Vulnerability index

Browse CVEs

7,732 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
MEDIUM 6.9 CVE-2026-45080 Klaw is a self-service Apache Kafka Topic Management/Governance tool/portal. Prior to version 2.10.4, improper access control allows disclosure of pa… Mitigation only Fix from $1,6002026-06-02 HIGH 7.5 CVE-2026-45553 NiceGUI is a Python-based UI framework. Prior to version 3.12.0, ui.restructured_text() renders reStructuredText server-side with Docutils without di… Mitigation only Fix from $1,9502026-06-02 MEDIUM 6.5 CVE-2026-8993 D.Launcher 2 component of Slovak eID client ecosystem contains Improper URL Handler Processing vulnerability. Application registers multiple custom U… Mitigation only Fix from $1,6002026-06-02 CRITICAL 10.0 CVE-2026-40965 Cloud Foundry UAA versions v76.12.0 through v78.12.0 are vulnerable to a private key exposure. The server contains a vulnerability where EC (Elliptic… Mitigation only Fix from $2,3002026-06-01 MEDIUM 6.5 CVE-2026-45267 Nextcloud is an open source content collaboration platform. Prior to version 5.2.6, a missing permissions check allowed users to request reading form… Patch available Fix from $1,6002026-06-01 MEDIUM 5.3 CVE-2026-10254 A flaw has been found in SourceCodester Pet Grooming Management Software 1.0. Affected is an unknown function of the file /admin/. This manipulation … Mitigation only Fix from $1,6002026-06-01 MEDIUM 6.5 CVE-2026-42360 A bug in Apache Airflow's rendered-template field handling caused nested sensitive-key masking (e.g. nested `password` / `token` / `secret` / `api_ke… Airflow 3.2.2+ Fix from $1,6002026-06-01 MEDIUM 6.5 CVE-2026-42358 A bug in Apache Airflow's Variable response masker caused nested-key redaction (triggered by secret-suffixed key names like `password`, `token`, `sec… Airflow 3.2.2+ Fix from $1,6002026-06-01 MEDIUM 6.5 CVE-2026-45192 A bug in the GET `/api/v2/connections/{connection_id}` REST API endpoint in Apache Airflow allowed an authenticated UI/API user with Connection-read … Airflow 3.2.2+ Fix from $1,6002026-06-01 MEDIUM 5.7 CVE-2026-48189 An improper Input Validation vulnerability in OTRS Customer Backend module allows to access customer information which are restricted to other groups… Otrs 2026.4.1+ Fix from $1,6002026-06-01 MEDIUM 5.7 CVE-2026-48210 An improper default configuration in OTRS 2026.3.1 causes ticket article forwarding actions to enforce the “Is visible for customer” flag by default … Otrs Mitigation only Fix from $1,6002026-05-31 MEDIUM 5.3 CVE-2026-2128 The Breeze plugin for WordPress is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor in all versions up to, and including, 2.5… Mitigation only Fix from $1,6002026-05-29 MEDIUM 6.5 CVE-2026-9981 Inappropriate implementation in Skia in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to obtain potentially sensitive information f… Chrome 148.0.7778.215 / 148.0.7778.216+ Fix from $1,6002026-05-28 MEDIUM 6.5 CVE-2026-9912 Inappropriate implementation in GPU in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker to obtain potentially sensitive inf… Chrome 148.0.7778.216+ Fix from $1,6002026-05-28 CRITICAL 9.9 CVE-2026-44881 Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage Docker, Swarm, Kuber… Portainer 2.33.8 / 2.39.2+ Fix from $2,3002026-05-28 MEDIUM 5.3 CVE-2026-46830 Vulnerability in Oracle REST Data Services (component: Mongoapi). Supported versions that are affected are 24.2.0-26.1.0. Easily exploitable vulnera… Rest Data Services after 26.1.0 Fix from $1,6002026-05-28 MEDIUM 5.3 CVE-2026-46841 Vulnerability in Oracle REST Data Services (component: General). Supported versions that are affected are 24.2.0-26.1.0. Easily exploitable vulnerab… Rest Data Services after 26.1.0 Fix from $1,6002026-05-28 HIGH 7.5 CVE-2026-45332 Automad is a flat-file content management system and template engine. From 2.0.0-alpha.1 to 2.0.0-beta.27, a Broken Access Control vulnerability allo… Mitigation only Fix from $1,9502026-05-28 MEDIUM 6.9 CVE-2026-47136 RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.2, the RustFS console endpoint GET /rustfs/console/license returns p… Mitigation only Fix from $1,6002026-05-28 MEDIUM 5.3 CVE-2026-42878 FacturaScripts is an open source accounting and invoicing software. Prior to v2026, an unauthenticated information disclosure vulnerability in the In… Mitigation only Fix from $1,6002026-05-27 HIGH 7.7 CVE-2026-46427 Budibase is an open-source low-code platform. Prior to 3.38.3, removeSecrets at packages/server/src/sdk/workspace/datasources/datasources.ts masks on… Mitigation only Fix from $1,9502026-05-27 HIGH 7.4 CVE-2026-44460 FileRise is a self-hosted web-based file manager with multi-file upload, editing, and batch operations. Prior to 3.12.0, /api/totp_setup.php is calla… Mitigation only Fix from $1,9502026-05-27 MEDIUM 6.5 CVE-2026-8405 IBM Guardium Data Protection 12.2.1, and 12.2.2 's add-on feature of Guardium Data Protection named "Long Term Retention" (LTR) can expose sensitive … Guardium Data Protection Mitigation only Fix from $1,6002026-05-27 HIGH 7.3 CVE-2026-36539 Netis AC1200 Router NC21 V4.0.1.4296 exposes a CGI endpoint /cgi-bin/skk_get.cgi that returns the entire router configuration as a JSON response with… Mitigation only Fix from $1,9502026-05-27 MEDIUM 5.6 CVE-2026-24198 NVIDIA GPU Display Driver for Linux contains a vulnerability where an advanced attacker could use a race condition to leak sensitive memory, which m… No fix yet Fix from $1,6002026-05-26 MEDIUM 5.3 CVE-2026-9352 A weakness has been identified in NousResearch hermes-agent up to 2026.4.23. This issue affects the function _make_run_env of the file tools/environm… No fix yet Fix from $1,6002026-05-24 MEDIUM 5.3 CVE-2026-9349 A vulnerability was determined in calcom cal.diy up to 4.9.4. Affected by this issue is the function getServerSideProps of the file apps/web/modules/… Mitigation only Fix from $1,6002026-05-24 HIGH 7.1 CVE-2026-40166 authentik is an open-source identity provider. In versions prior to 2025.12.5 and 2026.2.0-rc1 through 2026.2.2, authenticated non-admin users with a… Mitigation only Fix from $1,9502026-05-22 HIGH 7.5 CVE-2026-44409 There is an an information disclosure vulnerability in ZTE MU5250. Due to improper configuration of the access control mechanism, attackers can obtai… Mu5250 Firmware Mitigation only Fix from $1,9502026-05-22 MEDIUM 5.3 CVE-2026-6826 Concrete CMS 9.5.0 and below  is vulnerable to unauthenticated file usage disclosure via missing permission check in the usage controller.  Any unaut… Concrete Cms 9.5.1+ Fix from $1,6002026-05-21