CVE-2024-40582
Pentaminds CuroVMS v2.0.1 was discovered to contain exposed sensitive information.
CVSS
7.5
Alto
EPSS
0.3%
p23
KEV
—
Exploit Today
7
0-100
Publicado: 9 dic 2024 · Última mod.: 5 jul 2026 · CWE-312
0.3%EPSS · 30 días0.3%
2026-08-132026-09-09
Pentaminds CuroVMS v2.0.1 was discovered to contain exposed sensitive information.
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-41307.1 ALT—
———There is a storage of sensitive information in cleartext vulnerability in NI SystemLink. This vulnerability may allow an attacker with local access to obtain sensitive information stored by the system in the clear. This vulnerability affects NI SystemLink and NI SystemLink Server 2026 Q3 and prior versions.13hCVE-2026-800585.5 MED0.1%
——0Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Cleartext Storage of Sensitive Information vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to information exposure.2dCVE-2026-862805.3 MED11.9%
——4A vulnerability was identified in SourceCodester Syllabus-Aligned Learning Management & Examination System 1.0. This affects an unknown function of the file cict_portal.sql. Such manipulation leads to cleartext storage of sensitive information. It is possible to launch the attack remotely. The exploit is publicly available and might be used.3dCVE-2026-53603—10.4%
——3nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN. Prior to version 0.3.8, Operator session tokens are stored in plaintext in the operator_sessions table (the token column is the PRIMARY KEY). The session token is a 32-byte random hex value sent directly in a cookie and valid for 24 hours. Anyone who can read the database (backup, snapshot, file copy, or SQL-level disclosure) obtains every active session token and can hijack operator sessions directly, with no further authentication. This issue has been patched in version 0.3.8.2dCVE-2026-737482.2 BAJ1.3%
——0A vulnerability in the affected interface of HPE Networking Fabric Composer allows an attacker with administrative privileges to access sensitive information in a cleartext format. A successful exploit allows an attacker to retrieve information which could be used to potentially gain further access to network services supported by HPE Networking Fabric Composer.9dCVE-2026-835517.2 ALT31.2%
——9Cleartext storage of sensitive information in the @step and @remote decorator pipeline component in Amazon SageMaker Python SDK before v3.11.0 and v2.256.0 might allow an authenticated remote user to extract the HMAC signing key from SageMaker DescribePipeline API responses and forge valid integrity signatures for specially crafted function payloads, achieving code execution in another user's pipeline execution context within the same AWS account.8d