Vulnerability index

Browse CVEs

7,732 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
MEDIUM 5.5 CVE-2026-42972 Exposure of sensitive information to an unauthorized actor in Windows Hyper-V allows an authorized attacker to disclose information locally. Windows 10 1607 10.0.14393.9234 / 10.0.17763.8880+ Fix from $1,6002026-06-09 MEDIUM 5.5 CVE-2026-42906 Exposure of sensitive information to an unauthorized actor in Windows Shell allows an authorized attacker to disclose information locally. Windows 10 21h2 10.0.19044.7417 / 10.0.19045.7417+ Fix from $1,6002026-06-09 MEDIUM 6.5 CVE-2026-42907 Exposure of sensitive information to an unauthorized actor in Windows Shell allows an authorized attacker to disclose information over a network. Windows 10 1809 10.0.17763.8880 / 10.0.19044.7417+ Fix from $1,6002026-06-09 HIGH 8.0 CVE-2026-0411 An information disclosure vulnerability in the NETGEAR Orbi satellites (RBR/RBE/RBS Series) could allow a user connected to your network to gain admi… Rbe970 Firmware 4.4.2.2 / 6.3.8.11+ Fix from $1,9502026-06-09 HIGH 7.1 CVE-2026-49742 Backend users with file download permissions were able to download files from the fallback storage of the file abstraction layer (FAL) via the Media … Patch available Fix from $1,9502026-06-09 MEDIUM 5.3 CVE-2026-47351 Backend users were able to insert arbitrary records and files into the TYPO3 clipboard without proper read permission checks, which allowed users to … Patch available Fix from $1,6002026-06-09 MEDIUM 6.5 CVE-2026-7542 The Slider Revolution plugin for WordPress is vulnerable to Sensitive Information Disclosure in versions 7.0 to 7.0.10. This is due to three compound… Mitigation only Fix from $1,6002026-06-09 MEDIUM 6.5 CVE-2026-34905 Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. The unl… Answer 2.0.1+ Fix from $1,6002026-06-09 MEDIUM 5.5 CVE-2026-41980 Permission control vulnerability in the file preview module. Impact: Successful exploitation of this vulnerability may affect service confidentiality. No fix yet Fix from $1,6002026-06-09 MEDIUM 6.5 CVE-2026-46443 Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, when credentials are fetched with a … Flowise 3.1.2+ Fix from $1,6002026-06-08 MEDIUM 5.3 CVE-2026-11458 A weakness has been identified in erzhongxmu JeeWMS up to 141740afb2ba14d441c82a833d0a418d07ca2d69. This issue affects some unknown processing of the… Mitigation only Fix from $1,6002026-06-07 HIGH 8.3 CVE-2026-11424 A server-side request forgery (SSRF) vulnerability exists in a GraphQL service component shared by Altium Enterprise Server and Altium 365. An authen… Mitigation only Fix from $1,9502026-06-05 HIGH 8.3 CVE-2026-11431 A path traversal vulnerability exists in the Projects Service download endpoint shared by Altium Enterprise Server and Altium 365. An authenticated u… Mitigation only Fix from $1,9502026-06-05 HIGH 7.4 CVE-2026-45300 The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. Versions on the… Async Http Client 2.15.0 / 3.0.10+ Fix from $1,9502026-06-05 CRITICAL 9.3 CVE-2026-46395 HAX CMS helps manage microsite universe with PHP or NodeJs backends. Prior to version 26.0.0, the `hmacBase64()` function in the HAXcms Node.js backe… Mitigation only Fix from $2,3002026-06-05 MEDIUM 6.5 CVE-2026-11271 Inappropriate implementation in Passwords in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who convinced a user to engage in specifi… Chrome 149.0.7827.53+ Fix from $1,6002026-06-05 MEDIUM 6.5 CVE-2026-47655 Exposure of sensitive information to an unauthorized actor in Microsoft Graph allows an authorized attacker to disclose information over a network. Graph No fix yet Fix from $1,6002026-06-04 MEDIUM 6.5 CVE-2026-11209 Inappropriate implementation in Passwords in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process … Chrome 149.0.7827.53+ Fix from $1,6002026-06-04 MEDIUM 6.5 CVE-2026-11203 Inappropriate implementation in GPU in Google Chrome on Mac prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted … Chrome 149.0.7827.53+ Fix from $1,6002026-06-04 MEDIUM 6.5 CVE-2026-11182 Inappropriate implementation in SVG in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML pa… Chrome 149.0.7827.53+ Fix from $1,6002026-06-04 MEDIUM 6.5 CVE-2026-11180 Inappropriate implementation in SVG in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML pa… Chrome 149.0.7827.53+ Fix from $1,6002026-06-04 MEDIUM 6.5 CVE-2026-11168 Inappropriate implementation in Extensions in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process… Chrome 149.0.7827.53+ Fix from $1,6002026-06-04 HIGH 8.2 CVE-2025-69755 An issue in Neterbit NW-431F Router vNW-431F-20241014-IR03 allows a remote attacker to obtain sensitive information and execute arbitrary code via a … Mitigation only Fix from $1,9502026-06-04 HIGH 7.5 CVE-2026-50210 The device encrypts data using AES-CBC with static zero-filled Initialization Vectors (IVs), making it susceptible to replay attacks and known-plaint… Connect M6e 5g Firmware Mitigation only Fix from $1,9502026-06-04 HIGH 7.5 CVE-2026-49193 Overly permissive configuration settings on cloud storage containers expose active telemetry information publicly to the internet. Connect M6e 5g Firmware Mitigation only Fix from $1,9502026-06-04 HIGH 7.5 CVE-2026-49187 The hard-coded APK resource files never expire, and the shared scepter leads to information leaks and potential misuse. Connect M6e 5g Firmware No fix yet Fix from $1,9502026-06-04 MEDIUM 6.9 CVE-2026-40495 FOSSBilling is a free, open-source billing and client management system. Versions prior to 0.8.0 leak the exact system version through asset cache bu… Mitigation only Fix from $1,6002026-06-03 HIGH 7.3 CVE-2026-36611 Mercusys AC12G (EU) V1 with firmware AC12G(EU)_V1_200909 returns 128 bytes of uninitialized buffer when receiving POST requests without SOAPAction he… Mitigation only Fix from $1,9502026-06-03 HIGH 7.5 CVE-2026-41032 It is possible for an unauthenticated adjacent attacker to download log files of the controller, which may disclose some restricted information. Mitigation only Fix from $1,9502026-06-03 CRITICAL 9.6 CVE-2026-32625 LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. In versions up to and including 0.8.3, the Model Context Protocol (MCP) s… Librechat 0.8.4+ Fix from $2,3002026-06-02