Vulnerability index

Browse CVEs

7,720 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
HIGH 7.5 CVE-2026-57231 Podman is a tool for managing OCI containers and pods. From 1.8.1 until 5.8.4, a container image that contains a environment variable with just a key… Podman 5.8.4+ Fix from $1,9502026-06-26 HIGH 7.5 CVE-2026-37452 Insecure Permissions vulnerability in MSI NBFoundation Service v.2.0.2506.1201 allows a remote attacker to obtain sensitive information via the MSIAP… Mitigation only Fix from $1,9502026-06-25 HIGH 7.5 CVE-2026-37453 Insecure Permissions vulnerability in MSI NBFoundation Service v.2.0.2506.1201 allows a remote attacker to obtain sensitive information via the MSI_S… Center 2.0.70.0+ Fix from $1,9502026-06-25 HIGH 7.5 CVE-2026-37454 Insecure Permissions vulnerability in MSI NBFoundation Service v.2.0.2506.1201 allows a remote attacker to obtain sensitive information via the 3DES-… Center 2.0.70.0+ Fix from $1,9502026-06-25 MEDIUM 6.5 CVE-2026-55180 pnpm is a package manager. Prior to 10.34.2 and 11.5.3, pnpm and pacquet expanded ${ENV_VAR} placeholders from repository-controlled .npmrc and pnpm-… Pnpm 10.34.2 / 11.5.3+ Fix from $1,6002026-06-25 MEDIUM 6.5 CVE-2026-50017 pnpm is a package manager. Prior to 10.34.0 and 11.4.0, pnpm can send user-level unscoped npm authentication credentials to a registry chosen by a re… Pnpm 10.34.0 / 11.4.0+ Fix from $1,6002026-06-25 MEDIUM 6.5 CVE-2026-9153 Arbitrary File Read vulnerability in Rapid7 InsightConnect Sed Plugin on Linux allows authenticated attackers to read arbitrary files via the express… Sed Mitigation only Fix from $1,6002026-06-25 MEDIUM 5.5 CVE-2026-52815 Gogs is an open source self-hosted Git service. Prior to 0.14.3, Gogs has an unauthenticated information disclosure vulnerability. The GET /api/v1/or… Mitigation only Fix from $1,6002026-06-24 MEDIUM 5.5 CVE-2026-32315 motionEye (mEye) is an online interface for motion software, a video surveillance program with motion detection. Versions prior to 0.44.0 create the … Mitigation only Fix from $1,6002026-06-24 HIGH 8.6 CVE-2026-47389 Mastodon is a free, open-source social network server based on ActivityPub. Prior to 4.5.10, 4.4.17, and 4.3.23, when using Ruby versions older than … Mitigation only Fix from $1,9502026-06-24 MEDIUM 5.3 CVE-2026-53949 Ghost is a Node.js content management system. From 5.46.1 until 6.21.2, the validation applied to filters on the public API endpoints could be partia… No fix yet Fix from $1,6002026-06-24 HIGH 8.6 CVE-2026-49269 Apple M1 GPUs retain register file data between compute shader dispatches from different processes. A sandboxed Metal attacker app can run a GPU read… Mitigation only Fix from $1,9502026-06-24 MEDIUM 5.3 CVE-2026-56337 Capgo before 12.128.2 contains an information disclosure vulnerability in the public.exist_app_v2 RPC function that allows unauthenticated attackers … Mitigation only Fix from $1,6002026-06-24 HIGH 7.1 CVE-2026-56244 Capgo before 12.128.2 allows non-admin API keys to read webhook signing secrets via Supabase REST due to insufficient row-level security policies on … Mitigation only Fix from $1,9502026-06-24 MEDIUM 5.3 CVE-2026-9612 The WhatsOrder – Instant Checkout for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and inc… Mitigation only Fix from $1,6002026-06-24 MEDIUM 6.9 CVE-2026-47379 NocoDB is software for building databases as spreadsheets. Prior to 2026.05.1, the shared-view password check fell back to strict-equality (===) comp… Mitigation only Fix from $1,6002026-06-23 CRITICAL 9.1 CVE-2026-54316 Claude Code is an agentic coding tool. From 0.2.54 until 2.1.163, because the hostname huggingface.co was pre-approved as a bare hostname for the We… Claude Code 2.1.163+ Fix from $2,3002026-06-23 HIGH 7.6 CVE-2026-54317 Home Assistant is open source home automation software that puts local control and privacy first. Prior to 2026.6.0, the Konnected integration regist… Home Assistant 2026.6.0+ Fix from $1,9502026-06-23 CRITICAL 9.6 CVE-2026-55447 Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.2, by controlling a files that are digested into the RAG,… Langflow 1.9.2+ Fix from $2,3002026-06-23 CRITICAL 9.3 CVE-2026-55450EPSS 12% Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.1, unauthenticated users can upload any amount of data to… Langflow 1.9.1+ Fix from $2,3002026-06-23 HIGH 7.7 CVE-2026-54304 n8n is an open source workflow automation platform. Prior to 1.123.55, 2.25.7, and 2.26.1, an authenticated user with permission to create or modify … N8n 1.123.55 / 2.25.7+ Fix from $1,9502026-06-23 CRITICAL 9.9 CVE-2026-54305 n8n is an open source workflow automation platform. Prior to 1.123.55, 2.25.7, and 2.26.2, three EE endpoints used by the Dynamic Credentials feature… N8n 1.123.55 / 2.25.7+ Fix from $2,3002026-06-23 HIGH 7.4 CVE-2026-50019 yt-dlp is a command-line audio/video downloader. From 2023.09.24 until 2026.06.09, if curl is used as an external downloader for yt-dlp, cookies may … Yt Dlp 2026.06.09+ Fix from $1,9502026-06-23 CRITICAL 10.0 CVE-2026-27604 FOSSBilling is a free, open-source billing and client management system. Starting in version 0.5.4 and prior to version 0.8.0, an authorization bypas… Mitigation only Fix from $2,3002026-06-23 HIGH 7.5 CVE-2026-56322 Capgo before 12.128.2 contains an information disclosure vulnerability in the unauthenticated /updates endpoint that resolves the defaultChannel para… Mitigation only Fix from $1,9502026-06-23 HIGH 7.5 CVE-2026-53923 vLLM is an inference and serving engine for large language models (LLMs). From 0.5.5 until 0.23.1rc0, integer truncation of tensor dimensions in vLLM… Vllm 0.23.1+ Fix from $1,9502026-06-22 HIGH 7.5 CVE-2026-56323 Capgo before 12.128.2 contains an information disclosure vulnerability in the /functions/v1/channel_self endpoint that allows unauthenticated attacke… Mitigation only Fix from $1,9502026-06-22 MEDIUM 6.1 CVE-2026-54276 AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, DigestAuthMiddleware can send an authentication resp… Aiohttp 3.14.1+ Fix from $1,6002026-06-22 HIGH 7.5 CVE-2026-53571 Vite is a frontend tooling framework for JavaScript. Prior to 8.0.16, 7.3.5, and 6.4.3, the contents of files that are specified by server.fs.deny ca… Vite 0.1.24 / 6.4.3+ Fix from $1,9502026-06-22 MEDIUM 6.1 CVE-2026-50169 Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 22.0.0-r… Angular 19.2.23 / 20.3.22+ Fix from $1,6002026-06-22