Vulnerability index

Browse CVEs

7,720 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Unclassified MEDIUM 5.3
CVE-2026-67339

guzzlehttp/guzzle versions before 7.14.2 fail to properly isolate Proxy-Authorization headers from origin servers in cURL handlers. Attackers can cap…

No fix yet
Fix from $1,600 2026-08-01
Unclassified HIGH 8.3
CVE-2026-67320

axios in a Node.js deployment using the HTTP adapter can route requests through an attacker-controlled proxy. axios hardens merged request configurat…

No fix yet
Fix from $1,950 2026-08-01
Unclassified HIGH 7.5
CVE-2026-67322

GitPython before 3.1.52 is vulnerable to environment-variable exfiltration in Repo.clone_from(). The caller-supplied remote URL is passed through Git…

No fix yet
Fix from $1,950 2026-08-01
Unclassified MEDIUM 5.3
CVE-2026-18059

The PixelYourSite – Your smart PIXEL (TAG) & API Manager plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, …

No fix yet
Fix from $1,600 2026-08-01
Unclassified HIGH 7.5
CVE-2026-14839

The Mapster WP Maps WordPress plugin before 1.24.0 does not perform any authorization or post-status check on a public REST endpoint, allowing unauth…

No fix yet
Fix from $1,950 2026-08-01
Unclassified MEDIUM 6.2
CVE-2026-54785

gemini-bridge is a lightweight MCP server bridging AI agents to Google's Gemini AI via the official CLI. From 1.0.0 until 1.3.1, consult_gemini_with_…

No fix yet
Fix from $1,600 2026-07-31
Unclassified MEDIUM 6.5
CVE-2026-45377

Decidim is a participatory democracy framework. Prior to 0.30.9, from 0.31.0 before 0.31.5, and in 0.32.0.rc1 before 0.32.0.rc2, the normal download_…

No fix yet
Fix from $1,600 2026-07-31
Unclassified CRITICAL 9.9
CVE-2026-52855

Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to 1.12.3, {{config.}} placeholders in egg…

No fix yet
Fix from $2,300 2026-07-31
Unclassified MEDIUM 6.5
CVE-2026-14928

The JS Help Desk WordPress plugin before 3.1.4 does not perform authorization or ownership checks before returning support-ticket content in a nonce…

No fix yet
Fix from $1,600 2026-07-31
Unclassified MEDIUM 6.5
CVE-2026-14931

The JS Help Desk WordPress plugin before 3.1.4 grants a support-agent capability to the Contributor role on activation and does not perform a capabi…

No fix yet
Fix from $1,600 2026-07-31
Unclassified HIGH 7.5
CVE-2026-15048

The Geeky Bot WordPress plugin before 1.2.8 does not perform an authorization check on one of its AJAX actions, allowing unauthenticated users to re…

No fix yet
Fix from $1,950 2026-07-31
Unclassified HIGH 7.5
CVE-2026-14319

The GiveWP WordPress plugin before 4.16.3 does not properly restrict access to a REST API endpoint that returns recurring-donation records, allowing…

No fix yet
Fix from $1,950 2026-07-31
Unclassified CRITICAL 9.3
CVE-2026-48499

Activepieces is an open source AI workflow automation platform. Prior to 0.84.0, an unsanitized path segment in the Code piece sandbox can let an aut…

No fix yet
Fix from $2,300 2026-07-30
Calico HIGH 7.5
CVE-2026-41186

When Calico's shared debug server is enabled (disabled by default), the Calico kube-controllers and Goldmane components bind their Go pprof debug lis…

Fix: 3.21.7 / 3.22.4+
Fix from $1,950 2026-07-30
Chrome MEDIUM 6.5
CVE-2026-18005

Inappropriate implementation in WebXR in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to obtain potentially sensitive information f…

Fix: 151.0.7922.72+
Fix from $1,600 2026-07-30
Chrome MEDIUM 6.5
CVE-2026-18001

Inappropriate implementation in WebGL in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to obtain potentially sensitive information f…

Fix: 151.0.7922.72+
Fix from $1,600 2026-07-30
Chrome MEDIUM 6.5
CVE-2026-17975

Inappropriate implementation in IME in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker to obtain potentially sensitive informat…

Fix: 151.0.7922.72+
Fix from $1,600 2026-07-30
Chrome MEDIUM 6.2
CVE-2026-17966

Inappropriate implementation in Views in Google Chrome on Mac prior to 151.0.7922.72 allowed a local attacker to obtain potentially sensitive informa…

Fix: 151.0.7922.72+
Fix from $1,600 2026-07-30
Chrome MEDIUM 5.5
CVE-2026-17973

Inappropriate implementation in Views in Google Chrome on Mac prior to 151.0.7922.72 allowed a local attacker to obtain potentially sensitive informa…

Fix: 151.0.7922.72+
Fix from $1,600 2026-07-30
Chrome MEDIUM 6.5
CVE-2026-17892

Inappropriate implementation in WebXR in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to obtain potentially sensitive information f…

Fix: 151.0.7922.72+
Fix from $1,600 2026-07-30
Chrome MEDIUM 6.5
CVE-2026-17683

Inappropriate implementation in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to obtain potentially sensitive information f…

Fix: 151.0.7922.72+
Fix from $1,600 2026-07-30
Unclassified MEDIUM 6.0
CVE-2026-67435

linuxfabrik-lib provides Python modules for database access, caching, shell execution, and API integrations. Prior to version 6.0.0, lib.url.fetch() …

No fix yet
Fix from $1,600 2026-07-29
Unclassified HIGH 8.3
CVE-2026-67436

Linuxfabrik monitoring-plugins provides Python monitoring plugins for Icinga, Nagios, and related monitoring systems. In 6.0.0 and earlier, the redfi…

No fix yet
Fix from $1,950 2026-07-29
Undici CRITICAL 9.1
CVE-2026-13697

undici's cache interceptor mishandles malformed Cache-Control private directives. In undici 7.0.0 up to before 7.29.0 and 8.0.0 up to before 8.9.0, a…

Fix: 7.29.0 / 8.9.0+
Fix from $2,300 2026-07-29
Unclassified HIGH 7.4
CVE-2026-54660

swagger-typescript-api generates API clients for Fetch or Axios from OpenAPI specifications. Prior to 13.12.2, src/resolved-swagger-schema.ts getRemo…

No fix yet
Fix from $1,950 2026-07-29
Gridbox MEDIUM 5.3
CVE-2026-66489

Joomla Extension - balbooa.com - Various unauthenticated file system disclosure in Gridbox < 2.20.2

Fix: 2.20.2+
Fix from $1,600 2026-07-29
Traffic Server HIGH 8.7
CVE-2026-58157

Apache Traffic Server can reuse server sessions and tunnels improperly, exposing data across client connections. This issue affects Apache Traffic S…

Fix: 9.2.15 / 10.1.4+
Fix from $1,950 2026-07-29
Unclassified MEDIUM 5.3
CVE-2026-11351

The ShinyStat Analytics WordPress plugin before 1.0.17 does not perform any authorization check on one of its REST API endpoints, allowing unauthenti…

No fix yet
Fix from $1,600 2026-07-29
Unclassified MEDIUM 6.9
CVE-2026-54659

Pagy is agnostic pagination in plain Ruby. From 43.0.0 until 43.5.6, Pagy::I18n.locale= in gem/lib/pagy/modules/i18n/i18n.rb stored locale values ver…

No fix yet
Fix from $1,600 2026-07-28
Datamodel Code Generator HIGH 7.5
CVE-2026-55389

datamodel-code-generator generates Pydantic v2 models, dataclasses, TypedDict, and msgspec.Struct from OpenAPI, JSON Schema, GraphQL, Avro, Protobuf,…

Fix: 0.62.0+
Fix from $1,950 2026-07-28