Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
MEDIUM 6.3
CVE-2026-44979
@hapi/wreck is an HTTP client utility. Prior to 18.1.1, when @hapi/wreck follows a 3xx redirect to a different hostname, only the Authorization and C…
No fix yet
MEDIUM 6.5
CVE-2026-16104
A flaw was found in the authentication configuration endpoint of the keycloak-services component, which is the core engine for Red Hat Build of Keycl…
Build Of Keycloak
No fix yet
MEDIUM 6.5
CVE-2026-62214
OpenClaw versions before 2026.5.28 Bot Framework contains an improper input validation vulnerability that allows lower-trust callers to expose bot to…
Openclaw
2026.5.28+
MEDIUM 6.5
CVE-2026-62208
OpenClaw before 2026.6.5 could forward Authorization headers during MCP SSE redirects. When the affected feature is enabled and reachable, a lower-tr…
Openclaw
2026.6.5+
MEDIUM 6.5
CVE-2026-62213
OpenClaw versions before 2026.5.27 contain a token leakage vulnerability in MS Teams outbound requests that allows lower-trust callers to expose Bot …
Openclaw
2026.5.27+
HIGH 7.1
CVE-2026-46458
ICU Scandinavia Boomerang is vulnerable to an information disclosure flaw where sensitive credential files are exposed via static HTTP. This allows a…
Mitigation only
HIGH 7.5
CVE-2026-48295
CAI Content Credentials is affected by an Insufficiently Protected Credentials vulnerability that could result in disclosure of sensitive information…
C2pa
after 0.84.0
CRITICAL 9.6
CVE-2026-59891
sigstore-js provides JavaScript libraries for interacting with Sigstore services. Prior to 0.7.1, getRegistryCredentials() reads credentials from the…
Mitigation only
MEDIUM 6.5
CVE-2026-47282
Insufficiently protected credentials in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to disclose information over a network.
Visual Studio Code
1.128.1+
CRITICAL 9.1
CVE-2026-62327
9Router through version 0.4.41 contains an unauthenticated information disclosure vulnerability that allows remote attackers to retrieve plaintext AP…
Mitigation only
HIGH 7.5
CVE-2026-57219
RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.20, 4.1.11, and 4.2.6, the obsolete GET /api/auth endpoint can disclose the OAuth…
Rabbitmq Server
4.2.6+
MEDIUM 6.8
CVE-2026-55885
Grav is a file-based Web platform. Prior to 1.7.53, an authenticated administrator with backup permissions can download a ZIP archive containing the …
Mitigation only
MEDIUM 6.5
CVE-2026-59209
n8n is an open source workflow automation platform. Prior to 1.123.61, 2.27.4, and, 2.28.1, an authenticated member with use-only editor access to a …
N8n
1.123.61 / 2.27.4+
MEDIUM 6.5
CVE-2026-59261
OpenClaw before 2026.5.28 contains a credential exposure vulnerability where workspace dotenv files can override provider credentials. Attackers with…
Openclaw
2026.5.28+
CRITICAL 9.9
CVE-2026-56843
Incorrect authorization in the XML-RPC API of WebPros Plesk before 18.0.78.4 allows a low-privileged authenticated customer to look up domains they d…
Mitigation only
MEDIUM 6.1
CVE-2026-55431
Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2, `coder o…
Coder
2.29.17 / 2.32.7+
HIGH 7.1
CVE-2026-7017
HTTP::Tiny versions before 0.095 for Perl forward credential headers to cross-origin redirect targets.
When the server returns a 3xx redirect, `_may…
Patch available
HIGH 8.8
CVE-2026-44938
A vulnerability has been identified in Fleet's agent-side deployer, which did not filter security-sensitive keys from namespaceLabels in fleet.yaml (…
Mitigation only
CRITICAL 9.1
CVE-2026-8926
When asking curl to use a `.netrc` file to find credentials and at the same
time specifying a URL with a username(without a password), like
`https://…
Curl
8.21.0+
CRITICAL 9.8
CVE-2026-9079
libcurl had a flaw that when instructed to clear proxy authentication
credentials which made it not do so, leaving the old credentials around to get
…
Curl
8.21.0+
MEDIUM 6.5
CVE-2026-14019
Inappropriate implementation in Passwords in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to leak cross-origin data via a crafted H…
Chrome
150.0.7871.47+
MEDIUM 6.5
CVE-2026-56783
Parseable before 2.9.2 contains an information disclosure vulnerability in the notification-target API endpoints that returns webhook tokens and basi…
Patch available
MEDIUM 6.8
CVE-2025-7386
Information exposure vulnerability in Hitachi Storage Navigator.
This issue affects Hitachi Virtual Storage Platform 5100, 5200, 5500, 5600, 5100H, …
Mitigation only
HIGH 8.2
CVE-2026-55188
RustFS is a distributed object storage system built in Rust. From 1.0.0-alpha.1 until 1.0.0-beta.9, RustFS contains an authorization bypass in the bu…
Mitigation only
MEDIUM 5.5
CVE-2026-45407
Dokku is a docker-powered PaaS. Prior to 0.38.2, the git:auth command creates $DOKKU_ROOT/.netrc using bash's touch command, which applies the defaul…
Dokku
0.38.2+
MEDIUM 6.5
CVE-2026-44622
Charging station authentication identifiers are publicly accessible via web-based mapping platforms.
Mitigation only
MEDIUM 6.5
CVE-2026-55180
pnpm is a package manager. Prior to 10.34.2 and 11.5.3, pnpm and pacquet expanded ${ENV_VAR} placeholders from repository-controlled .npmrc and pnpm-…
Pnpm
10.34.2 / 11.5.3+
MEDIUM 6.5
CVE-2026-50017
pnpm is a package manager. Prior to 10.34.0 and 11.4.0, pnpm can send user-level unscoped npm authentication credentials to a registry chosen by a re…
Pnpm
10.34.0 / 11.4.0+
HIGH 7.5
CVE-2026-9650
CWE-522 Insufficiently Protected Credentials vulnerability that could cause unauthorized access and exposure of sensitive information when unauthenti…
Easylogic T150 Firmware
11.06.32 / 11.06.38+
MEDIUM 5.5
CVE-2026-32315
motionEye (mEye) is an online interface for motion software, a video surveillance program with motion detection. Versions prior to 0.44.0 create the …
Mitigation only