Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
MEDIUM 6.1
CVE-2026-54276
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, DigestAuthMiddleware can send an authentication resp…
Aiohttp
3.14.1+
MEDIUM 5.5
CVE-2026-53632
launch-editor allows users to open files with line numbers in editor from Node.js. Prior to 2.14.1, the launch-editor NPM package accesses arbitrary …
Mitigation only
HIGH 7.1
CVE-2026-53840
OpenClaw before 2026.5.12 contains an information disclosure vulnerability in streamable-http MCP servers that forwards operator-configured custom he…
Openclaw
2026.5.12+
HIGH 7.7
CVE-2026-6517
Mattermost Desktop App versions <=6.1 5.5.13.0 fail to restrict the allow list of domains to which NTLM credentials were forwarded to in the Mattermo…
Mattermost Desktop
after 6.1.5
MEDIUM 5.3
CVE-2026-49949
CodexBar before 0.33.0 contains a credential forwarding vulnerability that allows network-adjacent attackers to intercept sensitive credentials by is…
Patch available
MEDIUM 6.1
CVE-2026-41715
In specific scenarios involving HTTP redirects from a secure to an insecure endpoint, the Reactor Netty HTTP client may leak credentials. In order fo…
Mitigation only
MEDIUM 6.5
CVE-2026-39908
OpenBullet2 through version 0.3.2 on Windows contains a credential disclosure vulnerability that allows remote attackers to capture the NTLMv2 hash o…
Mitigation only
CRITICAL 9.1
CVE-2026-46440
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, the checkBasicAuth endpoint validate…
Flowise
3.1.2+
HIGH 8.7
CVE-2026-46511
HAX CMS helps manage microsite universe with PHP or NodeJs backends. Prior to version 26.0.0, an attack chain utilizing Stored XSS alongside dynamic …
Mitigation only
HIGH 7.5
CVE-2026-7312
CWE‑522: Insufficiently Protected Credentials in web services in Progress Sitefinity version from 14.0.7700 to 14.4.8152, and 15.0.8200 to 15.0.8234,…
Sitefinity
14.4.8152 / 15.0.8234+
MEDIUM 6.5
CVE-2026-49379
In JetBrains TeamCity before 2026.1 credentials could be exposed in thread names
Teamcity
2026.1+
MEDIUM 5.4
CVE-2026-42951
An authenticated
user can download a backup of the Danelec MacGregor Voyage Data Recorder
device which includes account data and password hashes.
Interschalt Vdr G4e Firmware
5.250+
HIGH 7.1
CVE-2026-39968
TypeBot is a chatbot builder tool. In versions 3.15.2 and prior, the fix for GHSA-4xc5-wfwc-jw47 ("Credential Theft via Client-Side Script Execution …
Patch available
HIGH 7.1
CVE-2025-13477
Exposure of private personal information to an unauthorized actor, Insufficiently Protected Credentials vulnerability in Digital Operations Services …
Mitigation only
MEDIUM 6.5
CVE-2026-0393
The affected product may expose credentials remotely between low privileged visualization users during concurrent login operations due to insufficien…
Visualization
4.10.0.0+
MEDIUM 6.5
CVE-2026-6345
Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 fail prevent disclosure of created user password which allows a malicious…
Mattermost Server
10.11.14 / 11.4.4+
MEDIUM 5.9
CVE-2026-6253
curl might erroneously pass on credentials for a first proxy to a second
proxy.
This can happen when the following conditions are true:
1. curl is …
Curl
8.20.0+
CRITICAL 9.8
CVE-2026-43992
JunoClaw is an agentic AI platform built on Juno Network. Prior to 0.x.y-security-1, every MCP write tool (send_tokens, execute_contract, instantiate…
Patch available
MEDIUM 6.5
CVE-2026-8368
LWP::UserAgent versions before 6.83 for Perl leak Authorization and Proxy-Authorization headers on cross-origin redirects.
On a 3xx response, the re…
Patch available
CRITICAL 9.1
CVE-2026-45091
sealed-env is a cross-stack, zero-trust secret management library for Node.js and Java/Spring Boot. In sealed-env enterprise mode, versions 0.1.0-alp…
Mitigation only
CRITICAL 10.0
CVE-2026-42869
SOCFortress CoPilot focuses on providing a single pane of glass for all your security operations needs. Prior to 0.1.57, SOCFortress CoPilot ships a …
Patch available
HIGH 7.4
CVE-2026-41506
go-git is an extensible git implementation library written in pure Go. Prior to versions 5.18.0 and 6.0.0-alpha.2, go-git may leak HTTP authenticatio…
Go Git
5.18.0+
HIGH 7.5
CVE-2025-31976
HCL BigFix Service Management (SM) is vulnerable to insufficiently protected credentials for a short duration while communicating with a backend, int…
Bigfix Service Management
Mitigation only
MEDIUM 5.1
CVE-2026-23927
A user able to connect to Agent 2 can inject an Oracle TNS connection string via the 'service' parameter. This can lead to Agent 2 connecting to an a…
Mitigation only
MEDIUM 6.5
CVE-2026-42367
A privilege escalation vulnerability exists in the Web Interface / ssi.cgi functionality of GeoVision LPC2011/LPC2211 1.10. A specially crafted HTTP …
Gv Lpc2011 Firmware
Mitigation only
MEDIUM 5.4
CVE-2026-6446
The My Social Feeds – Social Feeds Embedder plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to and including …
Mitigation only
MEDIUM 6.5
CVE-2026-28909
Users who connect to malicious registries with hostnames matching the bypass patterns will have their registry credentials exposed in plaintext. This…
Container
0.12.3+
HIGH 7.1
CVE-2026-35155
Dell iDRAC10, versions 1.20.70.50 and 1.30.05.10, contains an Insufficiently Protected Credentials vulnerability. A race condition vulnerability exis…
Idrac10 Firmware
1.30.10.50+
HIGH 8.1
CVE-2026-39462
A vulnerability exists in SenseLive X3050’s web management interface in which password updates are not reliably applied due to improper handling of c…
X3500 Firmware
Mitigation only
MEDIUM 5.3
CVE-2026-41345
OpenClaw before 2026.3.31 contains a credential exposure vulnerability in media download functionality that forwards Authorization headers across cro…
Openclaw
2026.3.31+