Vulnerability index

Browse CVEs

7,720 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
HIGH 7.5 CVE-2026-46726 Improper Input Validation, Exposure of Sensitive Information to an Unauthorized Actor, Server-Side Request Forgery (SSRF) vulnerability in Apache Cam… Camel 4.14.8 / 4.18.3+ Fix from $1,9502026-07-06 HIGH 7.5 CVE-2026-58419 Notification API leaks private issue metadata after access revocation Patch available Fix from $1,9502026-07-03 MEDIUM 6.5 CVE-2026-56646 Exposure of sensitive information to an unauthorized actor in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing ove… Edge Chromium 150.0.4078.48+ Fix from $1,6002026-07-03 HIGH 7.5 CVE-2026-24451 Gitea 1.26.2 allows fork synchronization to continue after a parent repository changes from public to private, exposing data to a fork that should no… Patch available Fix from $1,9502026-07-03 HIGH 7.5 CVE-2026-25038 Gitea 1.26.2 allows unauthorized users to access labels of private organizations. Patch available Fix from $1,9502026-07-03 HIGH 8.5 CVE-2026-10055 In Eclipse Theia since version 1.26.0, the backend /services/request-service RPC accepts an attacker-controlled URL from any client connected to the … Mitigation only Fix from $1,9502026-07-03 MEDIUM 6.0 CVE-2026-55792 Craft CMS is a content management system (CMS). In versions starting from 4.0.0-RC1 and prior to 4.18.0, and 5.0.0-RC1 and above, prior to 5.10.0, th… Patch available Fix from $1,6002026-07-02 MEDIUM 5.3 CVE-2026-53467 ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-51 and 7.1.2-26, the MNG deco… Imagemagick 6.9.13-51 / 7.1.2-26+ Fix from $1,6002026-07-01 MEDIUM 6.5 CVE-2026-58033 Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with p… Mediawiki 1.43.9 / 1.44.6+ Fix from $1,6002026-07-01 HIGH 7.5 CVE-2026-58036 Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with p… Mediawiki Mitigation only Fix from $1,9502026-07-01 MEDIUM 5.7 CVE-2026-58024 Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with p… Mediawiki 1.43.9 / 1.44.6+ Fix from $1,6002026-07-01 MEDIUM 5.7 CVE-2026-58026 Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with p… Mediawiki 1.43.9 / 1.44.6+ Fix from $1,6002026-07-01 MEDIUM 6.5 CVE-2026-58027 Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation AbuseFilter. This vulnerability is associated with… Mediawiki 1.43.9 / 1.44.6+ Fix from $1,6002026-07-01 HIGH 7.5 CVE-2026-56300 Capgo before 12.128.2 contains unauthenticated security definer RPC functions get_user_id and get_org_perm_for_apikey that expose API key validity or… Mitigation only Fix from $1,9502026-06-30 MEDIUM 5.3 CVE-2026-56318 Capgo before 12.128.2 contains an information disclosure vulnerability in the /private/validate_password_compliance endpoint that returns different e… Mitigation only Fix from $1,6002026-06-30 HIGH 8.2 CVE-2026-54673 electron-updater allows for automatic updates for Electron apps. Prior to 9.7.0, the HTTP redirect handler (HttpExecutor.prepareRedirectUrlOptions) o… Patch available Fix from $1,9502026-06-30 MEDIUM 6.5 CVE-2026-14146 Inappropriate implementation in CSS in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to leak cross-origin data via a crafted HTML pa… Chrome 150.0.7871.47+ Fix from $1,6002026-06-30 MEDIUM 6.5 CVE-2026-14096 Inappropriate implementation in Input in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer p… Chrome 150.0.7871.47+ Fix from $1,6002026-06-30 MEDIUM 6.5 CVE-2026-14098 Inappropriate implementation in CSS in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to leak cross-origin data via a crafted HTML pa… Chrome 150.0.7871.46+ Fix from $1,6002026-06-30 MEDIUM 5.9 CVE-2026-14062 Inappropriate implementation in Views in Google Chrome on ChromeOS prior to 150.0.7871.47 allowed an attacker who convinced a user to install a malic… Chrome 150.0.7871.47+ Fix from $1,6002026-06-30 MEDIUM 5.3 CVE-2026-14049 Inappropriate implementation in GPU in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to obt… Chrome 150.0.7871.46+ Fix from $1,6002026-06-30 MEDIUM 6.5 CVE-2026-14004 Inappropriate implementation in CSS in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to leak cross-origin data via a crafted HTML pa… Chrome 150.0.7871.47+ Fix from $1,6002026-06-30 MEDIUM 6.5 CVE-2026-13810 Inappropriate implementation in Input in Google Chrome on Linux prior to 150.0.7871.47 allowed a remote attacker to obtain potentially sensitive info… Chrome 150.0.7871.47+ Fix from $1,6002026-06-30 HIGH 7.5 CVE-2026-9836 IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is affected by an information disclosure vulnerability. Infosphere Information Server after 11.7.1.6 Fix from $1,9502026-06-30 HIGH 7.5 CVE-2026-14161 Hospital Quening Management developed by Advantech has a Sensitive Data Exposure vulnerability, allowing unauthenticated remote attackers to access a… Mitigation only Fix from $1,9502026-06-30 MEDIUM 6.1 CVE-2026-46406 Claude Code is an agentic coding tool. From 2.1.59 until 2.1.128, the Claude Code /copy command wrote responses to a hardcoded, predictable path (/t… Claude Code 2.1.128+ Fix from $1,6002026-06-29 HIGH 7.7 CVE-2026-49984 Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.45 and 1.3.23, the local internal-storage backend validates user-supplied… Kestra 1.0.45 / 1.3.23+ Fix from $1,9502026-06-26 HIGH 8.2 CVE-2026-55188 RustFS is a distributed object storage system built in Rust. From 1.0.0-alpha.1 until 1.0.0-beta.9, RustFS contains an authorization bypass in the bu… Mitigation only Fix from $1,9502026-06-26 HIGH 7.5 CVE-2026-47193 OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, the journal diff endpoint discloses hidden historical … Mitigation only Fix from $1,9502026-06-26 MEDIUM 6.5 CVE-2026-44736 OpenProject is open-source, web-based project management software. Prior to 17.4.0, the GET /api/v3/relations endpoint allows any authenticated user … Mitigation only Fix from $1,6002026-06-26