Vulnerabilities (CVE)

Filtered by CWE-201
Total 410 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2026-20484 1 Mediatek 78 Mt6739, Mt6739 Firmware, Mt6761 and 75 more 2026-08-19 N/A 4.4 MEDIUM
In TFA, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11053160; Issue ID: MSV-8004.
CVE-2026-34226 1 Capricorn86 1 Happy Dom 2026-08-19 N/A 7.5 HIGH
Happy DOM is a JavaScript implementation of a web browser without its graphical user interface. Versions prior to 20.8.9 may attach cookies from the current page origin (`window.location`) instead of the request target URL when `fetch(..., { credentials: "include" })` is used. This can leak cookies from origin A to destination B. Version 20.8.9 fixes the issue.
CVE-2026-28174 2026-08-14 N/A 6.5 MEDIUM
Customer Sensitive Data Exposure in WP Event SOlution <= 4.1.18 versions.
CVE-2026-66463 2026-08-14 N/A 7.5 HIGH
Unauthenticated Sensitive Data Exposure in iCARRY <= 2.9 versions.
CVE-2026-66443 2026-08-14 N/A 7.5 HIGH
Unauthenticated Sensitive Data Exposure in REST API Log <= 1.7.1 versions.
CVE-2026-13380 1 Vsee 2 Clinic, Clinic Api 2026-08-14 N/A 7.5 HIGH
VSee Clinic 7.1.26 and VSee Clinic API 1.3.0 exposes cleartext SFTP credentials in the HTTP responses of three unauthenticated endpoints. The credentials are present in these responses only when SFTP connections have been configured within the application. No authentication is required to retrieve these credentials. An unauthenticated remote attacker who observes any of these HTTP responses on an instance where SFTP is configured can obtain the credentials and use them to access the associated SFTP server.
CVE-2026-4035 1 Lfprojects 1 Mlflow 2026-08-14 N/A 7.7 HIGH
A vulnerability in mlflow/mlflow versions prior to 3.11.0 allows for the resolution of environment variables in AI Gateway secrets, which can be exploited to exfiltrate sensitive server-side environment credentials to an attacker-controlled endpoint. This issue arises because the `api_key` field in gateway secrets can accept `$ENV_VAR` references, which are resolved against the MLflow server's environment during runtime. The resolved secrets are then sent in provider authentication headers to the configured upstream `api_base`. This vulnerability can be exploited by low-privileged authenticated users in basic-auth deployments or by unauthenticated users in default deployments without `basic-auth`. The impact includes potential leakage of sensitive credentials such as cloud artifact credentials (`AWS_ACCESS_KEY_ID`, `AWS_SECRET_ACCESS_KEY`), which could lead to artifact poisoning and cross-boundary code execution in downstream environments. The issue is fixed in version 3.11.0.
CVE-2025-7708 2026-08-13 N/A 6.8 MEDIUM
Insertion of Sensitive Information Into Sent Data vulnerability in Atlas Educational Software Industry Ltd. Co. K12net allows Communication Channel Manipulation. This issue affects k12net: through 26072025.
CVE-2026-66696 2026-08-12 N/A 4.3 MEDIUM
Contributor Sensitive Data Exposure in Gutenberg Blocks by Kadence Blocks <= 3.7.8 versions.
CVE-2026-28144 2026-08-12 N/A 4.3 MEDIUM
Insertion of Sensitive Information Into Sent Data vulnerability in Flipper Code WP Maps allows Retrieve Embedded Sensitive Data. This issue affects WP Maps: from n/a through 4.9.6.
CVE-2026-66683 2026-08-12 N/A 5.3 MEDIUM
Unauthenticated Sensitive Data Exposure in Custom CSS and JavaScript <= 2.0.16 versions.
CVE-2026-66684 2026-08-12 N/A 5.3 MEDIUM
Unauthenticated Sensitive Data Exposure in Export Import Menus <= 1.9.2 versions.
CVE-2026-65543 2026-08-12 N/A 7.5 HIGH
Subscriber Sensitive Data Exposure in Vimeo <= 1.2.2 versions.
CVE-2026-66685 2026-08-12 N/A 5.3 MEDIUM
Unauthenticated Sensitive Data Exposure in Featured Video Plus <= 2.3.3 versions.
CVE-2026-6267 1 Gitlab 1 Gitlab 2026-08-03 N/A 8.5 HIGH
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.1.0 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain conditions could have allowed an authenticated user with Developer role to access unauthorized information due to insufficient access controls on internal request handling.
CVE-2026-54660 2026-07-30 N/A 7.4 HIGH
swagger-typescript-api generates API clients for Fetch or Axios from OpenAPI specifications. Prior to 13.12.2, src/resolved-swagger-schema.ts getRemoteRequestHeaders forwards --authorizationToken to every URL fetched by fetchRemoteSchemaDocument while warmUpRemoteSchemasCache resolves external $ref URLs, allowing an attacker-controlled OpenAPI spec to exfiltrate the developer or CI bearer token to a cross-origin endpoint. This issue is fixed in version 13.12.2.
CVE-2026-67425 2026-07-30 N/A 8.6 HIGH
Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.6, llm.chat reads provider keys such as OPENAI_API_KEY and ANTHROPIC_API_KEY from the environment and sends them in the Authorization: Bearer header to caller-controlled base_url, allowing an attacker to receive the operator's key on a public host that passes the SSRF guard. This issue is fixed in version 2.26.6.
CVE-2026-16798 1 Devolutions 1 Powershell Universal 2026-07-29 N/A 6.5 MEDIUM
Insertion of sensitive information into sent data in the automation jobs API in Devolutions PowerShell Universal 2026.2.2 and earlier allows an authenticated user with scoped job or script read permission to obtain another user's stored OAuth refresh token via job read responses that fail to strip the refresh token.
CVE-2026-54171 1 Excon Project 1 Excon 2026-07-29 N/A 6.5 MEDIUM
Excon is usable, fast, simple HTTP 1.1 for Ruby. Prior to 1.5.0, Excon's RedirectFollower middleware failed to strip additional sensitive headers when following redirects and did not provide a custom list of headers to strip. This could cause inadvertent leakage of sensitive data when the initial request includes header information that is not intended for the new target. This issue is fixed in version 1.5.0.
CVE-2026-64643 1 Vercel 1 Next.js 2026-07-29 N/A 5.3 MEDIUM
Next.js is a React framework for building full-stack web applications. In versions 12.0.0 through 15.5.20 and 16.0.0 through 16.2.10, Next.js applications using App Router, Server Actions (use server) or use cache endpoints can be disclosed bypassing any authentication on the pages where these endpoints are usually used. Server Action IDs can be disclosed to unauthenticated users via publicly served client artifacts (for example, static chunks containing action references). Affected users are applications using App Router and Server Actions. By itself, this disclosure is typically a recon/enumeration primitive; however, it can increase risk when combined with other weaknesses. This issue has been fixed in versions 15.5.21 and 16.2.11.