Vulnerability index

Browse CVEs

1,244 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Insufficiently Protected CredentialsCWE-522 × clear
MEDIUM 6.9 CVE-2026-53454 Blueprint Studio is a VS Code-like file editor for Home Assistant configuration files. Prior to 2.5.2, Blueprint Studio configured Git's credential.h… Fix unknown Fix from $4,0002026-08-18 MEDIUM 5.6 CVE-2026-53456 Blueprint Studio is a VS Code-like file editor for Home Assistant configuration files. Prior to 2.5.2, Blueprint Studio terminal SSH key authenticati… Fix unknown Fix from $4,0002026-08-18 MEDIUM 6.0 CVE-2026-15806 The HTTPPasswordMgr class in the urllib.request module, along with its subclasses HTTPPasswordMgrWithDefaultRealm and HTTPPasswordMgrWithPriorAuth, d… Fix unknown Fix from $4,0002026-08-18 HIGH 8.5 CVE-2026-57485 Stirling-PDF is a locally hosted web application that facilitates various operations on PDF files. Prior to 2.9.0, the /api/v1/pipeline/handleData en… Fix unknown Fix from $4,9002026-08-17 CRITICAL 9.0 CVE-2026-14564 Insufficiently Protected Credentials vulnerability in Innotim Software Telecommunications and Consulting Trade Ltd. Co. Logsign SIEM allows Retrieve … Fix unknown Fix from $5,7502026-08-17 HIGH 7.7 CVE-2026-72857 Budibase before 3.40.0 fails to redact datasource credentials stored in STRING typed fields, allowing authenticated users to read MongoDB connection … No fix yet Fix from $4,9002026-08-13 HIGH 7.5 CVE-2026-72801 SiYuan versions before v3.7.4 disclose encrypted-notebook key-derivation material and wrapped data keys through unauthenticated endpoints in publish … No fix yet Fix from $4,9002026-08-12 HIGH 8.6 CVE-2026-72793 SiYuan versions before v3.7.4 fail to mask sensitive configuration fields in the /api/system/getConf endpoint, allowing anonymous or publish-reader u… No fix yet Fix from $4,9002026-08-12 HIGH 8.6 CVE-2026-72794 siyuan versions before v3.7.4 expose the session cookie signing key through the /api/system/getConf endpoint to unauthenticated users in publish mode… No fix yet Fix from $4,9002026-08-12 MEDIUM 6.8 CVE-2026-49349 regclient is a Docker and OCI Registry Client in Go. Prior to version 0.11.5, credentials for a registry may be inadvertently leaked to external serv… No fix yet Fix from $4,0002026-08-12 MEDIUM 6.5 CVE-2026-62839 Insufficiently protected credentials in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. Sharepoint Server 16.0.19725.20522+ Fix from $4,0002026-08-11 MEDIUM 6.3 CVE-2026-71577 A flaw was found in multicluster-global-hub. During a ManagedClusterMigration, the system incorrectly grants all managed hubs read access to a shared… No fix yet Fix from $4,0002026-08-10 HIGH 8.2 CVE-2026-12984 Insufficiently Protected Credentials vulnerability in Zyxel Networks WAH7601 allows Retrieve Embedded Sensitive Data. This issue affects WAH7601: th… No fix yet Fix from $4,9002026-08-10 HIGH 8.7 CVE-2026-47662 Pathling is a set of tools that make it easier to use FHIR and clinical terminology within health data analytics. Prior to version 2.0.0 of Pathling … No fix yet Fix from $1,9502026-08-07 HIGH 8.7 CVE-2026-47660 Pathling is a set of tools that make it easier to use FHIR and clinical terminology within health data analytics. Prior to version 2.0.0 of Pathling … No fix yet Fix from $1,9502026-08-07 MEDIUM 5.4 CVE-2026-21766 The default login portlet in HCL Digital Experience and Digital Experience Compose insufficiently protects credentials.  Under certain very specific … No fix yet Fix from $1,6002026-08-05 MEDIUM 6.5 CVE-2026-71260 ESPHome through 2026.7.0-dev discloses plaintext passwords via its web_server component. In WebServer::text_json_ (esphome/components/web_server/web_… No fix yet Fix from $1,6002026-08-05 CRITICAL 9.9 CVE-2026-52855 Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to 1.12.3, {{config.}} placeholders in egg… No fix yet Fix from $2,3002026-07-31 MEDIUM 5.3 CVE-2026-56570 HCL iControl was affected by Auto complete Enabled vulnerabilities. It involves expose sensitive information such as: Valid usernames, Email addresse… Icontrol No fix yet Fix from $1,6002026-07-31 CRITICAL 9.6 CVE-2026-17349 /misc/workspace/adhoc_connect_server, part of the Workspaces feature introduced in pgAdmin 4 9.0, when passed the id of an existing server, clones th… Pgadmin 4 9.17+ Fix from $2,3002026-07-31 HIGH 7.5 CVE-2026-15977 SGLang contains a credential leakage vulnerability in the /server_info endpoint, which will return API keys and SSL keyfile information when only the… Sglang after 0.5.15 Fix from $1,9502026-07-30 MEDIUM 6.5 CVE-2026-15657 A vulnerability in the foreUP customer REST API allows any authenticated user to read cleartext payment-processor merchant credentials in the respons… No fix yet Fix from $1,6002026-07-30 MEDIUM 5.4 CVE-2026-16553 GitLab has remediated an issue in GitLab EE affecting all versions from 18.8 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under cer… GitLab 19.0.5 / 19.1.3+ Fix from $1,6002026-07-29 HIGH 8.6 CVE-2026-67425 Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.6, llm.chat reads provider keys such as OPENAI_API_KEY and AN… No fix yet Fix from $1,9502026-07-29 CRITICAL 9.3 CVE-2026-67426 Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.7, the standalone flyto-verification service in src/core/veri… No fix yet Fix from $2,3002026-07-29 HIGH 8.6 CVE-2026-67427 Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.6, the workflow engine variable resolver expands ${env.VAR} f… No fix yet Fix from $1,9502026-07-29 HIGH 7.4 CVE-2026-54660 swagger-typescript-api generates API clients for Fetch or Axios from OpenAPI specifications. Prior to 13.12.2, src/resolved-swagger-schema.ts getRemo… No fix yet Fix from $1,9502026-07-29 HIGH 8.7 CVE-2026-14354 CWE-522 Insufficiently Protected Credentials vulnerability exists that could cause authentication bypass and unauthorized credential modification, po… No fix yet Fix from $1,9502026-07-29 MEDIUM 5.5 CVE-2026-54422 In OpenStack Ironic Python Agent through 11.5.0, a malicious bootc container, when deployed using ironic-python-agent, may be able to extract the cre… No fix yet Fix from $1,6002026-07-24 MEDIUM 6.5 CVE-2026-48022 @hapi/wreck is an HTTP client utility. Prior to 18.1.2, Wreck strips credential headers including Authorization, Cookie, and Proxy-Authorization befo… No fix yet Fix from $1,6002026-07-17