CVE-2026-25562
WeKan versions prior to 8.19 contain an information disclosure vulnerability in the attachments publication. Attachment metadata can be retu
CVSS
4.3
Medio
EPSS
0.3%
p21
KEV
—
Exploit Today
6
0-100
Publicado: 7 feb 2026 · Última mod.: 14 jul 2026 · CWE-203
0.3%EPSS · 30 días0.3%
2026-08-092026-09-05
WeKan versions prior to 8.19 contain an information disclosure vulnerability in the attachments publication. Attachment metadata can be returned without properly scoping results to boards and cards accessible to the requesting user, potentially exposing attachment metadata to unauthorized users.
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-78617—24.8%
——7WatchGuard Dimension's web login endpoint does not enforce effective rate-limiting or account lockout by default allowing a remote attacker to perform automated password guessing against user accounts. If the account lockout setting is enabled, brute-force attempts are blocked after a defined number of failed attempts, but this setting is not enabled by default.10dCVE-2026-370645.3 MED17.7%
——5User enumeration in /vfm-admin/ajax/usr-check.php in Veno File Manager Project 4.4.9 allows an unauthenticated attacker to enumerate the application users via sending a specially crafted POST request to the affected endpoint with a chosen 'user_name' parameter to test if the user exists.6dCVE-2026-117545.3 MED15.0%
——5Observable discrepancy vulnerability in Seres Software syWEB allows Account Footprinting.
This issue affects syWEB: through 27082026.
NOTE: The vendor was contacted and it was learned that the product is not supported.10dCVE-2026-552274.3 MED8.0%
——2Weblate is a web-based localization tool. In versions prior to 2026.7, several endpoints look up objects in a globally scoped manner rather than restricting the lookup to projects the user can access, so they return HTTP 403 (Forbidden) instead of 404 (Not Found) when a user requests an object they are not authorized to see. This difference lets unauthorized users infer whether a given object exists in a private Weblate project. The issue has been fixed in version 2026.7.11dCVE-2026-792875.3 MED19.8%
——6Observable discrepancy in Forms in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)11dCVE-2026-792425.3 MED19.8%
——6Observable discrepancy in HTML in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)10d