Vulnerability index

Browse CVEs

7,720 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Unclassified MEDIUM 5.3
CVE-2026-6801

The Context Blog theme for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.3.5 via the context_blog…

Mitigation only
Fix from $1,600 2026-07-11
Unclassified MEDIUM 5.3
CVE-2026-10865

The Cost Calculator Builder plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.0.11 via the…

Mitigation only
Fix from $1,600 2026-07-11
Unclassified MEDIUM 5.3
CVE-2026-12426

The Members – Membership & User Role Editor Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and in…

Mitigation only
Fix from $1,600 2026-07-11
Unclassified MEDIUM 6.9
CVE-2026-59155

Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. Prior to 2.2.5, the GET /api/v1/ddns and GET /api/v1/…

Patch available
Fix from $1,600 2026-07-10
Unclassified HIGH 8.3
CVE-2026-55882

Tilt defines dev environments as code for microservice apps on Kubernetes. From 0.19.5 through 0.37.3, the Tilt HUD server mounts Go net/http/pprof h…

Patch available
Fix from $1,950 2026-07-10
Rabbitmq Server HIGH 7.5
CVE-2026-57219

RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.20, 4.1.11, and 4.2.6, the obsolete GET /api/auth endpoint can disclose the OAuth…

Fix: 4.2.6+
Fix from $1,950 2026-07-10
Ai Assist For Customer MEDIUM 5.3
CVE-2026-57474

Deloitte AI Assist for Customer disclosed some configuration information through public-facing API endpoints that accepted unauthenticated requests. …

Fix: 2026-03-25+
Fix from $1,600 2026-07-10
Unclassified CRITICAL 9.9
CVE-2026-55500

9Router is an AI router & token saver. Prior to 0.4.80, the /api/settings/database endpoint allows full database export (containing all credentials, …

Patch available
Fix from $2,300 2026-07-10
Unclassified MEDIUM 5.3
CVE-2026-57994

phpMyFAQ before 4.1.5 applies inconsistent active=yes and publication-date filtering across its public FAQ API endpoints, allowing unauthenticated at…

Mitigation only
Fix from $1,600 2026-07-10
Discourse MEDIUM 5.3
CVE-2026-59828

Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, post revisions that should be hidden from regul…

Fix: 2026.1.5 / 2026.4.2+
Fix from $1,600 2026-07-09
Discourse HIGH 7.5
CVE-2026-49256

Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, restricted tag and tag-group names attached to …

Fix: 2026.1.5 / 2026.4.2+
Fix from $1,950 2026-07-09
Unclassified MEDIUM 5.3
CVE-2026-45780

Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, EventSerializer could expose invited group name…

Patch available
Fix from $1,600 2026-07-09
Discourse HIGH 7.5
CVE-2026-45788

Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, secure uploads could be exposed by pull_hotlink…

Fix: 2026.1.5 / 2026.4.2+
Fix from $1,950 2026-07-09
Unclassified HIGH 7.5
CVE-2025-63579

Unauthorized use of Kyocera printers, allows all information stored in the Kyocera address book to be exported. The security measure that encrypts in…

Mitigation only
Fix from $1,950 2026-07-09
Unclassified HIGH 7.5
CVE-2026-59720

Hoppscotch is an open source API development ecosystem. Prior to 2026.6.0, mock server creation in mock-server.service.ts does not persist the isPubl…

Patch available
Fix from $1,950 2026-07-09
Open Webui MEDIUM 6.5
CVE-2026-59222

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.7.0 before 0.10.0, GET /api/v1/channels//members returne…

Fix: 0.10.0+
Fix from $1,600 2026-07-09
Open Webui CRITICAL 9.0
CVE-2026-59216

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.10.0, get_event_call delivered execute:python and ex…

Fix: 0.10.0+
Fix from $2,300 2026-07-09
N8n MEDIUM 6.5
CVE-2026-59209

n8n is an open source workflow automation platform. Prior to 1.123.61, 2.27.4, and, 2.28.1, an authenticated member with use-only editor access to a …

Fix: 1.123.61 / 2.27.4+
Fix from $1,600 2026-07-09
Unclassified MEDIUM 6.3
CVE-2026-15044

A flaw was found in the TrustyAI Service Operator. When deploying services like gorch or NemoGuardrails, if a specific security setting is not enable…

Mitigation only
Fix from $1,600 2026-07-08
Unclassified MEDIUM 5.3
CVE-2026-56284

Capgo (Cap-go/capgo) before 12.128.2 contains an information disclosure vulnerability in the Supabase PostgREST RPC function public.get_total_metrics…

Mitigation only
Fix from $1,600 2026-07-08
Unclassified HIGH 7.5
CVE-2026-56226

Capgo (Cap-go/capgo) before 12.128.2 exposes the Supabase PostgREST RPC function public.get_orgs_v6(userid uuid), which is SECURITY DEFINER and grant…

Mitigation only
Fix from $1,950 2026-07-08
Unclassified MEDIUM 6.5
CVE-2026-44877

An unauthenticated remote disclosure vulnerability has been identified in HPE Networking Instant On 1830, 1930, and 1960 Switches. Successful exploit…

Mitigation only
Fix from $1,600 2026-07-07
Airflow MEDIUM 6.5
CVE-2026-48828

The Bulk Variables API in Apache Airflow called the redactor without passing the variable's key, so the key-based `should_hide_value_for_key` check (…

Fix: 3.3.0+
Fix from $1,600 2026-07-07
Airflow MEDIUM 6.5
CVE-2026-48892

The Config API in Apache Airflow surfaced per-key secrets-backend overrides (environment variables like `AIRFLOW__SECRETS__BACKEND_KWARG__SECRET_ID` …

Fix: 3.3.0+
Fix from $1,600 2026-07-07
Airflow MEDIUM 6.5
CVE-2026-49487

In Apache Airflow before 3.3.0, the REST API task-instance detail and list endpoints returned a deferred task's trigger kwargs without masking. When …

Fix: 3.3.0+
Fix from $1,600 2026-07-07
Unclassified MEDIUM 6.9
CVE-2026-53647

FOSSBilling is a free, open-source billing and client management system. In versions 0.5.3 through 0.7.2, the Guest `serviceapikey/get_info` API endp…

Mitigation only
Fix from $1,600 2026-07-07
Unclassified HIGH 8.7
CVE-2026-53643

FOSSBilling is a free, open-source billing and client management system. Versions prior to 0.8.0 allow low-privileged staff accounts to perform unaut…

Mitigation only
Fix from $1,950 2026-07-06
Unclassified MEDIUM 6.5
CVE-2026-14898

The OpenAI Codex desktop app for macOS rendered remote images from Markdown in model responses. An attacker who could place an indirect prompt inject…

Mitigation only
Fix from $1,600 2026-07-06
Camel HIGH 7.5
CVE-2026-55994

Improper Input Validation, Exposure of Sensitive Information to an Unauthorized Actor, Server-Side Request Forgery (SSRF) vulnerability in Apache Cam…

Fix: 4.18.3 / 4.21.0+
Fix from $1,950 2026-07-06
Camel HIGH 7.5
CVE-2026-55993

Improper Input Validation, Exposure of Sensitive Information to an Unauthorized Actor, Server-Side Request Forgery (SSRF) vulnerability in Apache Cam…

Fix: 4.14.8 / 4.18.3+
Fix from $1,950 2026-07-06