CVE-2026-69507
Insertion of sensitive information into externally-accessible file or directory in Microsoft Windows Search Component allows an authorized a
CVSS
5.7
Medio
EPSS
—
KEV
—
Exploit Today
—
0-100
Publicado: 8 sept 2026 · Última mod.: 8 sept 2026 · CWE-538
Sin historial EPSS suficiente todavía.
Insertion of sensitive information into externally-accessible file or directory in Microsoft Windows Search Component allows an authorized attacker to disclose information over a network.
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-67361—6.0%
——2Joomla Extension - j2commerce.com - Unauthenticated file upload with missing directory protection in J2Store 1.0.0-3.3.20, 4.0.0-4.0.20, 4.1.0-4.1.5 - The file upload endpoint accepted POST requests from unauthenticated visitors with no CSRF token. Compounding this, the installer manifest omitted the upload and invoices directories, causing fresh installs to deploy those directories without .htaccess/web.config protection, making uploaded files directly web-accessible.18dCVE-2026-192295.3 MED25.6%
——8A vulnerability was determined in SourceCodester Online Clothing Store. Affected by this issue is some unknown functionality of the file /_notes/ of the component Dreamweaver Metadata Files. Executing a manipulation can lead to file and directory information exposure. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized.27dCVE-2026-127625.3 MED15.1%
——5IBM Cloud Pak For Business Automation 24.0.0, 24.0.1, 25.0.0, and 26.0.0 could allow a remote attacker to obtain sensitive information exposed in manifest files.29dCVE-2026-155747.5 ALT36.9%
——11A flaw was found in the vllm-orchestrator-gateway component. The system's production binary logs all incoming authorization headers and full chat payloads, which may contain personally identifiable information (PII) and secrets, to persistent logs. This sensitive data, including bearer tokens and chat content, can be accessed by any user with logging privileges. This vulnerability leads to information disclosure, potentially allowing an attacker to harvest credentials and sensitive conversation content.57dCVE-2025-363725.5 MED22.6%
——7IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 for Linux, UNIX and Windows (includes Db2 Connect Server) could disclose sensitive information to an authenticated user from the monitoring and event tables.68dCVE-2026-29114—8.6%
——3A vulnerability has been found in some Dahua products. An attacker
may obtain the device’s CA root certificate. If that CA is installed and
trusted on client systems, the attacker could issue fraudulent certificates
trusted by those clients and undermine the certificate trust chain.48d