CVE-2026-39709
Insertion of Sensitive Information Into Sent Data vulnerability in thetechtribe The Tribal the-tech-tribe allows Retrieve Embedded Sensitive
CVSS
5.3
Medio
EPSS
0.2%
p10
KEV
—
Exploit Today
3
0-100
Publicado: 8 abr 2026 · Última mod.: 24 jul 2026 · CWE-201
0.2%EPSS · 30 días0.2%
2026-07-152026-08-12
Insertion of Sensitive Information Into Sent Data vulnerability in thetechtribe The Tribal the-tech-tribe allows Retrieve Embedded Sensitive Data.This issue affects The Tribal: from n/a through <= 1.3.4.
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-477177.5 ALT—
——0FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. In fuxa-server version 1.3.0, the GET /api/project endpoint exposes sensitive project configuration data to guest-context requests even when secureEnabled is enabled. Version 1.3.1 fixes the issue.14hCVE-2026-166376.5 MED37.6%
——11OPeNDAP Hyrax allows SSRF and credential disclosure via unvalidated HTTP redirects that bypass the AllowedHosts allowlist and leak Earthdata headers (User-Id, Echo-Token) to attacker-controlled endpoints.3dCVE-2026-646523.3 BAJ1.9%
——1GitHub CLI (gh) is GitHub's official command line tool. Prior to version 2.97.0, gh auth status masked only the characters after the last underscore in certain fine-grained personal access tokens and GitHub App tokens. As a result, part of an affected token could appear in terminal or CI output that is captured or shared. Authenticated users are affected if they ran gh auth status (without the --show-token flag) with a token type whose format contains an underscore after the prefix. This includes fine-grained personal access tokens (github_pat_*) and GitHub App installation and user access tokens (ghs_*, ghu_*; for example, ghs_<APPID>_<JWT>), as well as the Actions GITHUB_TOKEN. Classic tokens such as gho_* and ghp_* have an underscore-free body and are not affected. This issue is fixed in version 2.97.0.6dCVE-2026-666964.3 MED7.4%
——2Contributor Sensitive Data Exposure in Gutenberg Blocks by Kadence Blocks <= 3.7.8 versions.16hCVE-2026-666855.3 MED9.8%
——3Unauthenticated Sensitive Data Exposure in Featured Video Plus <= 2.3.3 versions.16hCVE-2026-666845.3 MED15.2%
——5Unauthenticated Sensitive Data Exposure in Export Import Menus <= 1.9.2 versions.16h