Vulnerability index

Browse CVEs

7,720 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
MEDIUM 5.5 CVE-2026-50434 Exposure of sensitive information to an unauthorized actor in Windows Push Notifications allows an authorized attacker to disclose information locall… Windows 10 21h2 10.0.19044.7548 / 10.0.19045.7548+ Fix from $1,6002026-07-14 HIGH 8.2 CVE-2026-50429 Out-of-bounds read in Windows Kernel allows an unauthorized attacker to disclose information over a network. Windows 10 1607 10.0.14393.9339 / 10.0.17763.9020+ Fix from $1,9502026-07-14 MEDIUM 5.5 CVE-2026-50430 Exposure of sensitive information to an unauthorized actor in Windows Push Notifications allows an authorized attacker to disclose information locall… Windows 10 1607 10.0.14393.9339 / 10.0.17763.9020+ Fix from $1,6002026-07-14 MEDIUM 5.5 CVE-2026-50431 Windows Quality of Service (QoS) Packet Scheduler Information Disclosure Vulnerability Windows 10 1607 10.0.14393.9339 / 10.0.17763.9020+ Fix from $1,6002026-07-14 HIGH 7.5 CVE-2026-50415 Exposure of sensitive information to an unauthorized actor in Windows Media allows an unauthorized attacker to disclose information over a network. Windows 10 1809 10.0.17763.9020 / 10.0.19044.7548+ Fix from $1,9502026-07-14 MEDIUM 5.5 CVE-2026-50409 Exposure of sensitive information to an unauthorized actor in Windows Overlay Filter allows an authorized attacker to disclose information locally. Windows 10 1607 10.0.14393.9339 / 10.0.17763.9020+ Fix from $1,6002026-07-14 MEDIUM 5.5 CVE-2026-50394 Exposure of sensitive information to an unauthorized actor in Windows Media allows an authorized attacker to disclose information locally. Windows 10 1607 10.0.14393.9339 / 10.0.17763.9020+ Fix from $1,6002026-07-14 MEDIUM 5.5 CVE-2026-50389 Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally. Windows 10 1607 10.0.14393.9339 / 10.0.17763.9020+ Fix from $1,6002026-07-14 MEDIUM 5.5 CVE-2026-50352 Exposure of sensitive information to an unauthorized actor in Windows Cryptographic Services allows an authorized attacker to disclose information lo… Windows 10 1607 10.0.14393.9339 / 10.0.17763.9020+ Fix from $1,6002026-07-14 MEDIUM 5.5 CVE-2026-50339 Exposure of sensitive information to an unauthorized actor in Windows Push Notifications allows an authorized attacker to disclose information locall… Windows 10 1809 10.0.17763.9020 / 10.0.19044.7548+ Fix from $1,6002026-07-14 MEDIUM 5.5 CVE-2026-50334 Exposure of sensitive information to an unauthorized actor in Windows Notification allows an authorized attacker to disclose information locally. Windows 10 1607 10.0.14393.9339 / 10.0.17763.9020+ Fix from $1,6002026-07-14 HIGH 7.8 CVE-2026-50697 Exposure of sensitive information to an unauthorized actor in Windows Common Log File System Driver allows an authorized attacker to elevate privileg… Windows 10 1607 10.0.14393.9339 / 10.0.17763.9020+ Fix from $1,9502026-07-14 MEDIUM 5.5 CVE-2026-50350 Exposure of sensitive information to an unauthorized actor in Windows Trusted Runtime Interface Driver allows an authorized attacker to disclose info… Windows 10 21h2 10.0.19044.7548 / 10.0.19045.7548+ Fix from $1,6002026-07-14 MEDIUM 6.2 CVE-2026-49807 Exposure of sensitive information to an unauthorized actor in Windows DirectX allows an unauthorized attacker to disclose information locally. Windows 10 1809 10.0.17763.9020 / 10.0.19044.7548+ Fix from $1,6002026-07-14 MEDIUM 6.5 CVE-2026-47282 Insufficiently protected credentials in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to disclose information over a network. Visual Studio Code 1.128.1+ Fix from $1,6002026-07-14 MEDIUM 5.5 CVE-2026-41087 Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally. Windows 10 1607 10.0.14393.9339 / 10.0.17763.9020+ Fix from $1,6002026-07-14 MEDIUM 5.5 CVE-2026-33842 Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally. Windows 10 1607 10.0.14393.9339 / 10.0.17763.9020+ Fix from $1,6002026-07-14 MEDIUM 5.5 CVE-2026-34328 Exposure of sensitive information to an unauthorized actor in Windows Audio Service allows an authorized attacker to disclose information locally. Windows 10 1809 10.0.17763.9020 / 10.0.19044.7548+ Fix from $1,6002026-07-14 MEDIUM 5.5 CVE-2026-34349 Exposure of sensitive information to an unauthorized actor in Windows Media allows an authorized attacker to disclose information locally. Windows 10 1809 10.0.17763.9020 / 10.0.19044.7548+ Fix from $1,6002026-07-14 HIGH 7.1 CVE-2026-55651 Easy!Appointments is a self hosted appointment scheduler. In version 1.5.2, an Excessive Data Exposure vulnerability in the customers search endpoint… Mitigation only Fix from $1,9502026-07-14 MEDIUM 6.9 CVE-2026-52837 Easy!Appointments is a self hosted appointment scheduler. In versions up to and including 1.5.2, the booking reschedule view at `/index.php/booking/r… Mitigation only Fix from $1,6002026-07-14 HIGH 7.5 CVE-2026-15075 In Eclipse Vert.x versions up to and including 4.5.29 (4.x branch) and 5.1.4 (5.x branch), DefaultRedirectHandler (vertx-core) propagates all request… Vert.x after 5.1.4 Fix from $1,9502026-07-14 HIGH 7.5 CVE-2026-10051 In Eclipse Jetty, a first HTTP/1.1 request with trailers causes the server to retain the trailers in subsequent requests performed over the same conn… Jetty 12.0.36 / 12.1.10+ Fix from $1,9502026-07-14 MEDIUM 5.3 CVE-2026-15530 A flaw has been found in WuzhiCMS up to 4.1.0. Affected by this vulnerability is the function config/listimage of the file /index.php?m=attachment&f=… Mitigation only Fix from $1,6002026-07-13 HIGH 8.2 CVE-2026-56259 Crawl4AI before 0.8.8 contains credential exfiltration vulnerabilities in the Docker API server that allow attackers to redirect LLM API calls to att… Crawl4ai 0.8.8+ Fix from $1,9502026-07-12 MEDIUM 5.3 CVE-2026-56336 Capgo before 12.128.2 contains an information disclosure vulnerability in the unauthenticated /private/sso/check-domain endpoint that returns interna… Mitigation only Fix from $1,6002026-07-12 HIGH 7.5 CVE-2026-56238 Capgo before 12.128.2 contains an information disclosure vulnerability in the Supabase PostgREST global_stats endpoint that allows unauthenticated at… Mitigation only Fix from $1,9502026-07-12 MEDIUM 5.3 CVE-2026-61454 The Grav Admin2 plugin (getgrav/grav-plugin-admin2) before 2.0.4 embeds a global JavaScript variable window.__GRAV_CONFIG__ in the Admin2 SPA bootstr… Mitigation only Fix from $1,6002026-07-11 HIGH 8.6 CVE-2026-61426 PraisonAI before 1.7.3 contains an insecure default configuration that binds to all interfaces with no API key requirement and wildcard CORS. Unauthe… Mitigation only Fix from $1,9502026-07-11 HIGH 7.5 CVE-2026-56303 Capgo before 12.128.2 contains an information disclosure vulnerability in the find_apikey_by_value PostgreSQL function marked SECURITY DEFINER and ex… Mitigation only Fix from $1,9502026-07-11