Skip to main content

CWE archive

CWE-540 CVEs

Programmatic archive

31 CVEs tagged with CWE-5401 Critical, 8 High, 17 Medium, 5 Low, 0 Unrated.

CVE-2026-16581

Published Jul 28, 2026

In igloohome Smart Lock Mobile App versions 3.2.3 and prior, an Inclusion of Sensitive Information in Source Code vulnerability could allow an unauthorized actor to access functio…

CVSS 6.9 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-45728

Published May 26, 2026

Algernon is a small self-contained pure-Go web server. Prior to 1.17.7, when Algernon is invoked with a single file path instead of a directory, singleFileMode is set to true and…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-35383

Published Apr 2, 2026

Bentley Systems iTwin Platform exposed a Cesium ion access token in the source of some web pages. An unauthenticated attacker could use this token to enumerate or delete certain a…

CVSS 6.9 · Medium
evidence mentions
3
Buzz score
28.9

CVE-2026-22275

Published Jan 23, 2026

Dell ECS, versions 3.8.1.0 through 3.8.1.7, and Dell ObjectScale versions prior to 4.2.0.0, contains an Inclusion of Sensitive Information in Source Code vulnerability. A low priv…

CVSS 4.4 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-38327

Published Jul 10, 2025

IBM Analytics Content Hub 2.0, 2.1, 2.2, and 2.3 is vulnerable to information exposure and further attacks due to an exposed JavaScript source map which could assist an attacker t…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-49182

Published Jun 12, 2025

Files in the source code contain login credentials for the admin user and the property configuration password, allowing an attacker to get full access to the application.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-0923

Published Jun 11, 2025

IBM Cognos Analytics 11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 12.0.0, 12.0.1, 12.0.2, 12.0.3, and 12.0.4 stores source code on the web server that could aid in further attacks agai…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-3403

Published Apr 8, 2025

A vulnerability was found in Vivotek NVR ND8422P, NVR ND9525P and NVR ND9541P 2.4.0.204/3.3.0.104/4.2.0.101. It has been classified as problematic. Affected is an unknown function…

CVSS 5.1 · Medium

CVE-2024-55907

Published Mar 2, 2025

IBM Cognos Analytics Mobile 1.1 for iOS application could allow an attacker to reverse engineer the codebase to gain knowledge about the programming technique, interface, class de…

CVSS 2.0 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-26013

Published Feb 21, 2025

An issue in Loggrove v.1.0 allows a remote attacker to obtain sensitive information via the read.py component.

CVSS 8.2 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-23215

Published Jan 31, 2025

PMD is an extensible multilanguage static code analyzer. The passphrase for the PMD and PMD Designer release signing keys are included in jar published to Maven Central. The priva…

CVSS 9.3 · Critical
evidence mentions
3
Buzz score
18.9

CVE-2024-35144

Published Jan 25, 2025

IBM Maximo Application Suite 8.10, 8.11, and 9.0 - Monitor Component stores source code on the web server that could aid in further attacks against the system.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-38647

Published Nov 22, 2024

An exposure of sensitive information vulnerability has been reported to affect QNAP AI Core. If exploited, the vulnerability could allow remote attackers to compromise the securit…

CVSS 7.9 · High
Vendor/product tagsBeta · best-effort

CVE-2024-9596

Published Oct 10, 2024

An issue has been discovered in GitLab EE affecting all versions starting from 16.6 prior to 17.2.9, from 17.3 prior to 17.3.5, and from 17.4 prior to 17.4.2. It was possible for…

CVSS 3.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-8417

Published Sep 4, 2024

A vulnerability was found in 云课网络科技有限公司 Yunke Online School System up to 1.5.5. It has been declared as problematic. This vulnerability affects unknown code of the file /admin/edu…

CVSS 2.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-39729

Published Jul 15, 2024

IBM Datacap Navigator 9.1.5, 9.1.6, 9.1.7, 9.1.8, and 9.1.9 could allow an authenticated user to obtain sensitive information from source code that could be used in further attack…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-1272

Published Jun 5, 2024

Inclusion of Sensitive Information in Source Code vulnerability in TNB Mobile Solutions Cockpit Software allows Retrieve Embedded Sensitive Data. This issue affects Cockpit Softw…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-2355

Published Mar 10, 2024

A vulnerability has been found in keerti1924 Secret-Coder-PHP-Project 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /se…

CVSS 3.7 · Low
Showing 1-25 of 31 CVEsPage 1 of 2