Threats Tagged 'cwe-540'
View all threats tagged with 'cwe-540'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-540'
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-103097 is a high-severity vulnerability in GeoVision Inc.'s GV-Eye Android application version 3.6.0. The issue involves a hardcoded API key embedded within the application package, which can be extracted through reverse engineering. This exposure allows unauthorized users to misuse the API key, potentially leading to unauthorized access to services relying on this key. The vulnerability does not affect confidentiality of user data directly but compromises the security of the API key itself. Join the discussion | CVE Database V5 | 10/02/2026, 00:14:46 UTC Added: 10/02/2026, 01:02:07 UTC |
CVE-2026-103096 is a vulnerability in GeoVision Inc.'s GV-Eye Android application version 3.6.0 where an API key is hardcoded and can be extracted from the application package. Because Android apps can be reverse engineered, this allows unauthorized users to retrieve and misuse the embedded API key. The vulnerability has a high severity with a CVSS score of 7.5, indicating a network attack vector with no privileges or user interaction required and high confidentiality impact. No official patch or remediation guidance is currently provided by the vendor. Users should check for vendor advisories for updates and avoid distributing the vulnerable version until a fix is available. Join the discussion | CVE Database V5 | 10/02/2026, 00:14:08 UTC Added: 10/02/2026, 01:02:07 UTC |
0 A vulnerability was identified in Intelbras TIP 125i 4.3.35/4.3.41. The affected element is an unknown function of the component Básico Page. Such manipulation leads to inclusion of sensitive information in source code. The attack can be launched remotely. A high complexity level is associated with this attack. The exploitability is described as difficult. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure. Join the discussion | GCVE Database | 09/28/2026, 23:30:10 UTC Added: 09/29/2026, 04:41:35 UTC |
0 Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Inclusion of Sensitive Information in Source Code vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information exposure. Join the discussion | CVE Database V5 | 09/23/2026, 14:34:43 UTC Added: 09/23/2026, 14:48:31 UTC |
0 IBM Cognos Analytics 12.1.0 through 12.1.3 FP1, and 12.0.4 through 12.0.4 FP2 stores sensitive information in source code could be used by an authenticated user in further attacks against the system. Join the discussion | CVE Database V5 | 09/18/2026, 15:41:19 UTC Added: 09/18/2026, 15:47:08 UTC |
0 In igloohome Smart Lock Mobile App versions 3.2.3 and prior, an Inclusion of Sensitive Information in Source Code vulnerability could allow an unauthorized actor to access functions or backend services that were not sufficiently protected by authentication controls. Join the discussion | CVE Database V5 | 07/28/2026, 20:05:35 UTC Added: 07/28/2026, 20:37:45 UTC |
0 Algernon is a small self-contained pure-Go web server. Prior to 1.17.7, when Algernon is invoked with a single file path instead of a directory, singleFileMode is set to true and debugMode is forcibly enabled.debugMode activates the PrettyError renderer, which on any Lua or template error response dumps the absolute path of the file that errored, complete byte contents of that file, and exception or parser error text. This response is served with HTTP 200 OK to whoever sent the request that triggered the error. Any client able to reach the server and able to provoke a runtime error in the served script obtains the full server-side source of that script and of any sibling Lua data file consulted during the request. This vulnerability is fixed in 1.17.7. Join the discussion | CVE Database V5 | 05/26/2026, 16:38:50 UTC Added: 05/26/2026, 17:02:38 UTC |
0 CVE-2026-4155 is a high-severity vulnerability in ChargePoint Home Flex charging stations version 5.5.4.13. It involves the inclusion of a secret cryptographic seed value within the genpw script, which allows remote attackers to disclose sensitive information without authentication. This information disclosure can lead to further compromise by revealing stored credentials. No official patch or remediation level has been provided yet, and no known exploits are reported in the wild. Join the discussion | CVE Database V5 | 04/11/2026, 00:16:25 UTC Added: 04/11/2026, 01:05:50 UTC |
0 Bentley Systems iTwin Platform exposed a Cesium ion access token in the source of some web pages. An unauthenticated attacker could use this token to enumerate or delete certain assets. As of 2026-03-27, the token is no longer present in the web pages and cannot be used to enumerate or delete assets. Join the discussion | CVE Database V5 | 04/02/2026, 19:04:09 UTC Added: 04/02/2026, 19:38:18 UTC |
0 Dell ECS, versions 3.8.1.0 through 3.8.1.7, and Dell ObjectScale versions prior to 4.2.0.0, contains an Inclusion of Sensitive Information in Source Code vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information exposure. Join the discussion | CVE Database V5 | 01/23/2026, 09:34:34 UTC Added: 01/23/2026, 15:36:20 UTC |
Showing 1 to 10 of 15 results