Vulnerability index

Browse CVEs

7,732 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Gokapi MEDIUM 6.4
CVE-2026-28682

Gokapi is a self-hosted file sharing server with automatic expiration and encryption support. Prior to version 2.2.3, the upload status SSE implement…

Fix: 2.2.3+
Fix from $1,600 2026-03-06
Opensift MEDIUM 5.3
CVE-2026-28675

OpenSift is an AI study tool that sifts through large datasets using semantic search and generative AI. Prior to version 1.6.3-alpha, some endpoints …

Fix: 1.6.3+
Fix from $1,600 2026-03-06
Unclassified MEDIUM 5.3
CVE-2026-2589

The Greenshift – animation and page builder blocks plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and in…

Mitigation only
Fix from $1,600 2026-03-06
Filebrowser MEDIUM 6.5
CVE-2026-28492

File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename and edit files. Pr…

Fix: 2.61.0+
Fix from $1,600 2026-03-05
Cpp Httplib MEDIUM 5.3
CVE-2026-28434

cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.35.0, when a request handler throws a C++ exception and …

Fix: 0.35.0+
Fix from $1,600 2026-03-04
Seraphinite Accelerator MEDIUM 6.5
CVE-2026-3058

The Seraphinite Accelerator plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.28.14 via th…

Fix: 2.28.15+
Fix from $1,600 2026-03-04
Seppmail HIGH 7.5
CVE-2026-2747

SEPPmail Secure Email Gateway before version 15.0.1 decrypts inline PGP messages without isolating them from surrounding unencrypted content, allowin…

Fix: 15.0.1+
Fix from $1,950 2026-03-04
Unclassified HIGH 7.5
CVE-2026-2025

The Mail Mint WordPress plugin before 1.19.5 does not have authorization in one of its REST API endpoint, allowing unauthenticated users to call it …

Mitigation only
Fix from $1,950 2026-03-04
Unclassified MEDIUM 5.3
CVE-2026-1980

The WPBookit plugin for WordPress is vulnerable to unauthorized data disclosure due to a missing authorization check on the 'get_customer_list' route…

Mitigation only
Fix from $1,600 2026-03-04
Openemr HIGH 8.1
CVE-2026-25146

OpenEMR is a free and open source electronic health records and medical practice management application. From 5.0.2 to before 8.0.0, there are (at le…

Fix: 8.0.0+
Fix from $1,950 2026-03-03
Android HIGH 8.4
CVE-2026-0025

In hasImage of Notification.java, there is a possible way to reveal information across users due to a permissions bypass. This could lead to local es…

Mitigation only
Fix from $1,950 2026-03-02
Android MEDIUM 6.2
CVE-2026-0005

In onServiceDisconnected of KeyguardServiceDelegate.java, there is a possible partial bypass of app pinning allowing limited interaction with other a…

Mitigation only
Fix from $1,600 2026-03-02
Android MEDIUM 5.5
CVE-2025-48642

In jump_to_payload of payload.rs, there is a possible information disclosure due to a logic error in the code. This could lead to local information d…

Mitigation only
Fix from $1,600 2026-03-02
Android HIGH 7.7
CVE-2025-48635

In multiple functions of TaskFragmentOrganizerController.java, there is a possible activity token leak due to a logic error in the code. This could l…

Mitigation only
Fix from $1,950 2026-03-02
Zimaos MEDIUM 6.5
CVE-2025-64427

ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In version 1.5.0 and prior, due to insufficient valida…

Fix: after 1.5.0
Fix from $1,600 2026-03-02
Wpforo Forum MEDIUM 5.3
CVE-2026-28559

wpForo Forum 2.4.14 contains an information disclosure vulnerability that allows unauthenticated users to retrieve private and unapproved forum topic…

Fix: 2.4.16+
Fix from $1,600 2026-02-28
Ansible Automation Platform MEDIUM 6.7
CVE-2025-9908

A flaw was found in the Red Hat Ansible Automation Platform, Event-Driven Ansible (EDA) Event Streams. This vulnerability allows an authenticated use…

Fix: 2.6+
Fix from $1,600 2026-02-27
Ansible Automation Platform MEDIUM 6.7
CVE-2025-9907

A flaw was found in the Red Hat Ansible Automation Platform, Event-Driven Ansible (EDA) Event Stream API. This vulnerability allows exposure of sensi…

Fix: 2.6+
Fix from $1,600 2026-02-27
T5008 Firmware HIGH 7.5
CVE-2026-24498

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in EFM-Networks, Inc. IpTIME T5008, EFM-Networks, Inc. IpTIME AX2004M, EFM-N…

Fix: 15.27.2+
Fix from $1,950 2026-02-27
Initiative HIGH 7.5
CVE-2026-28276

Initiative is a self-hosted project management platform. An access control vulnerability exists in Initiative versions prior to 0.32.2 where uploaded…

Fix: 0.32.2+
Fix from $1,950 2026-02-26
Evershop CRITICAL 9.8
CVE-2026-28213

EverShop is a TypeScript-first eCommerce platform. Versions prior to 2.1.1 have a vulnerability in the "Forgot Password" functionality. When specifyi…

Fix: 2.1.1+
Fix from $2,300 2026-02-26
Unclassified HIGH 8.4
CVE-2026-2244

A vulnerability in Google Cloud Vertex AI Workbench from 7/21/2025 to 01/30/2026 allows an attacker to exfiltrate valid Google Cloud access tokens of…

Mitigation only
Fix from $1,950 2026-02-26
Openemr MEDIUM 6.5
CVE-2026-24487

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0, an authorization byp…

Fix: 8.0.0+
Fix from $1,600 2026-02-25
Catalyst Sd Wan Manager HIGH 7.5
CVE-2026-20133 KEVEPSS 31%

A vulnerability in Cisco Catalyst SD-WAN Software could allow an unauthenticated, remote attacker to view sensitive information on an affected system…

Fix: 20.9.8.2 / 20.12.5.3+
Fix from $1,950 2026-02-25
Filebrowser Quantum MEDIUM 6.5
CVE-2026-27611

FileBrowser Quantum is a free, self-hosted, web-based file manager. Prior to versions 1.1.3-stable and 1.2.6-beta, when users share password-protecte…

Fix: 1.1.3 / 1.2.6+
Fix from $1,600 2026-02-25
Devolutions Server MEDIUM 6.5
CVE-2026-3131

Improper access control in multiple DVLS REST API endpoints in Devolutions Server 2025.3.14.0 and earlier allows an authenticated user with view-on…

Fix: 2025.3.15.0+
Fix from $1,600 2026-02-24
Firefox HIGH 7.5
CVE-2026-2803

Information disclosure, mitigation bypass in the Settings UI component. This vulnerability was fixed in Firefox 148 and Thunderbird 148.

Fix: 148.0+
Fix from $1,950 2026-02-24
Firefox HIGH 7.5
CVE-2026-2783

Information disclosure due to JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 148, Firefox ESR 14…

Fix: 140.8.0 / 148.0+
Fix from $1,950 2026-02-24
Superset MEDIUM 6.5
CVE-2026-23983

A Sensitive Data Exposure vulnerability exists in Apache Superset allowing authenticated users to retrieve sensitive user information. The Tag endpoi…

Fix: 6.0.0+
Fix from $1,600 2026-02-24
Fastapiadmin MEDIUM 6.5
CVE-2026-2976

A weakness has been identified in FastApiAdmin up to 2.2.0. Affected by this issue is the function download_controller of the file /backend/app/api/v…

Fix: after 2.2.0
Fix from $1,600 2026-02-23