Export limit exceeded: 381158 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (1798 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-8470 | 2 Ibm, Langflow | 2 Langflow Oss, Langflow | 2026-08-05 | 7.4 High |
| IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, and 1.0.0 through 1.10.3 use Python's non-cryptographic random module for generating Fernet encryption keys from user secrets under 32 characters. The deterministic Mersenne Twister PRNG produces identical keys for identical seeds, allowing attackers to reproduce encryption keys and decrypt stored API keys and authentication tokens. | ||||
| CVE-2025-15627 | 2 Tp-link, Tp Link | 228 Omada Controller, Omada Ds1008x, Omada Ds1008x Firmware and 225 more | 2026-08-05 | 7.5 High |
| A cryptographic weakness exists in the Omada adoption protocol. The protocol relies on hard-coded cryptographic keys to establish trust and protect authentication exchanges between controllers and managed devices during device adoption. An attacker may be able to impersonate trusted controllers or managed devices and gain access to sensitive adoption-related communications. | ||||
| CVE-2026-18754 | 1 Geovision Inc. | 1 Gv-as1620 (gv-cloud) | 2026-08-05 | 9.1 Critical |
| The product firmware contains an embedded, static RSA private key utilized by the Lighttpd web server for TLS termination. Exposure of this private key allows malicious actors to breach the confidentiality and integrity of HTTPS communications, enabling traffic decryption and server spoofing. | ||||
| CVE-2026-14804 | 1 Bilin Software And Informatics Consultancy Inc. | 1 Humanist Digital Human Resources | 2026-08-05 | 9.1 Critical |
| Use of hard-coded cryptographic key vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Read Sensitive Constants Within an Executable. This issue affects HUMANIST Digital Human Resources: from 26.0 before 26.1. | ||||
| CVE-2026-18753 | 1 Geovision | 1 Gv-asmanager | 2026-08-05 | 9.1 Critical |
| The product firmware contains an embedded, static RSA private key utilized by the Lighttpd web server for TLS termination. Exposure of this private key allows malicious actors to breach the confidentiality and integrity of HTTPS communications, enabling traffic decryption and server spoofing. | ||||
| CVE-2026-8590 | 1 Spotfire | 3 Spotfire Enterprise, Spotfire Enterprise With External Consumers, Spotfire On Kubernetes | 2026-08-05 | N/A |
| Vulnerability in Spotfire Spotfire Enterprise (Spotfire Server modules), Spotfire Spotfire Enterprise with External Consumers (Spotfire Server modules), Spotfire Spotfire on Kubernetes (Spotfire Server modules). This issue affects Spotfire Enterprise: through 14.0.12, through 14.4.2, through 14.5.0, through 14.6.1, through 14.6.2, through 14.7.0, through 14.8.0; Spotfire Enterprise with External Consumers: through 14.0.12, through 14.5.0, through 14.6.0, through 14.6.1, through 14.6.2, through 14.7.0, through 14.8.0; Spotfire on Kubernetes: through 4.2.0, 5.0.X, 6.0.X. | ||||
| CVE-2021-32086 | 1 Quest | 2 Kace Systems Deployment Appliance, Kace Systems Management Appliance | 2026-08-05 | 9.8 Critical |
| An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. It uses a hardcoded symmetric encryption key to encrypt secrets in the MySQL databases. (This key is not unique for each installation.) An attacker that gains access to the MySQL server or a backup files can decrypt the secrets. Often, the decrypted secrets can be used to escalate privileges within KACE, or gain privileged access to unrelated systems or services. | ||||
| CVE-2026-16504 | 1 Vps.org | 1 Zulip Template | 2026-08-04 | 9.8 Critical |
| Deployment of the VPS.org one-click Zulip template deploys a hardcoded application signing key, a default database password ("zulip"), and DISABLE_HTTPS=True. | ||||
| CVE-2026-18654 | 1 Aws | 1 Aws-cli | 2026-08-04 | 6.8 Medium |
| Key exchange without entity authentication in the EMR SSH helper commands in Amazon AWS CLI before 1.45.28 and AWS CLI v2 before 2.35.3 might allow man-in-the-middle attackers to intercept SSHsessions and file transfers via network positioning between the client and the EMR cluster endpoint. To remediate this issue, users should upgrade to AWS CLI v1 1.45.28 or later, or AWS CLI v2 2.35.3 or later. | ||||
| CVE-2026-59651 | 1 Legion Of The Bouncy Castle Inc. | 2 Bc-java, Bc-lts-java | 2026-08-03 | N/A |
| In Bouncy Castle for Java before 1.85, BKS keystore accepts legacy version with 16-bit integrity MAC key. This issue also affects Bouncy Castle for Java LTS before 2.73.12. | ||||
| CVE-2026-56609 | 1 Hcltech | 1 Icontrol | 2026-08-03 | 4.8 Medium |
| HCL iControl is affected by Weak SSL/TLS Version Supported vulnerability. It was observed that the application was using weak TLS versions such as TLS 1.0 and 1.1. These outdated protocols lack modern security features, making them vulnerable to known attacks and exposing sensitive information during data transmission. | ||||
| CVE-2026-67336 | 1 Better-auth | 1 Better-auth\/oauth-provider | 2026-08-03 | 8.7 High |
| better-auth versions before 1.6.11 contain insecure cryptographic defaults in the oidcProvider and mcp plugins that advertise the none algorithm and accept plain PKCE by default. Attackers can exploit algorithm negotiation to accept unsigned tokens or intercept authorization codes when PKCE plain is used instead of the required S256 method. | ||||
| CVE-2026-58040 | 2 Nodejs, Redhat | 2 Nodejs, Hummingbird | 2026-08-03 | 6.3 Medium |
| An incomplete fix has been identified in Node.js: HTTPS Agent TLS session reuse skips hostname verification across identity policies (incomplete fix of CVE-2026-48934). This vulnerability affects Node.js **22.x**, **24.x**, and **26.x**. | ||||
| CVE-2024-23564 | 1 Hcl Software | 1 Aftermarket Epc | 2026-08-03 | 9.1 Critical |
| HCL Aftermarket EPC is affected by Business Logic Vulnerability using which a non valid user of the application can obtain passwords from the server and redirect them to their own email address by manipulating the server's response. The application includes checks in the initial requests to verify the validity of the provided UserId, but similar validation is not applied to Email requests when sending passwords to user emails. | ||||
| CVE-2026-5846 | 1 Watchfire | 4 Bc550, Bc750, Bc760 and 1 more | 2026-08-02 | 5.7 Medium |
| The affected Watchfire Controller Software contains self-signed hard-coded RSA private keys and corresponding X.509 certificates used for authenticating and encrypting HTTPS/TLS connections to the controller's built-in web management interface. These keys are embedded in plaintext within the application patch binaries in the firmware directly from Watchfire's Remote Support filestore. | ||||
| CVE-2026-65309 | 1 Andritz | 2 250 Scala, Hipase-250 | 2026-08-02 | 7.5 High |
| ANDRITZ HIPASE-250 (formerly 250 SCALA) in affected versions stores and transmits user passwords using a reversible format instead of a one-way password hash. This allows an attacker able to read the credential store or capture network traffic to recover all stored passwords. | ||||
| CVE-2026-54787 | 2 Redhat, Sigstore | 2 Hummingbird, Sigstore-go | 2026-08-02 | 3.1 Low |
| sigstore-go is a Go library for Sigstore signing and verification. Prior to 1.2.1, sigstore-go does not check a bundle signing timestamp against the validity window of an ExpiringKey wrapping a self-managed long-lived signing key without a certificate, which can allow an attacker holding expired key material to sign accepted bundles. This issue is fixed in version 1.2.1. | ||||
| CVE-2025-63579 | 1 Kyocera | 1 Command Center Rx | 2026-07-31 | 7.5 High |
| Unauthorized use of Kyocera printers, allows all information stored in the Kyocera address book to be exported. The security measure that encrypts incoming data ian be bypassed with this vulnerability, allowing encrypted data to be decrypted. Passwords and other sensitive information can be obtained. This affects Kyocera Command Center RX TASKalfa 2552ci, TASKalfa 3252ci, TASKalfa 2553ci, TASKalfa 3253ci, TASKalfa 3554ci, TASKalfa 4052ci, TASKalfa 5052ci, TASKalfa 6052ci, TASKalfa 7052ci, TASKalfa 8052ci, TASKalfa 7353ci, TASKalfa 8353ci, TASKalfa 2554ci, TASKalfa 3254ci, TASKalfa 505. | ||||
| CVE-2026-59776 | 1 Sony | 1 Felica Ic Chips | 2026-07-30 | N/A |
| Missing Cryptographic Step (CWE-325) vulnerability exists in certain FeliCa IC chips shipped in or before 2017. If the vulnerability is exploited, information stored in the IC chip may be read or tampered with. | ||||
| CVE-2026-17666 | 1 Google | 1 Chrome | 2026-07-30 | 9.1 Critical |
| Cryptographic Flaw in Enterprise in Google Chrome prior to 151.0.7922.72 allowed an attacker in a privileged network position to bypass discretionary access control via malicious network traffic. (Chromium security severity: High) | ||||