Vulnerability index

Browse CVEs

1,244 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Insufficiently Protected CredentialsCWE-522 × clear
Unclassified MEDIUM 6.5
CVE-2026-27770

Charging station authentication identifiers are publicly accessible via web-based mapping platforms.

Mitigation only
Fix from $1,600 2026-03-06
Rustdesk Server HIGH 7.5
CVE-2026-30796

Cleartext Transmission of Sensitive Information, Insufficiently Protected Credentials vulnerability in rustdesk-client RustDesk Client rustdesk-clien…

Fix: after 1.7.5
Fix from $1,950 2026-03-05
Sfx2100 Firmware CRITICAL 10.0
CVE-2026-29128

IDC SFX2100 Satellite Receiver firmware ships with multiple daemon configuration files for routing components (e.g., zebra, bgpd, ospfd, and ripd) th…

Mitigation only
Fix from $2,300 2026-03-05
Gradio MEDIUM 5.9
CVE-2026-27167

Gradio is an open-source Python package designed for quick prototyping. Starting in version 4.16.0 and prior to version 6.6.0, Gradio applications ru…

Fix: 6.6.0+
Fix from $1,600 2026-02-27
Frick Controls Quantum Hd Firmware CRITICAL 9.8
CVE-2026-21660

Hardcoded Email Credentials Saved as Plaintext in Firmware (CWE-256: Plaintext Storage of a Password) vulnerability in Frick Controls Quantum HD vers…

Fix: after 10.22
Fix from $2,300 2026-02-27
Ev.energy MEDIUM 5.3
CVE-2026-25774

Charging station authentication identifiers are publicly accessible via web-based mapping platforms.

Mitigation only
Fix from $1,600 2026-02-27
Mobility46.se MEDIUM 5.3
CVE-2026-22878

Charging station authentication identifiers are publicly accessible via web-based mapping platforms.

Mitigation only
Fix from $1,600 2026-02-27
Swtchenergy.com MEDIUM 5.3
CVE-2026-27773

Charging station authentication identifiers are publicly accessible via web-based mapping platforms.

No fix yet
Fix from $1,600 2026-02-27
Chargemap.com HIGH 7.5
CVE-2026-20791

Charging station authentication identifiers are publicly accessible via web-based mapping platforms.

Mitigation only
Fix from $1,950 2026-02-27
Ev2go.io MEDIUM 5.3
CVE-2026-22890

Charging station authentication identifiers are publicly accessible via web-based mapping platforms.

Mitigation only
Fix from $1,600 2026-02-27
Cloudcharge.se MEDIUM 5.3
CVE-2026-20733

Charging station authentication identifiers are publicly accessible via web-based mapping platforms.

No fix yet
Fix from $1,600 2026-02-27
Unclassified MEDIUM 5.7
CVE-2026-26049

The web management interface of the device renders the passwords in a plaintext input field. The current password is directly visible to anyone wit…

Mitigation only
Fix from $1,600 2026-02-20
Openclaw MEDIUM 5.5
CVE-2026-27003

OpenClaw is a personal AI assistant. Telegram bot tokens can appear in error messages and stack traces (for example, when request URLs include `https…

Fix: 2026.2.15+
Fix from $1,600 2026-02-20
N8n MEDIUM 6.5
CVE-2026-25631

n8n is an open source workflow automation platform. Prior to 1.121.0, there is a vulnerability in the HTTP Request node's credential domain validatio…

Fix: 1.121.0+
Fix from $1,600 2026-02-06
Uc 1222a Firmware MEDIUM 6.8
CVE-2026-0715

Moxa Arm-based industrial computers running Moxa Industrial Linux Secure use a device-unique bootloader password provided on the device. An attacker …

Fix: after 1.4
Fix from $1,600 2026-02-05
Ew 7438rpn Mini Firmware HIGH 7.5
CVE-2020-37097

Edimax EW-7438RPn 1.13 contains an information disclosure vulnerability that exposes WiFi network configuration details through the wlencrypt_wiz.asp…

No fix yet
Fix from $1,950 2026-02-03
Aion MEDIUM 6.5
CVE-2025-52623

HCL AION is affected by an Autocomplete HTML Attribute Not Disabled for Password Field vulnerability. This can allow autocomplete on password fields…

Mitigation only
Fix from $1,600 2026-02-03
Malcontent MEDIUM 6.5
CVE-2026-24845

malcontent discovers supply-chain compromises through. context, differential analysis, and YARA. Starting in version 0.10.0 and prior to version 1.20…

Fix: 1.20.3+
Fix from $1,600 2026-01-29
M\/monit MEDIUM 6.5
CVE-2020-36968

M/Monit 3.7.4 contains an authentication vulnerability that allows authenticated attackers to retrieve user password hashes through an administrative…

No fix yet
Fix from $1,600 2026-01-28
Omada Controller MEDIUM 6.5
CVE-2025-9521

Password Confirmation Bypass vulnerability in Omada Controllers, allowing an attacker with a valid session token to bypass secondary verification, an…

Fix: 6.0+
Fix from $1,600 2026-01-26
Typebot HIGH 7.4
CVE-2025-65098

Typebot is an open-source chatbot builder. In versions prior to 3.13.2, client-side script execution in Typebot allows stealing all stored credential…

Fix: 3.13.2+
Fix from $1,950 2026-01-22
Dataease CRITICAL 9.8
CVE-2026-23958

Dataease is an open source data visualization analysis tool. Prior to version 2.10.19, DataEase uses the MD5 hash of the user’s password as the JWT s…

Fix: 2.10.19+
Fix from $2,300 2026-01-22
Claude Code HIGH 7.5
CVE-2026-21852EPSS 23%

Claude Code is an agentic coding tool. Prior to version 2.0.65, vulnerability in Claude Code's project-load flow allowed malicious repositories to ex…

Fix: 2.0.65+
Fix from $1,950 2026-01-21
Imagedirector Capture HIGH 7.5
CVE-2025-58741

Insufficiently Protected Credentials vulnerability in the Credential Field of Milner ImageDirector Capture allows retrieval of credential material an…

Fix: 7.6.3.25808+
Fix from $1,950 2026-01-20
Imagedirector Capture MEDIUM 5.9
CVE-2025-58742

Insufficiently Protected Credentials, Improper Restriction of Communication Channel to Intended Endpoints vulnerability in the Connection Settings di…

Fix: 7.6.3.25808+
Fix from $1,600 2026-01-20
Skipper HIGH 8.8
CVE-2026-23742

Skipper is an HTTP router and reverse proxy for service composition. The default skipper configuration before 0.23.0 was -lua-sources=inline,file. Th…

Fix: 0.23.0+
Fix from $1,950 2026-01-16
Unclassified MEDIUM 6.2
CVE-2021-47759

MTPutty 1.0.1.21 contains a sensitive information disclosure vulnerability that allows local attackers to view SSH connection passwords through Windo…

No fix yet
Fix from $1,600 2026-01-15
Tdc X401gl Firmware HIGH 7.5
CVE-2026-22911

Firmware update files may expose password hashes for system accounts, which could allow a remote attacker to recover credentials and gain unauthorize…

Mitigation only
Fix from $1,950 2026-01-15
Bluvoyix HIGH 7.5
CVE-2026-22240

The vulnerability exists in BLUVOYIX due to an improper password storage implementation and subsequent exposure via unauthenticated APIs. An unauthen…

Mitigation only
Fix from $1,950 2026-01-14
Dx Netops Spectrum HIGH 7.5
CVE-2025-69271

Insufficiently Protected Credentials vulnerability in Broadcom DX NetOps Spectrum on Windows, Linux allows Sniffing Attacks.This issue affects DX Net…

Fix: 25.4.1+
Fix from $1,950 2026-01-12