Vulnerability index

Browse CVEs

7,732 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Inngest HIGH 8.6
CVE-2026-42047

Inngest is a platform for running event-driven and scheduled background functions with queueing, retries, and step orchestration. Versions 3.22.0 thr…

Fix: 3.54.0+
Fix from $1,950 2026-05-07
Unclassified MEDIUM 5.3
CVE-2026-8033

A vulnerability has been found in PicoTronica e-Clinic Healthcare System ECHS 5.7. This affects an unknown function of the file /cdemos/echs/api/v2/ …

Mitigation only
Fix from $1,600 2026-05-06
Unclassified HIGH 7.5
CVE-2026-34474EPSS 25%

Sensitive data exposure leading to admin/WLAN credential leak in ZTE ZXHN H298A 1.1 and H108N 2.6. A crafted request to the router web interface can …

Mitigation only
Fix from $1,950 2026-05-06
Bigfix Service Management HIGH 8.8
CVE-2025-52613

HCL BigFix Service Management (SM) is affected by use of a vulnerable WSGI Server was identified. Deploying an outdated or insecure WSGI server may e…

Mitigation only
Fix from $1,950 2026-05-06
Bigfix Service Management MEDIUM 5.4
CVE-2025-31984

HCL BigFix Service Management (SM) is affected by a security misconfiguration due to a missing or insecure “X-Content-Type-Options” header. This cou…

Mitigation only
Fix from $1,600 2026-05-06
Bigfix Service Management HIGH 7.5
CVE-2025-31976

HCL BigFix Service Management (SM) is vulnerable to insufficiently protected credentials for a short duration while communicating with a backend, int…

Mitigation only
Fix from $1,950 2026-05-06
Bigfix Service Management MEDIUM 6.5
CVE-2025-31982

HCL BigFix Service Management (SM) had directories that were not linked or publicly visible but could be accessed directly. This could allow an incre…

Mitigation only
Fix from $1,600 2026-05-06
Bigfix Service Management MEDIUM 5.3
CVE-2025-31975

HCL BigFix Service Management (SM) is affected by an Information Disclosure – Server Banner issue was identified. Exposed server banners may reveal s…

Mitigation only
Fix from $1,600 2026-05-06
Flowise MEDIUM 5.3
CVE-2026-8026

A security flaw has been discovered in FlowiseAI Flowise up to 3.0.12. Affected is the function Login of the file packages/server/src/enterprise/serv…

Fix: after 3.0.12
Fix from $1,600 2026-05-06
Wicket HIGH 7.5
CVE-2026-43646

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Wicket. This issue affects Apache Wicket: from 8.0.0 through 8.17…

Fix: 10.9.0+
Fix from $1,950 2026-05-06
Unclassified HIGH 7.7
CVE-2026-36355

The rtl8192cd Wi-Fi kernel driver in the Realtek rtl819x Jungle SDK (all known versions through v3.4.14B) does not perform any access control checks …

Mitigation only
Fix from $1,950 2026-05-05
Unclassified MEDIUM 6.5
CVE-2026-4409

The Subscribe To Comments Reloaded plugin for WordPress is vulnerable to unauthorized modification of data due to a leaked secret key and usage of a …

Mitigation only
Fix from $1,600 2026-05-05
Nginx Ui MEDIUM 6.5
CVE-2026-42223

Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.8, the GetSettings API handler (api/settings/settings.go:24-65) seria…

Fix: 2.3.8+
Fix from $1,600 2026-05-04
Nginx Ui MEDIUM 6.5
CVE-2026-42220

Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.8, an authenticated user can call GET /api/settings and retrieve sens…

Fix: 2.3.8+
Fix from $1,600 2026-05-04
Prometheus HIGH 7.5
CVE-2026-42151

Prometheus is an open-source monitoring system and time series database. Prior to versions 3.5.3 and 3.11.3, the client_secret field in the Azure AD …

Fix: 3.5.3 / 3.11.3+
Fix from $1,950 2026-05-04
Unclassified MEDIUM 6.5
CVE-2026-42092

titra is an open source time tracking project. In version 0.99.52, the globalsettings Meteor publication returns all global settings without any admi…

Mitigation only
Fix from $1,600 2026-05-04
Unclassified MEDIUM 5.3
CVE-2026-3504

The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution plugin for WordPress is vulnerable to Sensitive Information Exposure in all versio…

Mitigation only
Fix from $1,600 2026-05-02
Unclassified MEDIUM 6.5
CVE-2025-14726

The Widgets for Social Photo Feed plugin for WordPress is vulnerable to unauthorized access of data and modification of data due to a missing capabil…

Mitigation only
Fix from $1,600 2026-05-02
Unclassified MEDIUM 6.5
CVE-2026-7382

Exposure of Sensitive Information to an Unauthorized Actor, Exposure of private personal information to an unauthorized actor vulnerability in MeWare…

Mitigation only
Fix from $1,600 2026-04-30
Plack\ CRITICAL 9.1
CVE-2026-7381

Plack::Middleware::XSendfile versions through 1.0053 for Perl can allow client-controlled path rewriting. Plack::Middleware::XSendfile allows the va…

Fix: after 1.0053
Fix from $2,300 2026-04-29
Unclassified MEDIUM 5.3
CVE-2026-7071

A security vulnerability has been detected in CodeAstro Online Job Portal 1.0. Affected by this vulnerability is an unknown functionality of the file…

Mitigation only
Fix from $1,600 2026-04-27
Dgraph CRITICAL 9.8
CVE-2026-41492

Dgraph is an open source distributed GraphQL database. Prior to 25.3.3, Dgraphl exposes the process command line through the unauthenticated /debug/v…

Fix: 25.3.3+
Fix from $2,300 2026-04-24
Cups MEDIUM 5.4
CVE-2026-41079

OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. Prior to 2.4.17, a network-adjacent attacker can…

Fix: 2.4.17+
Fix from $1,600 2026-04-24
Azure Iot Central CRITICAL 9.9
CVE-2026-21515

Exposure of sensitive information to an unauthorized actor in Azure IOT Central allows an authorized attacker to elevate privileges over a network.

No fix yet
Fix from $2,300 2026-04-24
Kyverno CRITICAL 9.1
CVE-2026-41323

Kyverno is a policy engine designed for cloud native platform engineering teams. Prior to versions 1.18.0-rc1, 1.17.2-rc1, and 1.16.4, Kyverno's apiC…

Fix: 1.16.4 / 1.17.2+
Fix from $2,300 2026-04-24
Flowise HIGH 7.5
CVE-2026-41278

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the GET /api/v1/public-chatflows/:id endpoin…

Fix: 3.1.0+
Fix from $1,950 2026-04-23
Flowise HIGH 7.5
CVE-2026-41266

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, /api/v1/public-chatbotConfig/:id ep exposes …

Fix: 3.1.0+
Fix from $1,950 2026-04-23
Unclassified MEDIUM 5.3
CVE-2026-4106

The HT Mega Addons for Elementor WordPress plugin before 3.0.7 contains an unauthenticated AJAX action returning some PII (such as full name, city, …

Mitigation only
Fix from $1,600 2026-04-23
Unclassified MEDIUM 5.3
CVE-2026-41182

LangSmith Client SDKs provide SDK's for interacting with the LangSmith platform. Prior to version 0.5.19 of the JavaScript SDK and version 0.7.31 of …

Mitigation only
Fix from $1,600 2026-04-23
Follow Redirects HIGH 7.5
CVE-2026-40895

follow-redirects is an open source, drop-in replacement for Node's `http` and `https` modules that automatically follows redirects. Prior to 1.16.0, …

Fix: 1.16.0+
Fix from $1,950 2026-04-21