Vulnerability index

Browse CVEs

7,732 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Filefield Paths MEDIUM 6.5
CVE-2026-1556

Information disclosure in the file URI processing of File (Field) Paths in Drupal File (Field) Paths 7.x prior to 7.1.3 on Drupal 7.x allows authenti…

Fix: 7.x-1.3+
Fix from $1,600 2026-03-26
Aftermarket Cloud MEDIUM 5.3
CVE-2025-55276

HCL Aftermarket DPC is affected by Internal IP Disclosure vulnerability will give attackers a clearer map of the organization’s network layout.

Mitigation only
Fix from $1,600 2026-03-26
Aftermarket Cloud MEDIUM 5.3
CVE-2025-55272

HCL Aftermarket DPC is affected by Banner Disclosure vulnerability where attackers gain insights into the system’s software and version details which…

Mitigation only
Fix from $1,600 2026-03-26
Aftermarket Cloud HIGH 7.5
CVE-2025-55265

HCL Aftermarket DPC is affected by File Discovery which allows attacker could exploit this issue to read sensitive files present in the system and ma…

Mitigation only
Fix from $1,950 2026-03-26
Websphere Application Server HIGH 7.2
CVE-2025-14915

IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.3 IBM WebSphere Application Server Liberty is affected by privilege escalation. A …

Fix: 26.0.0.4+
Fix from $1,950 2026-03-25
Ipados MEDIUM 5.5
CVE-2026-28877

An authorization issue was addressed with improved state management. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.4 and iPadOS 26.4, m…

Fix: 15.7.5 / 26.4+
Fix from $1,600 2026-03-25
Ipados MEDIUM 6.5
CVE-2026-28878

A privacy issue was addressed by removing sensitive data. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Sequoi…

Fix: 14.8.5 / 18.7.7+
Fix from $1,600 2026-03-25
macOS MEDIUM 5.3
CVE-2026-28820

This issue was addressed with improved checks. This issue is fixed in macOS Tahoe 26.4. An app may be able to access sensitive user data.

Fix: 26.4+
Fix from $1,600 2026-03-25
Soft Serve MEDIUM 6.5
CVE-2026-33353

Soft Serve is a self-hostable Git server for the command line. From version 0.6.0 to before version 0.11.6, an authorization flaw in repo import allo…

Fix: 0.11.6+
Fix from $1,600 2026-03-24
Parse Server MEDIUM 6.5
CVE-2026-33627

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.61 and 9.6.0-alpha.55, …

Fix: 8.6.61 / 9.6.0+
Fix from $1,600 2026-03-24
Vikunja MEDIUM 6.5
CVE-2026-33677

Vikunja is an open-source self-hosted task management platform. Prior to version 2.2.1, the `GET /api/v1/projects/:project/webhooks` endpoint returns…

Fix: 2.2.1+
Fix from $1,600 2026-03-24
Firefox HIGH 7.5
CVE-2026-4712

Information disclosure in the Widget: Cocoa component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbi…

Fix: 140.9.0 / 149.0+
Fix from $1,950 2026-03-24
Unclassified MEDIUM 5.3
CVE-2026-4733

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in ixray-team ixray-1.6-stcop.This issue affects ixray-1.6-stcop: before 1.3.

Patch available
Fix from $1,600 2026-03-24
Csweb HIGH 7.5
CVE-2025-60949

Census CSWeb 8.0.1 allows "app/config" to be reachable via HTTP in some deployments. A remote, unauthenticated attacker could send requests to config…

Patch available
Fix from $1,950 2026-03-23
Blinko MEDIUM 5.3
CVE-2026-23486

Blinko is an AI-powered card note-taking project. Prior to version 1.8.4, a publicly accessible endpoint exposes all user information, including user…

Fix: 1.8.4+
Fix from $1,600 2026-03-23
Unclassified MEDIUM 5.5
CVE-2026-27131

The Sprig Plugin for Craft CMS is a reactive Twig component framework for Craft CMS. Starting in version 2.0.0 and prior to versions 2.15.2 and 3.15.…

Patch available
Fix from $1,600 2026-03-23
Unclassified MEDIUM 5.3
CVE-2025-13997

The King Addons for Elementor – 4,000+ ready Elementor sections, 650+ templates, 70+ FREE widgets for Elementor plugin for WordPress is vulnerable to…

Mitigation only
Fix from $1,600 2026-03-23
Unclassified HIGH 7.5
CVE-2026-33180

HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to version 6.9.0, when setting headers…

Mitigation only
Fix from $1,950 2026-03-20
Avideo MEDIUM 5.3
CVE-2026-33041

WWBN AVideo is an open source video platform. In versions 25.0 and below, /objects/encryptPass.json.php exposes the application's password hashing al…

Fix: 26.0+
Fix from $1,600 2026-03-20
Siyuan MEDIUM 6.5
CVE-2026-32938

SiYuan is a personal knowledge management system. In versions 3.6.0 and below, the /api/lute/html2BlockDOM on the desktop copies local files pointed …

Fix: 3.6.1+
Fix from $1,600 2026-03-20
Anchorr CRITICAL 9.6
CVE-2026-32890

Anchorr is a Discord bot for requesting movies and TV shows and receiving notifications when items are added to a media server. In versions 1.4.1 and…

Fix: after 1.4.1
Fix from $2,300 2026-03-20
Discourse MEDIUM 6.5
CVE-2026-30891

Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, a user could access another user's priv…

Fix: 2026.1.2 / 2026.2.1+
Fix from $1,600 2026-03-20
Suitecrm MEDIUM 6.5
CVE-2026-29108

SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versions 8.9.3, an authenticated A…

Fix: 8.9.3+
Fix from $1,600 2026-03-20
Discourse MEDIUM 6.5
CVE-2026-33355

Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, the `/private-posts` endpoint did not a…

Fix: 2026.1.2 / 2026.2.1+
Fix from $1,600 2026-03-19
Discourse MEDIUM 6.5
CVE-2026-32099

Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, when a user has `hide_profile` enabled,…

Fix: 2026.1.2 / 2026.2.1+
Fix from $1,600 2026-03-19
Openclaw MEDIUM 6.5
CVE-2026-32002

OpenClaw versions prior to 2026.2.23 contain a sandbox bypass vulnerability in the sandboxed image tool that fails to enforce tools.fs.workspaceOnly …

Fix: 2026.2.23+
Fix from $1,600 2026-03-19
Azure Data Factory HIGH 7.5
CVE-2026-23659

Exposure of sensitive information to an unauthorized actor in Azure Data Factory allows an unauthorized attacker to disclose information over a netwo…

No fix yet
Fix from $1,950 2026-03-19
Ecase Ecomplaint CRITICAL 9.8
CVE-2026-32865

OPEXUS eComplaint and eCASE before version 10.1.0.0 include the secret verification code in the HTTP response when requesting a password reset via 'F…

Fix: 10.1.0.0+
Fix from $2,300 2026-03-19
Parse Server MEDIUM 6.5
CVE-2026-33163

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.35 and 8.6.50, when a `P…

Fix: 8.6.50 / 9.6.0+
Fix from $1,600 2026-03-18
Glances CRITICAL 9.1
CVE-2026-32633

Glances is an open-source system cross-platform monitoring tool. Prior to version 4.5.2, in Central Browser mode, the `/api/4/serverslist` endpoint r…

Fix: 4.5.2+
Fix from $2,300 2026-03-18