Vulnerability index

Browse CVEs

7,720 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Unclassified MEDIUM 5.3
CVE-2026-58149

Joomla Extension - joomdonation.com - User enumeration in Events Booking < 5.8.0 - The Joomla extension Events Booking is vulnerable to an unauthenti…

No fix yet
Fix from $1,600 2026-07-17
Unclassified MEDIUM 5.3
CVE-2024-23568

HCL Aftermarket EPC is vulnerable to attacks since the server software version used by the application is revealed by the web server. Displaying vers…

No fix yet
Fix from $1,600 2026-07-17
Unclassified MEDIUM 5.3
CVE-2026-13402

The Royal Addons for Elementor WordPress plugin before 1.7.1063 does not check the post status of menu items or the templates they reference in one …

No fix yet
Fix from $1,600 2026-07-17
Unclassified MEDIUM 6.5
CVE-2026-14503

The pCloud WP Backup plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.0.3 via the wp2pcl_…

No fix yet
Fix from $1,600 2026-07-17
Unclassified MEDIUM 5.7
CVE-2024-32387

An issue in Kerlink Kerlink Wirnet iStation 868 KerOS v.4.3.3_20200803132042 allows a remote attacker to obtain sensitive information via the communi…

No fix yet
Fix from $1,600 2026-07-16
Unclassified MEDIUM 5.3
CVE-2026-47751

Claude Code Action is a general-purpose GitHub action that runs Claude Code on GitHub pull requests and issues. Prior to 1.0.74, because the action c…

No fix yet
Fix from $1,600 2026-07-16
Unclassified MEDIUM 5.9
CVE-2026-55406

Buffa is a pure-Rust Protocol Buffers implementation with first-class protobuf editions support. Prior to 0.7.0, a soundness bug in the OwnedView<V> …

No fix yet
Fix from $1,600 2026-07-16
Unclassified HIGH 7.5
CVE-2026-53598

Prompty is a markdown file format (.prompty) for LLM prompts. Prior to 2.0.0-beta.2, Prompty loaders expanded ${file:...} references in .prompty fron…

No fix yet
Fix from $1,950 2026-07-16
Dfxanalytics MEDIUM 5.3
CVE-2026-56456

HCL DFXAnalytics is affected by an Internal File Path Disclosure vulnerability. The application dashboard inadvertently leaks sensitive information r…

Fix: after 3.0
Fix from $1,600 2026-07-16
Dfxanalytics HIGH 7.2
CVE-2026-35140

HCL DFXAnalytics is affected by a Missing Secure Attribute in Encrypted Session (SSL) Cookie vulnerability. The application fails to set the "secure"…

Fix: after 3.0
Fix from $1,950 2026-07-16
Dfxanalytics HIGH 8.2
CVE-2026-35142

HCL DFXAnalytics is affected by an Internal IP Address Disclosure vulnerability. The application includes internal IP address details within its gene…

Fix: after 3.0
Fix from $1,950 2026-07-16
Dfxanalytics MEDIUM 6.5
CVE-2026-35143

HCL DFXAnalytics is affected by a Missing SameSite Attribute vulnerability. The application fails to set the "SameSite" attribute on session cookies …

Fix: after 3.0
Fix from $1,600 2026-07-16
N8n Mcp MEDIUM 5.4
CVE-2026-55608

n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. Prior to 2.57.4, multi-tenant HTTP…

Fix: 2.57.4+
Fix from $1,600 2026-07-15
Unclassified MEDIUM 6.8
CVE-2026-52888

NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. In 2.0.59 and earlier, NocoBase @noc…

Mitigation only
Fix from $1,600 2026-07-15
Argo Cd MEDIUM 6.5
CVE-2026-45737

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. From 3.2.0 until 3.2.12, 3.3.10, and 3.4.2, Argo CD ServerSideDiff can expo…

Fix: 3.2.12 / 3.3.10+
Fix from $1,600 2026-07-15
Repomix MEDIUM 5.5
CVE-2026-49988

Repomix is a tool that packs repositories into AI-friendly files. Prior to 1.14.1, the Repomix MCP server attach_packed_output and read_repomix_outpu…

Mitigation only
Fix from $1,600 2026-07-15
Splunk MEDIUM 6.5
CVE-2026-20298

In Splunk Enterprise versions below 10.4.1, 10.2.5, 10.0.8, and 9.4.13, and Splunk Cloud Platform versions below 10.5.2605.0, 10.4.2604.6, 10.3.2512.…

Fix: 9.4.13 / 10.0.8+
Fix from $1,600 2026-07-15
Unclassified HIGH 7.5
CVE-2026-45793

Composer is a dependency Manager for the PHP language. Prior to 1.10.28, 2.2.28, and 2.9.8, Composer\IO\BaseIO::loadConfiguration() validates GitHub …

No fix yet
Fix from $1,950 2026-07-15
Unclassified MEDIUM 6.6
CVE-2026-58554

Permission control vulnerability in the Settings module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

No fix yet
Fix from $1,600 2026-07-15
Kasa Ec70 Firmware MEDIUM 6.5
CVE-2026-13230

An information disclosure vulnerability was identified in TP-Link Kasa EC70 v4 and EC71 v4 in the local discovery mechanism, which exposes sensitive …

Fix: 2.4.1+
Fix from $1,600 2026-07-15
Unclassified CRITICAL 9.1
CVE-2026-52101

An issue in andreimarcu linux-server v.1.0 through v.2.3.8 allows a remote attacker to obtain sensitive information via the function uploadRemote fun…

Mitigation only
Fix from $2,300 2026-07-14
Unclassified HIGH 7.7
CVE-2026-49853

Tornado is a Python web framework and asynchronous networking library. Prior to 6.5.6, SimpleAsyncHTTPClient shallow-copied redirected requests and r…

Mitigation only
Fix from $1,950 2026-07-14
Windows 10 1607 HIGH 7.8
CVE-2026-57095

Exposure of sensitive information to an unauthorized actor in Windows Win32K allows an unauthorized attacker to elevate privileges locally.

Fix: 10.0.14393.9339 / 10.0.17763.9020+
Fix from $1,950 2026-07-14
Visual Studio Code HIGH 8.8
CVE-2026-57102

Inclusion of functionality from untrusted control sphere in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a ne…

Fix: 1.128.1+
Fix from $1,950 2026-07-14
Windows 10 21h2 MEDIUM 5.5
CVE-2026-56184

Exposure of sensitive information to an unauthorized actor in Windows Win32K allows an authorized attacker to disclose information locally.

Fix: 10.0.19044.7548 / 10.0.19045.7548+
Fix from $1,600 2026-07-14
Windows 10 1607 MEDIUM 5.5
CVE-2026-50681

Exposure of sensitive information to an unauthorized actor in Windows Cryptographic Services allows an authorized attacker to disclose information lo…

Fix: 10.0.14393.9339 / 10.0.17763.9020+
Fix from $1,600 2026-07-14
Windows 11 24h2 MEDIUM 5.5
CVE-2026-50483

Exposure of sensitive information to an unauthorized actor in Microsoft Graphics Component allows an authorized attacker to disclose information loca…

Fix: 10.0.26100.8875 / 10.0.26100.33158+
Fix from $1,600 2026-07-14
Windows 10 1607 MEDIUM 5.5
CVE-2026-50473

Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.

Fix: 10.0.14393.9339 / 10.0.17763.9020+
Fix from $1,600 2026-07-14
Windows 10 1607 MEDIUM 5.5
CVE-2026-50456

Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.

Fix: 10.0.14393.9339 / 10.0.17763.9020+
Fix from $1,600 2026-07-14
Windows 10 1607 MEDIUM 5.5
CVE-2026-50442

Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.

Fix: 10.0.14393.9339 / 10.0.17763.9020+
Fix from $1,600 2026-07-14