Vulnerability index

Browse CVEs

7,720 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
MEDIUM 6.5 CVE-2026-53959 4gaBoards is a boards system for realtime project management. Prior to 3.3.9, 4gaBoards allows any authenticated user to enumerate account informatio… Fix unknown Fix from $4,0002026-08-18 CRITICAL 9.0 CVE-2026-62988 Froxlor is open source server administration software. From 2.3.7 until 2.3.8, the Customers.get, Customers.listing, Admins.get, Admins.listing, Ftps… Fix unknown Fix from $5,7502026-08-18 HIGH 7.5 CVE-2026-75915 CodeWhale versions before 0.8.64 contain an environment variable exposure vulnerability in the js_execution tool that fails to scrub parent process e… Fix unknown Fix from $4,9002026-08-18 HIGH 7.6 CVE-2026-69189 Hoppscotch is an open source API development ecosystem. Prior to 2026.6.0, the team, teamMembers.user, RESTHistory, GQLHistory, currentRESTSession, c… Fix unknown Fix from $4,9002026-08-18 CRITICAL 9.8 CVE-2026-42164 Mahara before 25.04.5 and 26.04.0 is vulnerable in the Text block/section functionality when a call is crafted in a certain way that allows it to rec… Fix unknown Fix from $5,7502026-08-17 CRITICAL 9.6 CVE-2026-71424 Onyx is an open-source AI platform. Prior to 3.1.10, 3.2.14, and 4.0.0, Onyx's GET /api/mcp/servers and GET /api/mcp/servers/persona/{persona_id} end… Fix unknown Fix from $5,7502026-08-17 MEDIUM 6.5 CVE-2026-64778 The issue was addressed with improved checks. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, mac… Safari Fix unknown Fix from $4,0002026-08-17 MEDIUM 5.5 CVE-2026-64760 An information leakage was addressed with additional validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10. An app may be able to leak se… Ipados Fix unknown Fix from $4,0002026-08-17 HIGH 8.5 CVE-2026-57485 Stirling-PDF is a locally hosted web application that facilitates various operations on PDF files. Prior to 2.9.0, the /api/v1/pipeline/handleData en… Fix unknown Fix from $4,9002026-08-17 MEDIUM 5.3 CVE-2026-68520 Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.6, as_dict_secure() in glances/config.py checks only option names and e… Fix unknown Fix from $4,0002026-08-17 CRITICAL 9.1 CVE-2026-64859 New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to 1.0.0-rc.7, the admin user list and… Fix unknown Fix from $5,7502026-08-17 MEDIUM 6.2 CVE-2026-49302 Permission control vulnerability in the notification service module. Impact: Successful exploitation of this vulnerability may affect service confide… Fix unknown Fix from $4,0002026-08-17 MEDIUM 6.2 CVE-2026-49307 Permission control vulnerability in the multi-mode input module. Impact: Successful exploitation of this vulnerability may affect service confidentia… Fix unknown Fix from $4,0002026-08-17 MEDIUM 6.2 CVE-2026-49301 Permission control vulnerability in the Gallery module. Impact: Successful exploitation of this vulnerability may affect service confidentiality. Fix unknown Fix from $4,0002026-08-17 MEDIUM 6.5 CVE-2026-19613 The ECS WordPress plugin before 4.3.10 does not perform ownership or post-status checks when one of its dynamic repeater data sources reads custom f… Fix unknown Fix from $4,0002026-08-16 HIGH 7.5 CVE-2026-19717 The CatFolders Document Gallery & PDF Library WordPress plugin before 2.0.7 does not have authorisation checks in some of its REST API endpoints, all… Fix unknown Fix from $4,9002026-08-16 MEDIUM 6.2 CVE-2026-73047 siyuan versions <= 3.7.3 (fixed in v3.7.4) contain a server-side template injection vulnerability in the attribute-view Template calculation feature … No fix yet Fix from $4,0002026-08-15 MEDIUM 6.5 CVE-2026-16541 The Simply Schedule Appointments WordPress plugin before 1.6.12.17 does not restrict the user records returned by some of its REST endpoints to those… Fix unknown Fix from $4,0002026-08-15 HIGH 7.5 CVE-2026-16611 The Product Feed PRO for WooCommerce by AdTribes WordPress plugin before 13.5.7 does not perform an authorization check on one of its REST read rout… Fix unknown Fix from $4,9002026-08-15 MEDIUM 5.3 CVE-2026-66272 Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain a Missing Authentication for Critical Function vulnerability. An unauthenticate… Wyse Management Suite No fix yet Fix from $4,0002026-08-14 HIGH 7.7 CVE-2026-72670 A lower privileged user who holds only the privilege to read agent policies can read the entire configuration of a configured Fleet proxy. This would… No fix yet Fix from $4,9002026-08-13 MEDIUM 6.5 CVE-2026-58442 Repository migration SSRF via multi-answer DNS allow-list bypass No fix yet Fix from $4,0002026-08-13 MEDIUM 5.9 CVE-2026-58432 Missing Authorization and Authorization Bypass Through User-Controlled Key and Incorrect Permission Assignment for Critical Resource and Exposure of … No fix yet Fix from $4,0002026-08-13 HIGH 7.5 CVE-2026-58434 Private Repository Metadata Remains Accessible After Access Revocation No fix yet Fix from $4,9002026-08-13 MEDIUM 6.5 CVE-2026-57897 Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs No fix yet Fix from $4,0002026-08-13 HIGH 7.5 CVE-2026-58427 Private org member list leaked via /members API endpoint — incomplete fix for PR #38145 No fix yet Fix from $4,9002026-08-13 CRITICAL 9.1 CVE-2026-55982 OIDC userinfo Endpoint Returns Identity Claims Without Enforcing API Token Scopes No fix yet Fix from $5,7502026-08-13 HIGH 7.5 CVE-2026-73622 GitPython before 3.1.55 fails to disable environment variable expansion in Remote.create() and Submodule.add() URL handling, allowing attackers to ex… No fix yet Fix from $4,9002026-08-13 MEDIUM 6.5 CVE-2026-73604 Flowise before 3.1.3 contains an incomplete credential redaction vulnerability in the GET /api/v1/credentials/:id endpoint that returns decrypted sec… No fix yet Fix from $4,0002026-08-13 CRITICAL 9.1 CVE-2026-59503 CWE-200: Exposure of Sensitive Information to an Unauthorized Actor CWE-359: Exposure of Private Personal Information to an Unauthorized Actor No fix yet Fix from $5,7502026-08-13