Vulnerability index

Browse CVEs

7,732 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Statping Ng MEDIUM 5.3
CVE-2024-26478

An issue in Statping-ng v.0.91.0 allows an attacker to obtain sensitive information via a crafted request to the /api/users endpoint.

No fix yet
Fix from $1,600 2026-02-11
Statping Ng MEDIUM 5.3
CVE-2024-26479

An issue in Statping-ng v.0.91.0 allows an attacker to obtain sensitive information via a crafted request to the Command execution function.

No fix yet
Fix from $1,600 2026-02-11
Statping Ng HIGH 7.5
CVE-2024-26480

An issue in Statping-ng v.0.91.0 allows an attacker to obtain sensitive information via a crafted request to the admin parameter.

No fix yet
Fix from $1,950 2026-02-11
Statping Ng HIGH 7.5
CVE-2024-26477

An issue in Statping-ng v.0.91.0 allows an attacker to obtain sensitive information via a crafted request to the api parameter of the oauth, amazon_s…

No fix yet
Fix from $1,950 2026-02-11
Chrome MEDIUM 6.5
CVE-2026-2317

Inappropriate implementation in Animation in Google Chrome prior to 145.0.7632.45 allowed a remote attacker to leak cross-origin data via a crafted H…

Fix: 145.0.7632.45+
Fix from $1,600 2026-02-11
Unclassified MEDIUM 5.3
CVE-2026-2295

The WPZOOM Addons for Elementor – Starter Templates & Widgets plugin for WordPress is vulnerable to unauthorized access of data due to a missing capa…

Mitigation only
Fix from $1,600 2026-02-11
365 Apps HIGH 7.5
CVE-2026-21260

Exposure of sensitive information to an unauthorized actor in Microsoft Office Outlook allows an unauthorized attacker to perform spoofing over a net…

Fix: 16.0.19127.20518+
Fix from $1,950 2026-02-10
Fortios MEDIUM 5.9
CVE-2025-68686 KEV

An Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE-200] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.1, FortiOS …

Fix: 7.4.7 / 7.6.2+
Fix from $1,600 2026-02-10
Unclassified HIGH 7.5
CVE-2026-2268

The Ninja Forms plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.14.0. This is due to the…

Mitigation only
Fix from $1,950 2026-02-10
Airflow MEDIUM 6.5
CVE-2026-24098

Apache Airflow versions 3.0.0 - 3.1.7, has vulnerability that allows authenticated UI users with permission to one or more specific Dags to view impo…

Fix: 3.1.7+
Fix from $1,600 2026-02-09
Ac21 Firmware HIGH 7.5
CVE-2026-2148

A security vulnerability has been detected in Tenda AC21 16.03.08.16. Affected is an unknown function of the file /cgi-bin/DownloadFlash of the compo…

No fix yet
Fix from $1,950 2026-02-08
Ac21 Firmware MEDIUM 5.3
CVE-2026-2147

A weakness has been identified in Tenda AC21 16.03.08.16. This impacts an unknown function of the file /cgi-bin/DownloadLog of the component Web Mana…

No fix yet
Fix from $1,600 2026-02-08
Wekan MEDIUM 5.3
CVE-2026-2207

A weakness has been identified in WeKan up to 8.20. This issue affects some unknown processing of the file server/publications/activities.js of the c…

Fix: 8.21+
Fix from $1,600 2026-02-08
Unclassified CRITICAL 9.1
CVE-2026-1727

The Agentspace service was affected by a vulnerability that exposed sensitive information due to the use of predictable Google Cloud Storage bucket n…

Mitigation only
Fix from $2,300 2026-02-06
Mcp Salesforce Connector HIGH 7.5
CVE-2026-25650

MCP Salesforce Connector is a Model Context Protocol (MCP) server implementation for Salesforce integration. Prior to 0.1.10, arbitrary attribute acc…

Fix: 0.1.10+
Fix from $1,950 2026-02-06
Gophish HIGH 7.6
CVE-2025-70963

Gophish <=0.12.1 is vulnerable to Incorrect Access Control. The administrative dashboard exposes each user’s long-lived API key directly inside the r…

Fix: after 0.12.1
Fix from $1,950 2026-02-06
Dir 605l Firmware HIGH 7.5
CVE-2026-2056

A security vulnerability has been detected in D-Link DIR-605L and DIR-619L 2.06B01/2.13B01. The impacted element is an unknown function of the file /…

No fix yet
Fix from $1,950 2026-02-06
Dir 605l Firmware HIGH 7.5
CVE-2026-2054

A security flaw has been discovered in D-Link DIR-605L and DIR-619L 2.06B01/2.13B01. Impacted is an unknown function of the component Wifi Setting Ha…

No fix yet
Fix from $1,950 2026-02-06
Dir 605l Firmware HIGH 7.5
CVE-2026-2055

A weakness has been identified in D-Link DIR-605L and DIR-619L 2.06B01/2.13B01. The affected element is an unknown function of the component DHCP Cli…

No fix yet
Fix from $1,950 2026-02-06
Harmonyos MEDIUM 5.5
CVE-2026-24916

Identity authentication bypass vulnerability in the window module. Impact: Successful exploitation of this vulnerability may affect service confident…

No fix yet
Fix from $1,600 2026-02-06
Easydiscuss HIGH 7.5
CVE-2026-21626

Access control settings for forum post custom fields are not applied to the JSON output type, leading to an ACL violation vector an information discl…

Fix: after 5.0.15
Fix from $1,950 2026-02-06
Azure Functions HIGH 8.2
CVE-2026-21532

Azure Function Information Disclosure Vulnerability

No fix yet
Fix from $1,950 2026-02-05
Magento MEDIUM 5.3
CVE-2026-25523

Magento-lts is a long-term support alternative to Magento Community Edition (CE). Prior to version 20.16.1, the admin url can be discovered without p…

Fix: after 20.16.0
Fix from $1,600 2026-02-04
Openclaw MEDIUM 6.5
CVE-2026-25475

OpenClaw is a personal AI assistant. Prior to version 2026.1.30, the isValidMedia() function in src/media/parse.ts allows arbitrary file paths includ…

Fix: 2026.1.30+
Fix from $1,600 2026-02-04
N8n HIGH 7.7
CVE-2025-61917

n8n is an open source workflow automation platform. From version 1.65.0 to before 1.114.3, the use of Buffer.allocUnsafe() and Buffer.allocUnsafeSlow…

Fix: 1.114.3+
Fix from $1,950 2026-02-04
Unclassified MEDIUM 5.3
CVE-2025-15482

The Chapa Payment Gateway Plugin for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and incl…

Mitigation only
Fix from $1,600 2026-02-04
Unclassified MEDIUM 5.3
CVE-2025-15508

The Magic Import Document Extractor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.0.4 …

Mitigation only
Fix from $1,600 2026-02-04
Aion HIGH 8.1
CVE-2025-52631

HCL AION is affected by a Missing or Insecure HTTP Strict-Transport-Security (HSTS) Header vulnerability. This can allow insecure connections, potent…

Mitigation only
Fix from $1,950 2026-02-03
Open Eclass Platform MEDIUM 6.5
CVE-2020-37114

GUnet OpenEclass 1.7.3 allows unauthenticated and authenticated users to access sensitive information, including system information, application vers…

No fix yet
Fix from $1,600 2026-02-03
Decidim MEDIUM 6.5
CVE-2025-65017

Decidim is a participatory democracy framework. In versions from 0.30.0 to before 0.30.4 and from 0.31.0.rc1 to before 0.31.0, the private data expor…

Fix: 0.30.4+
Fix from $1,600 2026-02-03