Vulnerability index

Browse CVEs

7,720 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Payments HIGH 7.1
CVE-2026-60176

Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affected are 12.…

Fix: after 12.2.15
Fix from $1,950 2026-07-21
Hospitality Simphony HIGH 7.5
CVE-2026-60167

Vulnerability in the Oracle Hospitality Simphony product of Oracle Food and Beverage Applications (component: POS). Supported versions that are affe…

Fix: after 19.9.3
Fix from $1,950 2026-07-21
Apex MEDIUM 5.3
CVE-2026-60156

Vulnerability in Oracle APEX (component: General). Supported versions that are affected are 24.1, 24.2 and 26.1. Easily exploitable vulnerability al…

No fix yet
Fix from $1,600 2026-07-21
Libheif HIGH 7.5
CVE-2026-47247

libheif is a HEIF and AVIF file format decoder and encoder. Prior to version 1.22.0, two bugs in libheif chain to leak process heap memory as visible…

Fix: 1.22.0+
Fix from $1,950 2026-07-21
Agile Product Lifecycle Management MEDIUM 6.5
CVE-2026-47009

Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Folders, Files & Attachments). The supported version that is affec…

No fix yet
Fix from $1,600 2026-07-21
Unclassified HIGH 7.5
CVE-2026-52474

An issue in aiflowy <= 2.1.2 allows a remote attacker to obtain sensitive information via the JobUtil.java file.

No fix yet
Fix from $1,950 2026-07-21
Confluence Data Center HIGH 7.5
CVE-2026-21579

This High severity Information Disclosure vulnerability was introduced in versions 7.17.0, 7.19.0, 8.5.0, 8.9.0, 9.0.1, 9.1.0, 9.2.0, 10.0.2, 10.1.0,…

Fix: after 10.2.13
Fix from $1,950 2026-07-21
Unclassified HIGH 8.7
CVE-2026-47394

PraisonAI is a multi-agent teams system. Prior to version 4.6.40, the fix for GHSA-9mqq-jqxf-grvw / CVE-2026-44336 is incomplete. The original adviso…

No fix yet
Fix from $1,950 2026-07-21
Unclassified MEDIUM 5.5
CVE-2026-47395

PraisonAI is a multi-agent teams system. Prior to version 4.6.40 of PraisonAI, corresponding to version 1.6.40 of praisonaiagents, PraisonAI's direct…

No fix yet
Fix from $1,600 2026-07-21
Intelliops Event Management MEDIUM 5.3
CVE-2026-56584

HCL IEM was affected with the Information disclosure nginx server. It may enable attackers to identify outdated software versions and target known vu…

No fix yet
Fix from $1,600 2026-07-21
Firefox HIGH 7.5
CVE-2026-16398

Site isolation issue in the Graphics component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

Fix: 153.0 / 153.0.0+
Fix from $1,950 2026-07-21
Firefox HIGH 7.5
CVE-2026-16400

Information disclosure in the DOM: Security component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

Fix: 153.0 / 153.0.0+
Fix from $1,950 2026-07-21
Firefox HIGH 7.5
CVE-2026-16405

Information disclosure in the Networking: WebSockets component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and…

Fix: 140.13.0 / 153.0.0+
Fix from $1,950 2026-07-21
Firefox HIGH 7.5
CVE-2026-16391

Information disclosure in the Storage: IndexedDB component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thu…

Fix: 140.13.0 / 153.0+
Fix from $1,950 2026-07-21
Firefox CRITICAL 9.8
CVE-2026-16387

Site isolation issue in the Networking component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 1…

Fix: 140.13.0 / 153.0+
Fix from $2,300 2026-07-21
Firefox Mobile HIGH 7.5
CVE-2026-16373

Information disclosure in the Privacy component in Firefox for Android. This vulnerability was fixed in Firefox 153.

Fix: 153.0+
Fix from $1,950 2026-07-21
Firefox HIGH 7.5
CVE-2026-16374

Information disclosure in the Framework component in DevTools. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and …

Fix: 140.13.0 / 153.0+
Fix from $1,950 2026-07-21
Firefox HIGH 7.5
CVE-2026-16354

Information disclosure in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thun…

Fix: 115.38.0 / 140.13.0+
Fix from $1,950 2026-07-21
Unclassified HIGH 8.1
CVE-2026-44508

Rsync is a file-copying tool that uses a delta-transfer algorithm to synchronize remote and local files. In versions prior to 3.4.3, the receiver's …

Mitigation only
Fix from $1,950 2026-07-20
Request Tracker CRITICAL 9.1
CVE-2026-44231

RT is an open source, enterprise-grade issue and ticket tracking system. Versions prior to 5.0.10, 6.0.0 and above, prior to 6.0.3 contain an informa…

Fix: 5.0.10 / 6.0.3+
Fix from $2,300 2026-07-20
Unclassified MEDIUM 6.9
CVE-2026-60031

Joomla Extension - themexpert.com - Information disclosure in Quix Page Builder < 6.2.1 - The Joomla extension Quix Page Builder Pro is vulnerable to…

No fix yet
Fix from $1,600 2026-07-20
Unclassified CRITICAL 9.9
CVE-2026-51027

An issue in FileThingie v.2.5.7 allows a remote attacker to obtain sensitive information via the ft2.php component.

Mitigation only
Fix from $2,300 2026-07-20
Unclassified HIGH 8.7
CVE-2026-46410

FileBrowser Quantum is a free, self-hosted, web-based file manager. Versions prior to 1.3.2-stable and 1.4.1-beta may leak some sensitive info, such …

No fix yet
Fix from $1,950 2026-07-20
Surrealdb MEDIUM 6.5
CVE-2026-63746

SurrealDB versions before 3.1.0 fail to enforce table SELECT permissions when traversing graph edges or back-references. Authenticated users can read…

Fix: 3.1.0+
Fix from $1,600 2026-07-20
Unclassified MEDIUM 5.3
CVE-2026-16201

A vulnerability was found in zevorn rt-claw up to 0.2.0. Affected is the function claw_net_get/claw_net_post of the file claw/services/tools/net.c of…

No fix yet
Fix from $1,600 2026-07-19
Unclassified MEDIUM 6.3
CVE-2026-44979

@hapi/wreck is an HTTP client utility. Prior to 18.1.1, when @hapi/wreck follows a 3xx redirect to a different hostname, only the Authorization and C…

No fix yet
Fix from $1,600 2026-07-17
Unclassified HIGH 7.5
CVE-2026-52203

An issue in MCMS v.6.1.1 allows a remote attacker to obtain sensitive information via the source parameter.

No fix yet
Fix from $1,950 2026-07-17
Unclassified MEDIUM 6.8
CVE-2026-48009

Shopware is an open commerce platform. Prior to 6.6.10.18 and 6.7.10.1, a low-privilege admin user with user_recovery:read ACL can take over any admi…

No fix yet
Fix from $1,600 2026-07-17
Ux HIGH 7.5
CVE-2026-49211

Symfony UX is a JavaScript ecosystem for Symfony. From 2.2.0 until 2.36.0 and 3.1.0, Symfony\UX\Autocomplete\Doctrine\EntitySearchUtil::addSearchClau…

Fix: 2.36.0+
Fix from $1,950 2026-07-17
Build Of Keycloak MEDIUM 6.5
CVE-2026-16108

A flaw was found in the default-groups REST endpoint and realm representation of Keycloak. This component is responsible for managing groups that are…

No fix yet
Fix from $1,600 2026-07-17