Vulnerability index

Browse CVEs

7,720 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Unclassified MEDIUM 6.5
CVE-2026-53959

4gaBoards is a boards system for realtime project management. Prior to 3.3.9, 4gaBoards allows any authenticated user to enumerate account informatio…

Fix unknown
Fix from $4,000 2026-08-18
Unclassified CRITICAL 9.0
CVE-2026-62988

Froxlor is open source server administration software. From 2.3.7 until 2.3.8, the Customers.get, Customers.listing, Admins.get, Admins.listing, Ftps…

Fix unknown
Fix from $5,750 2026-08-18
Unclassified HIGH 7.5
CVE-2026-75915

CodeWhale versions before 0.8.64 contain an environment variable exposure vulnerability in the js_execution tool that fails to scrub parent process e…

Fix unknown
Fix from $4,900 2026-08-18
Unclassified HIGH 7.6
CVE-2026-69189

Hoppscotch is an open source API development ecosystem. Prior to 2026.6.0, the team, teamMembers.user, RESTHistory, GQLHistory, currentRESTSession, c…

Fix unknown
Fix from $4,900 2026-08-18
Unclassified CRITICAL 9.8
CVE-2026-42164

Mahara before 25.04.5 and 26.04.0 is vulnerable in the Text block/section functionality when a call is crafted in a certain way that allows it to rec…

Fix unknown
Fix from $5,750 2026-08-17
Unclassified CRITICAL 9.6
CVE-2026-71424

Onyx is an open-source AI platform. Prior to 3.1.10, 3.2.14, and 4.0.0, Onyx's GET /api/mcp/servers and GET /api/mcp/servers/persona/{persona_id} end…

Fix unknown
Fix from $5,750 2026-08-17
Safari MEDIUM 6.5
CVE-2026-64778

The issue was addressed with improved checks. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, mac…

Fix unknown
Fix from $4,000 2026-08-17
Ipados MEDIUM 5.5
CVE-2026-64760

An information leakage was addressed with additional validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10. An app may be able to leak se…

Fix unknown
Fix from $4,000 2026-08-17
Unclassified HIGH 8.5
CVE-2026-57485

Stirling-PDF is a locally hosted web application that facilitates various operations on PDF files. Prior to 2.9.0, the /api/v1/pipeline/handleData en…

Fix unknown
Fix from $4,900 2026-08-17
Unclassified MEDIUM 5.3
CVE-2026-68520

Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.6, as_dict_secure() in glances/config.py checks only option names and e…

Fix unknown
Fix from $4,000 2026-08-17
Unclassified CRITICAL 9.1
CVE-2026-64859

New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to 1.0.0-rc.7, the admin user list and…

Fix unknown
Fix from $5,750 2026-08-17
Unclassified MEDIUM 6.2
CVE-2026-49302

Permission control vulnerability in the notification service module. Impact: Successful exploitation of this vulnerability may affect service confide…

Fix unknown
Fix from $4,000 2026-08-17
Unclassified MEDIUM 6.2
CVE-2026-49307

Permission control vulnerability in the multi-mode input module. Impact: Successful exploitation of this vulnerability may affect service confidentia…

Fix unknown
Fix from $4,000 2026-08-17
Unclassified MEDIUM 6.2
CVE-2026-49301

Permission control vulnerability in the Gallery module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Fix unknown
Fix from $4,000 2026-08-17
Unclassified MEDIUM 6.5
CVE-2026-19613

The ECS WordPress plugin before 4.3.10 does not perform ownership or post-status checks when one of its dynamic repeater data sources reads custom f…

Fix unknown
Fix from $4,000 2026-08-16
Unclassified HIGH 7.5
CVE-2026-19717

The CatFolders Document Gallery & PDF Library WordPress plugin before 2.0.7 does not have authorisation checks in some of its REST API endpoints, all…

Fix unknown
Fix from $4,900 2026-08-16
Unclassified MEDIUM 6.2
CVE-2026-73047

siyuan versions <= 3.7.3 (fixed in v3.7.4) contain a server-side template injection vulnerability in the attribute-view Template calculation feature …

No fix yet
Fix from $4,000 2026-08-15
Unclassified MEDIUM 6.5
CVE-2026-16541

The Simply Schedule Appointments WordPress plugin before 1.6.12.17 does not restrict the user records returned by some of its REST endpoints to those…

Fix unknown
Fix from $4,000 2026-08-15
Unclassified HIGH 7.5
CVE-2026-16611

The Product Feed PRO for WooCommerce by AdTribes WordPress plugin before 13.5.7 does not perform an authorization check on one of its REST read rout…

Fix unknown
Fix from $4,900 2026-08-15
Wyse Management Suite MEDIUM 5.3
CVE-2026-66272

Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain a Missing Authentication for Critical Function vulnerability. An unauthenticate…

No fix yet
Fix from $4,000 2026-08-14
Unclassified HIGH 7.7
CVE-2026-72670

A lower privileged user who holds only the privilege to read agent policies can read the entire configuration of a configured Fleet proxy. This would…

No fix yet
Fix from $4,900 2026-08-13
Unclassified MEDIUM 6.5
CVE-2026-58442

Repository migration SSRF via multi-answer DNS allow-list bypass

No fix yet
Fix from $4,000 2026-08-13
Unclassified MEDIUM 5.9
CVE-2026-58432

Missing Authorization and Authorization Bypass Through User-Controlled Key and Incorrect Permission Assignment for Critical Resource and Exposure of …

No fix yet
Fix from $4,000 2026-08-13
Unclassified HIGH 7.5
CVE-2026-58434

Private Repository Metadata Remains Accessible After Access Revocation

No fix yet
Fix from $4,900 2026-08-13
Unclassified MEDIUM 6.5
CVE-2026-57897

Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs

No fix yet
Fix from $4,000 2026-08-13
Unclassified HIGH 7.5
CVE-2026-58427

Private org member list leaked via /members API endpoint — incomplete fix for PR #38145

No fix yet
Fix from $4,900 2026-08-13
Unclassified CRITICAL 9.1
CVE-2026-55982

OIDC userinfo Endpoint Returns Identity Claims Without Enforcing API Token Scopes

No fix yet
Fix from $5,750 2026-08-13
Unclassified HIGH 7.5
CVE-2026-73622

GitPython before 3.1.55 fails to disable environment variable expansion in Remote.create() and Submodule.add() URL handling, allowing attackers to ex…

No fix yet
Fix from $4,900 2026-08-13
Unclassified MEDIUM 6.5
CVE-2026-73604

Flowise before 3.1.3 contains an incomplete credential redaction vulnerability in the GET /api/v1/credentials/:id endpoint that returns decrypted sec…

No fix yet
Fix from $4,000 2026-08-13
Unclassified CRITICAL 9.1
CVE-2026-59503

CWE-200: Exposure of Sensitive Information to an Unauthorized Actor CWE-359: Exposure of Private Personal Information to an Unauthorized Actor

No fix yet
Fix from $5,750 2026-08-13