameter in wp-admin and only checks is_admin() && current_user_can('edit_posts'), a capability available to Contributor-level users and above. This makes it possible for authenticated attackers with Contributor-level access and above to supply an arbitrary calendar ID via the id parameter and extract customer booking information, including email addresses, names, phone numbers, booking times, and comments, from any calendar managed by the plugin. Join the discussion | CVE Database V5 | 06/18/2026, 06:50:06 UTC Added: 06/18/2026, 07:36:01 UTC |
Showing 1 to 10 of 76 results