CWE-524

CWE-524 · 3 records · 3 with a public proof-of-concept

Records the NVD classes under CWE-524, highest CVSS first.

  1. HIGH 7.3CVE-2026-25703public PoC

    NeuVector through 5.4.9 is can potentially leak information from manager /network/graph API due to missing authentication and cached data containing sensitive information.

    AI risk analysis on Exploit-DB.ai →

  2. UNSCOREDCVE-2026-19202public PoC

    A caching flaw in the toolbox-core package of the mcp-toolbox-sdk-python SDK causes the same Google ID token to be cached and reused across different audiences. If an application uses the SDK to authenticate to two or more different audiences within the same p…

    AI risk analysis on Exploit-DB.ai →

  3. UNSCOREDCVE-2026-89186public PoC

    Use of Cache Containing Sensitive Information in ZenHive mpp allows a shared HTTP cache to store a paid response and serve it to clients that never paid. MPP.Plug.verify_credential in lib/mpp/plug.ex sets payment-receipt and cache-control: private on the conn…

    AI risk analysis on Exploit-DB.ai →