Vulnerability index

Browse CVEs

7,720 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
HIGH 8.6 CVE-2026-59499 CWE-200: Exposure of Sensitive Information to an Unauthorized Actor No fix yet Fix from $4,9002026-08-13 MEDIUM 6.3 CVE-2026-73411 Shescape is a simple shell escape library for JavaScript. Prior to 2.1.14 and 3.0.1, getEscapeFunction in src/internal/unix/dash.js fails to escape ~… No fix yet Fix from $4,0002026-08-12 HIGH 7.5 CVE-2026-73406 Budibase is an open-source low-code platform. Prior to 3.39.32, GET /api/global/users/tenant/:id was listed in PUBLIC_ENDPOINTS in packages/worker/sr… No fix yet Fix from $4,9002026-08-12 MEDIUM 5.7 CVE-2026-73308 Budibase is an open-source low-code platform. Prior to 3.39.25, packages/server/src/api/controllers/automation.ts returned automation test results co… No fix yet Fix from $4,0002026-08-12 HIGH 8.6 CVE-2026-72804 SiYuan versions before v3.7.4 fail to validate publish-password tier in getGraph and getLocalGraph endpoints, allowing anonymous readers to retrieve … No fix yet Fix from $4,9002026-08-12 MEDIUM 5.3 CVE-2026-18673 When kuma-dp is configured with the Envoy admin API on a Unix domain socket, which is the default, its readiness service on TCP port 9902 - bound to … No fix yet Fix from $4,0002026-08-12 MEDIUM 6.5 CVE-2026-65017 Apache Airflow's Config API did not mask team-scoped sensitive configuration values in multi-team deployments. When an administrator has enabled mult… Airflow 3.3.1+ Fix from $4,0002026-08-12 MEDIUM 5.3 CVE-2026-19073 The Order Sync with Zendesk for WooCommerce WordPress plugin before 2.2.3 does not perform any capability check on one of its REST API endpoints, and… No fix yet Fix from $4,0002026-08-12 MEDIUM 6.5 CVE-2026-18943 The WPC Admin Columns WordPress plugin before 2.3.4 does not have authorisation checks in one of its AJAX actions, allowing users with a role as low … No fix yet Fix from $4,0002026-08-12 HIGH 7.5 CVE-2026-18049 The WP Photo Album Plus WordPress plugin before 9.2.07.002 does not perform any capability or nonce check on one of its public endpoint actions and b… No fix yet Fix from $4,9002026-08-12 HIGH 7.5 CVE-2026-16253 The Total Upkeep WordPress plugin before 1.17.3 does not adequately protect the secret that authorizes its backup-restore functionality and exposes … No fix yet Fix from $4,9002026-08-12 HIGH 7.5 CVE-2026-14925 The Import WP WordPress plugin before 2.14.23 does not perform any authorization check on one of its export-file download handlers, allowing unauthe… No fix yet Fix from $4,9002026-08-12 MEDIUM 6.5 CVE-2026-13168 The Eventin WordPress plugin before 4.1.20 does not properly restrict access to stored customer records, allowing users with contributor-level acces… No fix yet Fix from $4,0002026-08-12 MEDIUM 6.5 CVE-2026-12976 The LearnPress WordPress plugin before 4.4.4 does not verify that a user is enrolled in a course before processing AI-assistant requests against tha… No fix yet Fix from $4,0002026-08-12 HIGH 7.5 CVE-2026-73246 Kestra is an open-source, event-driven orchestration platform. Prior to 2.0.0-rc6, Kestra's worker/src/main/java/io/kestra/worker/endpoint/WorkerEndp… No fix yet Fix from $4,9002026-08-11 MEDIUM 5.9 CVE-2026-73230 Ente provides end-to-end encrypted cloud services and security tools. Prior to 2026.07.28, Ente 2of3 card format version 1 stored the secret byte len… No fix yet Fix from $4,0002026-08-11 HIGH 8.2 CVE-2026-48771 ishankportfolio is a portfolio website. Prior to version 1.0.1, contact form submissions could potentially be exposed due to improperly secured clien… No fix yet Fix from $4,9002026-08-11 HIGH 7.6 CVE-2026-48767 TypeBot is a chatbot builder tool. Versions prior to 3.17.0 allow a low-privilege guest member of a workspace to obtain a live Google Sheets OAuth ac… No fix yet Fix from $4,9002026-08-11 MEDIUM 5.3 CVE-2026-73082 Activepieces is an open source AI workflow automation platform. Prior to 0.82.0, the POST /api/v1/projects/:projectId/mcp-server/validate-agent-mcp-t… No fix yet Fix from $4,0002026-08-11 MEDIUM 6.5 CVE-2026-66301 Exposure of sensitive information to an unauthorized actor in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to disclose informat… Dynamics 365 No fix yet Fix from $4,0002026-08-11 HIGH 7.5 CVE-2026-65769 Exposure of sensitive information to an unauthorized actor in Microsoft Teams Mobile allows an unauthorized attacker to disclose information over a n… Teams 8.8.1+ Fix from $4,9002026-08-11 MEDIUM 6.5 CVE-2026-61921 Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network. Windows 10 1607 10.0.14393.9418 / 10.0.17763.9115+ Fix from $4,0002026-08-11 HIGH 7.5 CVE-2026-61924 Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network. Windows 10 1607 10.0.14393.9418 / 10.0.17763.9115+ Fix from $4,9002026-08-11 HIGH 7.5 CVE-2026-61918 Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network. Windows 10 1607 10.0.14393.9418 / 10.0.17763.9115+ Fix from $4,9002026-08-11 MEDIUM 5.6 CVE-2026-59130 No cwe for this issue in AMD Zen allows an authorized attacker to disclose information locally. Windows 10 1607 10.0.14393.9418 / 10.0.17763.9115+ Fix from $4,0002026-08-11 MEDIUM 5.5 CVE-2026-54123 Exposure of sensitive information to an unauthorized actor in Microsoft Defender for Endpoint allows an authorized attacker to disclose information l… Defender For Endpoint No fix yet Fix from $4,0002026-08-11 MEDIUM 6.3 CVE-2026-20737 Exposure of sensitive information to an unauthorized actor for some Intel(R) PROSet/Wireless WiFi Software for Windows within Ring 2: Device Drivers … No fix yet Fix from $4,0002026-08-11 HIGH 7.6 CVE-2026-48766 TypeBot is a chatbot builder tool. Versions prior to 3.17.0 allow a low-privilege guest member of a workspace to exfiltrate stored OpenAI-compatible … No fix yet Fix from $4,9002026-08-11 MEDIUM 6.2 CVE-2026-72744 Nuxt versions >= 4.4.7 and < 4.5.1, and >= 3.21.7 and < 3.21.10, contain an information disclosure vulnerability in the development server's Chrome D… No fix yet Fix from $4,0002026-08-11 HIGH 7.5 CVE-2026-72548 An information disclosure vulnerability in OpenSignLabs OpenSign through 2.37.0 allows unauthenticated remote attackers to retrieve any organisation … No fix yet Fix from $4,9002026-08-11