Vulnerability index

Browse CVEs

7,732 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Weblate HIGH 7.7
CVE-2026-34242

Weblate is a web based localization tool. In versions prior to 5.17, the ZIP download feature didn't verify downloaded files, potentially following …

Fix: 5.17+
Fix from $1,950 2026-04-15
Weblate MEDIUM 5.0
CVE-2026-34244

Weblate is a web based localization tool. In versions prior to 5.17, a user with the project.edit permission (granted by the per-project "Administrat…

Fix: 5.17+
Fix from $1,600 2026-04-15
Unclassified HIGH 7.4
CVE-2026-32631

Git for Windows is the Windows port of Git. Versions prior to 2.53.0.windows.3 do not have protections that prevent attackers from obtaining a user's…

Mitigation only
Fix from $1,950 2026-04-15
Grafana MEDIUM 6.5
CVE-2025-12141

In Grafana's alerting system, users with edit permissions for a contact point, specifically the permissions “alert.notifications:write” or “alert.not…

Fix: after 12.3.0
Fix from $1,600 2026-04-15
Airflow MEDIUM 6.5
CVE-2026-25219

The `access_key` and `connection_string` connection properties were not marked as sensitive names in secrets masker. This means that user with read p…

Fix: 3.2.0+
Fix from $1,600 2026-04-15
Windows 10 1607 MEDIUM 6.5
CVE-2026-32151

Exposure of sensitive information to an unauthorized actor in Windows Shell allows an authorized attacker to disclose information over a network.

Fix: 10.0.14393.9060 / 10.0.17763.8644+
Fix from $1,600 2026-04-14
Windows 10 1607 MEDIUM 5.5
CVE-2026-32085

Exposure of sensitive information to an unauthorized actor in Windows Remote Procedure Call allows an authorized attacker to disclose information loc…

Fix: 10.0.14393.9060 / 10.0.17763.8644+
Fix from $1,600 2026-04-14
Windows 10 1607 MEDIUM 5.5
CVE-2026-32084

Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.

Fix: 10.0.14393.9060 / 10.0.17763.8644+
Fix from $1,600 2026-04-14
Windows 10 1607 MEDIUM 5.5
CVE-2026-32079

Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.

Fix: 10.0.14393.9060 / 10.0.17763.8644+
Fix from $1,600 2026-04-14
Windows 10 1607 MEDIUM 5.5
CVE-2026-32081

Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.

Fix: 10.0.14393.9060 / 10.0.17763.8644+
Fix from $1,600 2026-04-14
External Secrets Operator MEDIUM 6.5
CVE-2026-34984

External Secrets Operator reads information from a third-party service and automatically injects the values as Kubernetes Secrets. Versions 2.2.0 and…

Fix: 2.3.0+
Fix from $1,600 2026-04-14
Unclassified MEDIUM 5.3
CVE-2026-6160

A vulnerability was found in code-projects Simple ChatBox 1.0. Affected by this issue is the function SimpleChatbox_PHP of the file chatbox.sql of th…

No fix yet
Fix from $1,600 2026-04-13
Openclaw MEDIUM 5.3
CVE-2026-3691

OpenClaw Client PKCE Verifier Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose stored credentials on affe…

Fix: 2026.2.25+
Fix from $1,600 2026-04-11
Praisonai MEDIUM 5.5
CVE-2026-40159

PraisonAI is a multi-agent teams system. Prior to 4.5.128, PraisonAI’s MCP (Model Context Protocol) integration allows spawning background servers vi…

Fix: 4.5.128+
Fix from $1,600 2026-04-10
Sportsbook MEDIUM 6.1
CVE-2026-31262

Cross Site Scripting vulnerability in Altenar Sportsbook Software Platform (SB2) v.2.0 allows a remote attacker to obtain sensitive information and e…

No fix yet
Fix from $1,600 2026-04-10
Praisonai MEDIUM 5.3
CVE-2026-40151

PraisonAI is a multi-agent teams system. Prior to 4.5.128, the AgentOS deployment platform exposes a GET /api/agents endpoint that returns agent name…

Fix: 4.5.128+
Fix from $1,600 2026-04-09
Directus MEDIUM 6.5
CVE-2026-39943

Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.17.0, Directus stores revision records (in directus_revi…

Fix: 11.17.0+
Fix from $1,600 2026-04-09
Unclassified HIGH 7.5
CVE-2026-4660

HashiCorp’s go-getter library up to v1.8.5 may allow arbitrary file reads on the file system during certain git operations through a maliciously craf…

Mitigation only
Fix from $1,950 2026-04-09
Dolphinscheduler HIGH 7.5
CVE-2025-62188

An Exposure of Sensitive Information to an Unauthorized Actor vulnerability exists in Apache DolphinScheduler. This vulnerability may allow unauthor…

Fix: 3.2.0+
Fix from $1,950 2026-04-09
Praisonai HIGH 7.5
CVE-2026-39889

PraisonAI is a multi-agent teams system. Prior to 4.5.115, the A2U (Agent-to-User) event stream server in PraisonAI exposes all agent activity withou…

Fix: after 4.5.114
Fix from $1,950 2026-04-08
Liquidjs HIGH 7.5
CVE-2026-39412

LiquidJS is a Shopify / GitHub Pages compatible template engine in pure JavaScript. Prior to 10.25.4, the sort_natural filter bypasses the ownPropert…

Fix: 10.25.4+
Fix from $1,950 2026-04-08
Unclassified MEDIUM 5.3
CVE-2026-3594

The Riaxe Product Customizer plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.4 via the '…

Mitigation only
Fix from $1,600 2026-04-08
Vite HIGH 7.5
CVE-2026-39363

Vite is a frontend tooling framework for JavaScript. From 6.0.0 to before 6.4.2, 7.3.2, and 8.0.5, if it is possible to connect to the Vite dev serve…

Fix: after 8.0.4
Fix from $1,950 2026-04-07
Avideo MEDIUM 5.3
CVE-2026-35449

WWBN AVideo is an open source video platform. In versions 26.0 and prior, the install/test.php diagnostic script has its CLI-only access guard disabl…

Fix: after 26.0
Fix from $1,600 2026-04-06
Avideo MEDIUM 5.3
CVE-2026-35452

WWBN AVideo is an open source video platform. In versions 26.0 and prior, the plugin/CloneSite/client.log.php endpoint serves the clone operation log…

Fix: after 26.0
Fix from $1,600 2026-04-06
Directus MEDIUM 5.3
CVE-2026-35413

Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.16.1, when GRAPHQL_INTROSPECTION=false is configured, Di…

Fix: 11.16.1+
Fix from $1,600 2026-04-06
Directus HIGH 8.1
CVE-2026-35442

Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.17.0, aggregate functions (min, max) applied to fields w…

Fix: 11.17.0+
Fix from $1,950 2026-04-06
Unclassified MEDIUM 5.3
CVE-2026-5666

A vulnerability was detected in code-projects Online FIR System 1.0. Affected by this issue is some unknown functionality of the file /complaints.sql…

Mitigation only
Fix from $1,600 2026-04-06
Nhost\/auth HIGH 7.5
CVE-2026-34969

Nhost is an open source Firebase alternative with GraphQL. Prior to 0.48.0, the auth service's OAuth provider callback flow places the refresh token …

Fix: 0.48.0+
Fix from $1,950 2026-04-06
Unclassified MEDIUM 5.3
CVE-2026-5650

A vulnerability was found in code-projects Online Application System for Admission 1.0. Impacted is an unknown function of the file /enrollment/datab…

No fix yet
Fix from $1,600 2026-04-06