Vulnerability index

Browse CVEs

7,720 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Unclassified HIGH 8.6
CVE-2026-59499

CWE-200: Exposure of Sensitive Information to an Unauthorized Actor

No fix yet
Fix from $4,900 2026-08-13
Unclassified MEDIUM 6.3
CVE-2026-73411

Shescape is a simple shell escape library for JavaScript. Prior to 2.1.14 and 3.0.1, getEscapeFunction in src/internal/unix/dash.js fails to escape ~…

No fix yet
Fix from $4,000 2026-08-12
Unclassified HIGH 7.5
CVE-2026-73406

Budibase is an open-source low-code platform. Prior to 3.39.32, GET /api/global/users/tenant/:id was listed in PUBLIC_ENDPOINTS in packages/worker/sr…

No fix yet
Fix from $4,900 2026-08-12
Unclassified MEDIUM 5.7
CVE-2026-73308

Budibase is an open-source low-code platform. Prior to 3.39.25, packages/server/src/api/controllers/automation.ts returned automation test results co…

No fix yet
Fix from $4,000 2026-08-12
Unclassified HIGH 8.6
CVE-2026-72804

SiYuan versions before v3.7.4 fail to validate publish-password tier in getGraph and getLocalGraph endpoints, allowing anonymous readers to retrieve …

No fix yet
Fix from $4,900 2026-08-12
Unclassified MEDIUM 5.3
CVE-2026-18673

When kuma-dp is configured with the Envoy admin API on a Unix domain socket, which is the default, its readiness service on TCP port 9902 - bound to …

No fix yet
Fix from $4,000 2026-08-12
Airflow MEDIUM 6.5
CVE-2026-65017

Apache Airflow's Config API did not mask team-scoped sensitive configuration values in multi-team deployments. When an administrator has enabled mult…

Fix: 3.3.1+
Fix from $4,000 2026-08-12
Unclassified MEDIUM 5.3
CVE-2026-19073

The Order Sync with Zendesk for WooCommerce WordPress plugin before 2.2.3 does not perform any capability check on one of its REST API endpoints, and…

No fix yet
Fix from $4,000 2026-08-12
Unclassified MEDIUM 6.5
CVE-2026-18943

The WPC Admin Columns WordPress plugin before 2.3.4 does not have authorisation checks in one of its AJAX actions, allowing users with a role as low …

No fix yet
Fix from $4,000 2026-08-12
Unclassified HIGH 7.5
CVE-2026-18049

The WP Photo Album Plus WordPress plugin before 9.2.07.002 does not perform any capability or nonce check on one of its public endpoint actions and b…

No fix yet
Fix from $4,900 2026-08-12
Unclassified HIGH 7.5
CVE-2026-16253

The Total Upkeep WordPress plugin before 1.17.3 does not adequately protect the secret that authorizes its backup-restore functionality and exposes …

No fix yet
Fix from $4,900 2026-08-12
Unclassified HIGH 7.5
CVE-2026-14925

The Import WP WordPress plugin before 2.14.23 does not perform any authorization check on one of its export-file download handlers, allowing unauthe…

No fix yet
Fix from $4,900 2026-08-12
Unclassified MEDIUM 6.5
CVE-2026-13168

The Eventin WordPress plugin before 4.1.20 does not properly restrict access to stored customer records, allowing users with contributor-level acces…

No fix yet
Fix from $4,000 2026-08-12
Unclassified MEDIUM 6.5
CVE-2026-12976

The LearnPress WordPress plugin before 4.4.4 does not verify that a user is enrolled in a course before processing AI-assistant requests against tha…

No fix yet
Fix from $4,000 2026-08-12
Unclassified HIGH 7.5
CVE-2026-73246

Kestra is an open-source, event-driven orchestration platform. Prior to 2.0.0-rc6, Kestra's worker/src/main/java/io/kestra/worker/endpoint/WorkerEndp…

No fix yet
Fix from $4,900 2026-08-11
Unclassified MEDIUM 5.9
CVE-2026-73230

Ente provides end-to-end encrypted cloud services and security tools. Prior to 2026.07.28, Ente 2of3 card format version 1 stored the secret byte len…

No fix yet
Fix from $4,000 2026-08-11
Unclassified HIGH 8.2
CVE-2026-48771

ishankportfolio is a portfolio website. Prior to version 1.0.1, contact form submissions could potentially be exposed due to improperly secured clien…

No fix yet
Fix from $4,900 2026-08-11
Unclassified HIGH 7.6
CVE-2026-48767

TypeBot is a chatbot builder tool. Versions prior to 3.17.0 allow a low-privilege guest member of a workspace to obtain a live Google Sheets OAuth ac…

No fix yet
Fix from $4,900 2026-08-11
Unclassified MEDIUM 5.3
CVE-2026-73082

Activepieces is an open source AI workflow automation platform. Prior to 0.82.0, the POST /api/v1/projects/:projectId/mcp-server/validate-agent-mcp-t…

No fix yet
Fix from $4,000 2026-08-11
Dynamics 365 MEDIUM 6.5
CVE-2026-66301

Exposure of sensitive information to an unauthorized actor in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to disclose informat…

No fix yet
Fix from $4,000 2026-08-11
Teams HIGH 7.5
CVE-2026-65769

Exposure of sensitive information to an unauthorized actor in Microsoft Teams Mobile allows an unauthorized attacker to disclose information over a n…

Fix: 8.8.1+
Fix from $4,900 2026-08-11
Windows 10 1607 MEDIUM 6.5
CVE-2026-61921

Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.

Fix: 10.0.14393.9418 / 10.0.17763.9115+
Fix from $4,000 2026-08-11
Windows 10 1607 HIGH 7.5
CVE-2026-61924

Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.

Fix: 10.0.14393.9418 / 10.0.17763.9115+
Fix from $4,900 2026-08-11
Windows 10 1607 HIGH 7.5
CVE-2026-61918

Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.

Fix: 10.0.14393.9418 / 10.0.17763.9115+
Fix from $4,900 2026-08-11
Windows 10 1607 MEDIUM 5.6
CVE-2026-59130

No cwe for this issue in AMD Zen allows an authorized attacker to disclose information locally.

Fix: 10.0.14393.9418 / 10.0.17763.9115+
Fix from $4,000 2026-08-11
Defender For Endpoint MEDIUM 5.5
CVE-2026-54123

Exposure of sensitive information to an unauthorized actor in Microsoft Defender for Endpoint allows an authorized attacker to disclose information l…

No fix yet
Fix from $4,000 2026-08-11
Unclassified MEDIUM 6.3
CVE-2026-20737

Exposure of sensitive information to an unauthorized actor for some Intel(R) PROSet/Wireless WiFi Software for Windows within Ring 2: Device Drivers …

No fix yet
Fix from $4,000 2026-08-11
Unclassified HIGH 7.6
CVE-2026-48766

TypeBot is a chatbot builder tool. Versions prior to 3.17.0 allow a low-privilege guest member of a workspace to exfiltrate stored OpenAI-compatible …

No fix yet
Fix from $4,900 2026-08-11
Unclassified MEDIUM 6.2
CVE-2026-72744

Nuxt versions >= 4.4.7 and < 4.5.1, and >= 3.21.7 and < 3.21.10, contain an information disclosure vulnerability in the development server's Chrome D…

No fix yet
Fix from $4,000 2026-08-11
Unclassified HIGH 7.5
CVE-2026-72548

An information disclosure vulnerability in OpenSignLabs OpenSign through 2.37.0 allows unauthenticated remote attackers to retrieve any organisation …

No fix yet
Fix from $4,900 2026-08-11