Vulnerability index

Browse CVEs

1,244 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Insufficiently Protected CredentialsCWE-522 × clear
MEDIUM 6.3 CVE-2026-44979 @hapi/wreck is an HTTP client utility. Prior to 18.1.1, when @hapi/wreck follows a 3xx redirect to a different hostname, only the Authorization and C… No fix yet Fix from $1,6002026-07-17 MEDIUM 6.5 CVE-2026-16104 A flaw was found in the authentication configuration endpoint of the keycloak-services component, which is the core engine for Red Hat Build of Keycl… Build Of Keycloak No fix yet Fix from $1,6002026-07-17 MEDIUM 6.5 CVE-2026-62214 OpenClaw versions before 2026.5.28 Bot Framework contains an improper input validation vulnerability that allows lower-trust callers to expose bot to… Openclaw 2026.5.28+ Fix from $1,6002026-07-17 MEDIUM 6.5 CVE-2026-62208 OpenClaw before 2026.6.5 could forward Authorization headers during MCP SSE redirects. When the affected feature is enabled and reachable, a lower-tr… Openclaw 2026.6.5+ Fix from $1,6002026-07-17 MEDIUM 6.5 CVE-2026-62213 OpenClaw versions before 2026.5.27 contain a token leakage vulnerability in MS Teams outbound requests that allows lower-trust callers to expose Bot … Openclaw 2026.5.27+ Fix from $1,6002026-07-17 HIGH 7.1 CVE-2026-46458 ICU Scandinavia Boomerang is vulnerable to an information disclosure flaw where sensitive credential files are exposed via static HTTP. This allows a… Mitigation only Fix from $1,9502026-07-15 HIGH 7.5 CVE-2026-48295 CAI Content Credentials is affected by an Insufficiently Protected Credentials vulnerability that could result in disclosure of sensitive information… C2pa after 0.84.0 Fix from $1,9502026-07-14 CRITICAL 9.6 CVE-2026-59891 sigstore-js provides JavaScript libraries for interacting with Sigstore services. Prior to 0.7.1, getRegistryCredentials() reads credentials from the… Mitigation only Fix from $2,3002026-07-14 MEDIUM 6.5 CVE-2026-47282 Insufficiently protected credentials in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to disclose information over a network. Visual Studio Code 1.128.1+ Fix from $1,6002026-07-14 CRITICAL 9.1 CVE-2026-62327 9Router through version 0.4.41 contains an unauthenticated information disclosure vulnerability that allows remote attackers to retrieve plaintext AP… Mitigation only Fix from $2,3002026-07-13 HIGH 7.5 CVE-2026-57219 RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.20, 4.1.11, and 4.2.6, the obsolete GET /api/auth endpoint can disclose the OAuth… Rabbitmq Server 4.2.6+ Fix from $1,9502026-07-10 MEDIUM 6.8 CVE-2026-55885 Grav is a file-based Web platform. Prior to 1.7.53, an authenticated administrator with backup permissions can download a ZIP archive containing the … Mitigation only Fix from $1,6002026-07-10 MEDIUM 6.5 CVE-2026-59209 n8n is an open source workflow automation platform. Prior to 1.123.61, 2.27.4, and, 2.28.1, an authenticated member with use-only editor access to a … N8n 1.123.61 / 2.27.4+ Fix from $1,6002026-07-09 MEDIUM 6.5 CVE-2026-59261 OpenClaw before 2026.5.28 contains a credential exposure vulnerability where workspace dotenv files can override provider credentials. Attackers with… Openclaw 2026.5.28+ Fix from $1,6002026-07-08 CRITICAL 9.9 CVE-2026-56843 Incorrect authorization in the XML-RPC API of WebPros Plesk before 18.0.78.4 allows a low-privileged authenticated customer to look up domains they d… Mitigation only Fix from $2,3002026-07-08 MEDIUM 6.1 CVE-2026-55431 Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2, `coder o… Coder 2.29.17 / 2.32.7+ Fix from $1,6002026-07-08 HIGH 7.1 CVE-2026-7017 HTTP::Tiny versions before 0.095 for Perl forward credential headers to cross-origin redirect targets. When the server returns a 3xx redirect, `_may… Patch available Fix from $1,9502026-07-07 HIGH 8.8 CVE-2026-44938 A vulnerability has been identified in Fleet's agent-side deployer, which did not filter security-sensitive keys from namespaceLabels in fleet.yaml (… Mitigation only Fix from $1,9502026-07-07 CRITICAL 9.1 CVE-2026-8926 When asking curl to use a `.netrc` file to find credentials and at the same time specifying a URL with a username(without a password), like `https://… Curl 8.21.0+ Fix from $2,3002026-07-03 CRITICAL 9.8 CVE-2026-9079 libcurl had a flaw that when instructed to clear proxy authentication credentials which made it not do so, leaving the old credentials around to get … Curl 8.21.0+ Fix from $2,3002026-07-03 MEDIUM 6.5 CVE-2026-14019 Inappropriate implementation in Passwords in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to leak cross-origin data via a crafted H… Chrome 150.0.7871.47+ Fix from $1,6002026-06-30 MEDIUM 6.5 CVE-2026-56783 Parseable before 2.9.2 contains an information disclosure vulnerability in the notification-target API endpoints that returns webhook tokens and basi… Patch available Fix from $1,6002026-06-29 MEDIUM 6.8 CVE-2025-7386 Information exposure vulnerability in Hitachi Storage Navigator. This issue affects Hitachi Virtual Storage Platform 5100, 5200, 5500, 5600, 5100H, … Mitigation only Fix from $1,6002026-06-29 HIGH 8.2 CVE-2026-55188 RustFS is a distributed object storage system built in Rust. From 1.0.0-alpha.1 until 1.0.0-beta.9, RustFS contains an authorization bypass in the bu… Mitigation only Fix from $1,9502026-06-26 MEDIUM 5.5 CVE-2026-45407 Dokku is a docker-powered PaaS. Prior to 0.38.2, the git:auth command creates $DOKKU_ROOT/.netrc using bash's touch command, which applies the defaul… Dokku 0.38.2+ Fix from $1,6002026-06-26 MEDIUM 6.5 CVE-2026-44622 Charging station authentication identifiers are publicly accessible via web-based mapping platforms. Mitigation only Fix from $1,6002026-06-25 MEDIUM 6.5 CVE-2026-55180 pnpm is a package manager. Prior to 10.34.2 and 11.5.3, pnpm and pacquet expanded ${ENV_VAR} placeholders from repository-controlled .npmrc and pnpm-… Pnpm 10.34.2 / 11.5.3+ Fix from $1,6002026-06-25 MEDIUM 6.5 CVE-2026-50017 pnpm is a package manager. Prior to 10.34.0 and 11.4.0, pnpm can send user-level unscoped npm authentication credentials to a registry chosen by a re… Pnpm 10.34.0 / 11.4.0+ Fix from $1,6002026-06-25 HIGH 7.5 CVE-2026-9650 CWE-522 Insufficiently Protected Credentials vulnerability that could cause unauthorized access and exposure of sensitive information when unauthenti… Easylogic T150 Firmware 11.06.32 / 11.06.38+ Fix from $1,9502026-06-25 MEDIUM 5.5 CVE-2026-32315 motionEye (mEye) is an online interface for motion software, a video surveillance program with motion detection. Versions prior to 0.44.0 create the … Mitigation only Fix from $1,6002026-06-24