Vulnerability index

Browse CVEs

7,732 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
CRITICAL 9.4 CVE-2026-9129 A path traversal vulnerability exists in the Altium Enterprise Server Viewer StorageController due to improper handling of file path route parameters… Mitigation only Fix from $2,3002026-05-20 MEDIUM 6.5 CVE-2025-31985 HCL BigFix Service Management (SM) is affected by a security misconfiguration due to a missing or insecure “X-Content-Type-Options” header. This cou… Bigfix Service Management Mitigation only Fix from $1,6002026-05-20 MEDIUM 5.3 CVE-2026-6728 The Slider Revolution plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 7.0.9 via the 'get_strea… Mitigation only Fix from $1,6002026-05-20 MEDIUM 5.3 CVE-2026-34970 Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions 2.28.1 and prior allow a bugnote author to access the note's Revisions page a… Patch available Fix from $1,6002026-05-20 MEDIUM 5.3 CVE-2026-34579 Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions 2.28.1 and prior are vulnerable to Authorization Bypass through the private i… Patch available Fix from $1,6002026-05-19 MEDIUM 5.7 CVE-2026-34600 Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Versions 3.5.2 and prior contain a logic er… Patch available Fix from $1,6002026-05-19 MEDIUM 5.3 CVE-2026-34744 Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions 2.28.1 and prior permit a user to list and download their own attachments fro… Patch available Fix from $1,6002026-05-19 MEDIUM 6.5 CVE-2026-32814 libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and prior, when decoding a HEIF grid image with strict_decoding=false … Mitigation only Fix from $1,6002026-05-19 MEDIUM 6.5 CVE-2026-8706 Firefox for iOS hosted Reader mode on an unauthenticated local web server, allowing another application on the same device to request arbitrary URLs … Firefox 151.0+ Fix from $1,6002026-05-19 HIGH 7.5 CVE-2026-8966 Information disclosure in the IP Protection component. This vulnerability was fixed in Firefox 151 and Thunderbird 151. Firefox 151.0.0+ Fix from $1,9502026-05-19 HIGH 7.5 CVE-2026-8967 Information disclosure in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 151 and Thunderbird 151. Firefox 151.0.0+ Fix from $1,9502026-05-19 HIGH 7.5 CVE-2026-8965 Information disclosure in the DOM: Security component. This vulnerability was fixed in Firefox 151 and Thunderbird 151. Firefox 151.0.0+ Fix from $1,9502026-05-19 HIGH 7.5 CVE-2026-31909 Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Users a… Ofbiz 24.09.06+ Fix from $1,9502026-05-19 MEDIUM 6.3 CVE-2026-44408 There is an unauthorized access vulnerability in ZTE MU5250. Due to improper permission control of the Web interface, an unauthorized attacker can  m… Mitigation only Fix from $1,6002026-05-19 MEDIUM 5.3 CVE-2026-32244 Discourse is an open-source discussion platform. In versions prior to 2026.1.4, 2026.3.1, 2026.4.1 and 2026.5.0-latest.1, outdated cached AI summarie… Discourse 2026.1.4 / 2026.3.1+ Fix from $1,6002026-05-19 MEDIUM 6.5 CVE-2026-27892 FacturaScripts is an open source accounting and invoicing software. In versions prior to 2026, the Library module stores and serves uploaded images b… Patch available Fix from $1,6002026-05-18 HIGH 7.5 CVE-2026-39079 An issue in prestashop upsshipping all versions through at least 2.4.0 allows a remote attacker to obtain sensitive information via the /modules/upss… Mitigation only Fix from $1,9502026-05-18 HIGH 8.7 CVE-2026-6346 Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 fail to sanitize sensitive configuration fields before including them in … Mattermost Server 10.11.14 / 11.4.4+ Fix from $1,9502026-05-18 HIGH 7.6 CVE-2026-6347 Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 fail to sanitize sensitive configuration fields in the Mattermost Calls p… Mattermost Server 10.11.14 / 11.4.4+ Fix from $1,9502026-05-18 MEDIUM 6.5 CVE-2026-8766 A flaw has been found in Kilo-Org kilocode up to 7.0.47. This issue affects the function Load of the file packages/opencode/src/config/config.ts of t… Kilo Code Cli after 7.0.47 Fix from $1,6002026-05-17 HIGH 7.5 CVE-2026-8750 A vulnerability was identified in h2oai h2o-3 up to 7402. Affected by this issue is the function importFiles of the file h2o-core/src/main/java/water… H2o after 7402 Fix from $1,9502026-05-17 MEDIUM 6.5 CVE-2026-45351 Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.8.9, when a regular user [non-admin] lo… Open Webui 0.8.9+ Fix from $1,6002026-05-15 HIGH 7.4 CVE-2026-45539 Microsoft APM is an open-source, community-driven dependency manager for AI agents. From 0.5.4 to 0.12.4, two primitive integrators in apm-cli enumer… No fix yet Fix from $1,9502026-05-15 MEDIUM 5.8 CVE-2026-41960 Permission control vulnerability in calls. Impact: Successful exploitation of this vulnerability may affect availability. No fix yet Fix from $1,6002026-05-15 HIGH 7.5 CVE-2026-27886 Strapi is an open source headless content management system. Strapi versions starting in 4.0.0 and prior to 5.37.0 did not sufficiently sanitize quer… Strapi 5.37.0+ Fix from $1,9502026-05-14 HIGH 7.4 CVE-2026-41615 Exposure of sensitive information to an unauthorized actor in Microsoft Authenticator allows an unauthorized attacker to disclose information over a … Authenticator 6.8.47 / 6.2605.2973+ Fix from $1,9502026-05-14 HIGH 7.8 CVE-2026-42283 DevSpace is a client-only developer tool for cloud-native development with Kubernetes. Prior to 6.3.21, DevSpace's UI server WebSocket accepts connec… Devspace Mitigation only Fix from $1,9502026-05-14 MEDIUM 5.5 CVE-2026-0245 Multiple information disclosure vulnerabilities in Prisma Access Agent® allow a local user to access sensitive configuration data and credentials. … Prisma Access Agent 26.2.1+ Fix from $1,6002026-05-13 MEDIUM 5.5 CVE-2026-44479 Vercel’s AI Cloud is a unified platform for building modern applications. From 50.16.0 to 52.0.0, hen the Vercel CLI runs in non-interactive mode (-… Vercel 52.0.1+ Fix from $1,6002026-05-13 MEDIUM 5.3 CVE-2026-44431 urllib3 is an HTTP client library for Python. From 1.23 to before 2.7.0, cross-origin redirects followed from the low-level API via ProxyManager.conn… Urllib3 2.7.0+ Fix from $1,6002026-05-13