Vulnerability index

Browse CVEs

1,244 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Insufficiently Protected CredentialsCWE-522 × clear
Unclassified MEDIUM 6.9
CVE-2026-53454

Blueprint Studio is a VS Code-like file editor for Home Assistant configuration files. Prior to 2.5.2, Blueprint Studio configured Git's credential.h…

Fix unknown
Fix from $4,000 2026-08-18
Unclassified MEDIUM 5.6
CVE-2026-53456

Blueprint Studio is a VS Code-like file editor for Home Assistant configuration files. Prior to 2.5.2, Blueprint Studio terminal SSH key authenticati…

Fix unknown
Fix from $4,000 2026-08-18
Unclassified MEDIUM 6.0
CVE-2026-15806

The HTTPPasswordMgr class in the urllib.request module, along with its subclasses HTTPPasswordMgrWithDefaultRealm and HTTPPasswordMgrWithPriorAuth, d…

Fix unknown
Fix from $4,000 2026-08-18
Unclassified HIGH 8.5
CVE-2026-57485

Stirling-PDF is a locally hosted web application that facilitates various operations on PDF files. Prior to 2.9.0, the /api/v1/pipeline/handleData en…

Fix unknown
Fix from $4,900 2026-08-17
Unclassified CRITICAL 9.0
CVE-2026-14564

Insufficiently Protected Credentials vulnerability in Innotim Software Telecommunications and Consulting Trade Ltd. Co. Logsign SIEM allows Retrieve …

Fix unknown
Fix from $5,750 2026-08-17
Unclassified HIGH 7.7
CVE-2026-72857

Budibase before 3.40.0 fails to redact datasource credentials stored in STRING typed fields, allowing authenticated users to read MongoDB connection …

No fix yet
Fix from $4,900 2026-08-13
Unclassified HIGH 7.5
CVE-2026-72801

SiYuan versions before v3.7.4 disclose encrypted-notebook key-derivation material and wrapped data keys through unauthenticated endpoints in publish …

No fix yet
Fix from $4,900 2026-08-12
Unclassified HIGH 8.6
CVE-2026-72793

SiYuan versions before v3.7.4 fail to mask sensitive configuration fields in the /api/system/getConf endpoint, allowing anonymous or publish-reader u…

No fix yet
Fix from $4,900 2026-08-12
Unclassified HIGH 8.6
CVE-2026-72794

siyuan versions before v3.7.4 expose the session cookie signing key through the /api/system/getConf endpoint to unauthenticated users in publish mode…

No fix yet
Fix from $4,900 2026-08-12
Unclassified MEDIUM 6.8
CVE-2026-49349

regclient is a Docker and OCI Registry Client in Go. Prior to version 0.11.5, credentials for a registry may be inadvertently leaked to external serv…

No fix yet
Fix from $4,000 2026-08-12
Sharepoint Server MEDIUM 6.5
CVE-2026-62839

Insufficiently protected credentials in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

Fix: 16.0.19725.20522+
Fix from $4,000 2026-08-11
Unclassified MEDIUM 6.3
CVE-2026-71577

A flaw was found in multicluster-global-hub. During a ManagedClusterMigration, the system incorrectly grants all managed hubs read access to a shared…

No fix yet
Fix from $4,000 2026-08-10
Unclassified HIGH 8.2
CVE-2026-12984

Insufficiently Protected Credentials vulnerability in Zyxel Networks WAH7601 allows Retrieve Embedded Sensitive Data. This issue affects WAH7601: th…

No fix yet
Fix from $4,900 2026-08-10
Unclassified HIGH 8.7
CVE-2026-47662

Pathling is a set of tools that make it easier to use FHIR and clinical terminology within health data analytics. Prior to version 2.0.0 of Pathling …

No fix yet
Fix from $1,950 2026-08-07
Unclassified HIGH 8.7
CVE-2026-47660

Pathling is a set of tools that make it easier to use FHIR and clinical terminology within health data analytics. Prior to version 2.0.0 of Pathling …

No fix yet
Fix from $1,950 2026-08-07
Unclassified MEDIUM 5.4
CVE-2026-21766

The default login portlet in HCL Digital Experience and Digital Experience Compose insufficiently protects credentials.  Under certain very specific …

No fix yet
Fix from $1,600 2026-08-05
Unclassified MEDIUM 6.5
CVE-2026-71260

ESPHome through 2026.7.0-dev discloses plaintext passwords via its web_server component. In WebServer::text_json_ (esphome/components/web_server/web_…

No fix yet
Fix from $1,600 2026-08-05
Unclassified CRITICAL 9.9
CVE-2026-52855

Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to 1.12.3, {{config.}} placeholders in egg…

No fix yet
Fix from $2,300 2026-07-31
Icontrol MEDIUM 5.3
CVE-2026-56570

HCL iControl was affected by Auto complete Enabled vulnerabilities. It involves expose sensitive information such as: Valid usernames, Email addresse…

No fix yet
Fix from $1,600 2026-07-31
Pgadmin 4 CRITICAL 9.6
CVE-2026-17349

/misc/workspace/adhoc_connect_server, part of the Workspaces feature introduced in pgAdmin 4 9.0, when passed the id of an existing server, clones th…

Fix: 9.17+
Fix from $2,300 2026-07-31
Sglang HIGH 7.5
CVE-2026-15977

SGLang contains a credential leakage vulnerability in the /server_info endpoint, which will return API keys and SSL keyfile information when only the…

Fix: after 0.5.15
Fix from $1,950 2026-07-30
Unclassified MEDIUM 6.5
CVE-2026-15657

A vulnerability in the foreUP customer REST API allows any authenticated user to read cleartext payment-processor merchant credentials in the respons…

No fix yet
Fix from $1,600 2026-07-30
GitLab MEDIUM 5.4
CVE-2026-16553

GitLab has remediated an issue in GitLab EE affecting all versions from 18.8 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under cer…

Fix: 19.0.5 / 19.1.3+
Fix from $1,600 2026-07-29
Unclassified HIGH 8.6
CVE-2026-67425

Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.6, llm.chat reads provider keys such as OPENAI_API_KEY and AN…

No fix yet
Fix from $1,950 2026-07-29
Unclassified CRITICAL 9.3
CVE-2026-67426

Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.7, the standalone flyto-verification service in src/core/veri…

No fix yet
Fix from $2,300 2026-07-29
Unclassified HIGH 8.6
CVE-2026-67427

Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.6, the workflow engine variable resolver expands ${env.VAR} f…

No fix yet
Fix from $1,950 2026-07-29
Unclassified HIGH 7.4
CVE-2026-54660

swagger-typescript-api generates API clients for Fetch or Axios from OpenAPI specifications. Prior to 13.12.2, src/resolved-swagger-schema.ts getRemo…

No fix yet
Fix from $1,950 2026-07-29
Unclassified HIGH 8.7
CVE-2026-14354

CWE-522 Insufficiently Protected Credentials vulnerability exists that could cause authentication bypass and unauthorized credential modification, po…

No fix yet
Fix from $1,950 2026-07-29
Unclassified MEDIUM 5.5
CVE-2026-54422

In OpenStack Ironic Python Agent through 11.5.0, a malicious bootc container, when deployed using ironic-python-agent, may be able to extract the cre…

No fix yet
Fix from $1,600 2026-07-24
Unclassified MEDIUM 6.5
CVE-2026-48022

@hapi/wreck is an HTTP client utility. Prior to 18.1.2, Wreck strips credential headers including Authorization, Cookie, and Proxy-Authorization befo…

No fix yet
Fix from $1,600 2026-07-17