Export limit exceeded: 22561 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (406 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-78268 | 2026-08-24 | 7.5 High | ||
| Unauthenticated Sensitive Data Exposure in Lead Generation Contact Widget & AI Chatbot: Chat Button, Phone Call, Telegram, Email – SiteLeads <= 1.2.0 versions. | ||||
| CVE-2026-32468 | 2 Duitku, Wordpress | 2 Duitku Payment Gateway, Wordpress | 2026-08-24 | 7.5 High |
| Unauthenticated Sensitive Data Exposure in Duitku Payment Gateway <= 2.11.14 versions. | ||||
| CVE-2026-74948 | 1 Mozilla | 2 Firefox, Thunderbird | 2026-08-24 | 6.5 Medium |
| Information disclosure in the Graphics component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1. | ||||
| CVE-2026-74007 | 2 Iberezansky, Wordpress | 2 3d Flipbook – Pdf Embedder, Pdf Flipbook Viewer, Flipbook Image Gallery, Wordpress | 2026-08-21 | 5.3 Medium |
| Unauthenticated Sensitive Data Exposure in 3D FlipBook – PDF Flipbook Viewer, Flipbook Image Gallery <= 1.16.20 versions. | ||||
| CVE-2026-75928 | 1 Brushfire | 1 Online Experience | 2026-08-21 | 5.3 Medium |
| The Brushfire platform's video content streaming application (https://online.brushfire.com) exposes database path in requests to users, allowing a remote, unauthenticated attacker to read information about other users. Fixed February 2026. | ||||
| CVE-2026-67267 | 1 Dell | 2 Command Update, Dell Command Update (dcu) | 2026-08-21 | 5.5 Medium |
| Dell Command Update (DCU), versions prior to 5.7.1, contain an Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information disclosure. | ||||
| CVE-2024-58375 | 1 Opentofu | 1 Opentofu | 2026-08-17 | 7.5 High |
| OpenTofu versions 1.8.0 through 1.8.2 do not properly restrict sensitive variables and locals when users have opted into static evaluation of module sources, versions, and backend configurations. As a result, values marked as sensitive may be exposed through these configuration elements instead of producing an error. This is fixed in OpenTofu 1.8.3, which adds explicit errors to prevent the use of sensitive values in these contexts. | ||||
| CVE-2026-72498 | 1 Linux | 1 Linux Kernel | 2026-08-17 | 5.5 Medium |
| In the Linux kernel, the following vulnerability has been resolved: RDMA/bnxt_re: Avoid displaying the kernel pointer While dumping the info on MR using the rdma tool, we dump the mr_hwq which is a kernel pointer. There is no need to expose this value for end user. So avoid it. | ||||
| CVE-2026-66444 | 2 Kendysond, Wordpress | 2 Payment Forms For Paystack, Wordpress | 2026-08-14 | 6.5 Medium |
| Subscriber Sensitive Data Exposure in Payment Forms for Paystack <= 4.0.5 versions. | ||||
| CVE-2026-66462 | 2 Bookingwp, Wordpress | 2 Woocommerce Appointments, Wordpress | 2026-08-14 | 7.5 High |
| Unauthenticated Sensitive Data Exposure in WooCommerce Appointments <= 5.3.8 versions. | ||||
| CVE-2025-15680 | 1 Tbea | 1 Tbea Tlogger | 2026-08-12 | N/A |
| TBEA TLogger V2.1.0.0B0.0.0.0 exposes a UART interface on the device's circuit board without sufficient protection. A physically proximate attacker can connect to the UART interface and observe the device boot process and runtime debug output. The disclosed information includes operating system details, software versions, network configuration, filesystem paths, and other implementation and debugging information that may assist an attacker in further compromising the device. | ||||
| CVE-2026-65498 | 2 Complianz, Wordpress | 2 Complianz, Wordpress | 2026-08-12 | 5.3 Medium |
| Unauthenticated Sensitive Data Exposure in Complianz <= 7.5.0 versions. | ||||
| CVE-2026-69127 | 1 Getkirby | 1 Kirby | 2026-08-11 | N/A |
| Kirby is an open-source content management system. Prior to 4.9.5 and from 5.0.0 through 5.5.1, the REST API error handler can return unsanitized PHP error messages that expose the full filesystem path of the Kirby installation to unauthenticated API users. This vulnerability affects all Kirby sites that have not disabled the REST API with the 'api' => false option. This issue is fixed in versions 4.9.5 and 5.5.2. | ||||
| CVE-2026-17595 | 1 Sonatype | 1 Nexus Repository Manager | 2026-08-11 | N/A |
| Nexus Repository 3 did not fully sandbox JEXL expressions used in Content Selectors. An account holding the nexus:selectors:create permission could construct an expression that read Java object properties not intended to be exposed to the expression engine, disclosing internal JVM class metadata such as class and classloader names. This issue does not permit method invocation, object construction, or arbitrary code execution. This has been fixed by restricting property access in the JEXL sandbox to the intended data types. | ||||
| CVE-2026-6373 | 1 Zyxel Networks | 1 Wah7601 | 2026-08-11 | 6.5 Medium |
| Exposure of sensitive system information to an unauthorized control sphere vulnerability in Zyxel Networks WAH7601 allows Web Application Fingerprinting. This issue affects WAH7601: through 20072026. | ||||
| CVE-2026-28169 | 2 Wordpress, Yithemes | 2 Wordpress, Yith Woocommerce Zoom Magnifier | 2026-08-06 | 5.3 Medium |
| Unauthenticated Sensitive Data Exposure in YITH WooCommerce Zoom Magnifier <= 2.52.0 versions. | ||||
| CVE-2026-65458 | 2 Chouby, Wordpress | 2 Polylang, Wordpress | 2026-08-06 | 4.3 Medium |
| Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Chouby Polylang and Chouby Polylang Pro allows Retrieve Embedded Sensitive Data. This issue affects Polylang: through 3.8.5; Polylang Pro: through 3.8.5. | ||||
| CVE-2026-44945 | 1 Suse | 1 Rancher | 2026-08-06 | 9.1 Critical |
| A privilege escalation vulnerability exists in Rancher's impersonation middleware (pkg/auth/requests/impersonate.go). An authenticated Rancher user with the default user global role can gain full administrative access to the Rancher control plane and transitively to all downstream clusters it manages. This issue affects Rancher: from 2.11.0 before 2.11.16, from 2.12.0 before 2.12.12, from 2.13.0 before 2.13.8, and from 2.14.0 before 2.14.2. | ||||
| CVE-2026-56569 | 1 Hcltech | 1 Icontrol | 2026-08-02 | 4 Medium |
| HCL iControl was affected by Sensitive Data Exposure vulnerabilities. It involves the public exposure of internal configuration files due to improper web server or application hardening. | ||||
| CVE-2026-10588 | 1 Lenovo | 57 Ideapad 5 15aba7 Bios, Ideapad Pro 5 16agp11 Bios, Ideapad Pro 5 16asp10 Bios and 54 more | 2026-08-01 | 4.4 Medium |
| A potential vulnerability could allow a local privileged attacker to disclose the address of protected System Management Mode memory. | ||||