Vulnerability index

Browse CVEs

7,732 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Unclassified MEDIUM 5.3
CVE-2026-5601

A vulnerability was found in Acrel Electrical Prepaid Cloud Platform 1.0. This issue affects some unknown processing of the file /bin.rar of the comp…

Mitigation only
Fix from $1,600 2026-04-05
Ai Infra Guard HIGH 7.5
CVE-2026-5585

A vulnerability was found in Tencent AI-Infra-Guard 4.0. The affected element is an unknown function of the file common/websocket/task_manager.go of …

No fix yet
Fix from $1,950 2026-04-05
Hi Led Wr120 G2 Firmware HIGH 7.5
CVE-2026-5571

A vulnerability was identified in Technostrobe HI-LED-WR120-G2 5.5.0.1R6.03.30. The impacted element is an unknown function of the file /fs of the co…

No fix yet
Fix from $1,950 2026-04-05
Discourse MEDIUM 5.3
CVE-2026-34947

Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to before 2026.2.2, and 2026.3.0-l…

Fix: after 2026.2.1
Fix from $1,600 2026-04-03
Discourse MEDIUM 5.3
CVE-2026-27481

Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to before 2026.2.2, and 2026.3.0-l…

Fix: after 2026.2.1
Fix from $1,600 2026-04-03
Signal K Server MEDIUM 6.5
CVE-2026-35038

Signal K Server is a server application that runs on a central hub in a boat. Prior to version 2.24.0, there is an arbitrary prototype read vulnerabi…

Fix: 2.24.0+
Fix from $1,600 2026-04-02
Rack HIGH 7.5
CVE-2026-34785

Rack is a modular Ruby web server interface. Prior to versions 2.2.23, 3.1.21, and 3.2.6, Rack::Static determines whether a request should be served …

Fix: 2.2.23 / 3.1.21+
Fix from $1,950 2026-04-02
Unclassified HIGH 7.5
CVE-2026-5032

The W3 Total Cache plugin for WordPress is vulnerable to information exposure in all versions up to, and including, 2.9.3. This is due to the plugin …

Mitigation only
Fix from $1,950 2026-04-02
Aiohttp MEDIUM 5.3
CVE-2026-34518

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, when following redirects to a different orig…

Fix: 3.13.4+
Fix from $1,600 2026-04-01
Sage Dpw HIGH 7.5
CVE-2025-67805

A non-default configuration in Sage DPW 2025_06_004 allows unauthenticated access to diagnostic endpoints within the Database Monitor feature, exposi…

Mitigation only
Fix from $1,950 2026-04-01
Unclassified MEDIUM 5.3
CVE-2026-2696

The Export All URLs WordPress plugin before 5.1 generates CSV filenames containing posts URLS (including private posts) in a predictable pattern usin…

Mitigation only
Fix from $1,600 2026-04-01
Chrome MEDIUM 6.5
CVE-2026-5291

Inappropriate implementation in WebGL in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to obtain potentially sensitive information …

Fix: 146.0.7680.177+
Fix from $1,600 2026-04-01
Pdf Editor HIGH 7.5
CVE-2026-3774

The application allows PDF JavaScript and document/print actions (such as WillPrint/DidPrint) to update form fields, annotations, or optional content…

Fix: after 2025.3.0.35737
Fix from $1,950 2026-04-01
Xenforo MEDIUM 5.5
CVE-2025-71280

XenForo before 2.3.7 allows information disclosure via local account page caching on shared systems. On systems where multiple users share a browser …

Fix: 2.3.7+
Fix from $1,600 2026-04-01
Parse Server MEDIUM 6.5
CVE-2026-34215

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.63 and 9.7.0-alpha.7, t…

Fix: 8.6.63 / 9.7.0+
Fix from $1,600 2026-03-31
Discourse MEDIUM 6.5
CVE-2026-33300

Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to before 2026.2.2, and 2026.3.0-l…

Fix: 2026.1.3 / 2026.2.2+
Fix from $1,600 2026-03-31
Discourse MEDIUM 5.3
CVE-2026-33073

Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to before 2026.2.2, and 2026.3.0-l…

Fix: 2026.1.3 / 2026.2.2+
Fix from $1,600 2026-03-31
Discourse MEDIUM 6.5
CVE-2026-32143

Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to before 2026.2.2, and 2026.3.0-l…

Fix: 2026.1.3 / 2026.2.2+
Fix from $1,600 2026-03-31
Unclassified HIGH 7.5
CVE-2026-4020EPSS 42%

The Gravity SMTP plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.1.4. This is due to a R…

Mitigation only
Fix from $1,950 2026-03-31
Awesome Llm Apps HIGH 8.2
CVE-2026-29872

A cross-session information disclosure vulnerability exists in the awesome-llm-apps project in commit e46690f99c3f08be80a9877fab52acacf7ab8251 (2026-…

No fix yet
Fix from $1,950 2026-03-30
Zxhn H188a Firmware HIGH 7.1
CVE-2026-34472EPSS 9%

Unauthenticated credential disclosure in the wizard interface in ZTE ZXHN H188A V6.0.10P2_TE and V6.0.10P3N3_TE allows unauthenticated attackers on t…

Mitigation only
Fix from $1,950 2026-03-30
Unclassified MEDIUM 5.3
CVE-2026-5003

A vulnerability was found in PromtEngineer localGPT up to 4d41c7d1713b16b216d8e062e51a5dd88b20b054. This affects the function handle_index of the fil…

Mitigation only
Fix from $1,600 2026-03-28
Unclassified MEDIUM 6.5
CVE-2026-1307

The Ninja Forms - The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions u…

Mitigation only
Fix from $1,600 2026-03-28
Changedetection MEDIUM 6.5
CVE-2026-33981

changedetection.io is a free open source web page change detection tool. Prior to 0.54.7, the `jq:` and `jqraw:` include filter expressions allow use…

Fix: 0.54.7+
Fix from $1,600 2026-03-27
Statamic MEDIUM 6.5
CVE-2026-33886

Statamic is a Laravel and Git powered content management system (CMS). Starting in version 5.7.12 and prior to versions 5.73.16 and 6.7.2, a control …

Fix: 5.73.16 / 6.7.2+
Fix from $1,600 2026-03-27
Statamic MEDIUM 6.5
CVE-2026-33882

Statamic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.16 and 6.7.2, the markdown preview endpoint could be ma…

Fix: 5.73.16 / 6.7.2+
Fix from $1,600 2026-03-27
Librechat MEDIUM 5.7
CVE-2026-31951

LibreChat is a ChatGPT clone with additional features. In versions 0.8.2-rc1 through 0.8.3-rc1, user-created MCP (Model Context Protocol) servers can…

Fix: 0.8.3+
Fix from $1,600 2026-03-27
Mlflow HIGH 7.1
CVE-2025-15381

In the latest version of mlflow/mlflow, when the `basic-auth` app is enabled, tracing and assessment endpoints are not protected by permission valida…

No fix yet
Fix from $1,950 2026-03-27
Avideo MEDIUM 5.3
CVE-2026-33761

WWBN AVideo is an open source video platform. In versions up to and including 26.0, three `list.json.php` endpoints in the Scheduler plugin lack any …

Fix: after 26.0
Fix from $1,600 2026-03-27
Cpp Httplib HIGH 7.4
CVE-2026-33745

cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.39.0, the cpp-httplib HTTP client forwards stored Basic …

Fix: 0.39.0+
Fix from $1,950 2026-03-27