Vulnerability index

Browse CVEs

7,732 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Glances HIGH 7.5
CVE-2026-32609

Glances is an open-source system cross-platform monitoring tool. The GHSA-gh4x fix (commit 5d3de60) addressed unauthenticated configuration secrets e…

Fix: 4.5.2+
Fix from $1,950 2026-03-18
Glances HIGH 7.5
CVE-2026-32596

Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.2, Glances web server runs without authentication by default when start…

Fix: 4.5.2+
Fix from $1,950 2026-03-18
Unclassified MEDIUM 6.9
CVE-2026-32265

The Amazon S3 for Craft CMS plugin provides an Amazon S3 integration for Craft CMS. In versions 2.0.2 through 2.2.4, unauthenticated users can view a…

Patch available
Fix from $1,600 2026-03-18
Planning Analytics Local MEDIUM 6.5
CVE-2026-1267

IBM Planning Analytics Local 2.1.0 through 2.1.17 could allow an unauthorized access to sensitive application data and administrative functionalities…

Fix: 2.1.18+
Fix from $1,600 2026-03-17
Aion MEDIUM 5.3
CVE-2025-52649

HCL AION is affected by a vulnerability where certain identifiers may be predictable in nature. Predictable identifiers may allow an attacker to infe…

Fix: 2.1.2+
Fix from $1,600 2026-03-16
Backstage\/plugin Scaffolder Backend MEDIUM 6.5
CVE-2026-32237

Backstage is an open framework for building developer portals. Prior to 3.1.5, authenticated users with permission to execute scaffolder dry-runs can…

Fix: 3.1.5+
Fix from $1,600 2026-03-12
Unclassified MEDIUM 5.3
CVE-2026-32142

Shopware is an open commerce platform. /api/_info/config route exposes information about licenses. This vulnerability is fixed in 7.8.1 and 6.10.15.

Mitigation only
Fix from $1,600 2026-03-12
Unclassified MEDIUM 5.3
CVE-2026-32100

Shopware is an open commerce platform. /api/_info/config route exposes information about active security fixes. This vulnerability is fixed in 2.0.16…

Mitigation only
Fix from $1,600 2026-03-12
Tinacms\/cli MEDIUM 6.2
CVE-2026-29066

Tina is a headless content management system. Prior to 2.1.8, the TinaCMS CLI dev server configures Vite with server.fs.strict: false, which disables…

Fix: 2.1.8+
Fix from $1,600 2026-03-12
Openclaw MEDIUM 5.5
CVE-2026-4040

A vulnerability was identified in OpenClaw up to 2026.2.17. This issue affects the function tools.exec.safeBins of the component File Existence Handl…

Fix: 2026.2.19+
Fix from $1,600 2026-03-12
Parse Server HIGH 7.5
CVE-2026-32098

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.9 and 8.6.35, an attacke…

Fix: 8.6.35 / 9.6.0+
Fix from $1,950 2026-03-11
Shescape MEDIUM 6.5
CVE-2026-32094

Shescape is a simple shell escape library for JavaScript. Prior to 2.1.10, Shescape#escape() does not escape square-bracket glob syntax for Bash, Bus…

Fix: 2.1.10+
Fix from $1,600 2026-03-11
Splunk MEDIUM 5.4
CVE-2026-20166

In Splunk Enterprise versions below 10.2.1 and 10.0.4, and Splunk Cloud Platform versions below 10.2.2510.5, 10.1.2507.16, and 10.0.2503.12, a low-pr…

Fix: 10.0.4 / 10.0.2503.12+
Fix from $1,600 2026-03-11
Splunk MEDIUM 6.5
CVE-2026-20164

In Splunk Enterprise versions below 10.2.0, 10.0.3, 9.4.9, and 9.3.10, and Splunk Cloud Platform versions below 10.2.2510.5, 10.1.2507.16, 10.0.2503.…

Fix: 9.3.10 / 9.3.2411.123+
Fix from $1,600 2026-03-11
Unclassified MEDIUM 5.9
CVE-2026-1867

The Guest posting / Frontend Posting / Front Editor WordPress plugin before 5.0.6 allows passing a URL parameter to regenerate a .json file based on…

Mitigation only
Fix from $1,600 2026-03-11
Istio HIGH 7.5
CVE-2026-31837

Istio is an open platform to connect, manage, and secure microservices. Prior to 1.29.1, 1.28.5, and 1.27.8, a user of Istio is impacted if the JWKS …

Fix: 1.27.8 / 1.28.5+
Fix from $1,950 2026-03-10
Git MEDIUM 6.5
CVE-2025-66413

Git for Windows is the Windows port of Git. Prior to 2.53.0(2), it is possible to obtain a user's NTLM hash by tricking them into cloning from a mali…

Fix: after 2.53.0
Fix from $1,600 2026-03-10
Filebrowser HIGH 7.5
CVE-2026-30933

FileBrowser Quantum is a free, self-hosted, web-based file manager. Prior to 1.3.1-beta and 1.2.2-stable, the remediation for CVE-2026-27611 is incom…

Fix: after 1.2.9
Fix from $1,950 2026-03-10
Glances HIGH 7.5
CVE-2026-30928

Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.1, the /api/4/config REST API endpoint returns the entire parsed Glance…

Fix: 4.5.1+
Fix from $1,950 2026-03-10
Windows 10 1607 MEDIUM 5.5
CVE-2026-25186

Exposure of sensitive information to an unauthorized actor in Windows Accessibility Infrastructure (ATBroker.exe) allows an authorized attacker to di…

Fix: 10.0.14393.8957 / 10.0.17763.8511+
Fix from $1,600 2026-03-10
Windows 10 1607 MEDIUM 5.3
CVE-2026-25185

Exposure of sensitive information to an unauthorized actor in Windows Shell Link Processing allows an unauthorized attacker to perform spoofing over …

Fix: 10.0.14393.8957 / 10.0.17763.8511+
Fix from $1,600 2026-03-10
Caddy HIGH 7.5
CVE-2026-30852

Caddy is an extensible server platform that uses TLS by default. From version 2.7.5 to before version 2.11.2, the vars_regexp matcher in vars.go:337 …

Fix: 2.11.2+
Fix from $1,950 2026-03-07
Mcp Memory Service MEDIUM 5.3
CVE-2026-29787

mcp-memory-service is an open-source memory backend for multi-agent systems. Prior to version 10.21.0, the /api/health/detailed endpoint returns deta…

Fix: 10.21.0+
Fix from $1,600 2026-03-07
Uptimeflare HIGH 7.5
CVE-2026-29779

UptimeFlare is a serverless uptime monitoring & status page solution, powered by Cloudflare Workers. Prior to commit 377a596, configuration file upti…

Fix: 2026-03-04+
Fix from $1,950 2026-03-07
Checkmate MEDIUM 5.3
CVE-2026-30829

Checkmate is an open-source, self-hosted tool designed to track and monitor server hardware, uptime, response times, and incidents in real-time with …

Fix: 3.4.0+
Fix from $1,600 2026-03-07
Homarr HIGH 7.5
CVE-2026-27796

Homarr is an open-source dashboard. Prior to version 1.54.0, the integration.all tRPC endpoint in Homarr is exposed as a publicProcedure, allowing un…

Fix: 1.54.0+
Fix from $1,950 2026-03-07
Plane HIGH 7.5
CVE-2026-30244

Plane is an an open-source project management tool. Prior to version 1.2.2, unauthenticated attackers can enumerate workspace members and extract sen…

Fix: 1.2.2+
Fix from $1,950 2026-03-06
Wekan HIGH 8.2
CVE-2026-30845

Wekan is an open source kanban tool built with Meteor. In versions 8.31.0 through 8.33, the board composite publication in Wekan publishes all integr…

Fix: 8.33+
Fix from $1,950 2026-03-06
Wekan HIGH 7.5
CVE-2026-30846

Wekan is an open source kanban tool built with Meteor. In versions 8.31.0 through 8.33, the globalwebhooks publication exposes all global webhook int…

Fix: 8.33+
Fix from $1,950 2026-03-06
Wekan MEDIUM 6.5
CVE-2026-30847

Wekan is an open source kanban tool built with Meteor. In versions 8.31.0 through 8.33, the notificationUsers publication in Wekan publishes user doc…

Fix: 8.33+
Fix from $1,600 2026-03-06