Vulnerability index

Browse CVEs

1,244 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Insufficiently Protected CredentialsCWE-522 × clear
HIGH 7.5 CVE-2026-41266 Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, /api/v1/public-chatbotConfig/:id ep exposes … Flowise 3.1.0+ Fix from $1,9502026-04-23 HIGH 7.8 CVE-2025-36568 Dell PowerProtect Data Domain BoostFS for client of Feature Release versions 7.7.1.0 through 8.5, LTS2025 release version 8.3.1.0 through 8.3.1.20, L… Data Domain Operating System 7.13.1.60 / 8.3.1.30+ Fix from $1,9502026-04-17 MEDIUM 6.2 CVE-2025-15622 Insufficiently Protected Credentials vulnerability in Sparx Systems Pty Ltd. Sparx Enterprise Architect. Client reveals plaintext OAuth2 client secre… Mitigation only Fix from $1,6002026-04-17 MEDIUM 5.7 CVE-2025-15621 Insufficiently Protected Credentials in Sparx Systems Pty Ltd. Sparx Enterprise Architect. Client does not verify the receiver of OAuth2 credentials … Mitigation only Fix from $1,6002026-04-16 CRITICAL 9.4 CVE-2026-40173 Dgraph is an open source distributed GraphQL database. Versions 25.3.1 and prior contain an unauthenticated credential disclosure vulnerability where… Dgraph 25.3.2+ Fix from $2,3002026-04-15 HIGH 8.8 CVE-2026-32171 Insufficiently protected credentials in Azure Logic Apps allows an authorized attacker to elevate privileges over a network. Azure Logic Apps Mitigation only Fix from $1,9502026-04-14 MEDIUM 6.5 CVE-2026-22574 A storing passwords in a recoverable format vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.4, FortiSOAR PaaS 7.5.0 through 7.5.2, FortiSO… Fortisoar 7.5.3 / 7.6.5+ Fix from $1,6002026-04-14 MEDIUM 6.5 CVE-2026-22576 A storing passwords in a recoverable format vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.4, FortiSOAR PaaS 7.5.0 through 7.5.2, FortiSO… Fortisoar 7.5.3 / 7.6.5+ Fix from $1,6002026-04-14 HIGH 7.5 CVE-2026-35185 HAX CMS helps manage microsite universe with PHP or NodeJs backends. Prior to 25.0.0, the /server-status endpoint is publicly accessible and exposes … Haxiam No fix yet Fix from $1,9502026-04-06 HIGH 7.5 CVE-2026-35467 The stored API keys in temporary browser client is not marked as protected allowing for JavScript console or other errors to allow for extraction of … Cveclient 1.0.24+ Fix from $1,9502026-04-02 MEDIUM 6.5 CVE-2026-4819 In Search Guard FLX versions from 1.0.0 up to 4.0.1, the audit logging feature might log user credentials from users logging into Kibana. Flx 4.1.0+ Fix from $1,6002026-03-31 HIGH 8.2 CVE-2026-29872 A cross-session information disclosure vulnerability exists in the awesome-llm-apps project in commit e46690f99c3f08be80a9877fab52acacf7ab8251 (2026-… Awesome Llm Apps No fix yet Fix from $1,9502026-03-30 HIGH 7.5 CVE-2026-33575 OpenClaw before 2026.3.12 embeds long-lived shared gateway credentials directly in pairing setup codes generated by /pair endpoint and OpenClaw qr co… Openclaw 2026.3.12+ Fix from $1,9502026-03-29 HIGH 8.1 CVE-2025-15617 Wazuh version 4.12.0 contains an exposure vulnerability in GitHub Actions workflow artifacts that allows attackers to extract the GITHUB_TOKEN from u… Wazuh No fix yet Fix from $1,9502026-03-27 HIGH 8.4 CVE-2025-13478 Cache misconfiguration vulnerability in OpenText Identity Manager on Windows, Linux allows remote authenticated users to obtain another user's sessio… Mitigation only Fix from $1,9502026-03-27 HIGH 7.5 CVE-2026-33182 Saloon is a PHP library that gives users tools to build API integrations and SDKs. Prior to version 4.0.0, when building the request URL, Saloon comb… Saloon 4.0.0+ Fix from $1,9502026-03-26 MEDIUM 5.5 CVE-2025-36440 IBM Concert 1.0.0 through 2.2.0 could allow a local user to obtain sensitive information due to missing function level access control. Concert after 2.2.0 Fix from $1,6002026-03-25 MEDIUM 6.5 CVE-2025-14790 IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 could allow an attacker to obtain sensitive information due to insufficiently protected c… Infosphere Information Server after 11.7.1.6 Fix from $1,6002026-03-25 HIGH 7.2 CVE-2025-64998 Exposure of session signing secret in Checkmk <2.4.0p23, <2.3.0p45 and 2.2.0 allows an administrator of a remote site with config sync enabled to hij… Checkmk Mitigation only Fix from $1,9502026-03-24 CRITICAL 9.1 CVE-2026-32913 OpenClaw before 2026.3.7 contains an improper header validation vulnerability in fetchWithSsrFGuard that forwards custom authorization headers across… Openclaw 2026.3.7+ Fix from $2,3002026-03-23 MEDIUM 6.5 CVE-2026-31926 Charging station authentication identifiers are publicly accessible via web-based mapping platforms. Mitigation only Fix from $1,6002026-03-20 MEDIUM 6.5 CVE-2026-28204 Charging station authentication identifiers are publicly accessible via web-based mapping platforms. Mitigation only Fix from $1,6002026-03-20 CRITICAL 9.8 CVE-2026-23658 Insufficiently protected credentials in Azure DevOps allows an unauthorized attacker to elevate privileges over a network. Azure Devops No fix yet Fix from $2,3002026-03-19 HIGH 8.1 CVE-2026-32634 Glances is an open-source system cross-platform monitoring tool. Prior to version 4.5.2, in Central Browser mode, Glances stores both the Zeroconf-ad… Glances 4.5.2+ Fix from $1,9502026-03-18 CRITICAL 9.1 CVE-2026-32633 Glances is an open-source system cross-platform monitoring tool. Prior to version 4.5.2, in Central Browser mode, the `/api/4/serverslist` endpoint r… Glances 4.5.2+ Fix from $2,3002026-03-18 HIGH 7.6 CVE-2026-32606 IncusOS is an immutable OS image dedicated to running Incus. Prior to 202603142010, the default configuration of systemd-cryptenroll as used by Incus… Patch available Fix from $1,9502026-03-18 MEDIUM 6.5 CVE-2026-21670 A vulnerability allowing a low-privileged user to extract saved SSH credentials. Veeam Backup \& Replication after 13.0.1.1071 Fix from $1,6002026-03-12 MEDIUM 5.3 CVE-2026-3783 When an OAuth2 bearer token is used for an HTTP(S) transfer, and that transfer performs a redirect to a second URL, curl could leak that token to the… Curl 8.19.0+ Fix from $1,6002026-03-11 MEDIUM 6.5 CVE-2026-27777 Charging station authentication identifiers are publicly accessible via web-based mapping platforms. Mitigation only Fix from $1,6002026-03-06 MEDIUM 6.5 CVE-2026-27027 Charging station authentication identifiers are publicly accessible via web-based mapping platforms. Mitigation only Fix from $1,6002026-03-06