VulnSea

CWE-522

CVEs classified under CWE-522, newest first.

134 CVEsRSS

CVE-2026-59158High· 7.5
1w ago

Nuxt Ollama: Public Runtime Config Exposes Ollama API Key to Browser Clients

Nuxt Ollama: Public Runtime Config Exposes Ollama API Key to Browser Clients

Twilightnuxt-ollama · nuxt-ollamavia GHSA
CVE-2026-81381Medium· 6.5
1w ago

Insufficiently protected credentials in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to disclose information over a network.

Insufficiently protected credentials in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to disclose information over a network.

Sunlitmicrosoft · visual_studio_codeEPSS 0.60%via NVD
CVE-2026-77909High· 7.7
1w ago

Insufficiently protected credentials in Azure CycleCloud allows an authorized attacker to disclose information over a network.

Insufficiently protected credentials in Azure CycleCloud allows an authorized attacker to disclose information over a network.

TwilightMicrosoft · Azure CycleCloud 8.9.2EPSS 0.59%via NVD
CVE-2026-69805High· 7.5
1w ago

External control of file name or path in .NET allows an unauthorized attacker to elevate privileges over a network.

External control of file name or path in .NET allows an unauthorized attacker to elevate privileges over a network.

TwilightMicrosoft · Microsoft Visual Studio 2022 version 17.14EPSS 0.51%via NVD
CVE-2026-64918Medium· 6.5
1w ago

Insufficiently protected credentials in Microsoft Office allows an unauthorized attacker to perform spoofing over a network.

Insufficiently protected credentials in Microsoft Office allows an unauthorized attacker to perform spoofing over a network.

Sunlitmicrosoft · 365_appsEPSS 0.48%via NVD
CVE-2026-82070Medium· 6.5
1w ago

A security issue in MongoDB Server's diagnostic reporting interface allows an authenticated user with monitoring privileges to access insufficiently protected credentials from concurrent administrative operations

A security issue in MongoDB Server's diagnostic reporting interface allows an authenticated user with monitoring privileges to access insufficiently protected credentials from concurrent administrative operations. The same credentials ar…

Sunlitmongodb · mongodbEPSS 0.24%via NVD
CVE-2026-86600High· 8.2
1w ago

In affected Snowflake drivers, WORKLOAD_IDENTITY authentication requests a cloud workload-identity token and attaches it to the login request without verifying that the configured host is a Snowflake endpoint

In affected Snowflake drivers, WORKLOAD_IDENTITY authentication requests a cloud workload-identity token and attaches it to the login request without verifying that the configured host is a Snowflake endpoint. An attacker who can modify …

TwilightSnowflake · snowflake-connector-pythonEPSS 0.31%via NVD
CVE-2026-86726Medium· 6.5
1w ago

AVideo through 29.0 contains an information disclosure vulnerability in restreamsActive.json.php that allows authenticated streamers to enumerate source stream keys and identities of all other streamers' active restreams

AVideo through 29.0 contains an information disclosure vulnerability in restreamsActive.json.php that allows authenticated streamers to enumerate source stream keys and identities of all other streamers' active restreams. The endpoint fa…

SunlitWWBN · AVideoEPSS 0.26%via NVD
CVE-2026-61516Critical· 9.8
1w ago

Netis NX10 firmware V4.0.1.5808 and V3.0.0.4142 contain an information disclosure vulnerability that allows unauthenticated attackers to retrieve the administrator password by sending a request to the sysinfo action in the web management…

Netis NX10 firmware V4.0.1.5808 and V3.0.0.4142 contain an information disclosure vulnerability that allows unauthenticated attackers to retrieve the administrator password by sending a request to the sysinfo action in the web management…

MidnightNetis Systems · NX10EPSS 0.38%via NVD
CVE-2026-76969Critical· 9.4
1w ago

@sap/cds-mtxs NPM library does not perform sufficient checks on certain functionality used in multitenant CAP applications with extensibility enabled

@sap/cds-mtxs NPM library does not perform sufficient checks on certain functionality used in multitenant CAP applications with extensibility enabled. An unauthenticated attacker could send specially crafted requests to obtain sensitive …

MidnightSAP_SE · SAP Cloud Application Programming Model (CAP)EPSS 0.29%via NVD
CVE-2026-86175Medium· 6.5PoC
2w ago

NetBox through 4.7.0 fails to redact sensitive data source backend credentials in REST and GraphQL API responses

NetBox through 4.7.0 fails to redact sensitive data source backend credentials in REST and GraphQL API responses. Authenticated users with only view permission can retrieve plaintext passwords and secret keys for Git and Amazon S3 backen…

Twilightnetbox-community · netboxEPSS 0.26%via NVD
CVE-2026-72794High· 8.6
2w ago

SiYuan: The session-cookie signing key (Conf.CookieKey) is returned to anonymous readers by /api/system/getConf

SiYuan: The session-cookie signing key (Conf.CookieKey) is returned to anonymous readers by /api/system/getConf

Twilightsiyuan-note · github.com/siyuan-note/siyuan/kernelEPSS 0.25%via OSV
CVE-2026-53603High· 7.1
2w ago

nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN

nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN. Prior to version 0.3.8, Operator session tokens are stored in plaintext in the operator_sessions table (the token column is the PRIMARY KEY). The session token is a 32…

Twilightforgekeep · nebula-meshEPSS 0.20%via NVD
CVE-2026-8862High· 7.5
2w ago

IBM Netezza Software 11.3.0.3 through Interim Fix 002 has credentials that are hardcoded in the application source code, allowing unauthorized access to the container registry

IBM Netezza Software 11.3.0.3 through Interim Fix 002 has credentials that are hardcoded in the application source code, allowing unauthorized access to the container registry. The exposed secret enables attackers to pull private contain…

Twilightibm · netezza_performance_serverEPSS 0.23%via NVD
CVE-2026-75136Medium· 6.1
2w ago

UpSignOn for Windows before 7.19.0 contains an insecure credential storage vulnerability that allows local attackers to retrieve the biometric unlock key stored in the Windows PasswordVault API without triggering any authentication promp…

UpSignOn for Windows before 7.19.0 contains an insecure credential storage vulnerability that allows local attackers to retrieve the biometric unlock key stored in the Windows PasswordVault API without triggering any authentication promp…

SunlitEPSS 0.11%via NVD
GHSA-vx52-2968-3vc6High· 7.4
2w ago

pnpm: Environment secrets exfiltrated via env-placeholder expansion in proxy settings read from an untrusted pnpm-workspace.yaml

pnpm: Environment secrets exfiltrated via env-placeholder expansion in proxy settings read from an untrusted pnpm-workspace.yaml

Twilightpnpm · pnpmvia GHSA
GHSA-3f6p-5ww8-9rcrHigh
2w ago

MySQL2: Auth Plugin Downgrade to mysql_clear_password Leaks Plaintext Credentials

MySQL2: Auth Plugin Downgrade to mysql_clear_password Leaks Plaintext Credentials

Twilightmysql2 · mysql2via GHSA
CVE-2026-61802Medium· 6.5
3w ago

Wazuh is an open-source security platform providing unified XDR and SIEM protection for endpoints and cloud workloads

Wazuh is an open-source security platform providing unified XDR and SIEM protection for endpoints and cloud workloads. In versions 4.14.0 through 4.14.6, a low-privilege API user can read the cleartext cluster key from a configuration en…

Sunlitwazuh · wazuhEPSS 0.41%via NVD
CVE-2026-55856Medium· 5.9
3w ago

MariaDB Connector/J is used to connect applications developed in Java to MariaDB and MySQL databases

MariaDB Connector/J is used to connect applications developed in Java to MariaDB and MySQL databases. Prior to 2.7.14, 3.3.5, 3.4.3, and 3.5.9, when a Java application connects with sslMode=verify-full or sslMode=verify-ca, supplies a pa…

Sunlitmariadb · org.mariadb.jdbc:mariadb-java-clientEPSS 0.22%via NVD
CVE-2026-55857Medium· 5.9
3w ago

MariaDB Connector/J is used to connect applications developed in Java to MariaDB and MySQL databases

MariaDB Connector/J is used to connect applications developed in Java to MariaDB and MySQL databases. Prior to 2.7.14, 3.3.5, 3.4.3, and 3.5.9, PAM dialog authentication can be coerced into transmitting the account password over an insec…

Sunlitmariadb · org.mariadb.jdbc:mariadb-java-clientEPSS 0.20%via NVD
CVE-2026-55860Medium· 5.9
3w ago

MariaDB Connector/R2DBC is a non-blocking MariaDB and MySQL client implemented in Java

MariaDB Connector/R2DBC is a non-blocking MariaDB and MySQL client implemented in Java. Prior to 1.4.1, org.mariadb:r2dbc-mariadb does not gate clear-text password authentication plugins on transport encryption because the Authentication…

Sunlitmariadb · org.mariadb:r2dbc-mariadbEPSS 0.15%via NVD
CVE-2026-55854Medium· 5.9
3w ago

MariaDB Connector/Node.js is used to connect applications developed on Node.js to MariaDB and MySQL databases

MariaDB Connector/Node.js is used to connect applications developed on Node.js to MariaDB and MySQL databases. Prior to 3.2.4, 3.3.3, 3.4.6, and 3.5.3, MariaDB Connector/Node.js can disclose an account password when PAM dialog authentica…

Sunlitmariadb · mariadbEPSS 0.28%via NVD
CVE-2026-55215High· 7.5
3w ago

MariaDB Connector/Node.js is used to connect applications developed on Node.js to MariaDB and MySQL databases

MariaDB Connector/Node.js is used to connect applications developed on Node.js to MariaDB and MySQL databases. Prior to versions 3.3.3, 3.4.6, and 3.5.3, when ssl is enabled without a pinned CA or server certificate, MariaDB Connector/No…

Twilightmariadb · mariadbEPSS 0.42%via NVD
CVE-2026-75960High· 8.1
3w ago

Rently Smart Home versions 20.1.0 and prior are vulnerable to an Insufficiently Protected Credentials vulnerability

Rently Smart Home versions 20.1.0 and prior are vulnerable to an Insufficiently Protected Credentials vulnerability. This could allow an attacker to retrieve pins including the Master Pin, overriding standard user permissions.

TwilightEPSS 0.35%via NVD
GHSA-93qj-5q5v-3c2hCritical
3w ago

Trojanized pantheon-agents 0.6.1 and 0.6.2 on PyPI ship a credential stealer (supply-chain account compromise)

Trojanized pantheon-agents 0.6.1 and 0.6.2 on PyPI ship a credential stealer (supply-chain account compromise)

Midnightpantheon-agents · pantheon-agentsvia GHSA
GHSA-crrc-vpp2-f5x7High· 7.5
3w ago

Duplicate Advisory: Grav: config_denied_paths default list omits `system`, exposing real secrets (e.g. system.cache.redis.password) via the Twig sandbox when config_access is enabled

Duplicate Advisory: Grav: config_denied_paths default list omits `system`, exposing real secrets (e.g. system.cache.redis.password) via the Twig sandbox when config_access is enabled

Twilightgetgrav · getgrav/gravvia GHSA
GHSA-8vp7-8q4w-vv7mHigh· 6.5
3w ago

Duplicate Advisory: Grav: UserInterface offsetget/offsetexists allow-listed in Twig sandbox let editor-authored content leak hashed_password and 2FA secrets via offsetGet()

Duplicate Advisory: Grav: UserInterface offsetget/offsetexists allow-listed in Twig sandbox let editor-authored content leak hashed_password and 2FA secrets via offsetGet()

Twilightgetgrav · getgrav/gravvia GHSA
CVE-2026-55553High· 7.5
3w ago

urllib is an HTTP client for Node.js that supports authentication, redirects, timeouts, and other request features

urllib is an HTTP client for Node.js that supports authentication, redirects, timeouts, and other request features. Prior to 4.9.1 and 2.44.1, urllib follows redirects through followRedirect but reuses caller-supplied options across orig…

Twilighturllib · urllibEPSS 0.37%via NVD
CVE-2026-71511Medium· 6.5
4w ago

Dolibarr before 24.0.0 contains a sensitive data exposure vulnerability in the Members REST API that allows authenticated attackers with member-read rights to retrieve bcrypt password verifiers by querying member endpoints

Dolibarr before 24.0.0 contains a sensitive data exposure vulnerability in the Members REST API that allows authenticated attackers with member-read rights to retrieve bcrypt password verifiers by querying member endpoints. Attackers can…

SunlitEPSS 0.24%via NVD
CVE-2026-71862High· 7.5
1mo ago

Checkmate is an open-source, self-hosted tool designed to track and monitor server hardware, uptime, response times, and incidents in real-time with beautiful visualizations

Checkmate is an open-source, self-hosted tool designed to track and monitor server hardware, uptime, response times, and incidents in real-time with beautiful visualizations. From 3.3.0 until 3.9.2, enabling the global showURL setting ca…

TwilightEPSS 0.35%via NVD
CWE-522 vulnerabilities (CVEs) — page 2 · VulnSea