CVE-2026-97240High· 7.5▾ TwilightUnauthenticated Sensitive Data Exposure in StifLi Backup Tools <= 2.2.7 versions.
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Unauthenticated Sensitive Data Exposure in StifLi Backup Tools <= 2.2.7 versions.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-97241High· 7.5Unauthenticated Sensitive Data Exposure in BackupEase <= 2.2.2 versions.
CVE-2026-97261Medium· 5.3Unauthenticated Sensitive Data Exposure in Notivo <= 1.4.2 versions.
CVE-2026-97302Medium· 5.3Unauthenticated Sensitive Data Exposure in MPG <= 4.2.3 versions.
CVE-2026-86450High· 7.5Insertion of sensitive information into sent data vulnerability in Parla Auto Automotive Trading Limited Company DetaWix Mobile Web Portal allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects DetaWix Mobil…
CVE-2026-101043High· 7.4pnpm versions 11.0.0 before 11.11.0 and 10.7.0 before 10.34.5 expand ${VAR} environment-variable placeholders in the httpProxy, httpsProxy, and noProxy settings read from a project's pnpm-workspace.yaml
CVE-2026-91766Medium· 5.9When the http:// stream wrapper follows a redirect it forwards the user-supplied Authorization, Cookie and Proxy-Authorization headers unchanged, even when the redirect target is a different host, a different port, or a downgrade from HT…