Vulnerability index

Browse CVEs

7,732 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Langflow CRITICAL 9.6
CVE-2026-55447

Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.2, by controlling a files that are digested into the RAG,…

Fix: 1.9.2+
Fix from $2,300 2026-06-23
Langflow CRITICAL 9.3
CVE-2026-55450EPSS 12%

Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.1, unauthenticated users can upload any amount of data to…

Fix: 1.9.1+
Fix from $2,300 2026-06-23
N8n HIGH 7.7
CVE-2026-54304

n8n is an open source workflow automation platform. Prior to 1.123.55, 2.25.7, and 2.26.1, an authenticated user with permission to create or modify …

Fix: 1.123.55 / 2.25.7+
Fix from $1,950 2026-06-23
N8n CRITICAL 9.9
CVE-2026-54305

n8n is an open source workflow automation platform. Prior to 1.123.55, 2.25.7, and 2.26.2, three EE endpoints used by the Dynamic Credentials feature…

Fix: 1.123.55 / 2.25.7+
Fix from $2,300 2026-06-23
Yt Dlp HIGH 7.4
CVE-2026-50019

yt-dlp is a command-line audio/video downloader. From 2023.09.24 until 2026.06.09, if curl is used as an external downloader for yt-dlp, cookies may …

Fix: 2026.06.09+
Fix from $1,950 2026-06-23
Unclassified CRITICAL 10.0
CVE-2026-27604

FOSSBilling is a free, open-source billing and client management system. Starting in version 0.5.4 and prior to version 0.8.0, an authorization bypas…

Mitigation only
Fix from $2,300 2026-06-23
Unclassified HIGH 7.5
CVE-2026-56322

Capgo before 12.128.2 contains an information disclosure vulnerability in the unauthenticated /updates endpoint that resolves the defaultChannel para…

Mitigation only
Fix from $1,950 2026-06-23
Vllm HIGH 7.5
CVE-2026-53923

vLLM is an inference and serving engine for large language models (LLMs). From 0.5.5 until 0.23.1rc0, integer truncation of tensor dimensions in vLLM…

Fix: 0.23.1+
Fix from $1,950 2026-06-22
Unclassified HIGH 7.5
CVE-2026-56323

Capgo before 12.128.2 contains an information disclosure vulnerability in the /functions/v1/channel_self endpoint that allows unauthenticated attacke…

Mitigation only
Fix from $1,950 2026-06-22
Aiohttp MEDIUM 6.1
CVE-2026-54276

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, DigestAuthMiddleware can send an authentication resp…

Fix: 3.14.1+
Fix from $1,600 2026-06-22
Vite HIGH 7.5
CVE-2026-53571

Vite is a frontend tooling framework for JavaScript. Prior to 8.0.16, 7.3.5, and 6.4.3, the contents of files that are specified by server.fs.deny ca…

Fix: 0.1.24 / 6.4.3+
Fix from $1,950 2026-06-22
Angular MEDIUM 6.1
CVE-2026-50169

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 22.0.0-r…

Fix: 19.2.23 / 20.3.22+
Fix from $1,600 2026-06-22
Angular MEDIUM 6.1
CVE-2026-50184

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 22.0.0-r…

Fix: 19.2.23 / 20.3.22+
Fix from $1,600 2026-06-22
Angular MEDIUM 6.1
CVE-2026-54264

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 22.0.1, …

Fix: 20.3.25 / 21.2.17+
Fix from $1,600 2026-06-22
Unclassified CRITICAL 9.2
CVE-2026-7166

Vulnerability involving the exposure of sensitive data provided without adequate protection. The API exposes email and phone number data from the ‘em…

Mitigation only
Fix from $2,300 2026-06-22
Unclassified MEDIUM 6.9
CVE-2026-7167

The vulnerability arises when the system fails to properly validate the 'email' field during the authentication process, allowing unverified or fake …

Mitigation only
Fix from $1,600 2026-06-22
Unclassified HIGH 7.5
CVE-2026-56242

Capgo before 12.128.2 contains an unauthenticated security definer RPC function get_identity_apikey_only that returns the owning user_id for supplied…

Mitigation only
Fix from $1,950 2026-06-21
Unclassified MEDIUM 5.3
CVE-2026-56282

Capgo before 12.128.2 contains an information disclosure vulnerability in the unauthenticated /replication endpoint that exposes internal PostgreSQL …

Mitigation only
Fix from $1,600 2026-06-20
Unclassified MEDIUM 5.3
CVE-2026-56218

Capgo before 12.128.2 fails to strip EXIF metadata including GPS geolocation data from uploaded images, allowing information disclosure. Attackers ca…

Mitigation only
Fix from $1,600 2026-06-20
Unclassified MEDIUM 5.3
CVE-2026-56235

Cap-go capgo before 12.128.2 contains an authorization bypass in several Supabase PostgREST RPC functions (get_app_metrics, get_global_metrics, get_t…

Mitigation only
Fix from $1,600 2026-06-20
Unclassified MEDIUM 6.9
CVE-2026-56267

Flowise before 3.0.13 contains an information exposure vulnerability in the POST /api/v1/account/forgot-password endpoint that returns full user obje…

Mitigation only
Fix from $1,600 2026-06-20
Unclassified HIGH 7.5
CVE-2026-56214

Capgo before 12.128.2 contains an information disclosure vulnerability in Supabase PostgREST RPC endpoints is_trial_org and is_paying_org that allows…

Mitigation only
Fix from $1,950 2026-06-20
Unclassified MEDIUM 6.5
CVE-2026-56079

Capgo before 12.128.2 contains a cross-tenant authorization bypass vulnerability in PostgREST endpoints that allows org-scoped read API keys to acces…

Mitigation only
Fix from $1,600 2026-06-19
Unclassified MEDIUM 5.5
CVE-2026-49336

@microsoft/kiota-http-fetchlibrary provides TypeScript libraries for Kiota-generated API clients. In versions 1.0.0-preview.97 through 1.0.0-preview.…

Patch available
Fix from $1,600 2026-06-19
Gridtime 3000 Firmware MEDIUM 6.5
CVE-2026-12620

The GridTime 3000 GNSS Time Server leaks the access token in the URL parameters of some endpoints. This issue affects GridTime 3000: from 1.0r0.03 t…

Fix: 1.2r0.0+
Fix from $1,600 2026-06-19
Cost Management HIGH 7.5
CVE-2026-47633

Exposure of sensitive information to an unauthorized actor in Cost Management Interactive Experiences allows an unauthorized attacker to disclose inf…

No fix yet
Fix from $1,950 2026-06-18
Unclassified MEDIUM 5.3
CVE-2026-12120

The FireBox Popups – Increase Sales and Grow Your Email List plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up …

Mitigation only
Fix from $1,600 2026-06-18
Unclassified HIGH 7.5
CVE-2026-50200

Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applications. In Steeltoe.Management.E…

Patch available
Fix from $1,950 2026-06-17
Dolphinscheduler MEDIUM 6.5
CVE-2026-47340

Allow authenticated users to access alert instances associated with alert groups they do not have permission to access. in Apache DolphinScheduler. …

Fix: 3.4.2+
Fix from $1,600 2026-06-17
Jd Edwards Enterpriseone Tools CRITICAL 9.3
CVE-2026-46912

Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime Security). Supported versions that are affe…

Fix: after 9.2.26.2
Fix from $2,300 2026-06-17