Vulnerability index

Browse CVEs

7,720 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
MEDIUM 5.3 CVE-2026-58149 Joomla Extension - joomdonation.com - User enumeration in Events Booking < 5.8.0 - The Joomla extension Events Booking is vulnerable to an unauthenti… No fix yet Fix from $1,6002026-07-17 MEDIUM 5.3 CVE-2024-23568 HCL Aftermarket EPC is vulnerable to attacks since the server software version used by the application is revealed by the web server. Displaying vers… No fix yet Fix from $1,6002026-07-17 MEDIUM 5.3 CVE-2026-13402 The Royal Addons for Elementor WordPress plugin before 1.7.1063 does not check the post status of menu items or the templates they reference in one … No fix yet Fix from $1,6002026-07-17 MEDIUM 6.5 CVE-2026-14503 The pCloud WP Backup plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.0.3 via the wp2pcl_… No fix yet Fix from $1,6002026-07-17 MEDIUM 5.7 CVE-2024-32387 An issue in Kerlink Kerlink Wirnet iStation 868 KerOS v.4.3.3_20200803132042 allows a remote attacker to obtain sensitive information via the communi… No fix yet Fix from $1,6002026-07-16 MEDIUM 5.3 CVE-2026-47751 Claude Code Action is a general-purpose GitHub action that runs Claude Code on GitHub pull requests and issues. Prior to 1.0.74, because the action c… No fix yet Fix from $1,6002026-07-16 MEDIUM 5.9 CVE-2026-55406 Buffa is a pure-Rust Protocol Buffers implementation with first-class protobuf editions support. Prior to 0.7.0, a soundness bug in the OwnedView<V> … No fix yet Fix from $1,6002026-07-16 HIGH 7.5 CVE-2026-53598 Prompty is a markdown file format (.prompty) for LLM prompts. Prior to 2.0.0-beta.2, Prompty loaders expanded ${file:...} references in .prompty fron… No fix yet Fix from $1,9502026-07-16 MEDIUM 5.3 CVE-2026-56456 HCL DFXAnalytics is affected by an Internal File Path Disclosure vulnerability. The application dashboard inadvertently leaks sensitive information r… Dfxanalytics after 3.0 Fix from $1,6002026-07-16 HIGH 7.2 CVE-2026-35140 HCL DFXAnalytics is affected by a Missing Secure Attribute in Encrypted Session (SSL) Cookie vulnerability. The application fails to set the "secure"… Dfxanalytics after 3.0 Fix from $1,9502026-07-16 HIGH 8.2 CVE-2026-35142 HCL DFXAnalytics is affected by an Internal IP Address Disclosure vulnerability. The application includes internal IP address details within its gene… Dfxanalytics after 3.0 Fix from $1,9502026-07-16 MEDIUM 6.5 CVE-2026-35143 HCL DFXAnalytics is affected by a Missing SameSite Attribute vulnerability. The application fails to set the "SameSite" attribute on session cookies … Dfxanalytics after 3.0 Fix from $1,6002026-07-16 MEDIUM 5.4 CVE-2026-55608 n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. Prior to 2.57.4, multi-tenant HTTP… N8n Mcp 2.57.4+ Fix from $1,6002026-07-15 MEDIUM 6.8 CVE-2026-52888 NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. In 2.0.59 and earlier, NocoBase @noc… Mitigation only Fix from $1,6002026-07-15 MEDIUM 6.5 CVE-2026-45737 Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. From 3.2.0 until 3.2.12, 3.3.10, and 3.4.2, Argo CD ServerSideDiff can expo… Argo Cd 3.2.12 / 3.3.10+ Fix from $1,6002026-07-15 MEDIUM 5.5 CVE-2026-49988 Repomix is a tool that packs repositories into AI-friendly files. Prior to 1.14.1, the Repomix MCP server attach_packed_output and read_repomix_outpu… Repomix Mitigation only Fix from $1,6002026-07-15 MEDIUM 6.5 CVE-2026-20298 In Splunk Enterprise versions below 10.4.1, 10.2.5, 10.0.8, and 9.4.13, and Splunk Cloud Platform versions below 10.5.2605.0, 10.4.2604.6, 10.3.2512.… Splunk 9.4.13 / 10.0.8+ Fix from $1,6002026-07-15 HIGH 7.5 CVE-2026-45793 Composer is a dependency Manager for the PHP language. Prior to 1.10.28, 2.2.28, and 2.9.8, Composer\IO\BaseIO::loadConfiguration() validates GitHub … No fix yet Fix from $1,9502026-07-15 MEDIUM 6.6 CVE-2026-58554 Permission control vulnerability in the Settings module. Impact: Successful exploitation of this vulnerability may affect service confidentiality. No fix yet Fix from $1,6002026-07-15 MEDIUM 6.5 CVE-2026-13230 An information disclosure vulnerability was identified in TP-Link Kasa EC70 v4 and EC71 v4 in the local discovery mechanism, which exposes sensitive … Kasa Ec70 Firmware 2.4.1+ Fix from $1,6002026-07-15 CRITICAL 9.1 CVE-2026-52101 An issue in andreimarcu linux-server v.1.0 through v.2.3.8 allows a remote attacker to obtain sensitive information via the function uploadRemote fun… Mitigation only Fix from $2,3002026-07-14 HIGH 7.7 CVE-2026-49853 Tornado is a Python web framework and asynchronous networking library. Prior to 6.5.6, SimpleAsyncHTTPClient shallow-copied redirected requests and r… Mitigation only Fix from $1,9502026-07-14 HIGH 7.8 CVE-2026-57095 Exposure of sensitive information to an unauthorized actor in Windows Win32K allows an unauthorized attacker to elevate privileges locally. Windows 10 1607 10.0.14393.9339 / 10.0.17763.9020+ Fix from $1,9502026-07-14 HIGH 8.8 CVE-2026-57102 Inclusion of functionality from untrusted control sphere in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a ne… Visual Studio Code 1.128.1+ Fix from $1,9502026-07-14 MEDIUM 5.5 CVE-2026-56184 Exposure of sensitive information to an unauthorized actor in Windows Win32K allows an authorized attacker to disclose information locally. Windows 10 21h2 10.0.19044.7548 / 10.0.19045.7548+ Fix from $1,6002026-07-14 MEDIUM 5.5 CVE-2026-50681 Exposure of sensitive information to an unauthorized actor in Windows Cryptographic Services allows an authorized attacker to disclose information lo… Windows 10 1607 10.0.14393.9339 / 10.0.17763.9020+ Fix from $1,6002026-07-14 MEDIUM 5.5 CVE-2026-50483 Exposure of sensitive information to an unauthorized actor in Microsoft Graphics Component allows an authorized attacker to disclose information loca… Windows 11 24h2 10.0.26100.8875 / 10.0.26100.33158+ Fix from $1,6002026-07-14 MEDIUM 5.5 CVE-2026-50473 Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally. Windows 10 1607 10.0.14393.9339 / 10.0.17763.9020+ Fix from $1,6002026-07-14 MEDIUM 5.5 CVE-2026-50456 Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally. Windows 10 1607 10.0.14393.9339 / 10.0.17763.9020+ Fix from $1,6002026-07-14 MEDIUM 5.5 CVE-2026-50442 Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally. Windows 10 1607 10.0.14393.9339 / 10.0.17763.9020+ Fix from $1,6002026-07-14