Vulnerability index

Browse CVEs

7,720 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Camel HIGH 7.5
CVE-2026-46726

Improper Input Validation, Exposure of Sensitive Information to an Unauthorized Actor, Server-Side Request Forgery (SSRF) vulnerability in Apache Cam…

Fix: 4.14.8 / 4.18.3+
Fix from $1,950 2026-07-06
Unclassified HIGH 7.5
CVE-2026-58419

Notification API leaks private issue metadata after access revocation

Patch available
Fix from $1,950 2026-07-03
Edge Chromium MEDIUM 6.5
CVE-2026-56646

Exposure of sensitive information to an unauthorized actor in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing ove…

Fix: 150.0.4078.48+
Fix from $1,600 2026-07-03
Unclassified HIGH 7.5
CVE-2026-24451

Gitea 1.26.2 allows fork synchronization to continue after a parent repository changes from public to private, exposing data to a fork that should no…

Patch available
Fix from $1,950 2026-07-03
Unclassified HIGH 7.5
CVE-2026-25038

Gitea 1.26.2 allows unauthorized users to access labels of private organizations.

Patch available
Fix from $1,950 2026-07-03
Unclassified HIGH 8.5
CVE-2026-10055

In Eclipse Theia since version 1.26.0, the backend /services/request-service RPC accepts an attacker-controlled URL from any client connected to the …

Mitigation only
Fix from $1,950 2026-07-03
Unclassified MEDIUM 6.0
CVE-2026-55792

Craft CMS is a content management system (CMS). In versions starting from 4.0.0-RC1 and prior to 4.18.0, and 5.0.0-RC1 and above, prior to 5.10.0, th…

Patch available
Fix from $1,600 2026-07-02
Imagemagick MEDIUM 5.3
CVE-2026-53467

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-51 and 7.1.2-26, the MNG deco…

Fix: 6.9.13-51 / 7.1.2-26+
Fix from $1,600 2026-07-01
Mediawiki MEDIUM 6.5
CVE-2026-58033

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with p…

Fix: 1.43.9 / 1.44.6+
Fix from $1,600 2026-07-01
Mediawiki HIGH 7.5
CVE-2026-58036

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with p…

Mitigation only
Fix from $1,950 2026-07-01
Mediawiki MEDIUM 5.7
CVE-2026-58024

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with p…

Fix: 1.43.9 / 1.44.6+
Fix from $1,600 2026-07-01
Mediawiki MEDIUM 5.7
CVE-2026-58026

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with p…

Fix: 1.43.9 / 1.44.6+
Fix from $1,600 2026-07-01
Mediawiki MEDIUM 6.5
CVE-2026-58027

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation AbuseFilter. This vulnerability is associated with…

Fix: 1.43.9 / 1.44.6+
Fix from $1,600 2026-07-01
Unclassified HIGH 7.5
CVE-2026-56300

Capgo before 12.128.2 contains unauthenticated security definer RPC functions get_user_id and get_org_perm_for_apikey that expose API key validity or…

Mitigation only
Fix from $1,950 2026-06-30
Unclassified MEDIUM 5.3
CVE-2026-56318

Capgo before 12.128.2 contains an information disclosure vulnerability in the /private/validate_password_compliance endpoint that returns different e…

Mitigation only
Fix from $1,600 2026-06-30
Unclassified HIGH 8.2
CVE-2026-54673

electron-updater allows for automatic updates for Electron apps. Prior to 9.7.0, the HTTP redirect handler (HttpExecutor.prepareRedirectUrlOptions) o…

Patch available
Fix from $1,950 2026-06-30
Chrome MEDIUM 6.5
CVE-2026-14146

Inappropriate implementation in CSS in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to leak cross-origin data via a crafted HTML pa…

Fix: 150.0.7871.47+
Fix from $1,600 2026-06-30
Chrome MEDIUM 6.5
CVE-2026-14096

Inappropriate implementation in Input in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer p…

Fix: 150.0.7871.47+
Fix from $1,600 2026-06-30
Chrome MEDIUM 6.5
CVE-2026-14098

Inappropriate implementation in CSS in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to leak cross-origin data via a crafted HTML pa…

Fix: 150.0.7871.46+
Fix from $1,600 2026-06-30
Chrome MEDIUM 5.9
CVE-2026-14062

Inappropriate implementation in Views in Google Chrome on ChromeOS prior to 150.0.7871.47 allowed an attacker who convinced a user to install a malic…

Fix: 150.0.7871.47+
Fix from $1,600 2026-06-30
Chrome MEDIUM 5.3
CVE-2026-14049

Inappropriate implementation in GPU in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to obt…

Fix: 150.0.7871.46+
Fix from $1,600 2026-06-30
Chrome MEDIUM 6.5
CVE-2026-14004

Inappropriate implementation in CSS in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to leak cross-origin data via a crafted HTML pa…

Fix: 150.0.7871.47+
Fix from $1,600 2026-06-30
Chrome MEDIUM 6.5
CVE-2026-13810

Inappropriate implementation in Input in Google Chrome on Linux prior to 150.0.7871.47 allowed a remote attacker to obtain potentially sensitive info…

Fix: 150.0.7871.47+
Fix from $1,600 2026-06-30
Infosphere Information Server HIGH 7.5
CVE-2026-9836

IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is affected by an information disclosure vulnerability.

Fix: after 11.7.1.6
Fix from $1,950 2026-06-30
Unclassified HIGH 7.5
CVE-2026-14161

Hospital Quening Management developed by Advantech has a Sensitive Data Exposure vulnerability, allowing unauthenticated remote attackers to access a…

Mitigation only
Fix from $1,950 2026-06-30
Claude Code MEDIUM 6.1
CVE-2026-46406

Claude Code is an agentic coding tool. From 2.1.59 until 2.1.128, the Claude Code /copy command wrote responses to a hardcoded, predictable path (/t…

Fix: 2.1.128+
Fix from $1,600 2026-06-29
Kestra HIGH 7.7
CVE-2026-49984

Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.45 and 1.3.23, the local internal-storage backend validates user-supplied…

Fix: 1.0.45 / 1.3.23+
Fix from $1,950 2026-06-26
Unclassified HIGH 8.2
CVE-2026-55188

RustFS is a distributed object storage system built in Rust. From 1.0.0-alpha.1 until 1.0.0-beta.9, RustFS contains an authorization bypass in the bu…

Mitigation only
Fix from $1,950 2026-06-26
Unclassified HIGH 7.5
CVE-2026-47193

OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, the journal diff endpoint discloses hidden historical …

Mitigation only
Fix from $1,950 2026-06-26
Unclassified MEDIUM 6.5
CVE-2026-44736

OpenProject is open-source, web-based project management software. Prior to 17.4.0, the GET /api/v3/relations endpoint allows any authenticated user …

Mitigation only
Fix from $1,600 2026-06-26