Vulnerability index

Browse CVEs

7,732 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Unclassified HIGH 7.5
CVE-2025-8590

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in AKCE Software Technology R&D Industry and Trade Inc. SKSPro allows Direct…

Mitigation only
Fix from $1,950 2026-02-03
Unclassified MEDIUM 5.3
CVE-2026-1371

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and …

Mitigation only
Fix from $1,600 2026-02-03
Unclassified MEDIUM 5.3
CVE-2026-0950

The Spectra Gutenberg Blocks – Website Builder for the Block Editor plugin for WordPress is vulnerable to Information Disclosure in all versions up t…

Mitigation only
Fix from $1,600 2026-02-03
Polarlearn HIGH 7.5
CVE-2026-25222

PolarLearn is a free and open-source learning program. In 0-PRERELEASE-15 and earlier, a timing attack vulnerability in the sign-in process allows un…

Patch available
Fix from $1,950 2026-02-02
Discourse HIGH 7.5
CVE-2026-23743

Discourse is an open source discussion platform. In versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0, permalinks pointing to access-restri…

Fix: 3.5.4 / 2025.11.2+
Fix from $1,950 2026-01-28
Unclassified MEDIUM 5.3
CVE-2026-1060

The WP Adminify plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.0.7.7 via the /wp-json/a…

Mitigation only
Fix from $1,600 2026-01-28
Openemr MEDIUM 6.5
CVE-2025-54373

OpenEMR is a free and open source electronic health records and medical practice management application. Versions prior to 7.0.4 have a vulnerability…

Patch available
Fix from $1,600 2026-01-28
Hono MEDIUM 5.3
CVE-2026-24473

Hono is a Web application framework that provides support for any JavaScript runtime. Prior to version 4.11.7, Serve static Middleware for the Cloudf…

Fix: 4.11.7+
Fix from $1,600 2026-01-27
Ix Ray Engine 1.6 HIGH 7.5
CVE-2026-24870

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in ixray-team ixray-1.6-stcop.This issue affects ixray-1.6-stcop: before 1.3.

Fix: 1.3+
Fix from $1,950 2026-01-27
Aangine HIGH 7.5
CVE-2025-67274

An issue in continuous.software aangine v.2025.2 allows a remote attacker to obtain sensitive information via the excel-integration-service template …

Mitigation only
Fix from $1,950 2026-01-26
Unclassified MEDIUM 5.3
CVE-2025-13920

The WP Directory Kit plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.4.9 via the wdk_pub…

Mitigation only
Fix from $1,600 2026-01-24
Phpmyfaq HIGH 7.5
CVE-2026-24422

phpMyFAQ is an open source FAQ web application. In versions 4.0.16 and below, multiple public API endpoints improperly expose sensitive user informat…

Fix: 4.0.17+
Fix from $1,950 2026-01-24
Gemscms Backend HIGH 7.5
CVE-2025-52026

An information disclosure vulnerability exists in the /srvs/membersrv/getCashiers endpoint of the Aptsys gemscms backend platform thru 2025-05-28. Th…

Fix: after 2025-05-28
Fix from $1,950 2026-01-23
8180 Ip Audio Alerter Firmware HIGH 7.5
CVE-2026-0789

ALGO 8180 IP Audio Alerter Web UI Inclusion of Authentication Cookie in Response Body Information Disclosure Vulnerability. This vulnerability allows…

Mitigation only
Fix from $1,950 2026-01-23
Azure Data Explorer HIGH 7.4
CVE-2026-21524

Exposure of sensitive information to an unauthorized actor in Azure Data Explorer allows an unauthorized attacker to disclose information over a netw…

No fix yet
Fix from $1,950 2026-01-22
Gitea MEDIUM 6.5
CVE-2026-20800

Gitea's notification API does not re-validate repository access permissions when returning notification details. After a user's access to a private r…

Fix: 1.25.4+
Fix from $1,600 2026-01-22
Erica Smart Fan Firmware HIGH 7.4
CVE-2025-69822

An issue in Atomberg Atomberg Erica Smart Fan Firmware Version: V1.0.36 allows an attacker to obtain sensitive information and escalate privileges vi…

No fix yet
Fix from $1,950 2026-01-22
Typebot HIGH 7.4
CVE-2025-65098

Typebot is an open-source chatbot builder. In versions prior to 3.13.2, client-side script execution in Typebot allows stealing all stored credential…

Fix: 3.13.2+
Fix from $1,950 2026-01-22
Life Sciences Central Designer MEDIUM 5.3
CVE-2026-21974

Vulnerability in the Oracle Life Sciences Central Designer product of Oracle Health Sciences Applications (component: Platform). The supported vers…

Mitigation only
Fix from $1,600 2026-01-20
Supply Chain Products Suite HIGH 7.5
CVE-2026-21940

Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: User and User Group). The supported version that is affected is 9.…

Mitigation only
Fix from $1,950 2026-01-20
Solaris MEDIUM 5.3
CVE-2026-21928

Vulnerability in the Oracle Solaris product of Oracle Systems (component: Kernel). The supported version that is affected is 11. Easily exploitable…

Mitigation only
Fix from $1,600 2026-01-20
Chrome CRITICAL 9.8
CVE-2026-0905

Insufficient policy enforcement in Network in Google Chrome prior to 144.0.7559.59 allowed an attack who obtained a network log file to potentially o…

Fix: 144.0.7559.59 / 144.0.7559.60+
Fix from $2,300 2026-01-20
Mineadmin MEDIUM 5.3
CVE-2026-1196

A security vulnerability has been detected in MineAdmin 1.x/2.x. Affected is an unknown function of the file /system/getFileInfoById. Such manipulati…

No fix yet
Fix from $1,600 2026-01-20
Mineadmin HIGH 7.5
CVE-2026-1194

A security flaw has been discovered in MineAdmin 1.x/2.x. This affects an unknown function of the component Swagger. The manipulation results in info…

No fix yet
Fix from $1,950 2026-01-20
Prime HIGH 7.5
CVE-2026-1175

A vulnerability was identified in birkir prime up to 0.4.0.beta.0. This impacts an unknown function of the file /graphql of the component GraphQL Dir…

Fix: after 0.4.0
Fix from $1,950 2026-01-19
Prime MEDIUM 5.3
CVE-2026-1170

A vulnerability was detected in birkir prime up to 0.4.0.beta.0. This issue affects some unknown processing of the file /graphql of the component Gra…

Fix: after 0.4.0
Fix from $1,600 2026-01-19
Unclassified MEDIUM 5.3
CVE-2025-12129

The CubeWP – All-in-One Dynamic Content Framework plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.…

Mitigation only
Fix from $1,600 2026-01-17
Unclassified MEDIUM 5.3
CVE-2025-14075

The WP Hotel Booking plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.2.7. This is due to…

Mitigation only
Fix from $1,600 2026-01-17
Ipados MEDIUM 5.3
CVE-2025-24089

A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 18.3 and iPadOS 18.3. An app may be able to enumerate a us…

Fix: 18.3+
Fix from $1,600 2026-01-16
Airflow HIGH 7.5
CVE-2025-68438

In Apache Airflow versions before 3.1.6, when rendered template fields in a Dag exceed [core] max_templated_field_length, sensitive values could be e…

Fix: 3.1.6+
Fix from $1,950 2026-01-16