Vulnerability index

Browse CVEs

7,720 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
MEDIUM 5.3 CVE-2026-6801 The Context Blog theme for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.3.5 via the context_blog… Mitigation only Fix from $1,6002026-07-11 MEDIUM 5.3 CVE-2026-10865 The Cost Calculator Builder plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.0.11 via the… Mitigation only Fix from $1,6002026-07-11 MEDIUM 5.3 CVE-2026-12426 The Members – Membership & User Role Editor Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and in… Mitigation only Fix from $1,6002026-07-11 MEDIUM 6.9 CVE-2026-59155 Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. Prior to 2.2.5, the GET /api/v1/ddns and GET /api/v1/… Patch available Fix from $1,6002026-07-10 HIGH 8.3 CVE-2026-55882 Tilt defines dev environments as code for microservice apps on Kubernetes. From 0.19.5 through 0.37.3, the Tilt HUD server mounts Go net/http/pprof h… Patch available Fix from $1,9502026-07-10 HIGH 7.5 CVE-2026-57219 RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.20, 4.1.11, and 4.2.6, the obsolete GET /api/auth endpoint can disclose the OAuth… Rabbitmq Server 4.2.6+ Fix from $1,9502026-07-10 MEDIUM 5.3 CVE-2026-57474 Deloitte AI Assist for Customer disclosed some configuration information through public-facing API endpoints that accepted unauthenticated requests. … Ai Assist For Customer 2026-03-25+ Fix from $1,6002026-07-10 CRITICAL 9.9 CVE-2026-55500 9Router is an AI router & token saver. Prior to 0.4.80, the /api/settings/database endpoint allows full database export (containing all credentials, … Patch available Fix from $2,3002026-07-10 MEDIUM 5.3 CVE-2026-57994 phpMyFAQ before 4.1.5 applies inconsistent active=yes and publication-date filtering across its public FAQ API endpoints, allowing unauthenticated at… Mitigation only Fix from $1,6002026-07-10 MEDIUM 5.3 CVE-2026-59828 Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, post revisions that should be hidden from regul… Discourse 2026.1.5 / 2026.4.2+ Fix from $1,6002026-07-09 HIGH 7.5 CVE-2026-49256 Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, restricted tag and tag-group names attached to … Discourse 2026.1.5 / 2026.4.2+ Fix from $1,9502026-07-09 MEDIUM 5.3 CVE-2026-45780 Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, EventSerializer could expose invited group name… Patch available Fix from $1,6002026-07-09 HIGH 7.5 CVE-2026-45788 Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, secure uploads could be exposed by pull_hotlink… Discourse 2026.1.5 / 2026.4.2+ Fix from $1,9502026-07-09 HIGH 7.5 CVE-2025-63579 Unauthorized use of Kyocera printers, allows all information stored in the Kyocera address book to be exported. The security measure that encrypts in… Mitigation only Fix from $1,9502026-07-09 HIGH 7.5 CVE-2026-59720 Hoppscotch is an open source API development ecosystem. Prior to 2026.6.0, mock server creation in mock-server.service.ts does not persist the isPubl… Patch available Fix from $1,9502026-07-09 MEDIUM 6.5 CVE-2026-59222 Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.7.0 before 0.10.0, GET /api/v1/channels//members returne… Open Webui 0.10.0+ Fix from $1,6002026-07-09 CRITICAL 9.0 CVE-2026-59216 Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.10.0, get_event_call delivered execute:python and ex… Open Webui 0.10.0+ Fix from $2,3002026-07-09 MEDIUM 6.5 CVE-2026-59209 n8n is an open source workflow automation platform. Prior to 1.123.61, 2.27.4, and, 2.28.1, an authenticated member with use-only editor access to a … N8n 1.123.61 / 2.27.4+ Fix from $1,6002026-07-09 MEDIUM 6.3 CVE-2026-15044 A flaw was found in the TrustyAI Service Operator. When deploying services like gorch or NemoGuardrails, if a specific security setting is not enable… Mitigation only Fix from $1,6002026-07-08 MEDIUM 5.3 CVE-2026-56284 Capgo (Cap-go/capgo) before 12.128.2 contains an information disclosure vulnerability in the Supabase PostgREST RPC function public.get_total_metrics… Mitigation only Fix from $1,6002026-07-08 HIGH 7.5 CVE-2026-56226 Capgo (Cap-go/capgo) before 12.128.2 exposes the Supabase PostgREST RPC function public.get_orgs_v6(userid uuid), which is SECURITY DEFINER and grant… Mitigation only Fix from $1,9502026-07-08 MEDIUM 6.5 CVE-2026-44877 An unauthenticated remote disclosure vulnerability has been identified in HPE Networking Instant On 1830, 1930, and 1960 Switches. Successful exploit… Mitigation only Fix from $1,6002026-07-07 MEDIUM 6.5 CVE-2026-48828 The Bulk Variables API in Apache Airflow called the redactor without passing the variable's key, so the key-based `should_hide_value_for_key` check (… Airflow 3.3.0+ Fix from $1,6002026-07-07 MEDIUM 6.5 CVE-2026-48892 The Config API in Apache Airflow surfaced per-key secrets-backend overrides (environment variables like `AIRFLOW__SECRETS__BACKEND_KWARG__SECRET_ID` … Airflow 3.3.0+ Fix from $1,6002026-07-07 MEDIUM 6.5 CVE-2026-49487 In Apache Airflow before 3.3.0, the REST API task-instance detail and list endpoints returned a deferred task's trigger kwargs without masking. When … Airflow 3.3.0+ Fix from $1,6002026-07-07 MEDIUM 6.9 CVE-2026-53647 FOSSBilling is a free, open-source billing and client management system. In versions 0.5.3 through 0.7.2, the Guest `serviceapikey/get_info` API endp… Mitigation only Fix from $1,6002026-07-07 HIGH 8.7 CVE-2026-53643 FOSSBilling is a free, open-source billing and client management system. Versions prior to 0.8.0 allow low-privileged staff accounts to perform unaut… Mitigation only Fix from $1,9502026-07-06 MEDIUM 6.5 CVE-2026-14898 The OpenAI Codex desktop app for macOS rendered remote images from Markdown in model responses. An attacker who could place an indirect prompt inject… Mitigation only Fix from $1,6002026-07-06 HIGH 7.5 CVE-2026-55994 Improper Input Validation, Exposure of Sensitive Information to an Unauthorized Actor, Server-Side Request Forgery (SSRF) vulnerability in Apache Cam… Camel 4.18.3 / 4.21.0+ Fix from $1,9502026-07-06 HIGH 7.5 CVE-2026-55993 Improper Input Validation, Exposure of Sensitive Information to an Unauthorized Actor, Server-Side Request Forgery (SSRF) vulnerability in Apache Cam… Camel 4.14.8 / 4.18.3+ Fix from $1,9502026-07-06