CVE-2026-61976
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Crocoblock JetBlocks For Elementor jet-blocks al
CVSS
5.3
Medium
EPSS
0.3%
p26
KEV
—
Exploit Today
8
0-100
Published: Jul 13, 2026 · Last modified: Jul 13, 2026 · CWE-497
0.2%EPSS · 30 days0.3%
2026-08-172026-09-14
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Crocoblock JetBlocks For Elementor jet-blocks allows Retrieve Embedded Sensitive Data.This issue affects JetBlocks For Elementor: from n/a through <= 1.5.0.
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-380588.1 HIG26.9%
——8The endpoint on the iDirect iQ200 VSAT terminal returns the complete device configuration as JSON, including the SECURITY section which contains MD5-crypt password hashes for the root SSH and web administration accounts. Any user with valid web credentials can extract these hashes and crack them offline using commodity hardware.4dCVE-2026-619114.3 MED12.2%
——4An issue was discovered in Cyrus IMAP before 3.12.4. There is a Sieve mailbox existence oracle. An authenticated user could install a Sieve script that probed whether another user's private mailbox existed, or read the value of shared mailbox annotations, by observing which fileinto branch fired during LMTP delivery.5dCVE-2026-813945.5 MED32.8%
——10Exposure of sensitive system information to an unauthorized control sphere in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.6dCVE-2026-813875.5 MED34.5%
——10Exposure of sensitive system information to an unauthorized control sphere in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.6dCVE-2026-713307.5 HIG54.2%
——16Exposure of sensitive system information to an unauthorized control sphere in Windows Services for NFS ONCRPC XDR Driver allows an unauthorized attacker to disclose information over a network.7dCVE-2026-698325.6 MED31.4%
——9Exposure of sensitive system information to an unauthorized control sphere in Windows Win32K allows an authorized attacker to disclose information locally.7d