Vulnerability index

Browse CVEs

1,244 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Insufficiently Protected CredentialsCWE-522 × clear
MEDIUM 6.1 CVE-2026-54276 AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, DigestAuthMiddleware can send an authentication resp… Aiohttp 3.14.1+ Fix from $1,6002026-06-22 MEDIUM 5.5 CVE-2026-53632 launch-editor allows users to open files with line numbers in editor from Node.js. Prior to 2.14.1, the launch-editor NPM package accesses arbitrary … Mitigation only Fix from $1,6002026-06-22 HIGH 7.1 CVE-2026-53840 OpenClaw before 2026.5.12 contains an information disclosure vulnerability in streamable-http MCP servers that forwards operator-configured custom he… Openclaw 2026.5.12+ Fix from $1,9502026-06-16 HIGH 7.7 CVE-2026-6517 Mattermost Desktop App versions <=6.1 5.5.13.0 fail to restrict the allow list of domains to which NTLM credentials were forwarded to in the Mattermo… Mattermost Desktop after 6.1.5 Fix from $1,9502026-06-15 MEDIUM 5.3 CVE-2026-49949 CodexBar before 0.33.0 contains a credential forwarding vulnerability that allows network-adjacent attackers to intercept sensitive credentials by is… Patch available Fix from $1,6002026-06-11 MEDIUM 6.1 CVE-2026-41715 In specific scenarios involving HTTP redirects from a secure to an insecure endpoint, the Reactor Netty HTTP client may leak credentials. In order fo… Mitigation only Fix from $1,6002026-06-09 MEDIUM 6.5 CVE-2026-39908 OpenBullet2 through version 0.3.2 on Windows contains a credential disclosure vulnerability that allows remote attackers to capture the NTLMv2 hash o… Mitigation only Fix from $1,6002026-06-08 CRITICAL 9.1 CVE-2026-46440 Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, the checkBasicAuth endpoint validate… Flowise 3.1.2+ Fix from $2,3002026-06-08 HIGH 8.7 CVE-2026-46511 HAX CMS helps manage microsite universe with PHP or NodeJs backends. Prior to version 26.0.0, an attack chain utilizing Stored XSS alongside dynamic … Mitigation only Fix from $1,9502026-06-05 HIGH 7.5 CVE-2026-7312 CWE‑522: Insufficiently Protected Credentials in web services in Progress Sitefinity version from 14.0.7700 to 14.4.8152, and 15.0.8200 to 15.0.8234,… Sitefinity 14.4.8152 / 15.0.8234+ Fix from $1,9502026-06-02 MEDIUM 6.5 CVE-2026-49379 In JetBrains TeamCity before 2026.1 credentials could be exposed in thread names Teamcity 2026.1+ Fix from $1,6002026-05-29 MEDIUM 5.4 CVE-2026-42951 An authenticated user can download a backup of the Danelec MacGregor Voyage Data Recorder device which includes account data and password hashes. Interschalt Vdr G4e Firmware 5.250+ Fix from $1,6002026-05-29 HIGH 7.1 CVE-2026-39968 TypeBot is a chatbot builder tool. In versions 3.15.2 and prior, the fix for GHSA-4xc5-wfwc-jw47 ("Credential Theft via Client-Side Script Execution … Patch available Fix from $1,9502026-05-22 HIGH 7.1 CVE-2025-13477 Exposure of private personal information to an unauthorized actor, Insufficiently Protected Credentials vulnerability in Digital Operations Services … Mitigation only Fix from $1,9502026-05-21 MEDIUM 6.5 CVE-2026-0393 The affected product may expose credentials remotely between low privileged visualization users during concurrent login operations due to insufficien… Visualization 4.10.0.0+ Fix from $1,6002026-05-21 MEDIUM 6.5 CVE-2026-6345 Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 fail prevent disclosure of created user password which allows a malicious… Mattermost Server 10.11.14 / 11.4.4+ Fix from $1,6002026-05-18 MEDIUM 5.9 CVE-2026-6253 curl might erroneously pass on credentials for a first proxy to a second proxy. This can happen when the following conditions are true: 1. curl is … Curl 8.20.0+ Fix from $1,6002026-05-13 CRITICAL 9.8 CVE-2026-43992 JunoClaw is an agentic AI platform built on Juno Network. Prior to 0.x.y-security-1, every MCP write tool (send_tokens, execute_contract, instantiate… Patch available Fix from $2,3002026-05-12 MEDIUM 6.5 CVE-2026-8368 LWP::UserAgent versions before 6.83 for Perl leak Authorization and Proxy-Authorization headers on cross-origin redirects. On a 3xx response, the re… Patch available Fix from $1,6002026-05-12 CRITICAL 9.1 CVE-2026-45091 sealed-env is a cross-stack, zero-trust secret management library for Node.js and Java/Spring Boot. In sealed-env enterprise mode, versions 0.1.0-alp… Mitigation only Fix from $2,3002026-05-12 CRITICAL 10.0 CVE-2026-42869 SOCFortress CoPilot focuses on providing a single pane of glass for all your security operations needs. Prior to 0.1.57, SOCFortress CoPilot ships a … Patch available Fix from $2,3002026-05-11 HIGH 7.4 CVE-2026-41506 go-git is an extensible git implementation library written in pure Go. Prior to versions 5.18.0 and 6.0.0-alpha.2, go-git may leak HTTP authenticatio… Go Git 5.18.0+ Fix from $1,9502026-05-08 HIGH 7.5 CVE-2025-31976 HCL BigFix Service Management (SM) is vulnerable to insufficiently protected credentials for a short duration while communicating with a backend, int… Bigfix Service Management Mitigation only Fix from $1,9502026-05-06 MEDIUM 5.1 CVE-2026-23927 A user able to connect to Agent 2 can inject an Oracle TNS connection string via the 'service' parameter. This can lead to Agent 2 connecting to an a… Mitigation only Fix from $1,6002026-05-06 MEDIUM 6.5 CVE-2026-42367 A privilege escalation vulnerability exists in the Web Interface / ssi.cgi functionality of GeoVision LPC2011/LPC2211 1.10. A specially crafted HTTP … Gv Lpc2011 Firmware Mitigation only Fix from $1,6002026-05-04 MEDIUM 5.4 CVE-2026-6446 The My Social Feeds – Social Feeds Embedder plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to and including … Mitigation only Fix from $1,6002026-05-02 MEDIUM 6.5 CVE-2026-28909 Users who connect to malicious registries with hostnames matching the bypass patterns will have their registry credentials exposed in plaintext. This… Container 0.12.3+ Fix from $1,6002026-04-30 HIGH 7.1 CVE-2026-35155 Dell iDRAC10, versions 1.20.70.50 and 1.30.05.10, contains an Insufficiently Protected Credentials vulnerability. A race condition vulnerability exis… Idrac10 Firmware 1.30.10.50+ Fix from $1,9502026-04-29 HIGH 8.1 CVE-2026-39462 A vulnerability exists in SenseLive X3050’s web management interface in which password updates are not reliably applied due to improper handling of c… X3500 Firmware Mitigation only Fix from $1,9502026-04-24 MEDIUM 5.3 CVE-2026-41345 OpenClaw before 2026.3.31 contains a credential exposure vulnerability in media download functionality that forwards Authorization headers across cro… Openclaw 2026.3.31+ Fix from $1,6002026-04-23