CWE-202

CWE-202 · 3 records · 2 with a public proof-of-concept

Records the NVD classes under CWE-202, highest CVSS first.

  1. HIGH 7.3CVE-2026-25703public PoC

    NeuVector through 5.4.9 is can potentially leak information from manager /network/graph API due to missing authentication and cached data containing sensitive information.

    AI risk analysis on Exploit-DB.ai →

  2. UNSCOREDCVE-2026-103440

    Exposure of sensitive information through data queries vulnerability in The Wikimedia Foundation MediaWiki PageTriage extension allows Information Elicitation. This issue affects MediaWiki PageTriage extension: 1.46, 1.45, and 1.43.

    AI risk analysis on Exploit-DB.ai →

  3. UNSCOREDCVE-2026-70473public PoC

    Flowise is a drag-and-drop user interface for building customized large language model (LLM) flows. Prior to 3.1.3, Flowise GET /api/v1/upsert-history returns the entire server-wide upsert history instead of being scoped to the requesting user, tenant, or work…

    AI risk analysis on Exploit-DB.ai →