Total
401 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-17595 | 2026-09-01 | N/A | N/A | ||
| Nexus Repository 3 did not fully sandbox JEXL expressions used in Content Selectors. An account holding the nexus:selectors:create permission could construct an expression that read Java object properties not intended to be exposed to the expression engine, disclosing internal JVM class metadata such as class and classloader names. This issue does not permit method invocation, object construction, or arbitrary code execution. This has been fixed by restricting property access in the JEXL sandbox to the intended data types. | |||||
| CVE-2026-44945 | 2026-09-01 | N/A | 9.1 CRITICAL | ||
| A privilege escalation vulnerability exists in Rancher's impersonation middleware (pkg/auth/requests/impersonate.go). An authenticated Rancher user with the default user global role can gain full administrative access to the Rancher control plane and transitively to all downstream clusters it manages. This issue affects Rancher: from 2.11.0 before 2.11.16, from 2.12.0 before 2.12.12, from 2.13.0 before 2.13.8, and from 2.14.0 before 2.14.2. | |||||
| CVE-2026-16072 | 1 Redhat | 1 Build Of Keycloak | 2026-08-31 | N/A | 4.9 MEDIUM |
| A flaw was found in the organization management component of Keycloak. A delegated administrator with permission to manage organizations can create an invitation for a non-existent email address and then retrieve the secret registration link directly through the application programming interface. By using this link, the administrator can create new user accounts and add them to the organization without having the required user management permissions or access to the invited email account. This allows an administrator to bypass security boundaries and add unauthorized members to an organization. | |||||
| CVE-2025-15680 | 2026-08-28 | N/A | N/A | ||
| TBEA TLogger V2.1.0.0B0.0.0.0 exposes a UART interface on the device's circuit board without sufficient protection. A physically proximate attacker can connect to the UART interface and observe the device boot process and runtime debug output. The disclosed information includes operating system details, software versions, network configuration, filesystem paths, and other implementation and debugging information that may assist an attacker in further compromising the device. | |||||
| CVE-2026-75928 | 2026-08-26 | N/A | 5.3 MEDIUM | ||
| The Brushfire platform's video content streaming application (https://online.brushfire.com) exposes database path in requests to users, allowing a remote, unauthenticated attacker to read information about other users. Fixed February 2026. | |||||
| CVE-2026-6373 | 2026-08-26 | N/A | 6.5 MEDIUM | ||
| Exposure of sensitive system information to an unauthorized control sphere vulnerability in Zyxel Networks WAH7601 allows Web Application Fingerprinting. This issue affects WAH7601: through 20072026. | |||||
| CVE-2026-78268 | 2026-08-26 | N/A | 7.5 HIGH | ||
| Unauthenticated Sensitive Data Exposure in Lead Generation Contact Widget & AI Chatbot: Chat Button, Phone Call, Telegram, Email – SiteLeads <= 1.2.0 versions. | |||||
| CVE-2026-67267 | 1 Dell | 1 Command Update | 2026-08-21 | N/A | 5.5 MEDIUM |
| Dell Command Update (DCU), versions prior to 5.7.1, contain an Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information disclosure. | |||||
| CVE-2026-32468 | 2026-08-20 | N/A | 7.5 HIGH | ||
| Unauthenticated Sensitive Data Exposure in Duitku Payment Gateway <= 2.11.14 versions. | |||||
| CVE-2026-74007 | 2026-08-20 | N/A | 5.3 MEDIUM | ||
| Unauthenticated Sensitive Data Exposure in 3D FlipBook – PDF Flipbook Viewer, Flipbook Image Gallery <= 1.16.20 versions. | |||||
| CVE-2026-66462 | 2026-08-14 | N/A | 7.5 HIGH | ||
| Unauthenticated Sensitive Data Exposure in WooCommerce Appointments <= 5.3.8 versions. | |||||
| CVE-2026-66444 | 2026-08-14 | N/A | 6.5 MEDIUM | ||
| Subscriber Sensitive Data Exposure in Payment Forms for Paystack <= 4.0.5 versions. | |||||
| CVE-2026-28169 | 2026-08-12 | N/A | 5.3 MEDIUM | ||
| Unauthenticated Sensitive Data Exposure in YITH WooCommerce Zoom Magnifier <= 2.52.0 versions. | |||||
| CVE-2026-65498 | 2026-08-12 | N/A | 5.3 MEDIUM | ||
| Unauthenticated Sensitive Data Exposure in Complianz <= 7.5.0 versions. | |||||
| CVE-2026-65458 | 2026-08-06 | N/A | 4.3 MEDIUM | ||
| Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Chouby Polylang and Chouby Polylang Pro allows Retrieve Embedded Sensitive Data. This issue affects Polylang: through 3.8.5; Polylang Pro: through 3.8.5. | |||||
| CVE-2026-56569 | 1 Hcltech | 1 Icontrol | 2026-08-05 | N/A | 4.0 MEDIUM |
| HCL iControl was affected by Sensitive Data Exposure vulnerabilities. It involves the public exposure of internal configuration files due to improper web server or application hardening. | |||||
| CVE-2023-37507 | 1 Hcltech | 1 Devops Plan | 2026-07-29 | N/A | 7.5 HIGH |
| HCL DevOps Plan is susceptible to an information disclosure that can allow an attacker to focus their attacks based upon the information revealed. | |||||
| CVE-2026-58246 | 2026-07-28 | N/A | 4.3 MEDIUM | ||
| SAP NetWeaver Application Server for ABAP and ABAP Platform writes sensitive session identifier information into a diagnostic trace when the trace is activated by a privileged user. An attacker with access to the resulting trace data could obtain identifiers that allow impersonation of legitimate users during their validity period. This leads to high impact on confidentiality. Integrity and availability are not impacted. | |||||
| CVE-2025-59178 | 2026-07-28 | N/A | N/A | ||
| Ericsson Packet Core Controller (PCC) versions prior to 1.39 contain an Exposure of Sensitive System Information vulnerability in Configuration Management allowing an attacker to enumerate other users on the system. | |||||
| CVE-2026-44955 | 2026-07-27 | N/A | 5.3 MEDIUM | ||
| Pronetiqs IntraVUE versions 3.2.1a14 and prior have an exposure of sensitive system information to an unauthorized control sphere vulnerability which could allow for asset discovery by unauthenticated users. | |||||
