Vulnerability index

Browse CVEs

7,732 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Jd Edwards Enterpriseone Tools CRITICAL 9.1
CVE-2026-46910

Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Enterprise Infrastructure Security). Supported versions…

Fix: after 9.2.26.2
Fix from $2,300 2026-06-17
Webcenter Content MEDIUM 5.3
CVE-2026-46790

Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). The supported version that is affect…

Mitigation only
Fix from $1,600 2026-06-17
Unclassified HIGH 7.5
CVE-2026-50870

An information disclosure vulnerability in the configuration endpoint of Ben Busby whoogle-search v1.2.3 allows attackers to obtain sensitive informa…

Mitigation only
Fix from $1,950 2026-06-15
Unclassified HIGH 7.5
CVE-2026-39007

An issue in Observeinc's Observe v.2026-01-28 and before allows a remote attacker to obtain sensitive information via the CSV Log export component.

Mitigation only
Fix from $1,950 2026-06-15
Unclassified MEDIUM 5.3
CVE-2026-8385

The WP Go Maps WordPress plugin before 10.0.10 does not properly enforce the marker approval filter on the admin-ajax fallback for its datatables ro…

Mitigation only
Fix from $1,600 2026-06-15
Unclassified MEDIUM 5.3
CVE-2026-12203

A vulnerability was found in HKUDS AI-Trader up to 74caf996f78dcc0c657df8365c8544678a16e215. This affects an unknown part of the file /api/research/a…

Patch available
Fix from $1,600 2026-06-15
Unclassified MEDIUM 6.5
CVE-2026-47124

Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. From version 1.4.0 to before version 2.0.9, any authe…

Mitigation only
Fix from $1,600 2026-06-12
Unclassified MEDIUM 5.3
CVE-2026-49397

Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. From version 2.0.0 to before version 2.0.14, private …

Mitigation only
Fix from $1,600 2026-06-12
Unclassified MEDIUM 5.3
CVE-2026-54396

An information disclosure vulnerability exists in the MISP AuthKey edit functionality. When a validation error occurs during an AuthKey edit request,…

Patch available
Fix from $1,600 2026-06-12
Discourse MEDIUM 5.3
CVE-2026-45085

Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.4, 2026.3.0-latest to before 2026.3.1, and 2026.4.0-l…

Fix: 2026.1.0 / 2026.1.4+
Fix from $1,600 2026-06-12
Discourse MEDIUM 5.3
CVE-2026-47264

Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.4, 2026.3.0-latest to before 2026.3.1, and 2026.4.0-l…

Fix: 2026.1.0 / 2026.1.4+
Fix from $1,600 2026-06-12
Discourse MEDIUM 6.5
CVE-2026-44784

Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.4, 2026.3.0-latest to before 2026.3.1, and 2026.4.0-l…

Fix: 2026.1.0 / 2026.1.4+
Fix from $1,600 2026-06-12
Discourse HIGH 7.5
CVE-2026-44786

Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.4, 2026.3.0-latest to before 2026.3.1, and 2026.4.0-l…

Fix: 2026.1.0 / 2026.1.4+
Fix from $1,950 2026-06-12
Unclassified MEDIUM 5.9
CVE-2026-53725

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. From version 9.8.0 to before version 9.9.1-al…

Patch available
Fix from $1,600 2026-06-12
Mattermost Server MEDIUM 5.3
CVE-2026-6046

Mattermost versions 11.6.x <= 11.6.1, 11.5.x <= 11.5.4, 10.11.x <= 10.11.15, 10.11.x <= 10.11.16 fail to validate that a username returned during bot…

Fix: 10.11.17 / 11.5.5+
Fix from $1,600 2026-06-12
Unclassified MEDIUM 6.9
CVE-2026-44206

Frappe is a full-stack web application framework. Prior to versions 15.107.2 and 16.17.4, DB Schema Enumeration is possible through exploiting an end…

Mitigation only
Fix from $1,600 2026-06-12
Unclassified MEDIUM 5.7
CVE-2026-47177

Quest Bot is an opensource modern Discord Bot built for moderation, utilities and support. Prior to version 1.0.4, a user who can configure bot setti…

Mitigation only
Fix from $1,600 2026-06-11
Unclassified MEDIUM 5.7
CVE-2026-47176

Quest Bot is an opensource modern Discord Bot built for moderation, utilities and support. Prior to version 1.0.4, a user who can configure bot setti…

Mitigation only
Fix from $1,600 2026-06-11
Axios HIGH 7.5
CVE-2026-44486

Axios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16.0, Axios’ Node.js HTTP adapter can leak proxy credentials …

Fix: 0.32.0 / 1.16.0+
Fix from $1,950 2026-06-11
Unclassified MEDIUM 5.1
CVE-2026-53912

Cerebrate before version 1.37 exposed credential material from self-registration requests. The self-registration workflow stored the registrant’s has…

Patch available
Fix from $1,600 2026-06-11
Imagemagick MEDIUM 5.5
CVE-2026-49219

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-48 and 7.1.2-24, an incorrect…

Fix: 6.9.13-48 / 7.1.2-24+
Fix from $1,600 2026-06-10
Erlang\/otp MEDIUM 6.5
CVE-2026-48855

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Erlang OTP ssh (ssh_sftpd module) allows File Discovery. The SSH_FXP_REA…

Fix: 5.2.11.8 / 5.5.2.1+
Fix from $1,600 2026-06-10
Esp Idf MEDIUM 6.5
CVE-2026-45329

ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.5.4 and 6.0, several ESP-TEE secure-service wrappers in esp_se…

Patch available
Fix from $1,600 2026-06-10
Unclassified HIGH 7.5
CVE-2026-36719

An information disclosure vulnerability in the /api/v1/user/info endpoint of AgentChat v2.3.0 allows unauthenticated attackers to obtain sensitive in…

Mitigation only
Fix from $1,950 2026-06-09
Windows 10 1607 HIGH 7.5
CVE-2026-50508EPSS 9%

Exposure of sensitive information to an unauthorized actor in Windows NTLM allows an unauthorized attacker to perform spoofing over a network.

Fix: 10.0.14393.9234 / 10.0.19045.7417+
Fix from $1,950 2026-06-09
Visual Studio Code MEDIUM 6.5
CVE-2026-47284

Exposure of sensitive information to an unauthorized actor in Visual Studio Code allows an unauthorized attacker to disclose information over a netwo…

Fix: 1.123.1+
Fix from $1,600 2026-06-09
Windows 10 1607 MEDIUM 5.5
CVE-2026-45594

Exposure of sensitive information to an unauthorized actor in Windows Application Identity (AppID) Subsystem allows an authorized attacker to disclos…

Fix: 10.0.14393.9234 / 10.0.17763.8880+
Fix from $1,600 2026-06-09
Windows 10 1607 MEDIUM 5.5
CVE-2026-42973

Exposure of sensitive information to an unauthorized actor in Windows Push Notifications allows an authorized attacker to disclose information locall…

Fix: 10.0.14393.9234 / 10.0.17763.8880+
Fix from $1,600 2026-06-09
Windows 10 1607 MEDIUM 5.5
CVE-2026-42970

Exposure of sensitive information to an unauthorized actor in Windows Push Notifications allows an authorized attacker to disclose information locall…

Fix: 10.0.14393.9234 / 10.0.17763.8880+
Fix from $1,600 2026-06-09
Windows 10 1607 MEDIUM 5.5
CVE-2026-42971

Exposure of sensitive information to an unauthorized actor in Windows Push Notifications allows an authorized attacker to disclose information locall…

Fix: 10.0.14393.9234 / 10.0.17763.8880+
Fix from $1,600 2026-06-09