Vulnerability index

Browse CVEs

7,732 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Incoming Goods Suite MEDIUM 5.3
CVE-2026-22645

The application discloses all used components, versions and license information to unauthenticated actors, giving attackers the opportunity to target…

Fix: 1.2.1+
Fix from $1,600 2026-01-15
Bluvoyix HIGH 7.5
CVE-2026-22240

The vulnerability exists in BLUVOYIX due to an improper password storage implementation and subsequent exposure via unauthenticated APIs. An unauthen…

Mitigation only
Fix from $1,950 2026-01-14
Bluvoyix CRITICAL 9.8
CVE-2026-22237

The vulnerability exists in BLUVOYIX due to the exposure of sensitive internal API documentation. An unauthenticated remote attacker could exploit th…

Mitigation only
Fix from $2,300 2026-01-14
Unclassified MEDIUM 5.3
CVE-2026-0717

The LottieFiles – Lottie block for Gutenberg plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includin…

Mitigation only
Fix from $1,600 2026-01-14
Unclassified MEDIUM 5.3
CVE-2025-14464

The PDF Resume Parser plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.0. This is due to …

Mitigation only
Fix from $1,600 2026-01-14
Harmonyos MEDIUM 5.5
CVE-2025-68965

Permission control vulnerability in the Notepad module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

No fix yet
Fix from $1,600 2026-01-14
Harmonyos MEDIUM 5.5
CVE-2025-68966

Permission control vulnerability in the Notepad module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

No fix yet
Fix from $1,600 2026-01-14
Emui MEDIUM 5.5
CVE-2025-68959

Permission verification bypass vulnerability in the media library module. Impact: Successful exploitation of this vulnerability may affect service co…

No fix yet
Fix from $1,600 2026-01-14
Windows 10 1607 MEDIUM 5.5
CVE-2026-20939

Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.

Fix: 10.0.14393.8783 / 10.0.17763.8276+
Fix from $1,600 2026-01-13
Windows 10 1607 MEDIUM 5.5
CVE-2026-20932

Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.

Fix: 10.0.14393.8783 / 10.0.17763.8276+
Fix from $1,600 2026-01-13
Windows 10 1607 MEDIUM 5.5
CVE-2026-20937

Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.

Fix: 10.0.14393.8783 / 10.0.17763.8276+
Fix from $1,600 2026-01-13
Windows 10 1809 MEDIUM 5.5
CVE-2026-20862

Exposure of sensitive information to an unauthorized actor in Windows Management Services allows an authorized attacker to disclose information local…

Fix: 10.0.17763.8276 / 10.0.19044.6809+
Fix from $1,600 2026-01-13
Windows 10 1607 MEDIUM 6.5
CVE-2026-20847

Exposure of sensitive information to an unauthorized actor in Windows Shell allows an authorized attacker to perform spoofing over a network.

Fix: 10.0.14393.8783 / 10.0.17763.8276+
Fix from $1,600 2026-01-13
Windows 10 1607 MEDIUM 5.5
CVE-2026-20827

Exposure of sensitive information to an unauthorized actor in Tablet Windows User Interface (TWINUI) Subsystem allows an authorized attacker to discl…

Fix: 10.0.14393.8783 / 10.0.17763.8276+
Fix from $1,600 2026-01-13
Windows 10 1607 MEDIUM 6.2
CVE-2026-20821

Exposure of sensitive information to an unauthorized actor in Windows Remote Procedure Call allows an unauthorized attacker to disclose information l…

Fix: 10.0.14393.8783 / 10.0.17763.8276+
Fix from $1,600 2026-01-13
Windows 10 1607 MEDIUM 5.5
CVE-2026-20823

Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.

Fix: 10.0.14393.8783 / 10.0.17763.8276+
Fix from $1,600 2026-01-13
Windows 10 1607 MEDIUM 5.5
CVE-2026-20805 KEVEPSS 5%

Exposure of sensitive information to an unauthorized actor in Desktop Windows Manager allows an authorized attacker to disclose information locally.

Fix: 10.0.14393.8783 / 10.0.17763.8276+
Fix from $1,600 2026-01-13
Unclassified HIGH 7.5
CVE-2025-37165

A vulnerability in the router mode configuration of HPE Instant On Access Points exposed certain network configuration details to unintended interfac…

Mitigation only
Fix from $1,950 2026-01-13
Unclassified CRITICAL 9.8
CVE-2025-47855

An exposure of sensitive information to an unauthorized actor [CWE-200] vulnerability in Fortinet FortiFone 7.0.0 through 7.0.1, FortiFone 3.0.13 thr…

Mitigation only
Fix from $2,300 2026-01-13
Firefox MEDIUM 5.3
CVE-2026-0888

Information disclosure in the XML component. This vulnerability was fixed in Firefox 147 and Thunderbird 147.

Fix: 147.0+
Fix from $1,600 2026-01-13
Firefox MEDIUM 5.3
CVE-2026-0883

Information disclosure in the Networking component. This vulnerability was fixed in Firefox 147, Firefox ESR 140.7, Thunderbird 147, and Thunderbird …

Fix: 140.7.0 / 147.0+
Fix from $1,600 2026-01-13
Unclassified MEDIUM 5.3
CVE-2025-14507

The EventPrime - Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, an…

Mitigation only
Fix from $1,600 2026-01-13
Wlc MEDIUM 5.5
CVE-2026-22251

wlc is a Weblate command-line client using Weblate's REST API. Prior to 1.17.0, wlc supported providing unscoped API keys in the setting. This practi…

Fix: 1.17.0+
Fix from $1,600 2026-01-12
Full Calendar Macro MEDIUM 5.3
CVE-2025-65090

XWiki Full Calendar Macro displays objects from the wiki on the calendar. Prior to version 2.4.6, users with the rights to view the Calendar.JSONServ…

Fix: 2.4.6+
Fix from $1,600 2026-01-10
Openproject MEDIUM 5.3
CVE-2026-22604

OpenProject is an open-source, web-based project management software. For OpenProject versions from 11.2.1 to before 16.6.2, when sending a POST requ…

Fix: 16.6.2+
Fix from $1,600 2026-01-10
Openproject CRITICAL 9.1
CVE-2026-22600

OpenProject is an open-source, web-based project management software. A Local File Read (LFR) vulnerability exists in the work package PDF export fun…

Fix: 16.6.4+
Fix from $2,300 2026-01-10
Unclassified MEDIUM 6.5
CVE-2025-14980

The BetterDocs plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.3.3 via the scripts() fun…

Mitigation only
Fix from $1,600 2026-01-09
Unclassified MEDIUM 5.3
CVE-2025-14574

The weDocs plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.1.15 via the `/wp-json/wp/v2/…

Mitigation only
Fix from $1,600 2026-01-09
Ks Wr1200 Firmware MEDIUM 5.4
CVE-2025-68718

KAYSUS KS-WR1200 routers with firmware 107 expose SSH and TELNET services on the LAN interface with hardcoded root credentials (root:12345678). The a…

No fix yet
Fix from $1,600 2026-01-08
Ks Wr3600 Firmware HIGH 8.8
CVE-2025-68719

KAYSUS KS-WR3600 routers with firmware 1.0.5.9.1 mishandle configuration management. Once any user is logged in and maintains an active session, an a…

No fix yet
Fix from $1,950 2026-01-08