The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.
1,403 vulnerabilities with CWE-522
CVE-2026-41266
HIGH
Flowise: Sensitive Data Leak in public-chatbotConfig
CVSS 7.5
CVE-2026-6408
LOW
Tanium addressed an information disclosure vulnerability in Tanium Server.
CVSS 2.7
CVE-2026-40173
CRITICAL
Dgraph: Unauthenticated pprof endpoint leaks admin auth token
CVSS 9.4
CVE-2026-32171
HIGH
Azure Logic Apps Elevation of Privilege Vulnerability
CVSS 8.8
CVE-2026-27316
LOW
Fortinet FortiSandbox <5.0.5 - Info Disclosure
CVSS 2.7
CVE-2026-22576
MEDIUM
FortiSOAR PaaS <7.6.4 - Info Disclosure
CVSS 4.3
CVE-2026-22574
MEDIUM
FortiSOAR PaaS <7.6.4 - Info Disclosure
CVSS 4.1
CVE-2026-34262
MEDIUM
Information Disclosure Vulnerability in SAP HANA Cockpit and HANA Database Explorer
CVSS 5.0
CVE-2026-35185
HIGH
HAX CMS's public /server-status endpoint exposes authentication tokens, user activity, and client IP addresses
CVSS 7.5
CVE-2026-35467
HIGH
Private Key stored as extractable in browser IndexeDB
CVSS 7.5
CVE-2026-4819
MEDIUM
Search Guard audit logs can contain under certain conditions user credentials
CVSS 4.9
CVE-2026-29872
HIGH
awesome-llm-apps e46690f - Info Disclosure
CVSS 8.2
CVE-2026-33575
HIGH
OpenClaw < 2026.3.12 - Long-lived Credential Exposure in Pairing Setup Codes
CVSS 7.5
CVE-2026-33182
HIGH
Saloon is vulnerable to SSRF and credential leakage via absolute URL in endpoint overriding base URL
CVSS 7.5
CVE-2026-32913
CRITICAL
OpenClaw < 2026.3.7 - Custom Authorization Header Leakage via Cross-Origin Redirects
CVSS 9.3
CVE-2026-31926
MEDIUM
IGL-Technologies eParking.fi Insufficiently Protected Credentials
CVSS 6.5
CVE-2026-28204
MEDIUM
CTEK Chargeportal Insufficiently Protected Credentials
CVSS 6.5
CVE-2026-23658
HIGH
Azure DevOps: msazure Elevation of Privilege Vulnerability
CVSS 8.6
CVE-2026-32634
HIGH
Glances Central Browser Autodiscovery Leaks Reusable Credentials to Zeroconf-Spoofed Servers
CVSS 8.1
CVE-2026-32633
CRITICAL
Glances's Browser API Exposes Reusable Downstream Credentials via `/api/4/serverslist`
CVSS 9.1
CVE-2026-32606
HIGH
IncusOS <202603142010 LUKS - TPM Policy Encryption Bypass
CVSS 7.6
CVE-2026-21670
HIGH
Veeam Backup & Replication 13.0.0.496-13.0.1 - Insufficiently Protected SSH Credentials
CVSS 7.7
CVE-2026-3783
MEDIUM
curl 7.33.0-8.19.0 - OAuth2 Bearer Token Leak via Redirect with .netrc Hostname Match
CVSS 5.3
CVE-2026-27777
MEDIUM
Mobiliti e-mobi.hu - Unprotected User Data Exposure via Web-Based Mapping Platform
CVSS 6.5
CVE-2026-27027
MEDIUM
Everon api.everon.io - Unprotected Credential Exposure via Web Mapping Platform
CVSS 6.5
Details
Vulnerabilities
1,403