Vulnerability index

Browse CVEs

1,244 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Insufficiently Protected CredentialsCWE-522 × clear
Aiohttp MEDIUM 6.1
CVE-2026-54276

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, DigestAuthMiddleware can send an authentication resp…

Fix: 3.14.1+
Fix from $1,600 2026-06-22
Unclassified MEDIUM 5.5
CVE-2026-53632

launch-editor allows users to open files with line numbers in editor from Node.js. Prior to 2.14.1, the launch-editor NPM package accesses arbitrary …

Mitigation only
Fix from $1,600 2026-06-22
Openclaw HIGH 7.1
CVE-2026-53840

OpenClaw before 2026.5.12 contains an information disclosure vulnerability in streamable-http MCP servers that forwards operator-configured custom he…

Fix: 2026.5.12+
Fix from $1,950 2026-06-16
Mattermost Desktop HIGH 7.7
CVE-2026-6517

Mattermost Desktop App versions <=6.1 5.5.13.0 fail to restrict the allow list of domains to which NTLM credentials were forwarded to in the Mattermo…

Fix: after 6.1.5
Fix from $1,950 2026-06-15
Unclassified MEDIUM 5.3
CVE-2026-49949

CodexBar before 0.33.0 contains a credential forwarding vulnerability that allows network-adjacent attackers to intercept sensitive credentials by is…

Patch available
Fix from $1,600 2026-06-11
Unclassified MEDIUM 6.1
CVE-2026-41715

In specific scenarios involving HTTP redirects from a secure to an insecure endpoint, the Reactor Netty HTTP client may leak credentials. In order fo…

Mitigation only
Fix from $1,600 2026-06-09
Unclassified MEDIUM 6.5
CVE-2026-39908

OpenBullet2 through version 0.3.2 on Windows contains a credential disclosure vulnerability that allows remote attackers to capture the NTLMv2 hash o…

Mitigation only
Fix from $1,600 2026-06-08
Flowise CRITICAL 9.1
CVE-2026-46440

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, the checkBasicAuth endpoint validate…

Fix: 3.1.2+
Fix from $2,300 2026-06-08
Unclassified HIGH 8.7
CVE-2026-46511

HAX CMS helps manage microsite universe with PHP or NodeJs backends. Prior to version 26.0.0, an attack chain utilizing Stored XSS alongside dynamic …

Mitigation only
Fix from $1,950 2026-06-05
Sitefinity HIGH 7.5
CVE-2026-7312

CWE‑522: Insufficiently Protected Credentials in web services in Progress Sitefinity version from 14.0.7700 to 14.4.8152, and 15.0.8200 to 15.0.8234,…

Fix: 14.4.8152 / 15.0.8234+
Fix from $1,950 2026-06-02
Teamcity MEDIUM 6.5
CVE-2026-49379

In JetBrains TeamCity before 2026.1 credentials could be exposed in thread names

Fix: 2026.1+
Fix from $1,600 2026-05-29
Interschalt Vdr G4e Firmware MEDIUM 5.4
CVE-2026-42951

An authenticated user can download a backup of the Danelec MacGregor Voyage Data Recorder device which includes account data and password hashes.

Fix: 5.250+
Fix from $1,600 2026-05-29
Unclassified HIGH 7.1
CVE-2026-39968

TypeBot is a chatbot builder tool. In versions 3.15.2 and prior, the fix for GHSA-4xc5-wfwc-jw47 ("Credential Theft via Client-Side Script Execution …

Patch available
Fix from $1,950 2026-05-22
Unclassified HIGH 7.1
CVE-2025-13477

Exposure of private personal information to an unauthorized actor, Insufficiently Protected Credentials vulnerability in Digital Operations Services …

Mitigation only
Fix from $1,950 2026-05-21
Visualization MEDIUM 6.5
CVE-2026-0393

The affected product may expose credentials remotely between low privileged visualization users during concurrent login operations due to insufficien…

Fix: 4.10.0.0+
Fix from $1,600 2026-05-21
Mattermost Server MEDIUM 6.5
CVE-2026-6345

Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 fail prevent disclosure of created user password which allows a malicious…

Fix: 10.11.14 / 11.4.4+
Fix from $1,600 2026-05-18
Curl MEDIUM 5.9
CVE-2026-6253

curl might erroneously pass on credentials for a first proxy to a second proxy. This can happen when the following conditions are true: 1. curl is …

Fix: 8.20.0+
Fix from $1,600 2026-05-13
Unclassified CRITICAL 9.8
CVE-2026-43992

JunoClaw is an agentic AI platform built on Juno Network. Prior to 0.x.y-security-1, every MCP write tool (send_tokens, execute_contract, instantiate…

Patch available
Fix from $2,300 2026-05-12
Unclassified MEDIUM 6.5
CVE-2026-8368

LWP::UserAgent versions before 6.83 for Perl leak Authorization and Proxy-Authorization headers on cross-origin redirects. On a 3xx response, the re…

Patch available
Fix from $1,600 2026-05-12
Unclassified CRITICAL 9.1
CVE-2026-45091

sealed-env is a cross-stack, zero-trust secret management library for Node.js and Java/Spring Boot. In sealed-env enterprise mode, versions 0.1.0-alp…

Mitigation only
Fix from $2,300 2026-05-12
Unclassified CRITICAL 10.0
CVE-2026-42869

SOCFortress CoPilot focuses on providing a single pane of glass for all your security operations needs. Prior to 0.1.57, SOCFortress CoPilot ships a …

Patch available
Fix from $2,300 2026-05-11
Go Git HIGH 7.4
CVE-2026-41506

go-git is an extensible git implementation library written in pure Go. Prior to versions 5.18.0 and 6.0.0-alpha.2, go-git may leak HTTP authenticatio…

Fix: 5.18.0+
Fix from $1,950 2026-05-08
Bigfix Service Management HIGH 7.5
CVE-2025-31976

HCL BigFix Service Management (SM) is vulnerable to insufficiently protected credentials for a short duration while communicating with a backend, int…

Mitigation only
Fix from $1,950 2026-05-06
Unclassified MEDIUM 5.1
CVE-2026-23927

A user able to connect to Agent 2 can inject an Oracle TNS connection string via the 'service' parameter. This can lead to Agent 2 connecting to an a…

Mitigation only
Fix from $1,600 2026-05-06
Gv Lpc2011 Firmware MEDIUM 6.5
CVE-2026-42367

A privilege escalation vulnerability exists in the Web Interface / ssi.cgi functionality of GeoVision LPC2011/LPC2211 1.10. A specially crafted HTTP …

Mitigation only
Fix from $1,600 2026-05-04
Unclassified MEDIUM 5.4
CVE-2026-6446

The My Social Feeds – Social Feeds Embedder plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to and including …

Mitigation only
Fix from $1,600 2026-05-02
Container MEDIUM 6.5
CVE-2026-28909

Users who connect to malicious registries with hostnames matching the bypass patterns will have their registry credentials exposed in plaintext. This…

Fix: 0.12.3+
Fix from $1,600 2026-04-30
Idrac10 Firmware HIGH 7.1
CVE-2026-35155

Dell iDRAC10, versions 1.20.70.50 and 1.30.05.10, contains an Insufficiently Protected Credentials vulnerability. A race condition vulnerability exis…

Fix: 1.30.10.50+
Fix from $1,950 2026-04-29
X3500 Firmware HIGH 8.1
CVE-2026-39462

A vulnerability exists in SenseLive X3050’s web management interface in which password updates are not reliably applied due to improper handling of c…

Mitigation only
Fix from $1,950 2026-04-24
Openclaw MEDIUM 5.3
CVE-2026-41345

OpenClaw before 2026.3.31 contains a credential exposure vulnerability in media download functionality that forwards Authorization headers across cro…

Fix: 2026.3.31+
Fix from $1,600 2026-04-23