CWE-202
CWE-202 · 3 records · 2 with a public proof-of-concept
Records the NVD classes under CWE-202, highest CVSS first.
- HIGH 7.3CVE-2026-25703public PoC
NeuVector through 5.4.9 is can potentially leak information from manager /network/graph API due to missing authentication and cached data containing sensitive information.
- UNSCOREDCVE-2026-103440
Exposure of sensitive information through data queries vulnerability in The Wikimedia Foundation MediaWiki PageTriage extension allows Information Elicitation. This issue affects MediaWiki PageTriage extension: 1.46, 1.45, and 1.43.
- UNSCOREDCVE-2026-70473public PoC
Flowise is a drag-and-drop user interface for building customized large language model (LLM) flows. Prior to 3.1.3, Flowise GET /api/v1/upsert-history returns the entire server-wide upsert history instead of being scoped to the requesting user, tenant, or work…