Vulnerability index

Browse CVEs

1,244 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Insufficiently Protected CredentialsCWE-522 × clear
Flowise HIGH 7.5
CVE-2026-41266

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, /api/v1/public-chatbotConfig/:id ep exposes …

Fix: 3.1.0+
Fix from $1,950 2026-04-23
Data Domain Operating System HIGH 7.8
CVE-2025-36568

Dell PowerProtect Data Domain BoostFS for client of Feature Release versions 7.7.1.0 through 8.5, LTS2025 release version 8.3.1.0 through 8.3.1.20, L…

Fix: 7.13.1.60 / 8.3.1.30+
Fix from $1,950 2026-04-17
Unclassified MEDIUM 6.2
CVE-2025-15622

Insufficiently Protected Credentials vulnerability in Sparx Systems Pty Ltd. Sparx Enterprise Architect. Client reveals plaintext OAuth2 client secre…

Mitigation only
Fix from $1,600 2026-04-17
Unclassified MEDIUM 5.7
CVE-2025-15621

Insufficiently Protected Credentials in Sparx Systems Pty Ltd. Sparx Enterprise Architect. Client does not verify the receiver of OAuth2 credentials …

Mitigation only
Fix from $1,600 2026-04-16
Dgraph CRITICAL 9.4
CVE-2026-40173

Dgraph is an open source distributed GraphQL database. Versions 25.3.1 and prior contain an unauthenticated credential disclosure vulnerability where…

Fix: 25.3.2+
Fix from $2,300 2026-04-15
Azure Logic Apps HIGH 8.8
CVE-2026-32171

Insufficiently protected credentials in Azure Logic Apps allows an authorized attacker to elevate privileges over a network.

Mitigation only
Fix from $1,950 2026-04-14
Fortisoar MEDIUM 6.5
CVE-2026-22574

A storing passwords in a recoverable format vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.4, FortiSOAR PaaS 7.5.0 through 7.5.2, FortiSO…

Fix: 7.5.3 / 7.6.5+
Fix from $1,600 2026-04-14
Fortisoar MEDIUM 6.5
CVE-2026-22576

A storing passwords in a recoverable format vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.4, FortiSOAR PaaS 7.5.0 through 7.5.2, FortiSO…

Fix: 7.5.3 / 7.6.5+
Fix from $1,600 2026-04-14
Haxiam HIGH 7.5
CVE-2026-35185

HAX CMS helps manage microsite universe with PHP or NodeJs backends. Prior to 25.0.0, the /server-status endpoint is publicly accessible and exposes …

No fix yet
Fix from $1,950 2026-04-06
Cveclient HIGH 7.5
CVE-2026-35467

The stored API keys in temporary browser client is not marked as protected allowing for JavScript console or other errors to allow for extraction of …

Fix: 1.0.24+
Fix from $1,950 2026-04-02
Flx MEDIUM 6.5
CVE-2026-4819

In Search Guard FLX versions from 1.0.0 up to 4.0.1, the audit logging feature might log user credentials from users logging into Kibana.

Fix: 4.1.0+
Fix from $1,600 2026-03-31
Awesome Llm Apps HIGH 8.2
CVE-2026-29872

A cross-session information disclosure vulnerability exists in the awesome-llm-apps project in commit e46690f99c3f08be80a9877fab52acacf7ab8251 (2026-…

No fix yet
Fix from $1,950 2026-03-30
Openclaw HIGH 7.5
CVE-2026-33575

OpenClaw before 2026.3.12 embeds long-lived shared gateway credentials directly in pairing setup codes generated by /pair endpoint and OpenClaw qr co…

Fix: 2026.3.12+
Fix from $1,950 2026-03-29
Wazuh HIGH 8.1
CVE-2025-15617

Wazuh version 4.12.0 contains an exposure vulnerability in GitHub Actions workflow artifacts that allows attackers to extract the GITHUB_TOKEN from u…

No fix yet
Fix from $1,950 2026-03-27
Unclassified HIGH 8.4
CVE-2025-13478

Cache misconfiguration vulnerability in OpenText Identity Manager on Windows, Linux allows remote authenticated users to obtain another user's sessio…

Mitigation only
Fix from $1,950 2026-03-27
Saloon HIGH 7.5
CVE-2026-33182

Saloon is a PHP library that gives users tools to build API integrations and SDKs. Prior to version 4.0.0, when building the request URL, Saloon comb…

Fix: 4.0.0+
Fix from $1,950 2026-03-26
Concert MEDIUM 5.5
CVE-2025-36440

IBM Concert 1.0.0 through 2.2.0 could allow a local user to obtain sensitive information due to missing function level access control.

Fix: after 2.2.0
Fix from $1,600 2026-03-25
Infosphere Information Server MEDIUM 6.5
CVE-2025-14790

IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 could allow an attacker to obtain sensitive information due to insufficiently protected c…

Fix: after 11.7.1.6
Fix from $1,600 2026-03-25
Checkmk HIGH 7.2
CVE-2025-64998

Exposure of session signing secret in Checkmk <2.4.0p23, <2.3.0p45 and 2.2.0 allows an administrator of a remote site with config sync enabled to hij…

Mitigation only
Fix from $1,950 2026-03-24
Openclaw CRITICAL 9.1
CVE-2026-32913

OpenClaw before 2026.3.7 contains an improper header validation vulnerability in fetchWithSsrFGuard that forwards custom authorization headers across…

Fix: 2026.3.7+
Fix from $2,300 2026-03-23
Unclassified MEDIUM 6.5
CVE-2026-31926

Charging station authentication identifiers are publicly accessible via web-based mapping platforms.

Mitigation only
Fix from $1,600 2026-03-20
Unclassified MEDIUM 6.5
CVE-2026-28204

Charging station authentication identifiers are publicly accessible via web-based mapping platforms.

Mitigation only
Fix from $1,600 2026-03-20
Azure Devops CRITICAL 9.8
CVE-2026-23658

Insufficiently protected credentials in Azure DevOps allows an unauthorized attacker to elevate privileges over a network.

No fix yet
Fix from $2,300 2026-03-19
Glances HIGH 8.1
CVE-2026-32634

Glances is an open-source system cross-platform monitoring tool. Prior to version 4.5.2, in Central Browser mode, Glances stores both the Zeroconf-ad…

Fix: 4.5.2+
Fix from $1,950 2026-03-18
Glances CRITICAL 9.1
CVE-2026-32633

Glances is an open-source system cross-platform monitoring tool. Prior to version 4.5.2, in Central Browser mode, the `/api/4/serverslist` endpoint r…

Fix: 4.5.2+
Fix from $2,300 2026-03-18
Unclassified HIGH 7.6
CVE-2026-32606

IncusOS is an immutable OS image dedicated to running Incus. Prior to 202603142010, the default configuration of systemd-cryptenroll as used by Incus…

Patch available
Fix from $1,950 2026-03-18
Veeam Backup \& Replication MEDIUM 6.5
CVE-2026-21670

A vulnerability allowing a low-privileged user to extract saved SSH credentials.

Fix: after 13.0.1.1071
Fix from $1,600 2026-03-12
Curl MEDIUM 5.3
CVE-2026-3783

When an OAuth2 bearer token is used for an HTTP(S) transfer, and that transfer performs a redirect to a second URL, curl could leak that token to the…

Fix: 8.19.0+
Fix from $1,600 2026-03-11
Unclassified MEDIUM 6.5
CVE-2026-27777

Charging station authentication identifiers are publicly accessible via web-based mapping platforms.

Mitigation only
Fix from $1,600 2026-03-06
Unclassified MEDIUM 6.5
CVE-2026-27027

Charging station authentication identifiers are publicly accessible via web-based mapping platforms.

Mitigation only
Fix from $1,600 2026-03-06