Vulnerability index

Browse CVEs

7,732 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Unclassified CRITICAL 9.4
CVE-2026-9129

A path traversal vulnerability exists in the Altium Enterprise Server Viewer StorageController due to improper handling of file path route parameters…

Mitigation only
Fix from $2,300 2026-05-20
Bigfix Service Management MEDIUM 6.5
CVE-2025-31985

HCL BigFix Service Management (SM) is affected by a security misconfiguration due to a missing or insecure “X-Content-Type-Options” header. This cou…

Mitigation only
Fix from $1,600 2026-05-20
Unclassified MEDIUM 5.3
CVE-2026-6728

The Slider Revolution plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 7.0.9 via the 'get_strea…

Mitigation only
Fix from $1,600 2026-05-20
Unclassified MEDIUM 5.3
CVE-2026-34970

Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions 2.28.1 and prior allow a bugnote author to access the note's Revisions page a…

Patch available
Fix from $1,600 2026-05-20
Unclassified MEDIUM 5.3
CVE-2026-34579

Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions 2.28.1 and prior are vulnerable to Authorization Bypass through the private i…

Patch available
Fix from $1,600 2026-05-19
Unclassified MEDIUM 5.7
CVE-2026-34600

Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Versions 3.5.2 and prior contain a logic er…

Patch available
Fix from $1,600 2026-05-19
Unclassified MEDIUM 5.3
CVE-2026-34744

Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions 2.28.1 and prior permit a user to list and download their own attachments fro…

Patch available
Fix from $1,600 2026-05-19
Unclassified MEDIUM 6.5
CVE-2026-32814

libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and prior, when decoding a HEIF grid image with strict_decoding=false …

Mitigation only
Fix from $1,600 2026-05-19
Firefox MEDIUM 6.5
CVE-2026-8706

Firefox for iOS hosted Reader mode on an unauthenticated local web server, allowing another application on the same device to request arbitrary URLs …

Fix: 151.0+
Fix from $1,600 2026-05-19
Firefox HIGH 7.5
CVE-2026-8966

Information disclosure in the IP Protection component. This vulnerability was fixed in Firefox 151 and Thunderbird 151.

Fix: 151.0.0+
Fix from $1,950 2026-05-19
Firefox HIGH 7.5
CVE-2026-8967

Information disclosure in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 151 and Thunderbird 151.

Fix: 151.0.0+
Fix from $1,950 2026-05-19
Firefox HIGH 7.5
CVE-2026-8965

Information disclosure in the DOM: Security component. This vulnerability was fixed in Firefox 151 and Thunderbird 151.

Fix: 151.0.0+
Fix from $1,950 2026-05-19
Ofbiz HIGH 7.5
CVE-2026-31909

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Users a…

Fix: 24.09.06+
Fix from $1,950 2026-05-19
Unclassified MEDIUM 6.3
CVE-2026-44408

There is an unauthorized access vulnerability in ZTE MU5250. Due to improper permission control of the Web interface, an unauthorized attacker can  m…

Mitigation only
Fix from $1,600 2026-05-19
Discourse MEDIUM 5.3
CVE-2026-32244

Discourse is an open-source discussion platform. In versions prior to 2026.1.4, 2026.3.1, 2026.4.1 and 2026.5.0-latest.1, outdated cached AI summarie…

Fix: 2026.1.4 / 2026.3.1+
Fix from $1,600 2026-05-19
Unclassified MEDIUM 6.5
CVE-2026-27892

FacturaScripts is an open source accounting and invoicing software. In versions prior to 2026, the Library module stores and serves uploaded images b…

Patch available
Fix from $1,600 2026-05-18
Unclassified HIGH 7.5
CVE-2026-39079

An issue in prestashop upsshipping all versions through at least 2.4.0 allows a remote attacker to obtain sensitive information via the /modules/upss…

Mitigation only
Fix from $1,950 2026-05-18
Mattermost Server HIGH 8.7
CVE-2026-6346

Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 fail to sanitize sensitive configuration fields before including them in …

Fix: 10.11.14 / 11.4.4+
Fix from $1,950 2026-05-18
Mattermost Server HIGH 7.6
CVE-2026-6347

Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 fail to sanitize sensitive configuration fields in the Mattermost Calls p…

Fix: 10.11.14 / 11.4.4+
Fix from $1,950 2026-05-18
Kilo Code Cli MEDIUM 6.5
CVE-2026-8766

A flaw has been found in Kilo-Org kilocode up to 7.0.47. This issue affects the function Load of the file packages/opencode/src/config/config.ts of t…

Fix: after 7.0.47
Fix from $1,600 2026-05-17
H2o HIGH 7.5
CVE-2026-8750

A vulnerability was identified in h2oai h2o-3 up to 7402. Affected by this issue is the function importFiles of the file h2o-core/src/main/java/water…

Fix: after 7402
Fix from $1,950 2026-05-17
Open Webui MEDIUM 6.5
CVE-2026-45351

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.8.9, when a regular user [non-admin] lo…

Fix: 0.8.9+
Fix from $1,600 2026-05-15
Unclassified HIGH 7.4
CVE-2026-45539

Microsoft APM is an open-source, community-driven dependency manager for AI agents. From 0.5.4 to 0.12.4, two primitive integrators in apm-cli enumer…

No fix yet
Fix from $1,950 2026-05-15
Unclassified MEDIUM 5.8
CVE-2026-41960

Permission control vulnerability in calls. Impact: Successful exploitation of this vulnerability may affect availability.

No fix yet
Fix from $1,600 2026-05-15
Strapi HIGH 7.5
CVE-2026-27886

Strapi is an open source headless content management system. Strapi versions starting in 4.0.0 and prior to 5.37.0 did not sufficiently sanitize quer…

Fix: 5.37.0+
Fix from $1,950 2026-05-14
Authenticator HIGH 7.4
CVE-2026-41615

Exposure of sensitive information to an unauthorized actor in Microsoft Authenticator allows an unauthorized attacker to disclose information over a …

Fix: 6.8.47 / 6.2605.2973+
Fix from $1,950 2026-05-14
Devspace HIGH 7.8
CVE-2026-42283

DevSpace is a client-only developer tool for cloud-native development with Kubernetes. Prior to 6.3.21, DevSpace's UI server WebSocket accepts connec…

Mitigation only
Fix from $1,950 2026-05-14
Prisma Access Agent MEDIUM 5.5
CVE-2026-0245

Multiple information disclosure vulnerabilities in Prisma Access Agent® allow a local user to access sensitive configuration data and credentials. …

Fix: 26.2.1+
Fix from $1,600 2026-05-13
Vercel MEDIUM 5.5
CVE-2026-44479

Vercel’s AI Cloud is a unified platform for building modern applications. From 50.16.0 to 52.0.0, hen the Vercel CLI runs in non-interactive mode (-…

Fix: 52.0.1+
Fix from $1,600 2026-05-13
Urllib3 MEDIUM 5.3
CVE-2026-44431

urllib3 is an HTTP client library for Python. From 1.23 to before 2.7.0, cross-origin redirects followed from the low-level API via ProxyManager.conn…

Fix: 2.7.0+
Fix from $1,600 2026-05-13