Vulnerability index

Browse CVEs

7,732 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Fastapiadmin MEDIUM 5.3
CVE-2026-2975

A security flaw has been discovered in FastApiAdmin up to 2.2.0. Affected by this vulnerability is the function reset_api_docs of the file /backend/a…

Fix: after 2.2.0
Fix from $1,600 2026-02-23
Funadmin CRITICAL 9.1
CVE-2026-2894

A vulnerability was identified in funadmin up to 7.1.0-rc4. Affected by this vulnerability is the function getMember of the file app/frontend/view/lo…

Fix: 7.1.0+
Fix from $2,300 2026-02-21
Asn1 Ts MEDIUM 5.3
CVE-2026-27452

ASN.1 TypeScript ESM library, including codecs for Basic Encoding Rules (BER) and Distinguished Encoding Rules (DER). In versions 11.0.5 and below, i…

Fix: 11.0.6+
Fix from $1,600 2026-02-21
Foswiki MEDIUM 5.3
CVE-2026-2861

A vulnerability was detected in Foswiki up to 2.1.10. The affected element is an unknown function of the component Changes/Viewfile/Oops. The manipul…

Fix: 2.1.11+
Fix from $1,600 2026-02-21
Feathers MEDIUM 5.3
CVE-2026-27193

Feathersjs is a framework for creating web APIs and real-time applications with TypeScript or JavaScript. In versions 5.0.39 and below, all HTTP requ…

Fix: 5.0.40+
Fix from $1,600 2026-02-21
Getsimple Cms HIGH 7.5
CVE-2026-27161

GetSimple CMS is a content management system. All versions of GetSimple CMS rely on .htaccess files to restrict access to sensitive directories such …

Fix: after 3.3.22
Fix from $1,950 2026-02-21
Unclassified MEDIUM 5.3
CVE-2026-2832

Certain Samsung MultiXpress Multifunction Printers may be vulnerable to information disclosure, potentially exposing address book entries and other d…

Mitigation only
Fix from $1,600 2026-02-20
Unclassified MEDIUM 5.3
CVE-2025-13113

The Web Accessibility by accessiBe plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.11. T…

Mitigation only
Fix from $1,600 2026-02-19
Splunk MEDIUM 6.5
CVE-2026-20141

In Splunk Enterprise versions below 10.0.2, 10.0.3, 9.4.8, and 9.3.9, a low-privileged user who does not hold the "admin" Splunk role could access th…

Fix: 9.3.9 / 9.4.8+
Fix from $1,600 2026-02-18
Splunk MEDIUM 5.7
CVE-2026-20137

In Splunk Enterprise versions below 10.2.0, 10.0.3, 9.4.5, 9.3.7, and 9.2.9, and Splunk Cloud Platform versions below 10.1.2507.0, 10.0.2503.9, 9.3.2…

Fix: 9.2.9 / 9.3.7+
Fix from $1,600 2026-02-18
Unclassified MEDIUM 5.3
CVE-2025-12074

The Context Blog theme for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.2.5 via the 'context_blog_modal_po…

Mitigation only
Fix from $1,600 2026-02-18
Aruba Networking Private 5g Core MEDIUM 6.5
CVE-2026-23597

Vulnerabilities in the API error handling of an HPE Aruba Networking 5G Core server API could allow an unauthenticated remote attacker to obtain sen…

Fix: after 1.24.3.3
Fix from $1,600 2026-02-17
Datart MEDIUM 5.7
CVE-2025-70829

An information exposure vulnerability in Datart v1.0.0-rc.3 allows authenticated attackers to access sensitive data via a custom H2 JDBC connection s…

No fix yet
Fix from $1,600 2026-02-17
Mattermost Server MEDIUM 5.7
CVE-2025-13821

Mattermost versions 11.1.x <= 11.1.2, 10.11.x <= 10.11.9, 11.2.x <= 11.2.1 fail to sanitize sensitive data in WebSocket messages which allows authent…

Fix: 10.11.10 / 11.1.3+
Fix from $1,600 2026-02-16
Unclassified MEDIUM 5.3
CVE-2025-13973

The StickEasy Protected Contact Form plugin for WordPress is vulnerable to Sensitive Information Disclosure in all versions up to, and including, 1.0…

Mitigation only
Fix from $1,600 2026-02-14
Known CRITICAL 9.8
CVE-2026-26273

Known is a social publishing platform. Prior to 1.6.3, a Critical Broken Authentication vulnerability exists in Known 1.6.2 and earlier. The applicat…

Fix: 1.6.3+
Fix from $2,300 2026-02-13
Scraparr HIGH 7.5
CVE-2026-26069

Scraparr is a Prometheus Exporter for various components of the *arr Suite. From 3.0.0-beta to before 3.0.2, when the Readarr integration was enabled…

Fix: 3.0.2+
Fix from $1,950 2026-02-12
Grafana MEDIUM 5.3
CVE-2026-21722

Public dashboards with annotations enabled did not limit their annotation timerange to the locked timerange of the public dashboard. This means one c…

Fix: 11.6.10 / 12.1.6+
Fix from $1,600 2026-02-12
Ipados MEDIUM 5.5
CVE-2026-20678

An authorization issue was addressed with improved state management. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3. A…

Fix: 18.7.5 / 26.3+
Fix from $1,600 2026-02-11
Ipados MEDIUM 6.5
CVE-2026-20680

The issue was addressed with additional restrictions on the observability of app states. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.…

Fix: 14.8.4 / 15.7.4+
Fix from $1,600 2026-02-11
Ipados MEDIUM 5.3
CVE-2026-20682

A logic issue was addressed with improved state management. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3. An attacke…

Fix: 18.7.5 / 26.3+
Fix from $1,600 2026-02-11
Ipados HIGH 7.1
CVE-2026-20641

A privacy issue was addressed with improved checks. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3, macOS Sequoia 15.7…

Fix: 14.8.4 / 15.7.4+
Fix from $1,950 2026-02-11
macOS MEDIUM 5.5
CVE-2026-20647

This issue was addressed with improved data protection. This issue is fixed in macOS Tahoe 26.3. An app may be able to access sensitive user data.

Fix: 26.3+
Fix from $1,600 2026-02-11
macOS MEDIUM 5.5
CVE-2026-20648

A privacy issue was addressed by moving sensitive data to a protected location. This issue is fixed in macOS Tahoe 26.3. A malicious app may be able …

Fix: 26.3+
Fix from $1,600 2026-02-11
macOS MEDIUM 5.5
CVE-2026-20619

A logging issue was addressed with improved data redaction. This issue is fixed in macOS Sequoia 15.7.4, macOS Tahoe 26.3. An app may be able to acce…

Fix: 15.7.4 / 26.3+
Fix from $1,600 2026-02-11
macOS MEDIUM 5.5
CVE-2026-20623

A permissions issue was addressed by removing the vulnerable code. This issue is fixed in macOS Tahoe 26.3. An app may be able to access protected us…

Fix: 26.3+
Fix from $1,600 2026-02-11
Ipados HIGH 7.1
CVE-2026-20606

This issue was addressed by removing the vulnerable code. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3, macOS Sequoi…

Fix: 14.8.4 / 15.7.4+
Fix from $1,950 2026-02-11
macOS MEDIUM 5.5
CVE-2026-20612

A privacy issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.3. An app may be…

Fix: 14.8.4 / 15.7.4+
Fix from $1,600 2026-02-11
Keras HIGH 7.5
CVE-2026-1669

Arbitrary file read in the model loading mechanism (HDF5 integration) in Keras versions 3.0.0 through 3.13.1 on all supported platforms allows a remo…

Fix: after 3.13.1
Fix from $1,950 2026-02-11
Dtls MEDIUM 5.9
CVE-2026-26014

Pion DTLS is a Go implementation of Datagram Transport Layer Security. Pion DTLS versions v1.0.0 through v3.0.10 and 3.1.0 use random nonce generatio…

Fix: 3.1.0+
Fix from $1,600 2026-02-11