Vulnerability index

Browse CVEs

7,732 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
MEDIUM 5.8 CVE-2026-34318 Vulnerability in the MySQL Shell product of Oracle MySQL (component: Shell: Core Client). Supported versions that are affected are 8.0.0-8.0.45, 8.4… MySQL after 9.6.0 Fix from $1,6002026-04-21 MEDIUM 6.5 CVE-2026-34313 Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: P… Financial Services Analytical Applications Infrastructure Mitigation only Fix from $1,6002026-04-21 MEDIUM 6.5 CVE-2026-34300 Vulnerability in the PeopleSoft Enterprise FIN Contracts product of Oracle PeopleSoft (component: Contracts). The supported version that is affecte… Peoplesoft Enterprise Fin Contracts Mitigation only Fix from $1,6002026-04-21 HIGH 7.5 CVE-2026-34305 Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Services). Supported versions that are affected are … Weblogic Server Mitigation only Fix from $1,9502026-04-21 HIGH 7.5 CVE-2026-34297 Vulnerability in the Oracle HCM Common Architecture product of Oracle E-Business Suite (component: Knowledge Integration). Supported versions that a… Hcm Common Architecture after 12.2.15 Fix from $1,9502026-04-21 MEDIUM 5.3 CVE-2026-34273 Vulnerability in Oracle GoldenGate (component: Libraries). Supported versions that are affected are 23.4-23.10. Easily exploitable vulnerability all… Goldengate after 23.10 Fix from $1,6002026-04-21 HIGH 7.5 CVE-2026-22016 Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JAXP). Supporte… Jre Mitigation only Fix from $1,9502026-04-21 MEDIUM 5.4 CVE-2026-22006 Vulnerability in the PeopleSoft Enterprise HCM Human Resources product of Oracle PeopleSoft (component: Employee Snapshot). The supported version t… Peoplesoft Enterprise Hcm Human Resources Mitigation only Fix from $1,6002026-04-21 MEDIUM 5.3 CVE-2026-21999 Vulnerability in the XML Database component of Oracle Database Server. Supported versions that are affected are 23.4.0-23.26.1. Difficult to exploit… Xml Database after 23.26.1 Fix from $1,6002026-04-21 MEDIUM 5.3 CVE-2026-40908 WWBN AVideo is an open source video platform. In versions 29.0 and prior, the file `git.json.php` at the web root executes `git log -1` and returns t… Avideo after 29.0 Fix from $1,6002026-04-21 HIGH 8.8 CVE-2026-40885 goshs is a SimpleHTTPServer written in Go. From 2.0.0-beta.4 to 2.0.0-beta.5, goshs leaks file-based ACL credentials through its public collaborator … Goshs No fix yet Fix from $1,9502026-04-21 HIGH 7.5 CVE-2026-40584 RansomLook is a tool to monitor Ransomware groups and markets and extract their victims. Prior to 1.9.0, the API in the affected application improper… Ransomlook 1.9.0+ Fix from $1,9502026-04-21 CRITICAL 9.8 CVE-2026-40498 FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.213, an unauthenticated attacker can access diagnostic and system … Freescout 1.8.213+ Fix from $2,3002026-04-21 HIGH 7.5 CVE-2026-6782 Information disclosure in the IP Protection component. This vulnerability was fixed in Firefox 150 and Thunderbird 150. Firefox 150.0+ Fix from $1,9502026-04-21 MEDIUM 6.5 CVE-2026-6770 Other issue in the Storage: IndexedDB component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 14… Firefox 140.10.0 / 150.0+ Fix from $1,6002026-04-21 HIGH 7.5 CVE-2026-6756 Mitigation bypass in Firefox for Android. This vulnerability was fixed in Firefox 150. Firefox 150.0+ Fix from $1,9502026-04-21 MEDIUM 6.3 CVE-2026-31370 Honor E APP is affected by information leak vulnerability, successful exploitation of this vulnerability may affect service confidentiality. Mitigation only Fix from $1,6002026-04-21 MEDIUM 6.5 CVE-2026-34839 Glances is an open-source system cross-platform monitoring tool. Prior to version 4.5.4, the Glances web server exposes a REST API (`/api/4/*`) that … Glances 4.5.4+ Fix from $1,6002026-04-21 MEDIUM 6.8 CVE-2026-40490 The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. When redirect f… Patch available Fix from $1,6002026-04-18 HIGH 7.5 CVE-2026-2262 The Easy Appointments plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.12.21 via the `/wp… Mitigation only Fix from $1,9502026-04-18 MEDIUM 6.5 CVE-2026-40293 OpenFGA is an authorization/permission engine built for developers. In versions 0.1.4 through 1.13.1, when OpenFGA is configured to use preshared-key… Openfga 1.14.0+ Fix from $1,6002026-04-17 HIGH 7.5 CVE-2025-65104 Firebird is an open-source relational database management system. In versions FB3 of the client library placed incorrect data length values into XSQL… Firebird 3.0.14+ Fix from $1,9502026-04-17 MEDIUM 5.3 CVE-2026-6492 A vulnerability was detected in arnobt78 Hotel Booking Management System up to f8922d0e0f6ac1cc761974c7616f44c2bbc04bea. The impacted element is an u… Patch available Fix from $1,6002026-04-17 MEDIUM 6.5 CVE-2026-23777 Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.5, LTS2025 release version 8.3.… Powerprotect Data Domain after 8.5.0.0 Fix from $1,6002026-04-17 CRITICAL 9.8 CVE-2025-15625 Unauthenticated user is able to execute arbitrary SQL commands in Sparx Pro Cloud Server database in certain cases. Pro Cloud Server Mitigation only Fix from $2,3002026-04-17 HIGH 7.5 CVE-2026-40245 Free5GC is an open-source Linux Foundation project for 5th generation (5G) mobile core networks. Versions 4.2.1 and below contain an information disc… Free5gc after 4.2.1 Fix from $1,9502026-04-16 CRITICAL 9.4 CVE-2026-40173 Dgraph is an open source distributed GraphQL database. Versions 25.3.1 and prior contain an unauthenticated credential disclosure vulnerability where… Dgraph 25.3.2+ Fix from $2,3002026-04-15 MEDIUM 5.3 CVE-2026-39857 ApostropheCMS is an open-source Node.js content management system. Versions 4.28.0 and prior contain an authorization bypass vulnerability in the cho… Apostrophecms 4.29.0+ Fix from $1,6002026-04-15 MEDIUM 5.3 CVE-2026-33888 ApostropheCMS is an open-source Node.js content management system. Versions 4.28.0 and prior contain an authorization bypass vulnerability in the get… Apostrophecms 4.29.0+ Fix from $1,6002026-04-15 MEDIUM 6.8 CVE-2026-33220 Weblate is a web based localization tool. In versions prior to 5.17, the translation memory API exposed unintended endpoints, which in turn didn't pe… Weblate 5.17+ Fix from $1,6002026-04-15