Vulnerability index

Browse CVEs

7,732 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
HIGH 7.7 CVE-2026-34242 Weblate is a web based localization tool. In versions prior to 5.17, the ZIP download feature didn't verify downloaded files, potentially following … Weblate 5.17+ Fix from $1,9502026-04-15 MEDIUM 5.0 CVE-2026-34244 Weblate is a web based localization tool. In versions prior to 5.17, a user with the project.edit permission (granted by the per-project "Administrat… Weblate 5.17+ Fix from $1,6002026-04-15 HIGH 7.4 CVE-2026-32631 Git for Windows is the Windows port of Git. Versions prior to 2.53.0.windows.3 do not have protections that prevent attackers from obtaining a user's… Mitigation only Fix from $1,9502026-04-15 MEDIUM 6.5 CVE-2025-12141 In Grafana's alerting system, users with edit permissions for a contact point, specifically the permissions “alert.notifications:write” or “alert.not… Grafana after 12.3.0 Fix from $1,6002026-04-15 MEDIUM 6.5 CVE-2026-25219 The `access_key` and `connection_string` connection properties were not marked as sensitive names in secrets masker. This means that user with read p… Airflow 3.2.0+ Fix from $1,6002026-04-15 MEDIUM 6.5 CVE-2026-32151 Exposure of sensitive information to an unauthorized actor in Windows Shell allows an authorized attacker to disclose information over a network. Windows 10 1607 10.0.14393.9060 / 10.0.17763.8644+ Fix from $1,6002026-04-14 MEDIUM 5.5 CVE-2026-32085 Exposure of sensitive information to an unauthorized actor in Windows Remote Procedure Call allows an authorized attacker to disclose information loc… Windows 10 1607 10.0.14393.9060 / 10.0.17763.8644+ Fix from $1,6002026-04-14 MEDIUM 5.5 CVE-2026-32084 Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally. Windows 10 1607 10.0.14393.9060 / 10.0.17763.8644+ Fix from $1,6002026-04-14 MEDIUM 5.5 CVE-2026-32079 Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally. Windows 10 1607 10.0.14393.9060 / 10.0.17763.8644+ Fix from $1,6002026-04-14 MEDIUM 5.5 CVE-2026-32081 Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally. Windows 10 1607 10.0.14393.9060 / 10.0.17763.8644+ Fix from $1,6002026-04-14 MEDIUM 6.5 CVE-2026-34984 External Secrets Operator reads information from a third-party service and automatically injects the values as Kubernetes Secrets. Versions 2.2.0 and… External Secrets Operator 2.3.0+ Fix from $1,6002026-04-14 MEDIUM 5.3 CVE-2026-6160 A vulnerability was found in code-projects Simple ChatBox 1.0. Affected by this issue is the function SimpleChatbox_PHP of the file chatbox.sql of th… No fix yet Fix from $1,6002026-04-13 MEDIUM 5.3 CVE-2026-3691 OpenClaw Client PKCE Verifier Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose stored credentials on affe… Openclaw 2026.2.25+ Fix from $1,6002026-04-11 MEDIUM 5.5 CVE-2026-40159 PraisonAI is a multi-agent teams system. Prior to 4.5.128, PraisonAI’s MCP (Model Context Protocol) integration allows spawning background servers vi… Praisonai 4.5.128+ Fix from $1,6002026-04-10 MEDIUM 6.1 CVE-2026-31262 Cross Site Scripting vulnerability in Altenar Sportsbook Software Platform (SB2) v.2.0 allows a remote attacker to obtain sensitive information and e… Sportsbook No fix yet Fix from $1,6002026-04-10 MEDIUM 5.3 CVE-2026-40151 PraisonAI is a multi-agent teams system. Prior to 4.5.128, the AgentOS deployment platform exposes a GET /api/agents endpoint that returns agent name… Praisonai 4.5.128+ Fix from $1,6002026-04-09 MEDIUM 6.5 CVE-2026-39943 Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.17.0, Directus stores revision records (in directus_revi… Directus 11.17.0+ Fix from $1,6002026-04-09 HIGH 7.5 CVE-2026-4660 HashiCorp’s go-getter library up to v1.8.5 may allow arbitrary file reads on the file system during certain git operations through a maliciously craf… Mitigation only Fix from $1,9502026-04-09 HIGH 7.5 CVE-2025-62188 An Exposure of Sensitive Information to an Unauthorized Actor vulnerability exists in Apache DolphinScheduler. This vulnerability may allow unauthor… Dolphinscheduler 3.2.0+ Fix from $1,9502026-04-09 HIGH 7.5 CVE-2026-39889 PraisonAI is a multi-agent teams system. Prior to 4.5.115, the A2U (Agent-to-User) event stream server in PraisonAI exposes all agent activity withou… Praisonai after 4.5.114 Fix from $1,9502026-04-08 HIGH 7.5 CVE-2026-39412 LiquidJS is a Shopify / GitHub Pages compatible template engine in pure JavaScript. Prior to 10.25.4, the sort_natural filter bypasses the ownPropert… Liquidjs 10.25.4+ Fix from $1,9502026-04-08 MEDIUM 5.3 CVE-2026-3594 The Riaxe Product Customizer plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.4 via the '… Mitigation only Fix from $1,6002026-04-08 HIGH 7.5 CVE-2026-39363 Vite is a frontend tooling framework for JavaScript. From 6.0.0 to before 6.4.2, 7.3.2, and 8.0.5, if it is possible to connect to the Vite dev serve… Vite after 8.0.4 Fix from $1,9502026-04-07 MEDIUM 5.3 CVE-2026-35449 WWBN AVideo is an open source video platform. In versions 26.0 and prior, the install/test.php diagnostic script has its CLI-only access guard disabl… Avideo after 26.0 Fix from $1,6002026-04-06 MEDIUM 5.3 CVE-2026-35452 WWBN AVideo is an open source video platform. In versions 26.0 and prior, the plugin/CloneSite/client.log.php endpoint serves the clone operation log… Avideo after 26.0 Fix from $1,6002026-04-06 MEDIUM 5.3 CVE-2026-35413 Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.16.1, when GRAPHQL_INTROSPECTION=false is configured, Di… Directus 11.16.1+ Fix from $1,6002026-04-06 HIGH 8.1 CVE-2026-35442 Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.17.0, aggregate functions (min, max) applied to fields w… Directus 11.17.0+ Fix from $1,9502026-04-06 MEDIUM 5.3 CVE-2026-5666 A vulnerability was detected in code-projects Online FIR System 1.0. Affected by this issue is some unknown functionality of the file /complaints.sql… Mitigation only Fix from $1,6002026-04-06 HIGH 7.5 CVE-2026-34969 Nhost is an open source Firebase alternative with GraphQL. Prior to 0.48.0, the auth service's OAuth provider callback flow places the refresh token … Nhost\/auth 0.48.0+ Fix from $1,9502026-04-06 MEDIUM 5.3 CVE-2026-5650 A vulnerability was found in code-projects Online Application System for Admission 1.0. Impacted is an unknown function of the file /enrollment/datab… No fix yet Fix from $1,6002026-04-06