Vulnerability index

Browse CVEs

7,732 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
CRITICAL 9.1 CVE-2026-46910 Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Enterprise Infrastructure Security). Supported versions… Jd Edwards Enterpriseone Tools after 9.2.26.2 Fix from $2,3002026-06-17 MEDIUM 5.3 CVE-2026-46790 Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). The supported version that is affect… Webcenter Content Mitigation only Fix from $1,6002026-06-17 HIGH 7.5 CVE-2026-50870 An information disclosure vulnerability in the configuration endpoint of Ben Busby whoogle-search v1.2.3 allows attackers to obtain sensitive informa… Mitigation only Fix from $1,9502026-06-15 HIGH 7.5 CVE-2026-39007 An issue in Observeinc's Observe v.2026-01-28 and before allows a remote attacker to obtain sensitive information via the CSV Log export component. Mitigation only Fix from $1,9502026-06-15 MEDIUM 5.3 CVE-2026-8385 The WP Go Maps WordPress plugin before 10.0.10 does not properly enforce the marker approval filter on the admin-ajax fallback for its datatables ro… Mitigation only Fix from $1,6002026-06-15 MEDIUM 5.3 CVE-2026-12203 A vulnerability was found in HKUDS AI-Trader up to 74caf996f78dcc0c657df8365c8544678a16e215. This affects an unknown part of the file /api/research/a… Patch available Fix from $1,6002026-06-15 MEDIUM 6.5 CVE-2026-47124 Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. From version 1.4.0 to before version 2.0.9, any authe… Mitigation only Fix from $1,6002026-06-12 MEDIUM 5.3 CVE-2026-49397 Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. From version 2.0.0 to before version 2.0.14, private … Mitigation only Fix from $1,6002026-06-12 MEDIUM 5.3 CVE-2026-54396 An information disclosure vulnerability exists in the MISP AuthKey edit functionality. When a validation error occurs during an AuthKey edit request,… Patch available Fix from $1,6002026-06-12 MEDIUM 5.3 CVE-2026-45085 Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.4, 2026.3.0-latest to before 2026.3.1, and 2026.4.0-l… Discourse 2026.1.0 / 2026.1.4+ Fix from $1,6002026-06-12 MEDIUM 5.3 CVE-2026-47264 Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.4, 2026.3.0-latest to before 2026.3.1, and 2026.4.0-l… Discourse 2026.1.0 / 2026.1.4+ Fix from $1,6002026-06-12 MEDIUM 6.5 CVE-2026-44784 Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.4, 2026.3.0-latest to before 2026.3.1, and 2026.4.0-l… Discourse 2026.1.0 / 2026.1.4+ Fix from $1,6002026-06-12 HIGH 7.5 CVE-2026-44786 Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.4, 2026.3.0-latest to before 2026.3.1, and 2026.4.0-l… Discourse 2026.1.0 / 2026.1.4+ Fix from $1,9502026-06-12 MEDIUM 5.9 CVE-2026-53725 Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. From version 9.8.0 to before version 9.9.1-al… Patch available Fix from $1,6002026-06-12 MEDIUM 5.3 CVE-2026-6046 Mattermost versions 11.6.x <= 11.6.1, 11.5.x <= 11.5.4, 10.11.x <= 10.11.15, 10.11.x <= 10.11.16 fail to validate that a username returned during bot… Mattermost Server 10.11.17 / 11.5.5+ Fix from $1,6002026-06-12 MEDIUM 6.9 CVE-2026-44206 Frappe is a full-stack web application framework. Prior to versions 15.107.2 and 16.17.4, DB Schema Enumeration is possible through exploiting an end… Mitigation only Fix from $1,6002026-06-12 MEDIUM 5.7 CVE-2026-47177 Quest Bot is an opensource modern Discord Bot built for moderation, utilities and support. Prior to version 1.0.4, a user who can configure bot setti… Mitigation only Fix from $1,6002026-06-11 MEDIUM 5.7 CVE-2026-47176 Quest Bot is an opensource modern Discord Bot built for moderation, utilities and support. Prior to version 1.0.4, a user who can configure bot setti… Mitigation only Fix from $1,6002026-06-11 HIGH 7.5 CVE-2026-44486 Axios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16.0, Axios’ Node.js HTTP adapter can leak proxy credentials … Axios 0.32.0 / 1.16.0+ Fix from $1,9502026-06-11 MEDIUM 5.1 CVE-2026-53912 Cerebrate before version 1.37 exposed credential material from self-registration requests. The self-registration workflow stored the registrant’s has… Patch available Fix from $1,6002026-06-11 MEDIUM 5.5 CVE-2026-49219 ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-48 and 7.1.2-24, an incorrect… Imagemagick 6.9.13-48 / 7.1.2-24+ Fix from $1,6002026-06-10 MEDIUM 6.5 CVE-2026-48855 Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Erlang OTP ssh (ssh_sftpd module) allows File Discovery. The SSH_FXP_REA… Erlang\/otp 5.2.11.8 / 5.5.2.1+ Fix from $1,6002026-06-10 MEDIUM 6.5 CVE-2026-45329 ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.5.4 and 6.0, several ESP-TEE secure-service wrappers in esp_se… Esp Idf Patch available Fix from $1,6002026-06-10 HIGH 7.5 CVE-2026-36719 An information disclosure vulnerability in the /api/v1/user/info endpoint of AgentChat v2.3.0 allows unauthenticated attackers to obtain sensitive in… Mitigation only Fix from $1,9502026-06-09 HIGH 7.5 CVE-2026-50508EPSS 9% Exposure of sensitive information to an unauthorized actor in Windows NTLM allows an unauthorized attacker to perform spoofing over a network. Windows 10 1607 10.0.14393.9234 / 10.0.19045.7417+ Fix from $1,9502026-06-09 MEDIUM 6.5 CVE-2026-47284 Exposure of sensitive information to an unauthorized actor in Visual Studio Code allows an unauthorized attacker to disclose information over a netwo… Visual Studio Code 1.123.1+ Fix from $1,6002026-06-09 MEDIUM 5.5 CVE-2026-45594 Exposure of sensitive information to an unauthorized actor in Windows Application Identity (AppID) Subsystem allows an authorized attacker to disclos… Windows 10 1607 10.0.14393.9234 / 10.0.17763.8880+ Fix from $1,6002026-06-09 MEDIUM 5.5 CVE-2026-42973 Exposure of sensitive information to an unauthorized actor in Windows Push Notifications allows an authorized attacker to disclose information locall… Windows 10 1607 10.0.14393.9234 / 10.0.17763.8880+ Fix from $1,6002026-06-09 MEDIUM 5.5 CVE-2026-42970 Exposure of sensitive information to an unauthorized actor in Windows Push Notifications allows an authorized attacker to disclose information locall… Windows 10 1607 10.0.14393.9234 / 10.0.17763.8880+ Fix from $1,6002026-06-09 MEDIUM 5.5 CVE-2026-42971 Exposure of sensitive information to an unauthorized actor in Windows Push Notifications allows an authorized attacker to disclose information locall… Windows 10 1607 10.0.14393.9234 / 10.0.17763.8880+ Fix from $1,6002026-06-09