CVE-2026-74007
Unauthenticated Sensitive Data Exposure in 3D FlipBook – PDF Flipbook Viewer, Flipbook Image Gallery <= 1.16.20 versions.
CVSS
5.3
Medio
EPSS
0.2%
p15
KEV
—
Exploit Today
5
0-100
Publicado: 18 ago 2026 · Última mod.: 20 ago 2026 · CWE-497
Sin historial EPSS suficiente todavía.
Unauthenticated Sensitive Data Exposure in 3D FlipBook – PDF Flipbook Viewer, Flipbook Image Gallery <= 1.16.20 versions.
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-672675.5 MED—
——0Dell Command Update (DCU), versions prior to 5.7.1, contain an Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information disclosure.13hCVE-2026-324687.5 ALT22.9%
——7Unauthenticated Sensitive Data Exposure in Duitku Payment Gateway <= 2.11.14 versions.13hCVE-2024-583757.5 ALT17.2%
——5OpenTofu versions 1.8.0 through 1.8.2 do not properly restrict sensitive variables and locals when users have opted into static evaluation of module sources, versions, and backend configurations. As a result, values marked as sensitive may be exposed through these configuration elements instead of producing an error. This is fixed in OpenTofu 1.8.3, which adds explicit errors to prevent the use of sensitive values in these contexts.3dCVE-2026-664627.5 ALT22.9%
——7Unauthenticated Sensitive Data Exposure in WooCommerce Appointments <= 5.3.8 versions.6dCVE-2026-664446.5 MED28.8%
——9Subscriber Sensitive Data Exposure in Payment Forms for Paystack <= 4.0.5 versions.6dCVE-2025-15680—5.1%
——2TBEA TLogger V2.1.0.0B0.0.0.0 exposes a UART interface on the device's circuit board without sufficient protection. A physically proximate attacker can connect to the UART interface and observe the device boot process and runtime debug output. The disclosed information includes operating system details, software versions, network configuration, filesystem paths, and other implementation and debugging information that may assist an attacker in further compromising the device.8d