
CVE-2026-28766
CVE-2026-28766: Missing Authentication on User Account Endpoint — Gardyn Home Kit (ICSA-26-055-03)

CVE-2026-28766: Missing Authentication on User Account Endpoint — Gardyn Home Kit (ICSA-26-055-03)

WPQA < 5.5 - Unauthenticated Private Message Disclosure

Authenticated API Key Exposure in Nagios Log Server 2024R1.3.1

CVE on FlagForge on versions 2.0.0 to 2.3.0. Upgrade to version 2.3.1 to fix the issue.

Demonstrates an Insecure Direct Object Reference (IDOR) vulnerability in Liner's chat component, allowing attackers to tamper with other users'…

Appspec YML and YAML leaks

Download Monitor <= 4.7.60 - Sensitive Information Exposure via REST API

CVE-2025-54554 – Unauthenticated Access in tiaudit REST API leading to Sensitive Information Disclosure

VulnCheck's official command line tool

Your gateway to OWASP. Discover, engage, and help shape the future!

Browser privacy-leak detector — eight detection modules, risk scoring, and per-account history, all in your browser.

Detailed disclosure of CVE-2024-1208 and CVE-2024-1210: sensitive information exposure via REST API in LearnDash WordPress plugin, allowing…

Sensitive Information Exposure via assignments in LearnDash.

CVE-2026-25197: Authorization Bypass via IDOR — Gardyn Home Kit (ICSA-26-055-03)

Documents a high-severity ExaGrid EX10 MailConfiguration API access control flaw that leaks plaintext SMTP credentials to authenticated operators,…