Vulnerability index

Browse CVEs

7,732 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Windows 10 1607 MEDIUM 5.5
CVE-2026-42972

Exposure of sensitive information to an unauthorized actor in Windows Hyper-V allows an authorized attacker to disclose information locally.

Fix: 10.0.14393.9234 / 10.0.17763.8880+
Fix from $1,600 2026-06-09
Windows 10 21h2 MEDIUM 5.5
CVE-2026-42906

Exposure of sensitive information to an unauthorized actor in Windows Shell allows an authorized attacker to disclose information locally.

Fix: 10.0.19044.7417 / 10.0.19045.7417+
Fix from $1,600 2026-06-09
Windows 10 1809 MEDIUM 6.5
CVE-2026-42907

Exposure of sensitive information to an unauthorized actor in Windows Shell allows an authorized attacker to disclose information over a network.

Fix: 10.0.17763.8880 / 10.0.19044.7417+
Fix from $1,600 2026-06-09
Rbe970 Firmware HIGH 8.0
CVE-2026-0411

An information disclosure vulnerability in the NETGEAR Orbi satellites (RBR/RBE/RBS Series) could allow a user connected to your network to gain admi…

Fix: 4.4.2.2 / 6.3.8.11+
Fix from $1,950 2026-06-09
Unclassified HIGH 7.1
CVE-2026-49742

Backend users with file download permissions were able to download files from the fallback storage of the file abstraction layer (FAL) via the Media …

Patch available
Fix from $1,950 2026-06-09
Unclassified MEDIUM 5.3
CVE-2026-47351

Backend users were able to insert arbitrary records and files into the TYPO3 clipboard without proper read permission checks, which allowed users to …

Patch available
Fix from $1,600 2026-06-09
Unclassified MEDIUM 6.5
CVE-2026-7542

The Slider Revolution plugin for WordPress is vulnerable to Sensitive Information Disclosure in versions 7.0 to 7.0.10. This is due to three compound…

Mitigation only
Fix from $1,600 2026-06-09
Answer MEDIUM 6.5
CVE-2026-34905

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. The unl…

Fix: 2.0.1+
Fix from $1,600 2026-06-09
Unclassified MEDIUM 5.5
CVE-2026-41980

Permission control vulnerability in the file preview module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

No fix yet
Fix from $1,600 2026-06-09
Flowise MEDIUM 6.5
CVE-2026-46443

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, when credentials are fetched with a …

Fix: 3.1.2+
Fix from $1,600 2026-06-08
Unclassified MEDIUM 5.3
CVE-2026-11458

A weakness has been identified in erzhongxmu JeeWMS up to 141740afb2ba14d441c82a833d0a418d07ca2d69. This issue affects some unknown processing of the…

Mitigation only
Fix from $1,600 2026-06-07
Unclassified HIGH 8.3
CVE-2026-11424

A server-side request forgery (SSRF) vulnerability exists in a GraphQL service component shared by Altium Enterprise Server and Altium 365. An authen…

Mitigation only
Fix from $1,950 2026-06-05
Unclassified HIGH 8.3
CVE-2026-11431

A path traversal vulnerability exists in the Projects Service download endpoint shared by Altium Enterprise Server and Altium 365. An authenticated u…

Mitigation only
Fix from $1,950 2026-06-05
Async Http Client HIGH 7.4
CVE-2026-45300

The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. Versions on the…

Fix: 2.15.0 / 3.0.10+
Fix from $1,950 2026-06-05
Unclassified CRITICAL 9.3
CVE-2026-46395

HAX CMS helps manage microsite universe with PHP or NodeJs backends. Prior to version 26.0.0, the `hmacBase64()` function in the HAXcms Node.js backe…

Mitigation only
Fix from $2,300 2026-06-05
Chrome MEDIUM 6.5
CVE-2026-11271

Inappropriate implementation in Passwords in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who convinced a user to engage in specifi…

Fix: 149.0.7827.53+
Fix from $1,600 2026-06-05
Graph MEDIUM 6.5
CVE-2026-47655

Exposure of sensitive information to an unauthorized actor in Microsoft Graph allows an authorized attacker to disclose information over a network.

No fix yet
Fix from $1,600 2026-06-04
Chrome MEDIUM 6.5
CVE-2026-11209

Inappropriate implementation in Passwords in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process …

Fix: 149.0.7827.53+
Fix from $1,600 2026-06-04
Chrome MEDIUM 6.5
CVE-2026-11203

Inappropriate implementation in GPU in Google Chrome on Mac prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted …

Fix: 149.0.7827.53+
Fix from $1,600 2026-06-04
Chrome MEDIUM 6.5
CVE-2026-11182

Inappropriate implementation in SVG in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML pa…

Fix: 149.0.7827.53+
Fix from $1,600 2026-06-04
Chrome MEDIUM 6.5
CVE-2026-11180

Inappropriate implementation in SVG in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML pa…

Fix: 149.0.7827.53+
Fix from $1,600 2026-06-04
Chrome MEDIUM 6.5
CVE-2026-11168

Inappropriate implementation in Extensions in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process…

Fix: 149.0.7827.53+
Fix from $1,600 2026-06-04
Unclassified HIGH 8.2
CVE-2025-69755

An issue in Neterbit NW-431F Router vNW-431F-20241014-IR03 allows a remote attacker to obtain sensitive information and execute arbitrary code via a …

Mitigation only
Fix from $1,950 2026-06-04
Connect M6e 5g Firmware HIGH 7.5
CVE-2026-50210

The device encrypts data using AES-CBC with static zero-filled Initialization Vectors (IVs), making it susceptible to replay attacks and known-plaint…

Mitigation only
Fix from $1,950 2026-06-04
Connect M6e 5g Firmware HIGH 7.5
CVE-2026-49193

Overly permissive configuration settings on cloud storage containers expose active telemetry information publicly to the internet.

Mitigation only
Fix from $1,950 2026-06-04
Connect M6e 5g Firmware HIGH 7.5
CVE-2026-49187

The hard-coded APK resource files never expire, and the shared scepter leads to information leaks and potential misuse.

No fix yet
Fix from $1,950 2026-06-04
Unclassified MEDIUM 6.9
CVE-2026-40495

FOSSBilling is a free, open-source billing and client management system. Versions prior to 0.8.0 leak the exact system version through asset cache bu…

Mitigation only
Fix from $1,600 2026-06-03
Unclassified HIGH 7.3
CVE-2026-36611

Mercusys AC12G (EU) V1 with firmware AC12G(EU)_V1_200909 returns 128 bytes of uninitialized buffer when receiving POST requests without SOAPAction he…

Mitigation only
Fix from $1,950 2026-06-03
Unclassified HIGH 7.5
CVE-2026-41032

It is possible for an unauthenticated adjacent attacker to download log files of the controller, which may disclose some restricted information.

Mitigation only
Fix from $1,950 2026-06-03
Librechat CRITICAL 9.6
CVE-2026-32625

LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. In versions up to and including 0.8.3, the Model Context Protocol (MCP) s…

Fix: 0.8.4+
Fix from $2,300 2026-06-02