Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 7.5
CVE-2026-41266
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, /api/v1/public-chatbotConfig/:id ep exposes …
Flowise
3.1.0+
HIGH 7.8
CVE-2025-36568
Dell PowerProtect Data Domain BoostFS for client of Feature Release versions 7.7.1.0 through 8.5, LTS2025 release version 8.3.1.0 through 8.3.1.20, L…
Data Domain Operating System
7.13.1.60 / 8.3.1.30+
MEDIUM 6.2
CVE-2025-15622
Insufficiently Protected Credentials vulnerability in Sparx Systems Pty Ltd. Sparx Enterprise Architect. Client reveals plaintext OAuth2 client secre…
Mitigation only
MEDIUM 5.7
CVE-2025-15621
Insufficiently Protected Credentials in Sparx Systems Pty Ltd. Sparx Enterprise Architect. Client does not verify the receiver of OAuth2 credentials …
Mitigation only
CRITICAL 9.4
CVE-2026-40173
Dgraph is an open source distributed GraphQL database. Versions 25.3.1 and prior contain an unauthenticated credential disclosure vulnerability where…
Dgraph
25.3.2+
HIGH 8.8
CVE-2026-32171
Insufficiently protected credentials in Azure Logic Apps allows an authorized attacker to elevate privileges over a network.
Azure Logic Apps
Mitigation only
MEDIUM 6.5
CVE-2026-22574
A storing passwords in a recoverable format vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.4, FortiSOAR PaaS 7.5.0 through 7.5.2, FortiSO…
Fortisoar
7.5.3 / 7.6.5+
MEDIUM 6.5
CVE-2026-22576
A storing passwords in a recoverable format vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.4, FortiSOAR PaaS 7.5.0 through 7.5.2, FortiSO…
Fortisoar
7.5.3 / 7.6.5+
HIGH 7.5
CVE-2026-35185
HAX CMS helps manage microsite universe with PHP or NodeJs backends. Prior to 25.0.0, the /server-status endpoint is publicly accessible and exposes …
Haxiam
No fix yet
HIGH 7.5
CVE-2026-35467
The stored API keys in temporary browser client is not marked as protected allowing for JavScript console or other errors to allow for extraction of …
Cveclient
1.0.24+
MEDIUM 6.5
CVE-2026-4819
In Search Guard FLX versions from 1.0.0 up to 4.0.1, the audit logging feature might log user credentials from users logging into Kibana.
Flx
4.1.0+
HIGH 8.2
CVE-2026-29872
A cross-session information disclosure vulnerability exists in the awesome-llm-apps project in commit e46690f99c3f08be80a9877fab52acacf7ab8251 (2026-…
Awesome Llm Apps
No fix yet
HIGH 7.5
CVE-2026-33575
OpenClaw before 2026.3.12 embeds long-lived shared gateway credentials directly in pairing setup codes generated by /pair endpoint and OpenClaw qr co…
Openclaw
2026.3.12+
HIGH 8.1
CVE-2025-15617
Wazuh version 4.12.0 contains an exposure vulnerability in GitHub Actions workflow artifacts that allows attackers to extract the GITHUB_TOKEN from u…
Wazuh
No fix yet
HIGH 8.4
CVE-2025-13478
Cache misconfiguration vulnerability in OpenText Identity Manager on Windows, Linux allows remote authenticated users to obtain another user's sessio…
Mitigation only
HIGH 7.5
CVE-2026-33182
Saloon is a PHP library that gives users tools to build API integrations and SDKs. Prior to version 4.0.0, when building the request URL, Saloon comb…
Saloon
4.0.0+
MEDIUM 5.5
CVE-2025-36440
IBM Concert 1.0.0 through 2.2.0 could allow a local user to obtain sensitive information due to missing function level access control.
Concert
after 2.2.0
MEDIUM 6.5
CVE-2025-14790
IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 could allow an attacker to obtain sensitive information due to insufficiently protected c…
Infosphere Information Server
after 11.7.1.6
HIGH 7.2
CVE-2025-64998
Exposure of session signing secret in Checkmk <2.4.0p23, <2.3.0p45 and 2.2.0 allows an administrator of a remote site with config sync enabled to hij…
Checkmk
Mitigation only
CRITICAL 9.1
CVE-2026-32913
OpenClaw before 2026.3.7 contains an improper header validation vulnerability in fetchWithSsrFGuard that forwards custom authorization headers across…
Openclaw
2026.3.7+
MEDIUM 6.5
CVE-2026-31926
Charging station authentication identifiers are publicly accessible via web-based mapping platforms.
Mitigation only
MEDIUM 6.5
CVE-2026-28204
Charging station authentication identifiers are publicly accessible via web-based mapping platforms.
Mitigation only
CRITICAL 9.8
CVE-2026-23658
Insufficiently protected credentials in Azure DevOps allows an unauthorized attacker to elevate privileges over a network.
Azure Devops
No fix yet
HIGH 8.1
CVE-2026-32634
Glances is an open-source system cross-platform monitoring tool. Prior to version 4.5.2, in Central Browser mode, Glances stores both the Zeroconf-ad…
Glances
4.5.2+
CRITICAL 9.1
CVE-2026-32633
Glances is an open-source system cross-platform monitoring tool. Prior to version 4.5.2, in Central Browser mode, the `/api/4/serverslist` endpoint r…
Glances
4.5.2+
HIGH 7.6
CVE-2026-32606
IncusOS is an immutable OS image dedicated to running Incus. Prior to 202603142010, the default configuration of systemd-cryptenroll as used by Incus…
Patch available
MEDIUM 6.5
CVE-2026-21670
A vulnerability allowing a low-privileged user to extract saved SSH credentials.
Veeam Backup \& Replication
after 13.0.1.1071
MEDIUM 5.3
CVE-2026-3783
When an OAuth2 bearer token is used for an HTTP(S) transfer, and that transfer
performs a redirect to a second URL, curl could leak that token to the…
Curl
8.19.0+
MEDIUM 6.5
CVE-2026-27777
Charging station authentication identifiers are publicly accessible via web-based mapping platforms.
Mitigation only
MEDIUM 6.5
CVE-2026-27027
Charging station authentication identifiers are publicly accessible via web-based mapping platforms.
Mitigation only