CVE-2026-47717
FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. In fuxa-server version 1.3.0, the GET /api/project endpoint expose
CVSS
7.5
High
EPSS
—
KEV
—
Exploit Today
0
0-100
Published: Aug 12, 2026 · Last modified: Aug 12, 2026 · CWE-201
Not enough EPSS history yet.
FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. In fuxa-server version 1.3.0, the GET /api/project endpoint exposes sensitive project configuration data to guest-context requests even when secureEnabled is enabled. Version 1.3.1 fixes the issue.
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-166376.5 MED37.6%
——11OPeNDAP Hyrax allows SSRF and credential disclosure via unvalidated HTTP redirects that bypass the AllowedHosts allowlist and leak Earthdata headers (User-Id, Echo-Token) to attacker-controlled endpoints.3dCVE-2026-646523.3 LOW1.9%
——1GitHub CLI (gh) is GitHub's official command line tool. Prior to version 2.97.0, gh auth status masked only the characters after the last underscore in certain fine-grained personal access tokens and GitHub App tokens. As a result, part of an affected token could appear in terminal or CI output that is captured or shared. Authenticated users are affected if they ran gh auth status (without the --show-token flag) with a token type whose format contains an underscore after the prefix. This includes fine-grained personal access tokens (github_pat_*) and GitHub App installation and user access tokens (ghs_*, ghu_*; for example, ghs_<APPID>_<JWT>), as well as the Actions GITHUB_TOKEN. Classic tokens such as gho_* and ghp_* have an underscore-free body and are not affected. This issue is fixed in version 2.97.0.6dCVE-2026-666964.3 MED7.4%
——2Contributor Sensitive Data Exposure in Gutenberg Blocks by Kadence Blocks <= 3.7.8 versions.16hCVE-2026-666855.3 MED9.8%
——3Unauthenticated Sensitive Data Exposure in Featured Video Plus <= 2.3.3 versions.16hCVE-2026-666845.3 MED15.2%
——5Unauthenticated Sensitive Data Exposure in Export Import Menus <= 1.9.2 versions.16hCVE-2026-666835.3 MED15.2%
——5Unauthenticated Sensitive Data Exposure in Custom CSS and JavaScript <= 2.0.16 versions.16h