Total
410 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-20484 | 1 Mediatek | 78 Mt6739, Mt6739 Firmware, Mt6761 and 75 more | 2026-08-19 | N/A | 4.4 MEDIUM |
| In TFA, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11053160; Issue ID: MSV-8004. | |||||
| CVE-2026-34226 | 1 Capricorn86 | 1 Happy Dom | 2026-08-19 | N/A | 7.5 HIGH |
| Happy DOM is a JavaScript implementation of a web browser without its graphical user interface. Versions prior to 20.8.9 may attach cookies from the current page origin (`window.location`) instead of the request target URL when `fetch(..., { credentials: "include" })` is used. This can leak cookies from origin A to destination B. Version 20.8.9 fixes the issue. | |||||
| CVE-2026-28174 | 2026-08-14 | N/A | 6.5 MEDIUM | ||
| Customer Sensitive Data Exposure in WP Event SOlution <= 4.1.18 versions. | |||||
| CVE-2026-66463 | 2026-08-14 | N/A | 7.5 HIGH | ||
| Unauthenticated Sensitive Data Exposure in iCARRY <= 2.9 versions. | |||||
| CVE-2026-66443 | 2026-08-14 | N/A | 7.5 HIGH | ||
| Unauthenticated Sensitive Data Exposure in REST API Log <= 1.7.1 versions. | |||||
| CVE-2026-13380 | 1 Vsee | 2 Clinic, Clinic Api | 2026-08-14 | N/A | 7.5 HIGH |
| VSee Clinic 7.1.26 and VSee Clinic API 1.3.0 exposes cleartext SFTP credentials in the HTTP responses of three unauthenticated endpoints. The credentials are present in these responses only when SFTP connections have been configured within the application. No authentication is required to retrieve these credentials. An unauthenticated remote attacker who observes any of these HTTP responses on an instance where SFTP is configured can obtain the credentials and use them to access the associated SFTP server. | |||||
| CVE-2026-4035 | 1 Lfprojects | 1 Mlflow | 2026-08-14 | N/A | 7.7 HIGH |
| A vulnerability in mlflow/mlflow versions prior to 3.11.0 allows for the resolution of environment variables in AI Gateway secrets, which can be exploited to exfiltrate sensitive server-side environment credentials to an attacker-controlled endpoint. This issue arises because the `api_key` field in gateway secrets can accept `$ENV_VAR` references, which are resolved against the MLflow server's environment during runtime. The resolved secrets are then sent in provider authentication headers to the configured upstream `api_base`. This vulnerability can be exploited by low-privileged authenticated users in basic-auth deployments or by unauthenticated users in default deployments without `basic-auth`. The impact includes potential leakage of sensitive credentials such as cloud artifact credentials (`AWS_ACCESS_KEY_ID`, `AWS_SECRET_ACCESS_KEY`), which could lead to artifact poisoning and cross-boundary code execution in downstream environments. The issue is fixed in version 3.11.0. | |||||
| CVE-2025-7708 | 2026-08-13 | N/A | 6.8 MEDIUM | ||
| Insertion of Sensitive Information Into Sent Data vulnerability in Atlas Educational Software Industry Ltd. Co. K12net allows Communication Channel Manipulation. This issue affects k12net: through 26072025. | |||||
| CVE-2026-66696 | 2026-08-12 | N/A | 4.3 MEDIUM | ||
| Contributor Sensitive Data Exposure in Gutenberg Blocks by Kadence Blocks <= 3.7.8 versions. | |||||
| CVE-2026-28144 | 2026-08-12 | N/A | 4.3 MEDIUM | ||
| Insertion of Sensitive Information Into Sent Data vulnerability in Flipper Code WP Maps allows Retrieve Embedded Sensitive Data. This issue affects WP Maps: from n/a through 4.9.6. | |||||
| CVE-2026-66683 | 2026-08-12 | N/A | 5.3 MEDIUM | ||
| Unauthenticated Sensitive Data Exposure in Custom CSS and JavaScript <= 2.0.16 versions. | |||||
| CVE-2026-66684 | 2026-08-12 | N/A | 5.3 MEDIUM | ||
| Unauthenticated Sensitive Data Exposure in Export Import Menus <= 1.9.2 versions. | |||||
| CVE-2026-65543 | 2026-08-12 | N/A | 7.5 HIGH | ||
| Subscriber Sensitive Data Exposure in Vimeo <= 1.2.2 versions. | |||||
| CVE-2026-66685 | 2026-08-12 | N/A | 5.3 MEDIUM | ||
| Unauthenticated Sensitive Data Exposure in Featured Video Plus <= 2.3.3 versions. | |||||
| CVE-2026-6267 | 1 Gitlab | 1 Gitlab | 2026-08-03 | N/A | 8.5 HIGH |
| GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.1.0 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain conditions could have allowed an authenticated user with Developer role to access unauthorized information due to insufficient access controls on internal request handling. | |||||
| CVE-2026-54660 | 2026-07-30 | N/A | 7.4 HIGH | ||
| swagger-typescript-api generates API clients for Fetch or Axios from OpenAPI specifications. Prior to 13.12.2, src/resolved-swagger-schema.ts getRemoteRequestHeaders forwards --authorizationToken to every URL fetched by fetchRemoteSchemaDocument while warmUpRemoteSchemasCache resolves external $ref URLs, allowing an attacker-controlled OpenAPI spec to exfiltrate the developer or CI bearer token to a cross-origin endpoint. This issue is fixed in version 13.12.2. | |||||
| CVE-2026-67425 | 2026-07-30 | N/A | 8.6 HIGH | ||
| Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.6, llm.chat reads provider keys such as OPENAI_API_KEY and ANTHROPIC_API_KEY from the environment and sends them in the Authorization: Bearer header to caller-controlled base_url, allowing an attacker to receive the operator's key on a public host that passes the SSRF guard. This issue is fixed in version 2.26.6. | |||||
| CVE-2026-16798 | 1 Devolutions | 1 Powershell Universal | 2026-07-29 | N/A | 6.5 MEDIUM |
| Insertion of sensitive information into sent data in the automation jobs API in Devolutions PowerShell Universal 2026.2.2 and earlier allows an authenticated user with scoped job or script read permission to obtain another user's stored OAuth refresh token via job read responses that fail to strip the refresh token. | |||||
| CVE-2026-54171 | 1 Excon Project | 1 Excon | 2026-07-29 | N/A | 6.5 MEDIUM |
| Excon is usable, fast, simple HTTP 1.1 for Ruby. Prior to 1.5.0, Excon's RedirectFollower middleware failed to strip additional sensitive headers when following redirects and did not provide a custom list of headers to strip. This could cause inadvertent leakage of sensitive data when the initial request includes header information that is not intended for the new target. This issue is fixed in version 1.5.0. | |||||
| CVE-2026-64643 | 1 Vercel | 1 Next.js | 2026-07-29 | N/A | 5.3 MEDIUM |
| Next.js is a React framework for building full-stack web applications. In versions 12.0.0 through 15.5.20 and 16.0.0 through 16.2.10, Next.js applications using App Router, Server Actions (use server) or use cache endpoints can be disclosed bypassing any authentication on the pages where these endpoints are usually used. Server Action IDs can be disclosed to unauthenticated users via publicly served client artifacts (for example, static chunks containing action references). Affected users are applications using App Router and Server Actions. By itself, this disclosure is typically a recon/enumeration primitive; however, it can increase risk when combined with other weaknesses. This issue has been fixed in versions 15.5.21 and 16.2.11. | |||||
