Browse and filter security vulnerabilities across ecosystems
Browse and filter security vulnerabilities across ecosystems
AIOHTTP: DigestAuthMiddleware Applies Credentials to Cross-Origin Redirect Challenges
NTLMv2 hash disclosure via UNC path handling on Windows
OpenClaw < 2026.5.12 - Custom Header Leakage via MCP Streamable HTTP Cross-Origin Redirects
Mattermost Desktop App fails to restrict the allow list of domains which NTLM credentials are passed
CodexBar < 0.33.0 Credential Leakage via HTTP Redirect
Reactor Netty HTTP Client Leaks Credentials On Protocol Downgrade Redirect
OpenBullet2 0.3.2 NTLMv2 Hash Disclosure via UNC Path Proxy Source
Flowise: Basic Auth Credentials Exposed via API
HAXcms: Mass Token Exfiltration and Cross-Tenant Hijack
Unencrypted storage of authentication state in StrongDM Desktop Application state.kv file
In JetBrains TeamCity before 2026
MacGregor Voyage Data Recorder (VDR) G4e Insufficiently Protected Credentials
Insufficiently protected credentials vulnerability in IPSpeaker component in Synology Surveillance Station before 9
Hitachi Vantara Pentaho Data Integration & Analytics - Insufficiently Protected Credentials
Besen BS20 EV Charging Station BLE/UDP insufficiently protected credentials
TypeBot: Cross-Workspace Credential Theft via Bot-Engine Preview Endpoint
OTP Bypass in Digital Operation Services' WifiBurada
CODESYS Visualization - Insufficiently Protected Credentials
Prevent password disclosure and force reset during Slack import
HCL AION is affected by a vulnerability where basic authorization tokens are used for authentication
Showing 1 - 20 of 1,000+ results