CWE-424
CWE-424 · 3 records · 0 with a public proof-of-concept
Records the NVD classes under CWE-424, highest CVSS first.
- HIGH 7.7CVE-2026-107352
Missing authorization checks in Amazon Athena engine version 3 request handling could have allowed an authenticated user to read limited query metadata (AWS account identifiers and SQL statement text) from other AWS accounts. Query results, credentials, and Am…
- MEDIUM 6.5CVE-2026-89039
A caller who can invoke the convert_playwright_script prompt in mcp-k6 can pass a bare file path as the playwright_script argument and receive the contents of any file readable by the user running the server, including SSH keys and cloud credentials in that us…
- LOW 3.1CVE-2026-93353
copyparty contains a volume restriction bypass vulnerability in its SFTP front end that allows authenticated SFTP users to create, remove, and truncate arbitrary paths outside permitted volume boundaries by exploiting three handlers that bypass the xvol volfla…