Vulnerability index

Browse CVEs

1,244 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Insufficiently Protected CredentialsCWE-522 × clear
Unclassified MEDIUM 6.3
CVE-2026-44979

@hapi/wreck is an HTTP client utility. Prior to 18.1.1, when @hapi/wreck follows a 3xx redirect to a different hostname, only the Authorization and C…

No fix yet
Fix from $1,600 2026-07-17
Build Of Keycloak MEDIUM 6.5
CVE-2026-16104

A flaw was found in the authentication configuration endpoint of the keycloak-services component, which is the core engine for Red Hat Build of Keycl…

No fix yet
Fix from $1,600 2026-07-17
Openclaw MEDIUM 6.5
CVE-2026-62214

OpenClaw versions before 2026.5.28 Bot Framework contains an improper input validation vulnerability that allows lower-trust callers to expose bot to…

Fix: 2026.5.28+
Fix from $1,600 2026-07-17
Openclaw MEDIUM 6.5
CVE-2026-62208

OpenClaw before 2026.6.5 could forward Authorization headers during MCP SSE redirects. When the affected feature is enabled and reachable, a lower-tr…

Fix: 2026.6.5+
Fix from $1,600 2026-07-17
Openclaw MEDIUM 6.5
CVE-2026-62213

OpenClaw versions before 2026.5.27 contain a token leakage vulnerability in MS Teams outbound requests that allows lower-trust callers to expose Bot …

Fix: 2026.5.27+
Fix from $1,600 2026-07-17
Unclassified HIGH 7.1
CVE-2026-46458

ICU Scandinavia Boomerang is vulnerable to an information disclosure flaw where sensitive credential files are exposed via static HTTP. This allows a…

Mitigation only
Fix from $1,950 2026-07-15
C2pa HIGH 7.5
CVE-2026-48295

CAI Content Credentials is affected by an Insufficiently Protected Credentials vulnerability that could result in disclosure of sensitive information…

Fix: after 0.84.0
Fix from $1,950 2026-07-14
Unclassified CRITICAL 9.6
CVE-2026-59891

sigstore-js provides JavaScript libraries for interacting with Sigstore services. Prior to 0.7.1, getRegistryCredentials() reads credentials from the…

Mitigation only
Fix from $2,300 2026-07-14
Visual Studio Code MEDIUM 6.5
CVE-2026-47282

Insufficiently protected credentials in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to disclose information over a network.

Fix: 1.128.1+
Fix from $1,600 2026-07-14
Unclassified CRITICAL 9.1
CVE-2026-62327

9Router through version 0.4.41 contains an unauthenticated information disclosure vulnerability that allows remote attackers to retrieve plaintext AP…

Mitigation only
Fix from $2,300 2026-07-13
Rabbitmq Server HIGH 7.5
CVE-2026-57219

RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.20, 4.1.11, and 4.2.6, the obsolete GET /api/auth endpoint can disclose the OAuth…

Fix: 4.2.6+
Fix from $1,950 2026-07-10
Unclassified MEDIUM 6.8
CVE-2026-55885

Grav is a file-based Web platform. Prior to 1.7.53, an authenticated administrator with backup permissions can download a ZIP archive containing the …

Mitigation only
Fix from $1,600 2026-07-10
N8n MEDIUM 6.5
CVE-2026-59209

n8n is an open source workflow automation platform. Prior to 1.123.61, 2.27.4, and, 2.28.1, an authenticated member with use-only editor access to a …

Fix: 1.123.61 / 2.27.4+
Fix from $1,600 2026-07-09
Openclaw MEDIUM 6.5
CVE-2026-59261

OpenClaw before 2026.5.28 contains a credential exposure vulnerability where workspace dotenv files can override provider credentials. Attackers with…

Fix: 2026.5.28+
Fix from $1,600 2026-07-08
Unclassified CRITICAL 9.9
CVE-2026-56843

Incorrect authorization in the XML-RPC API of WebPros Plesk before 18.0.78.4 allows a low-privileged authenticated customer to look up domains they d…

Mitigation only
Fix from $2,300 2026-07-08
Coder MEDIUM 6.1
CVE-2026-55431

Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2, `coder o…

Fix: 2.29.17 / 2.32.7+
Fix from $1,600 2026-07-08
Unclassified HIGH 7.1
CVE-2026-7017

HTTP::Tiny versions before 0.095 for Perl forward credential headers to cross-origin redirect targets. When the server returns a 3xx redirect, `_may…

Patch available
Fix from $1,950 2026-07-07
Unclassified HIGH 8.8
CVE-2026-44938

A vulnerability has been identified in Fleet's agent-side deployer, which did not filter security-sensitive keys from namespaceLabels in fleet.yaml (…

Mitigation only
Fix from $1,950 2026-07-07
Curl CRITICAL 9.1
CVE-2026-8926

When asking curl to use a `.netrc` file to find credentials and at the same time specifying a URL with a username(without a password), like `https://…

Fix: 8.21.0+
Fix from $2,300 2026-07-03
Curl CRITICAL 9.8
CVE-2026-9079

libcurl had a flaw that when instructed to clear proxy authentication credentials which made it not do so, leaving the old credentials around to get …

Fix: 8.21.0+
Fix from $2,300 2026-07-03
Chrome MEDIUM 6.5
CVE-2026-14019

Inappropriate implementation in Passwords in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to leak cross-origin data via a crafted H…

Fix: 150.0.7871.47+
Fix from $1,600 2026-06-30
Unclassified MEDIUM 6.5
CVE-2026-56783

Parseable before 2.9.2 contains an information disclosure vulnerability in the notification-target API endpoints that returns webhook tokens and basi…

Patch available
Fix from $1,600 2026-06-29
Unclassified MEDIUM 6.8
CVE-2025-7386

Information exposure vulnerability in Hitachi Storage Navigator. This issue affects Hitachi Virtual Storage Platform 5100, 5200, 5500, 5600, 5100H, …

Mitigation only
Fix from $1,600 2026-06-29
Unclassified HIGH 8.2
CVE-2026-55188

RustFS is a distributed object storage system built in Rust. From 1.0.0-alpha.1 until 1.0.0-beta.9, RustFS contains an authorization bypass in the bu…

Mitigation only
Fix from $1,950 2026-06-26
Dokku MEDIUM 5.5
CVE-2026-45407

Dokku is a docker-powered PaaS. Prior to 0.38.2, the git:auth command creates $DOKKU_ROOT/.netrc using bash's touch command, which applies the defaul…

Fix: 0.38.2+
Fix from $1,600 2026-06-26
Unclassified MEDIUM 6.5
CVE-2026-44622

Charging station authentication identifiers are publicly accessible via web-based mapping platforms.

Mitigation only
Fix from $1,600 2026-06-25
Pnpm MEDIUM 6.5
CVE-2026-55180

pnpm is a package manager. Prior to 10.34.2 and 11.5.3, pnpm and pacquet expanded ${ENV_VAR} placeholders from repository-controlled .npmrc and pnpm-…

Fix: 10.34.2 / 11.5.3+
Fix from $1,600 2026-06-25
Pnpm MEDIUM 6.5
CVE-2026-50017

pnpm is a package manager. Prior to 10.34.0 and 11.4.0, pnpm can send user-level unscoped npm authentication credentials to a registry chosen by a re…

Fix: 10.34.0 / 11.4.0+
Fix from $1,600 2026-06-25
Easylogic T150 Firmware HIGH 7.5
CVE-2026-9650

CWE-522 Insufficiently Protected Credentials vulnerability that could cause unauthorized access and exposure of sensitive information when unauthenti…

Fix: 11.06.32 / 11.06.38+
Fix from $1,950 2026-06-25
Unclassified MEDIUM 5.5
CVE-2026-32315

motionEye (mEye) is an online interface for motion software, a video surveillance program with motion detection. Versions prior to 0.44.0 create the …

Mitigation only
Fix from $1,600 2026-06-24