Vulnerability index

Browse CVEs

7,732 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
MEDIUM 5.3 CVE-2025-9987 The Broadstreet plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.53.1 via the get_sponsor… Mitigation only Fix from $1,6002026-05-13 MEDIUM 5.0 CVE-2026-41610 Improper neutralization of input during web page generation ('cross-site scripting') in Visual Studio Code allows an unauthorized attacker to bypass … Visual Studio Code 1.119.1+ Fix from $1,6002026-05-12 MEDIUM 6.5 CVE-2026-40374 Exposure of sensitive information to an unauthorized actor in Power Automate allows an authorized attacker to disclose information over a network. Power Automate For Desktop 2.67+ Fix from $1,6002026-05-12 HIGH 7.5 CVE-2026-40379 Exposure of sensitive information to an unauthorized actor in Azure Entra ID allows an unauthorized attacker to perform spoofing over a network. Entra Id No fix yet Fix from $1,9502026-05-12 CRITICAL 9.8 CVE-2026-43992 JunoClaw is an agentic AI platform built on Juno Network. Prior to 0.x.y-security-1, every MCP write tool (send_tokens, execute_contract, instantiate… Patch available Fix from $2,3002026-05-12 HIGH 7.3 CVE-2026-42498 Exposure of HTTP Authentication Header to unexpected hosts during WebSocket authentication vulnerability in Apache Tomcat. This issue affects Apache… Tomcat 9.0.118 / 10.1.55+ Fix from $1,9502026-05-12 CRITICAL 9.1 CVE-2026-45091 sealed-env is a cross-stack, zero-trust secret management library for Node.js and Java/Spring Boot. In sealed-env enterprise mode, versions 0.1.0-alp… Mitigation only Fix from $2,3002026-05-12 MEDIUM 5.3 CVE-2026-7626 The Slek Gateway for WooCommerce plugin for WordPress is vulnerable to Information Exposure in version 1.0. This is due to the wsb_handle_slek_paymen… Mitigation only Fix from $1,6002026-05-12 HIGH 7.7 CVE-2026-43885 WWBN AVideo is an open source video platform. In versions up to and including 29.0, an unauthenticated user can read APISecret from objects/plugins.j… Patch available Fix from $1,9502026-05-11 HIGH 8.2 CVE-2026-42564 jotty·page is a self-hosted app for your checklists and notes. Prior to 1.22.0, an unauthenticated path traversal vulnerability exists in /api/app-ic… Mitigation only Fix from $1,9502026-05-11 HIGH 7.5 CVE-2026-28976 An information leakage was addressed with additional validation. This issue is fixed in macOS Tahoe 26.5. An app may be able to gain root privileges. macOS 26.5+ Fix from $1,9502026-05-11 HIGH 7.5 CVE-2026-28962 This issue was addressed with improved access restrictions. This issue is fixed in Safari 26.5, iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.… Ipados 18.7.9 / 26.5+ Fix from $1,9502026-05-11 MEDIUM 5.5 CVE-2026-28958 This issue was addressed with improved data protection. This issue is fixed in Safari 26.5, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5 and iPadOS 26.5,… Ipados 26.5+ Fix from $1,6002026-05-11 MEDIUM 6.5 CVE-2026-28920 An information leakage was addressed with additional validation. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS… Ipados 14.8.7 / 15.7.7+ Fix from $1,6002026-05-11 MEDIUM 6.5 CVE-2026-28922 This issue was addressed through improved state management. This issue is fixed in macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5. An ap… macOS 14.8.7 / 15.7.7+ Fix from $1,6002026-05-11 MEDIUM 6.9 CVE-2026-42871 WeGIA is a web manager for charitable institutions. In versions prior to 3.7.0, atendido/familiar_docfamiliar.php displays an overly descriptive erro… Mitigation only Fix from $1,6002026-05-11 MEDIUM 5.3 CVE-2026-34093 Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with p… Mediawiki 1.43.7 / 1.44.4+ Fix from $1,6002026-05-11 HIGH 7.7 CVE-2026-44738 Grav is a file-based Web platform. Prior to 2.0.0-rc.2, the Twig sandbox allow-list permits any user with the admin.pages role to call config.toArray… Grav 2.0.0+ Fix from $1,9502026-05-11 HIGH 7.5 CVE-2026-34087 Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation OATHAuth. This issue affects OATHAuth: from * befor… Mediawiki 1.43.7 / 1.44.4+ Fix from $1,9502026-05-11 HIGH 7.5 CVE-2026-34088 Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation MediaWiki. This issue affects MediaWiki: from * bef… Mediawiki 1.43.7 / 1.44.4+ Fix from $1,9502026-05-11 HIGH 7.5 CVE-2026-34090 Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation CheckUser. This issue affects CheckUser: from 1.45.… Checkuser 1.45.2+ Fix from $1,9502026-05-11 HIGH 7.5 CVE-2026-34091 Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation MediaWiki. This issue affects MediaWiki: from * bef… Mediawiki 1.43.7 / 1.44.4+ Fix from $1,9502026-05-11 HIGH 7.5 CVE-2026-34092 Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with p… Mediawiki 1.43.7 / 1.44.4+ Fix from $1,9502026-05-11 MEDIUM 6.3 CVE-2026-42333 Quarkus OpenAPI Generator is Quarkus' extensions for generation of Rest Clients and server stubs generation. Prior to versions 2.11.1-lts, 2.16.0-lts… Patch available Fix from $1,6002026-05-09 MEDIUM 5.3 CVE-2026-8198 The Activity Logs, User Activity Tracking, Multisite Activity Log from Logtivity plugin for WordPress is vulnerable to Authentication Bypass to Infor… Mitigation only Fix from $1,6002026-05-09 MEDIUM 5.1 CVE-2026-42213 SolidCAM-GPPL-IDE is an unofficial, independently developed extension, Postprocessor IDE for SolidCAM. From version 1.0.0 to before version 1.0.2, th… Patch available Fix from $1,6002026-05-08 CRITICAL 9.1 CVE-2026-25199 Instances deployed via the Proxmox extension allow unauthorized access to instances belonging to other tenants. This issue affects Apache CloudSt… Cloudstack 4.22.0.1+ Fix from $2,3002026-05-08 MEDIUM 5.5 CVE-2026-43942 electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. In versions 3.8.15 and prior, the getConstants() IPC handle… Electerm after 3.8.15 Fix from $1,6002026-05-08 CRITICAL 9.6 CVE-2026-42880 Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. From versions 3.2.0 to before 3.2.11 and 3.3.0 to before 3.3.9, there is a … Argo Cd 3.2.11 / 3.3.9+ Fix from $2,3002026-05-07 HIGH 7.5 CVE-2026-42826 Exposure of sensitive information to an unauthorized actor in Azure DevOps allows an unauthorized attacker to disclose information over a network. Azure Devops No fix yet Fix from $1,9502026-05-07