CWE-359

CWE-359 · 4 records · 3 with a public proof-of-concept

Records the NVD classes under CWE-359, highest CVSS first.

  1. MEDIUM 6.5CVE-2026-76855public PoC

    Netcore NR255-V version 1.5.130703 contains a sensitive information disclosure vulnerability in the audit endpoints handled by l7_web_auth_log_dump_cgi.c, audit_get_cgi.c, and mod_dispatch_auth/plan.json. Attackers can query these audit components to obtain ot…

    AI risk analysis on Exploit-DB.ai →

  2. MEDIUM 6.5CVE-2026-24078

    Information Disclosure when IPSec negotiation fails or is not established properly during NG-eCall SIP signaling.

    5g fixed wireless access platform firmware · 5g fixed wireless access platform · ar8035 firmware · ar8035 · csra6620 firmware · csra6620

    AI risk analysis on Exploit-DB.ai →

  3. MEDIUM 5.3CVE-2026-92565public PoC

    Rallly before 4.15.0 contains an information disclosure vulnerability in the polls.get tRPC procedure that returns scheduled-event invitee names and email addresses to unauthenticated callers. Attackers can access a poll's urlId from public invite links to ret…

    AI risk analysis on Exploit-DB.ai →

  4. MEDIUM 4.9CVE-2026-39372public PoC

    InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2, InvoicePlane stores and serves uploaded image attachments without stripping EXIF metadata. When an administrator uploads an image through invoic…

    AI risk analysis on Exploit-DB.ai →