Threats Tagged 'cwe-202'
View all threats tagged with 'cwe-202'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-202'
Click on any threat for detailed analysis and mitigation recommendations
0 Exposure of sensitive information through data queries vulnerability in The Wikimedia Foundation MediaWiki PageTriage extension allows Information Elicitation. This issue affects MediaWiki PageTriage extension: 1.46, 1.45, and 1.43. Join the discussion | CVE Database V5 | 09/30/2026, 17:38:27 UTC Added: 09/30/2026, 17:48:56 UTC |
0 Exposure of sensitive information through data queries vulnerability in Apache Syncope. An administrator with adequate entitlements for Derived Schemas can create a malicious JEXL expression which allows any administrator with sufficient entitlements for User read to access LinkedAccount's (if present) or Manager's (if defined) sensitive information, possibly including hashed credentials. This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 Through 4.0.7, from 4.1.0-M0 through 4.1.2. Users are recommended to upgrade to version 4.0.8 / 4.1.3, which fix this issue. Join the discussion | CVE Database V5 | 09/14/2026, 12:30:53 UTC Added: 09/14/2026, 12:47:56 UTC |
CVE-2026-16520 is a high-severity vulnerability affecting multiple versions of Genians Genian NAC and Genian ZTNA products. It involves improper input validation and exposure of sensitive information through data queries, leading to SQL Injection and authentication bypass. The affected versions span Genian NAC V4.0, V5.0, and Genian ZTNA V6.0, with specific version ranges detailed. The vulnerability has a CVSS 4.0 base score of 8.7, indicating a significant risk if exploited. Join the discussion | CVE Database V5 | 08/20/2026, 23:57:34 UTC Added: 08/21/2026, 00:37:39 UTC |
0 CVE-2026-25703 is a high-severity vulnerability in SUSE NeuVector versions up to and including 5.4.9. It involves missing authentication for the critical /network/graph API in the manager component, which can lead to potential information leakage through cached sensitive data. Join the discussion | CVE Database V5 | 08/05/2026, 09:48:19 UTC Added: 08/05/2026, 10:12:00 UTC |
0 Flowise is a drag-and-drop user interface for building customized large language model (LLM) flows. Prior to 3.1.3, Flowise GET /api/v1/upsert-history returns the entire server-wide upsert history instead of being scoped to the requesting user, tenant, or workspace. The response can exceed 100MB and includes sensitive configuration data, including Vector Store settings such as Qdrant Server URL and collection name. The observed behavior indicates missing or insufficient authorization checks, workspace/project/tenant isolation, and pagination or limits, exposing integration parameters and infrastructure details that may enable further targeted attacks. This issue is fixed in version 3.1.3. Join the discussion | CVE Database V5 | 08/04/2026, 17:56:50 UTC Added: 08/04/2026, 18:34:00 UTC |
0 Apache Syncope contains a vulnerability that allows exposure of sensitive information through crafted data queries. Specifically, an administrator with entitlements to manage Derived Schemas can create malicious JEXL expressions. These expressions enable any administrator with User read entitlements to access security-sensitive user information. The issue affects Apache Syncope versions 3.0 through 3.0.16, 4.0 through 4.0.5, and 4.1.0. Upgrading to versions 4.0.6 or 4.1.1 mitigates this vulnerability by restricting JEXL expression definitions. Join the discussion | CVE Database V5 | 05/25/2026, 15:00:55 UTC Added: 05/25/2026, 15:40:00 UTC |
0 CVE-2026-30778 is a vulnerability in Apache SkyWalking versions 9.7.0 through 10.3.0 where the /debugging/config/dump endpoint may expose sensitive configuration information related to MySQL and PostgreSQL databases. This exposure can lead to unauthorized access to critical configuration data. The issue is resolved in Apache SkyWalking version 10.4.0, which users are advised to upgrade to. The vulnerability has a CVSS score of 7. Join the discussion | CVE Database V5 | 04/15/2026, 10:54:25 UTC Added: 04/15/2026, 11:02:08 UTC |
0 The e-shot form builder plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.0.2. The eshot_form_builder_get_account_data() function is registered as a wp_ajax_ AJAX handler accessible to all authenticated users. The function lacks any capability check (e.g., current_user_can('manage_options')) and does not verify a nonce. It directly queries the database for the e-shot API token stored in the eshotformbuilder_control table and returns it along with all subaccount data as a JSON response. This makes it possible for authenticated attackers, with Subscriber-level access and above, to extract the e-shot API token and subaccount information, which could then be used to access the victim's e-shot platform account. Join the discussion | CVE Database V5 | 03/21/2026, 03:26:56 UTC Added: 03/21/2026, 04:01:20 UTC |
0 Vendure is an open-source headless commerce platform. Prior to version 3.5.3, the `NativeAuthenticationStrategy.authenticate()` method is vulnerable to a timing attack that allows attackers to enumerate valid usernames (email addresses). In `packages/core/src/config/auth/native-authentication-strategy.ts`, the authenticate method returns immediately if a user is not found. The significant timing difference (~200-400ms for bcrypt vs ~1-5ms for DB miss) allows attackers to reliably distinguish between existing and non-existing accounts. Version 3.5.3 fixes the issue. Join the discussion | CVE Database V5 | 01/30/2026, 15:11:40 UTC Added: 01/30/2026, 15:27:48 UTC |
0 CVE-2025-68456 is a high-severity vulnerability in Craft CMS versions 3.0.0 through 4.16.16 and 5.0.0-RC1 through 5.8.20 that allows unauthenticated users to trigger database backup operations. This can lead to resource exhaustion or potential information disclosure due to lack of limits or throttling on resource allocation. Join the discussion | CVE Database V5 | 01/05/2026, 22:03:11 UTC Added: 01/05/2026, 22:22:50 UTC |
Showing 1 to 10 of 15 results