EN
en direct
type de faiblesse

CWE-497

10
vulnérabilités suivies
2
critiques
18 août 2026
dernière publication
Éditeurs les plus touchés
cve

Veille des vulnérabilités

identifiantvulnérabilitésévéritépublié
CVE-2026-32468Unauthenticated Sensitive Data Exposure in Duitku Payment Gateway <= 2.11.14 versions. Élevée CVSS 7.5 18/08 CVE-2024-58375OpenTofu versions 1.8.0 through 1.8.2 do not properly restrict sensitive variables and locals when users have opted into static evaluation of module sources, versions, and backend configurations. As a result, values marked as sensitive may be exposed through these configuration elements instead of producing an error. This is fixed in OpenTofu 1.8.3, which adds explicit errors to prevent the use of sensitive values in these contexts.Analyse NVD en cours Élevée CVSS 7.5 16/08 CVE-2026-66462Unauthenticated Sensitive Data Exposure in WooCommerce Appointments <= 5.3.8 versions. Élevée CVSS 7.5 13/08 CVE-2026-44945A privilege escalation vulnerability exists in Rancher's impersonation middleware (pkg/auth/requests/impersonate.go). An authenticated Rancher user with the default user global role can gain full administrative access to the Rancher control plane and transitively to all downstream clusters it manages. This issue affects Rancher: from 2.11.0 before 2.11.16, from 2.12.0 before 2.12.12, from 2.13.0 before 2.13.8, and from 2.14.0 before 2.14.2.Analyse NVD en cours Critique CVSS 9.1 05/08 CVE-2026-59528Subscriber Sensitive Data Exposure in ShipTime: Discounted Shipping Rates <= 1.1.1 versions. Élevée CVSS 7.5 27/07 CVE-2026-59548Unauthenticated Sensitive Data Exposure in Byteflows Travel &amp; Hotel Booking <= 1.0.0 versions. Élevée CVSS 7.5 27/07 CVE-2026-28698Pronetiqs IntraVUE versions 3.2.1a14 and prior have an exposure of sensitive system information to an unauthorized control sphere vulnerability which could expose the underlying host/share filesystem. Élevée CVSS 8.6 23/07 CVE-2023-37507HCL DevOps Plan is susceptible to an information disclosure that can allow an attacker to focus their attacks based upon the information revealed.Hcltech Devops Plan Élevée CVSS 7.5 21/07 CVE-2026-14808Prog Management System developed by PROG MIS has a Exposure of Sensitive Information vulnerability, allowing unauthenticated remote attackers to view a specific page and obtain the database account and password. Critique CVSS 9.8 06/07 CVE-2026-56124phpUploader before 2.0.2 contains an unauthenticated information disclosure vulnerability that allows remote attackers to access the full contents of the uploaded-files database table by visiting any page of the application. The index model executes an unbounded SELECT query and embeds the complete JSON-encoded result set in an inline script block, exposing uploader IP addresses, Argon2ID key hashes, internal filenames, and SHA-256 fingerprints. Élevée CVSS 7.5 29/06

Tapez au moins deux caractères.

naviguer ouvrir esc fermer