Vulnerability index

Browse CVEs

7,732 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Unclassified MEDIUM 5.3
CVE-2025-9987

The Broadstreet plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.53.1 via the get_sponsor…

Mitigation only
Fix from $1,600 2026-05-13
Visual Studio Code MEDIUM 5.0
CVE-2026-41610

Improper neutralization of input during web page generation ('cross-site scripting') in Visual Studio Code allows an unauthorized attacker to bypass …

Fix: 1.119.1+
Fix from $1,600 2026-05-12
Power Automate For Desktop MEDIUM 6.5
CVE-2026-40374

Exposure of sensitive information to an unauthorized actor in Power Automate allows an authorized attacker to disclose information over a network.

Fix: 2.67+
Fix from $1,600 2026-05-12
Entra Id HIGH 7.5
CVE-2026-40379

Exposure of sensitive information to an unauthorized actor in Azure Entra ID allows an unauthorized attacker to perform spoofing over a network.

No fix yet
Fix from $1,950 2026-05-12
Unclassified CRITICAL 9.8
CVE-2026-43992

JunoClaw is an agentic AI platform built on Juno Network. Prior to 0.x.y-security-1, every MCP write tool (send_tokens, execute_contract, instantiate…

Patch available
Fix from $2,300 2026-05-12
Tomcat HIGH 7.3
CVE-2026-42498

Exposure of HTTP Authentication Header to unexpected hosts during WebSocket authentication vulnerability in Apache Tomcat. This issue affects Apache…

Fix: 9.0.118 / 10.1.55+
Fix from $1,950 2026-05-12
Unclassified CRITICAL 9.1
CVE-2026-45091

sealed-env is a cross-stack, zero-trust secret management library for Node.js and Java/Spring Boot. In sealed-env enterprise mode, versions 0.1.0-alp…

Mitigation only
Fix from $2,300 2026-05-12
Unclassified MEDIUM 5.3
CVE-2026-7626

The Slek Gateway for WooCommerce plugin for WordPress is vulnerable to Information Exposure in version 1.0. This is due to the wsb_handle_slek_paymen…

Mitigation only
Fix from $1,600 2026-05-12
Unclassified HIGH 7.7
CVE-2026-43885

WWBN AVideo is an open source video platform. In versions up to and including 29.0, an unauthenticated user can read APISecret from objects/plugins.j…

Patch available
Fix from $1,950 2026-05-11
Unclassified HIGH 8.2
CVE-2026-42564

jotty·page is a self-hosted app for your checklists and notes. Prior to 1.22.0, an unauthenticated path traversal vulnerability exists in /api/app-ic…

Mitigation only
Fix from $1,950 2026-05-11
macOS HIGH 7.5
CVE-2026-28976

An information leakage was addressed with additional validation. This issue is fixed in macOS Tahoe 26.5. An app may be able to gain root privileges.

Fix: 26.5+
Fix from $1,950 2026-05-11
Ipados HIGH 7.5
CVE-2026-28962

This issue was addressed with improved access restrictions. This issue is fixed in Safari 26.5, iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.…

Fix: 18.7.9 / 26.5+
Fix from $1,950 2026-05-11
Ipados MEDIUM 5.5
CVE-2026-28958

This issue was addressed with improved data protection. This issue is fixed in Safari 26.5, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5 and iPadOS 26.5,…

Fix: 26.5+
Fix from $1,600 2026-05-11
Ipados MEDIUM 6.5
CVE-2026-28920

An information leakage was addressed with additional validation. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS…

Fix: 14.8.7 / 15.7.7+
Fix from $1,600 2026-05-11
macOS MEDIUM 6.5
CVE-2026-28922

This issue was addressed through improved state management. This issue is fixed in macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5. An ap…

Fix: 14.8.7 / 15.7.7+
Fix from $1,600 2026-05-11
Unclassified MEDIUM 6.9
CVE-2026-42871

WeGIA is a web manager for charitable institutions. In versions prior to 3.7.0, atendido/familiar_docfamiliar.php displays an overly descriptive erro…

Mitigation only
Fix from $1,600 2026-05-11
Mediawiki MEDIUM 5.3
CVE-2026-34093

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with p…

Fix: 1.43.7 / 1.44.4+
Fix from $1,600 2026-05-11
Grav HIGH 7.7
CVE-2026-44738

Grav is a file-based Web platform. Prior to 2.0.0-rc.2, the Twig sandbox allow-list permits any user with the admin.pages role to call config.toArray…

Fix: 2.0.0+
Fix from $1,950 2026-05-11
Mediawiki HIGH 7.5
CVE-2026-34087

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation OATHAuth. This issue affects OATHAuth: from * befor…

Fix: 1.43.7 / 1.44.4+
Fix from $1,950 2026-05-11
Mediawiki HIGH 7.5
CVE-2026-34088

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation MediaWiki. This issue affects MediaWiki: from * bef…

Fix: 1.43.7 / 1.44.4+
Fix from $1,950 2026-05-11
Checkuser HIGH 7.5
CVE-2026-34090

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation CheckUser. This issue affects CheckUser: from 1.45.…

Fix: 1.45.2+
Fix from $1,950 2026-05-11
Mediawiki HIGH 7.5
CVE-2026-34091

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation MediaWiki. This issue affects MediaWiki: from * bef…

Fix: 1.43.7 / 1.44.4+
Fix from $1,950 2026-05-11
Mediawiki HIGH 7.5
CVE-2026-34092

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with p…

Fix: 1.43.7 / 1.44.4+
Fix from $1,950 2026-05-11
Unclassified MEDIUM 6.3
CVE-2026-42333

Quarkus OpenAPI Generator is Quarkus' extensions for generation of Rest Clients and server stubs generation. Prior to versions 2.11.1-lts, 2.16.0-lts…

Patch available
Fix from $1,600 2026-05-09
Unclassified MEDIUM 5.3
CVE-2026-8198

The Activity Logs, User Activity Tracking, Multisite Activity Log from Logtivity plugin for WordPress is vulnerable to Authentication Bypass to Infor…

Mitigation only
Fix from $1,600 2026-05-09
Unclassified MEDIUM 5.1
CVE-2026-42213

SolidCAM-GPPL-IDE is an unofficial, independently developed extension, Postprocessor IDE for SolidCAM. From version 1.0.0 to before version 1.0.2, th…

Patch available
Fix from $1,600 2026-05-08
Cloudstack CRITICAL 9.1
CVE-2026-25199

Instances deployed via the Proxmox extension allow unauthorized access to instances belonging to other tenants. This issue affects Apache CloudSt…

Fix: 4.22.0.1+
Fix from $2,300 2026-05-08
Electerm MEDIUM 5.5
CVE-2026-43942

electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. In versions 3.8.15 and prior, the getConstants() IPC handle…

Fix: after 3.8.15
Fix from $1,600 2026-05-08
Argo Cd CRITICAL 9.6
CVE-2026-42880

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. From versions 3.2.0 to before 3.2.11 and 3.3.0 to before 3.3.9, there is a …

Fix: 3.2.11 / 3.3.9+
Fix from $2,300 2026-05-07
Azure Devops HIGH 7.5
CVE-2026-42826

Exposure of sensitive information to an unauthorized actor in Azure DevOps allows an unauthorized attacker to disclose information over a network.

No fix yet
Fix from $1,950 2026-05-07