Vulnerability index

Browse CVEs

7,732 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Unclassified MEDIUM 6.9
CVE-2026-45080

Klaw is a self-service Apache Kafka Topic Management/Governance tool/portal. Prior to version 2.10.4, improper access control allows disclosure of pa…

Mitigation only
Fix from $1,600 2026-06-02
Unclassified HIGH 7.5
CVE-2026-45553

NiceGUI is a Python-based UI framework. Prior to version 3.12.0, ui.restructured_text() renders reStructuredText server-side with Docutils without di…

Mitigation only
Fix from $1,950 2026-06-02
Unclassified MEDIUM 6.5
CVE-2026-8993

D.Launcher 2 component of Slovak eID client ecosystem contains Improper URL Handler Processing vulnerability. Application registers multiple custom U…

Mitigation only
Fix from $1,600 2026-06-02
Unclassified CRITICAL 10.0
CVE-2026-40965

Cloud Foundry UAA versions v76.12.0 through v78.12.0 are vulnerable to a private key exposure. The server contains a vulnerability where EC (Elliptic…

Mitigation only
Fix from $2,300 2026-06-01
Unclassified MEDIUM 6.5
CVE-2026-45267

Nextcloud is an open source content collaboration platform. Prior to version 5.2.6, a missing permissions check allowed users to request reading form…

Patch available
Fix from $1,600 2026-06-01
Unclassified MEDIUM 5.3
CVE-2026-10254

A flaw has been found in SourceCodester Pet Grooming Management Software 1.0. Affected is an unknown function of the file /admin/. This manipulation …

Mitigation only
Fix from $1,600 2026-06-01
Airflow MEDIUM 6.5
CVE-2026-42360

A bug in Apache Airflow's rendered-template field handling caused nested sensitive-key masking (e.g. nested `password` / `token` / `secret` / `api_ke…

Fix: 3.2.2+
Fix from $1,600 2026-06-01
Airflow MEDIUM 6.5
CVE-2026-42358

A bug in Apache Airflow's Variable response masker caused nested-key redaction (triggered by secret-suffixed key names like `password`, `token`, `sec…

Fix: 3.2.2+
Fix from $1,600 2026-06-01
Airflow MEDIUM 6.5
CVE-2026-45192

A bug in the GET `/api/v2/connections/{connection_id}` REST API endpoint in Apache Airflow allowed an authenticated UI/API user with Connection-read …

Fix: 3.2.2+
Fix from $1,600 2026-06-01
Otrs MEDIUM 5.7
CVE-2026-48189

An improper Input Validation vulnerability in OTRS Customer Backend module allows to access customer information which are restricted to other groups…

Fix: 2026.4.1+
Fix from $1,600 2026-06-01
Otrs MEDIUM 5.7
CVE-2026-48210

An improper default configuration in OTRS 2026.3.1 causes ticket article forwarding actions to enforce the “Is visible for customer” flag by default …

Mitigation only
Fix from $1,600 2026-05-31
Unclassified MEDIUM 5.3
CVE-2026-2128

The Breeze plugin for WordPress is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor in all versions up to, and including, 2.5…

Mitigation only
Fix from $1,600 2026-05-29
Chrome MEDIUM 6.5
CVE-2026-9981

Inappropriate implementation in Skia in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to obtain potentially sensitive information f…

Fix: 148.0.7778.215 / 148.0.7778.216+
Fix from $1,600 2026-05-28
Chrome MEDIUM 6.5
CVE-2026-9912

Inappropriate implementation in GPU in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker to obtain potentially sensitive inf…

Fix: 148.0.7778.216+
Fix from $1,600 2026-05-28
Portainer CRITICAL 9.9
CVE-2026-44881

Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage Docker, Swarm, Kuber…

Fix: 2.33.8 / 2.39.2+
Fix from $2,300 2026-05-28
Rest Data Services MEDIUM 5.3
CVE-2026-46830

Vulnerability in Oracle REST Data Services (component: Mongoapi). Supported versions that are affected are 24.2.0-26.1.0. Easily exploitable vulnera…

Fix: after 26.1.0
Fix from $1,600 2026-05-28
Rest Data Services MEDIUM 5.3
CVE-2026-46841

Vulnerability in Oracle REST Data Services (component: General). Supported versions that are affected are 24.2.0-26.1.0. Easily exploitable vulnerab…

Fix: after 26.1.0
Fix from $1,600 2026-05-28
Unclassified HIGH 7.5
CVE-2026-45332

Automad is a flat-file content management system and template engine. From 2.0.0-alpha.1 to 2.0.0-beta.27, a Broken Access Control vulnerability allo…

Mitigation only
Fix from $1,950 2026-05-28
Unclassified MEDIUM 6.9
CVE-2026-47136

RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.2, the RustFS console endpoint GET /rustfs/console/license returns p…

Mitigation only
Fix from $1,600 2026-05-28
Unclassified MEDIUM 5.3
CVE-2026-42878

FacturaScripts is an open source accounting and invoicing software. Prior to v2026, an unauthenticated information disclosure vulnerability in the In…

Mitigation only
Fix from $1,600 2026-05-27
Unclassified HIGH 7.7
CVE-2026-46427

Budibase is an open-source low-code platform. Prior to 3.38.3, removeSecrets at packages/server/src/sdk/workspace/datasources/datasources.ts masks on…

Mitigation only
Fix from $1,950 2026-05-27
Unclassified HIGH 7.4
CVE-2026-44460

FileRise is a self-hosted web-based file manager with multi-file upload, editing, and batch operations. Prior to 3.12.0, /api/totp_setup.php is calla…

Mitigation only
Fix from $1,950 2026-05-27
Guardium Data Protection MEDIUM 6.5
CVE-2026-8405

IBM Guardium Data Protection 12.2.1, and 12.2.2 's add-on feature of Guardium Data Protection named "Long Term Retention" (LTR) can expose sensitive …

Mitigation only
Fix from $1,600 2026-05-27
Unclassified HIGH 7.3
CVE-2026-36539

Netis AC1200 Router NC21 V4.0.1.4296 exposes a CGI endpoint /cgi-bin/skk_get.cgi that returns the entire router configuration as a JSON response with…

Mitigation only
Fix from $1,950 2026-05-27
Unclassified MEDIUM 5.6
CVE-2026-24198

NVIDIA GPU Display Driver for Linux contains a vulnerability where an advanced attacker could use a race condition to leak sensitive memory, which m…

No fix yet
Fix from $1,600 2026-05-26
Unclassified MEDIUM 5.3
CVE-2026-9352

A weakness has been identified in NousResearch hermes-agent up to 2026.4.23. This issue affects the function _make_run_env of the file tools/environm…

No fix yet
Fix from $1,600 2026-05-24
Unclassified MEDIUM 5.3
CVE-2026-9349

A vulnerability was determined in calcom cal.diy up to 4.9.4. Affected by this issue is the function getServerSideProps of the file apps/web/modules/…

Mitigation only
Fix from $1,600 2026-05-24
Unclassified HIGH 7.1
CVE-2026-40166

authentik is an open-source identity provider. In versions prior to 2025.12.5 and 2026.2.0-rc1 through 2026.2.2, authenticated non-admin users with a…

Mitigation only
Fix from $1,950 2026-05-22
Mu5250 Firmware HIGH 7.5
CVE-2026-44409

There is an an information disclosure vulnerability in ZTE MU5250. Due to improper configuration of the access control mechanism, attackers can obtai…

Mitigation only
Fix from $1,950 2026-05-22
Concrete Cms MEDIUM 5.3
CVE-2026-6826

Concrete CMS 9.5.0 and below  is vulnerable to unauthenticated file usage disclosure via missing permission check in the usage controller.  Any unaut…

Fix: 9.5.1+
Fix from $1,600 2026-05-21