Total
410 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-45582 | 1 N8n-mcp | 1 N8n-mcp | 2026-07-21 | N/A | 6.5 MEDIUM |
| n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. Prior to 2.51.3, the workflow telemetry sanitizer could retain partial fragments of URL-shaped node parameters before sending workflow data to the project's anonymous telemetry backend. Values placed in HTTP-Request-style node parameters — such as customer or tenant identifiers, short secrets embedded in query strings, and signed request parameters — could therefore appear in stored telemetry, contrary to the collection boundary documented in PRIVACY.md. This vulnerability is fixed in 2.51.3. | |||||
| CVE-2026-7189 | 2026-07-17 | N/A | 7.5 HIGH | ||
| Insertion of sensitive information into sent data vulnerability in Proliz Software Ltd. Co. Proliz's OBS allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Proliz's OBS: before v3.6.0. | |||||
| CVE-2026-7488 | 2026-07-17 | N/A | 7.5 HIGH | ||
| Insertion of sensitive information into sent data vulnerability in IKAS Technology Inc. E-Commerce allows Retrieve Embedded Sensitive Data. This issue affects E-Commerce: through 03062026. | |||||
| CVE-2026-4525 | 1 Hashicorp | 1 Vault | 2026-07-15 | N/A | 7.5 HIGH |
| If a Vault auth mount is configured to pass through the "Authorization" header, and the "Authorization" header is used to authenticate to Vault, Vault forwarded the Vault token to the auth plugin backend. Fixed in 2.0.0, 1.21.5, 1.20.10, and 1.19.16. | |||||
| CVE-2026-33180 | 2026-07-15 | N/A | 7.5 HIGH | ||
| HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to version 6.9.0, when setting headers in HTTP requests, the internal HTTP client sends headers first to the host in the initial URL but also, if asked to follow redirects and a 30X HTTP response code is returned, to the host mentioned in URL in the Location: response header value. Sending the same set of headers to subsequent hosts is a problem as this header often contains privacy sensitive information or data that could allow others to impersonate the client's request. This issue has been patched in release 6.9.0. No known workarounds are available. | |||||
| CVE-2026-27877 | 1 Grafana | 1 Grafana | 2026-07-15 | N/A | 6.5 MEDIUM |
| When using public dashboards and direct data-sources, all direct data-sources' passwords are exposed despite not being used in dashboards. No passwords of proxied data-sources are exposed. We encourage all direct data-sources to be converted to proxied data-sources as far as possible to improve your deployments' security. | |||||
| CVE-2026-5483 | 1 Redhat | 1 Openshift Ai | 2026-07-15 | N/A | 8.5 HIGH |
| A flaw was found in odh-dashboard in Red Hat Openshift AI. This vulnerability in the `odh-dashboard` component of Red Hat OpenShift AI (RHOAI) allows for the disclosure of Kubernetes Service Account tokens through a NodeJS endpoint. This could enable an attacker to gain unauthorized access to Kubernetes resources. | |||||
| CVE-2026-39912 | 2026-07-14 | N/A | 9.1 CRITICAL | ||
| V2Board 1.6.1 through 1.7.4 and Xboard through 0.1.9 expose authentication tokens in HTTP response bodies of the loginWithMailLink endpoint when the login_with_mail_link_enable feature is active. Unauthenticated attackers can POST to the loginWithMailLink endpoint with a known email address to receive the full authentication URL in the response, then exchange the token at the token2Login endpoint to obtain a valid bearer token with complete account access including admin privileges. | |||||
| CVE-2026-42505 | 1 Golang | 1 Go | 2026-07-13 | N/A | 5.3 MEDIUM |
| Handshakes which used Encrypted Client Hello could be de-anonymized by a passive network observer due to a disclosure of pre-shared key identities in the unencrypted client hello. | |||||
| CVE-2026-56460 | 1 Hcltechsw | 2 Hcl Devops Deploy, Hcl Launch | 2026-07-13 | N/A | 6.5 MEDIUM |
| HCL DevOps Deploy / HCL Launch could disclose sensitive configurations and secrets to authenticated users in API responses that could be used in further attacks against the system. | |||||
| CVE-2026-1694 | 1 Arcinfo | 1 Pcvue | 2026-07-09 | N/A | 4.3 MEDIUM |
| HTTP headers are added by the default configuration of IIS and ASP.net, and are not removed at the deployment phase of the webservices used by the WebVue, WebScheduler, TouchVue and SnapVue features of PcVue in version 12.0.0 through 16.3.3 included. It unnecessarily exposes sensitive information about the server configuration. | |||||
| CVE-2026-1365 | 2026-07-09 | N/A | 6.5 MEDIUM | ||
| Insertion of sensitive information into sent data vulnerability in Sayax Energy Technologies Inc. OSOS allows Authentication Bypass. This issue affects OSOS: through 09072026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. | |||||
| CVE-2026-20151 | 1 Cisco | 1 Smart Software Manager On-prem | 2026-07-08 | N/A | 7.3 HIGH |
| A vulnerability in the web interface of Cisco Smart Software Manager On-Prem (SSM On-Prem) could allow an authenticated, remote attacker to elevate privileges on an affected system. This vulnerability is due to the improper transmission of sensitive user information. An attacker could exploit this vulnerability by sending a crafted message to an affected Cisco SSM On-Prem host and retrieving session credentials from subsequent status messages. A successful exploit could allow the attacker to elevate privileges on the affected system from low to administrative. To exploit this vulnerability, the attacker must have valid credentials for a user account with at least the role of System User. Note: This vulnerability exposes information only about users who logged in to the Cisco SSM On-Prem host using the web interface and who are currently logged in. SSH sessions are not affected. | |||||
| CVE-2026-59519 | 2026-07-07 | N/A | 5.3 MEDIUM | ||
| Insertion of Sensitive Information Into Sent Data vulnerability in Softaculous FormLayer allows Retrieve Embedded Sensitive Data. This issue affects FormLayer: from n/a through 1.0.6. | |||||
| CVE-2026-59511 | 2026-07-06 | N/A | 5.3 MEDIUM | ||
| Insertion of Sensitive Information Into Sent Data vulnerability in Tim Strifler Exclusive Addons Elementor allows Retrieve Embedded Sensitive Data. This issue affects Exclusive Addons Elementor: from n/a through 2.7.9.9. | |||||
| CVE-2025-69132 | 2026-07-02 | N/A | 6.5 MEDIUM | ||
| Subscriber Sensitive Data Exposure in Corpkit <= 1.0.5 versions. | |||||
| CVE-2026-13211 | 2026-07-02 | N/A | 4.3 MEDIUM | ||
| The genucenter web interface before version 8.0p11 unnecessarily exposes sensitive SNMP authentication and encryption keys in its HTTP responses to users with the “Service” or “Admin” role. | |||||
| CVE-2026-12085 | 1 Ibm | 2 Devops Deploy, Urbancode Deploy | 2026-07-02 | N/A | 6.5 MEDIUM |
| IBM UCD - IBM UrbanCode Deploy 7.3 through 7.3.2.18 and IBM UCD - IBM DevOps Deploy 8.0 through 8.0.1.13, 8.1 through 8.1.2.6, and 8.2 through 8.2.1.0 IBM DevOps Deploy could disclose sensitive configurations and secrets to authenticated users in API responses that could be used in further attacks against the system. | |||||
| CVE-2026-13437 | 1 Devolutions | 1 Powershell Universal | 2026-07-02 | N/A | 6.5 MEDIUM |
| Insertion of sensitive information into sent data in the AI Agent job API in Devolutions PowerShell Universal 2026.2.0 allows an authenticated user with AI Agent read access to obtain reusable, potentially higher-privileged authentication tokens via App Tokens serialized in plaintext in job API responses. | |||||
| CVE-2026-57347 | 2026-07-02 | N/A | 6.5 MEDIUM | ||
| Subscriber Sensitive Data Exposure in Hotel Booking Lite <= 6.0.3 versions. | |||||
