Vulnerability index

Browse CVEs

7,732 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
HIGH 8.6 CVE-2026-42047 Inngest is a platform for running event-driven and scheduled background functions with queueing, retries, and step orchestration. Versions 3.22.0 thr… Inngest 3.54.0+ Fix from $1,9502026-05-07 MEDIUM 5.3 CVE-2026-8033 A vulnerability has been found in PicoTronica e-Clinic Healthcare System ECHS 5.7. This affects an unknown function of the file /cdemos/echs/api/v2/ … Mitigation only Fix from $1,6002026-05-06 HIGH 7.5 CVE-2026-34474EPSS 25% Sensitive data exposure leading to admin/WLAN credential leak in ZTE ZXHN H298A 1.1 and H108N 2.6. A crafted request to the router web interface can … Mitigation only Fix from $1,9502026-05-06 HIGH 8.8 CVE-2025-52613 HCL BigFix Service Management (SM) is affected by use of a vulnerable WSGI Server was identified. Deploying an outdated or insecure WSGI server may e… Bigfix Service Management Mitigation only Fix from $1,9502026-05-06 MEDIUM 5.4 CVE-2025-31984 HCL BigFix Service Management (SM) is affected by a security misconfiguration due to a missing or insecure “X-Content-Type-Options” header. This cou… Bigfix Service Management Mitigation only Fix from $1,6002026-05-06 HIGH 7.5 CVE-2025-31976 HCL BigFix Service Management (SM) is vulnerable to insufficiently protected credentials for a short duration while communicating with a backend, int… Bigfix Service Management Mitigation only Fix from $1,9502026-05-06 MEDIUM 6.5 CVE-2025-31982 HCL BigFix Service Management (SM) had directories that were not linked or publicly visible but could be accessed directly. This could allow an incre… Bigfix Service Management Mitigation only Fix from $1,6002026-05-06 MEDIUM 5.3 CVE-2025-31975 HCL BigFix Service Management (SM) is affected by an Information Disclosure – Server Banner issue was identified. Exposed server banners may reveal s… Bigfix Service Management Mitigation only Fix from $1,6002026-05-06 MEDIUM 5.3 CVE-2026-8026 A security flaw has been discovered in FlowiseAI Flowise up to 3.0.12. Affected is the function Login of the file packages/server/src/enterprise/serv… Flowise after 3.0.12 Fix from $1,6002026-05-06 HIGH 7.5 CVE-2026-43646 Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Wicket. This issue affects Apache Wicket: from 8.0.0 through 8.17… Wicket 10.9.0+ Fix from $1,9502026-05-06 HIGH 7.7 CVE-2026-36355 The rtl8192cd Wi-Fi kernel driver in the Realtek rtl819x Jungle SDK (all known versions through v3.4.14B) does not perform any access control checks … Mitigation only Fix from $1,9502026-05-05 MEDIUM 6.5 CVE-2026-4409 The Subscribe To Comments Reloaded plugin for WordPress is vulnerable to unauthorized modification of data due to a leaked secret key and usage of a … Mitigation only Fix from $1,6002026-05-05 MEDIUM 6.5 CVE-2026-42223 Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.8, the GetSettings API handler (api/settings/settings.go:24-65) seria… Nginx Ui 2.3.8+ Fix from $1,6002026-05-04 MEDIUM 6.5 CVE-2026-42220 Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.8, an authenticated user can call GET /api/settings and retrieve sens… Nginx Ui 2.3.8+ Fix from $1,6002026-05-04 HIGH 7.5 CVE-2026-42151 Prometheus is an open-source monitoring system and time series database. Prior to versions 3.5.3 and 3.11.3, the client_secret field in the Azure AD … Prometheus 3.5.3 / 3.11.3+ Fix from $1,9502026-05-04 MEDIUM 6.5 CVE-2026-42092 titra is an open source time tracking project. In version 0.99.52, the globalsettings Meteor publication returns all global settings without any admi… Mitigation only Fix from $1,6002026-05-04 MEDIUM 5.3 CVE-2026-3504 The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution plugin for WordPress is vulnerable to Sensitive Information Exposure in all versio… Mitigation only Fix from $1,6002026-05-02 MEDIUM 6.5 CVE-2025-14726 The Widgets for Social Photo Feed plugin for WordPress is vulnerable to unauthorized access of data and modification of data due to a missing capabil… Mitigation only Fix from $1,6002026-05-02 MEDIUM 6.5 CVE-2026-7382 Exposure of Sensitive Information to an Unauthorized Actor, Exposure of private personal information to an unauthorized actor vulnerability in MeWare… Mitigation only Fix from $1,6002026-04-30 CRITICAL 9.1 CVE-2026-7381 Plack::Middleware::XSendfile versions through 1.0053 for Perl can allow client-controlled path rewriting. Plack::Middleware::XSendfile allows the va… Plack\ after 1.0053 Fix from $2,3002026-04-29 MEDIUM 5.3 CVE-2026-7071 A security vulnerability has been detected in CodeAstro Online Job Portal 1.0. Affected by this vulnerability is an unknown functionality of the file… Mitigation only Fix from $1,6002026-04-27 CRITICAL 9.8 CVE-2026-41492 Dgraph is an open source distributed GraphQL database. Prior to 25.3.3, Dgraphl exposes the process command line through the unauthenticated /debug/v… Dgraph 25.3.3+ Fix from $2,3002026-04-24 MEDIUM 5.4 CVE-2026-41079 OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. Prior to 2.4.17, a network-adjacent attacker can… Cups 2.4.17+ Fix from $1,6002026-04-24 CRITICAL 9.9 CVE-2026-21515 Exposure of sensitive information to an unauthorized actor in Azure IOT Central allows an authorized attacker to elevate privileges over a network. Azure Iot Central No fix yet Fix from $2,3002026-04-24 CRITICAL 9.1 CVE-2026-41323 Kyverno is a policy engine designed for cloud native platform engineering teams. Prior to versions 1.18.0-rc1, 1.17.2-rc1, and 1.16.4, Kyverno's apiC… Kyverno 1.16.4 / 1.17.2+ Fix from $2,3002026-04-24 HIGH 7.5 CVE-2026-41278 Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the GET /api/v1/public-chatflows/:id endpoin… Flowise 3.1.0+ Fix from $1,9502026-04-23 HIGH 7.5 CVE-2026-41266 Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, /api/v1/public-chatbotConfig/:id ep exposes … Flowise 3.1.0+ Fix from $1,9502026-04-23 MEDIUM 5.3 CVE-2026-4106 The HT Mega Addons for Elementor WordPress plugin before 3.0.7 contains an unauthenticated AJAX action returning some PII (such as full name, city, … Mitigation only Fix from $1,6002026-04-23 MEDIUM 5.3 CVE-2026-41182 LangSmith Client SDKs provide SDK's for interacting with the LangSmith platform. Prior to version 0.5.19 of the JavaScript SDK and version 0.7.31 of … Mitigation only Fix from $1,6002026-04-23 HIGH 7.5 CVE-2026-40895 follow-redirects is an open source, drop-in replacement for Node's `http` and `https` modules that automatically follows redirects. Prior to 1.16.0, … Follow Redirects 1.16.0+ Fix from $1,9502026-04-21