Vulnerability index

Browse CVEs

7,732 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
MySQL MEDIUM 5.8
CVE-2026-34318

Vulnerability in the MySQL Shell product of Oracle MySQL (component: Shell: Core Client). Supported versions that are affected are 8.0.0-8.0.45, 8.4…

Fix: after 9.6.0
Fix from $1,600 2026-04-21
Financial Services Analytical Applications Infrastructure MEDIUM 6.5
CVE-2026-34313

Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: P…

Mitigation only
Fix from $1,600 2026-04-21
Peoplesoft Enterprise Fin Contracts MEDIUM 6.5
CVE-2026-34300

Vulnerability in the PeopleSoft Enterprise FIN Contracts product of Oracle PeopleSoft (component: Contracts). The supported version that is affecte…

Mitigation only
Fix from $1,600 2026-04-21
Weblogic Server HIGH 7.5
CVE-2026-34305

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Services). Supported versions that are affected are …

Mitigation only
Fix from $1,950 2026-04-21
Hcm Common Architecture HIGH 7.5
CVE-2026-34297

Vulnerability in the Oracle HCM Common Architecture product of Oracle E-Business Suite (component: Knowledge Integration). Supported versions that a…

Fix: after 12.2.15
Fix from $1,950 2026-04-21
Goldengate MEDIUM 5.3
CVE-2026-34273

Vulnerability in Oracle GoldenGate (component: Libraries). Supported versions that are affected are 23.4-23.10. Easily exploitable vulnerability all…

Fix: after 23.10
Fix from $1,600 2026-04-21
Jre HIGH 7.5
CVE-2026-22016

Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JAXP). Supporte…

Mitigation only
Fix from $1,950 2026-04-21
Peoplesoft Enterprise Hcm Human Resources MEDIUM 5.4
CVE-2026-22006

Vulnerability in the PeopleSoft Enterprise HCM Human Resources product of Oracle PeopleSoft (component: Employee Snapshot). The supported version t…

Mitigation only
Fix from $1,600 2026-04-21
Xml Database MEDIUM 5.3
CVE-2026-21999

Vulnerability in the XML Database component of Oracle Database Server. Supported versions that are affected are 23.4.0-23.26.1. Difficult to exploit…

Fix: after 23.26.1
Fix from $1,600 2026-04-21
Avideo MEDIUM 5.3
CVE-2026-40908

WWBN AVideo is an open source video platform. In versions 29.0 and prior, the file `git.json.php` at the web root executes `git log -1` and returns t…

Fix: after 29.0
Fix from $1,600 2026-04-21
Goshs HIGH 8.8
CVE-2026-40885

goshs is a SimpleHTTPServer written in Go. From 2.0.0-beta.4 to 2.0.0-beta.5, goshs leaks file-based ACL credentials through its public collaborator …

No fix yet
Fix from $1,950 2026-04-21
Ransomlook HIGH 7.5
CVE-2026-40584

RansomLook is a tool to monitor Ransomware groups and markets and extract their victims. Prior to 1.9.0, the API in the affected application improper…

Fix: 1.9.0+
Fix from $1,950 2026-04-21
Freescout CRITICAL 9.8
CVE-2026-40498

FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.213, an unauthenticated attacker can access diagnostic and system …

Fix: 1.8.213+
Fix from $2,300 2026-04-21
Firefox HIGH 7.5
CVE-2026-6782

Information disclosure in the IP Protection component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.

Fix: 150.0+
Fix from $1,950 2026-04-21
Firefox MEDIUM 6.5
CVE-2026-6770

Other issue in the Storage: IndexedDB component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 14…

Fix: 140.10.0 / 150.0+
Fix from $1,600 2026-04-21
Firefox HIGH 7.5
CVE-2026-6756

Mitigation bypass in Firefox for Android. This vulnerability was fixed in Firefox 150.

Fix: 150.0+
Fix from $1,950 2026-04-21
Unclassified MEDIUM 6.3
CVE-2026-31370

Honor E APP is affected by information leak vulnerability, successful exploitation of this vulnerability may affect service confidentiality.

Mitigation only
Fix from $1,600 2026-04-21
Glances MEDIUM 6.5
CVE-2026-34839

Glances is an open-source system cross-platform monitoring tool. Prior to version 4.5.4, the Glances web server exposes a REST API (`/api/4/*`) that …

Fix: 4.5.4+
Fix from $1,600 2026-04-21
Unclassified MEDIUM 6.8
CVE-2026-40490

The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. When redirect f…

Patch available
Fix from $1,600 2026-04-18
Unclassified HIGH 7.5
CVE-2026-2262

The Easy Appointments plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.12.21 via the `/wp…

Mitigation only
Fix from $1,950 2026-04-18
Openfga MEDIUM 6.5
CVE-2026-40293

OpenFGA is an authorization/permission engine built for developers. In versions 0.1.4 through 1.13.1, when OpenFGA is configured to use preshared-key…

Fix: 1.14.0+
Fix from $1,600 2026-04-17
Firebird HIGH 7.5
CVE-2025-65104

Firebird is an open-source relational database management system. In versions FB3 of the client library placed incorrect data length values into XSQL…

Fix: 3.0.14+
Fix from $1,950 2026-04-17
Unclassified MEDIUM 5.3
CVE-2026-6492

A vulnerability was detected in arnobt78 Hotel Booking Management System up to f8922d0e0f6ac1cc761974c7616f44c2bbc04bea. The impacted element is an u…

Patch available
Fix from $1,600 2026-04-17
Powerprotect Data Domain MEDIUM 6.5
CVE-2026-23777

Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.5, LTS2025 release version 8.3.…

Fix: after 8.5.0.0
Fix from $1,600 2026-04-17
Pro Cloud Server CRITICAL 9.8
CVE-2025-15625

Unauthenticated user is able to execute arbitrary SQL commands in Sparx Pro Cloud Server database in certain cases.

Mitigation only
Fix from $2,300 2026-04-17
Free5gc HIGH 7.5
CVE-2026-40245

Free5GC is an open-source Linux Foundation project for 5th generation (5G) mobile core networks. Versions 4.2.1 and below contain an information disc…

Fix: after 4.2.1
Fix from $1,950 2026-04-16
Dgraph CRITICAL 9.4
CVE-2026-40173

Dgraph is an open source distributed GraphQL database. Versions 25.3.1 and prior contain an unauthenticated credential disclosure vulnerability where…

Fix: 25.3.2+
Fix from $2,300 2026-04-15
Apostrophecms MEDIUM 5.3
CVE-2026-39857

ApostropheCMS is an open-source Node.js content management system. Versions 4.28.0 and prior contain an authorization bypass vulnerability in the cho…

Fix: 4.29.0+
Fix from $1,600 2026-04-15
Apostrophecms MEDIUM 5.3
CVE-2026-33888

ApostropheCMS is an open-source Node.js content management system. Versions 4.28.0 and prior contain an authorization bypass vulnerability in the get…

Fix: 4.29.0+
Fix from $1,600 2026-04-15
Weblate MEDIUM 6.8
CVE-2026-33220

Weblate is a web based localization tool. In versions prior to 5.17, the translation memory API exposed unintended endpoints, which in turn didn't pe…

Fix: 5.17+
Fix from $1,600 2026-04-15