CWE-497
- 10
- vulnerabilities tracked
- 2
- critical
- 18 August 2026
- latest publication
cve
Vulnerability watch
idvulnerabilityseveritypublished
CVE-2026-32468Unauthenticated Sensitive Data Exposure in Duitku Payment Gateway <= 2.11.14 versions. High CVSS 7.5 CVE-2024-58375OpenTofu versions 1.8.0 through 1.8.2 do not properly restrict sensitive variables and locals when users have opted into static evaluation of module sources, versions, and backend configurations. As a result, values marked as sensitive may be exposed through these configuration elements instead of producing an error. This is fixed in OpenTofu 1.8.3, which adds explicit errors to prevent the use of sensitive values in these contexts.NVD analysis in progress High CVSS 7.5 CVE-2026-66462Unauthenticated Sensitive Data Exposure in WooCommerce Appointments <= 5.3.8 versions. High CVSS 7.5 CVE-2026-44945A privilege escalation vulnerability exists in Rancher's impersonation middleware (pkg/auth/requests/impersonate.go). An authenticated Rancher user with the default user
global role can gain full administrative access to the Rancher control
plane and transitively to all downstream clusters it manages.
This issue affects Rancher: from 2.11.0 before 2.11.16, from 2.12.0 before 2.12.12, from 2.13.0 before 2.13.8, and from 2.14.0 before 2.14.2.NVD analysis in progress Critical CVSS 9.1 CVE-2026-59528Subscriber Sensitive Data Exposure in ShipTime: Discounted Shipping Rates <= 1.1.1 versions. High CVSS 7.5 CVE-2026-59548Unauthenticated Sensitive Data Exposure in Byteflows Travel & Hotel Booking <= 1.0.0 versions. High CVSS 7.5 CVE-2026-28698Pronetiqs IntraVUE versions 3.2.1a14 and prior have an exposure of sensitive system information to an unauthorized control sphere vulnerability which could expose the underlying host/share filesystem. High CVSS 8.6 CVE-2023-37507HCL DevOps Plan is susceptible to an information disclosure that can allow an attacker to focus their attacks based upon the information revealed.Hcltech Devops Plan High CVSS 7.5 CVE-2026-14808Prog
Management System developed by PROG MIS has a Exposure of Sensitive
Information vulnerability, allowing unauthenticated remote attackers to view
a specific page and obtain the database account and password. Critical CVSS 9.8 CVE-2026-56124phpUploader before 2.0.2 contains an unauthenticated information disclosure vulnerability that allows remote attackers to access the full contents of the uploaded-files database table by visiting any page of the application. The index model executes an unbounded SELECT query and embeds the complete JSON-encoded result set in an inline script block, exposing uploader IP addresses, Argon2ID key hashes, internal filenames, and SHA-256 fingerprints. High CVSS 7.5