Vulnerability index

Browse CVEs

7,720 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Podman HIGH 7.5
CVE-2026-57231

Podman is a tool for managing OCI containers and pods. From 1.8.1 until 5.8.4, a container image that contains a environment variable with just a key…

Fix: 5.8.4+
Fix from $1,950 2026-06-26
Unclassified HIGH 7.5
CVE-2026-37452

Insecure Permissions vulnerability in MSI NBFoundation Service v.2.0.2506.1201 allows a remote attacker to obtain sensitive information via the MSIAP…

Mitigation only
Fix from $1,950 2026-06-25
Center HIGH 7.5
CVE-2026-37453

Insecure Permissions vulnerability in MSI NBFoundation Service v.2.0.2506.1201 allows a remote attacker to obtain sensitive information via the MSI_S…

Fix: 2.0.70.0+
Fix from $1,950 2026-06-25
Center HIGH 7.5
CVE-2026-37454

Insecure Permissions vulnerability in MSI NBFoundation Service v.2.0.2506.1201 allows a remote attacker to obtain sensitive information via the 3DES-…

Fix: 2.0.70.0+
Fix from $1,950 2026-06-25
Pnpm MEDIUM 6.5
CVE-2026-55180

pnpm is a package manager. Prior to 10.34.2 and 11.5.3, pnpm and pacquet expanded ${ENV_VAR} placeholders from repository-controlled .npmrc and pnpm-…

Fix: 10.34.2 / 11.5.3+
Fix from $1,600 2026-06-25
Pnpm MEDIUM 6.5
CVE-2026-50017

pnpm is a package manager. Prior to 10.34.0 and 11.4.0, pnpm can send user-level unscoped npm authentication credentials to a registry chosen by a re…

Fix: 10.34.0 / 11.4.0+
Fix from $1,600 2026-06-25
Sed MEDIUM 6.5
CVE-2026-9153

Arbitrary File Read vulnerability in Rapid7 InsightConnect Sed Plugin on Linux allows authenticated attackers to read arbitrary files via the express…

Mitigation only
Fix from $1,600 2026-06-25
Unclassified MEDIUM 5.5
CVE-2026-52815

Gogs is an open source self-hosted Git service. Prior to 0.14.3, Gogs has an unauthenticated information disclosure vulnerability. The GET /api/v1/or…

Mitigation only
Fix from $1,600 2026-06-24
Unclassified MEDIUM 5.5
CVE-2026-32315

motionEye (mEye) is an online interface for motion software, a video surveillance program with motion detection. Versions prior to 0.44.0 create the …

Mitigation only
Fix from $1,600 2026-06-24
Unclassified HIGH 8.6
CVE-2026-47389

Mastodon is a free, open-source social network server based on ActivityPub. Prior to 4.5.10, 4.4.17, and 4.3.23, when using Ruby versions older than …

Mitigation only
Fix from $1,950 2026-06-24
Unclassified MEDIUM 5.3
CVE-2026-53949

Ghost is a Node.js content management system. From 5.46.1 until 6.21.2, the validation applied to filters on the public API endpoints could be partia…

No fix yet
Fix from $1,600 2026-06-24
Unclassified HIGH 8.6
CVE-2026-49269

Apple M1 GPUs retain register file data between compute shader dispatches from different processes. A sandboxed Metal attacker app can run a GPU read…

Mitigation only
Fix from $1,950 2026-06-24
Unclassified MEDIUM 5.3
CVE-2026-56337

Capgo before 12.128.2 contains an information disclosure vulnerability in the public.exist_app_v2 RPC function that allows unauthenticated attackers …

Mitigation only
Fix from $1,600 2026-06-24
Unclassified HIGH 7.1
CVE-2026-56244

Capgo before 12.128.2 allows non-admin API keys to read webhook signing secrets via Supabase REST due to insufficient row-level security policies on …

Mitigation only
Fix from $1,950 2026-06-24
Unclassified MEDIUM 5.3
CVE-2026-9612

The WhatsOrder – Instant Checkout for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and inc…

Mitigation only
Fix from $1,600 2026-06-24
Unclassified MEDIUM 6.9
CVE-2026-47379

NocoDB is software for building databases as spreadsheets. Prior to 2026.05.1, the shared-view password check fell back to strict-equality (===) comp…

Mitigation only
Fix from $1,600 2026-06-23
Claude Code CRITICAL 9.1
CVE-2026-54316

Claude Code is an agentic coding tool. From 0.2.54 until 2.1.163, because the hostname huggingface.co was pre-approved as a bare hostname for the We…

Fix: 2.1.163+
Fix from $2,300 2026-06-23
Home Assistant HIGH 7.6
CVE-2026-54317

Home Assistant is open source home automation software that puts local control and privacy first. Prior to 2026.6.0, the Konnected integration regist…

Fix: 2026.6.0+
Fix from $1,950 2026-06-23
Langflow CRITICAL 9.6
CVE-2026-55447

Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.2, by controlling a files that are digested into the RAG,…

Fix: 1.9.2+
Fix from $2,300 2026-06-23
Langflow CRITICAL 9.3
CVE-2026-55450EPSS 12%

Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.1, unauthenticated users can upload any amount of data to…

Fix: 1.9.1+
Fix from $2,300 2026-06-23
N8n HIGH 7.7
CVE-2026-54304

n8n is an open source workflow automation platform. Prior to 1.123.55, 2.25.7, and 2.26.1, an authenticated user with permission to create or modify …

Fix: 1.123.55 / 2.25.7+
Fix from $1,950 2026-06-23
N8n CRITICAL 9.9
CVE-2026-54305

n8n is an open source workflow automation platform. Prior to 1.123.55, 2.25.7, and 2.26.2, three EE endpoints used by the Dynamic Credentials feature…

Fix: 1.123.55 / 2.25.7+
Fix from $2,300 2026-06-23
Yt Dlp HIGH 7.4
CVE-2026-50019

yt-dlp is a command-line audio/video downloader. From 2023.09.24 until 2026.06.09, if curl is used as an external downloader for yt-dlp, cookies may …

Fix: 2026.06.09+
Fix from $1,950 2026-06-23
Unclassified CRITICAL 10.0
CVE-2026-27604

FOSSBilling is a free, open-source billing and client management system. Starting in version 0.5.4 and prior to version 0.8.0, an authorization bypas…

Mitigation only
Fix from $2,300 2026-06-23
Unclassified HIGH 7.5
CVE-2026-56322

Capgo before 12.128.2 contains an information disclosure vulnerability in the unauthenticated /updates endpoint that resolves the defaultChannel para…

Mitigation only
Fix from $1,950 2026-06-23
Vllm HIGH 7.5
CVE-2026-53923

vLLM is an inference and serving engine for large language models (LLMs). From 0.5.5 until 0.23.1rc0, integer truncation of tensor dimensions in vLLM…

Fix: 0.23.1+
Fix from $1,950 2026-06-22
Unclassified HIGH 7.5
CVE-2026-56323

Capgo before 12.128.2 contains an information disclosure vulnerability in the /functions/v1/channel_self endpoint that allows unauthenticated attacke…

Mitigation only
Fix from $1,950 2026-06-22
Aiohttp MEDIUM 6.1
CVE-2026-54276

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, DigestAuthMiddleware can send an authentication resp…

Fix: 3.14.1+
Fix from $1,600 2026-06-22
Vite HIGH 7.5
CVE-2026-53571

Vite is a frontend tooling framework for JavaScript. Prior to 8.0.16, 7.3.5, and 6.4.3, the contents of files that are specified by server.fs.deny ca…

Fix: 0.1.24 / 6.4.3+
Fix from $1,950 2026-06-22
Angular MEDIUM 6.1
CVE-2026-50169

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 22.0.0-r…

Fix: 19.2.23 / 20.3.22+
Fix from $1,600 2026-06-22