Vulnerability index

Browse CVEs

7,732 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
MEDIUM 5.3 CVE-2026-5601 A vulnerability was found in Acrel Electrical Prepaid Cloud Platform 1.0. This issue affects some unknown processing of the file /bin.rar of the comp… Mitigation only Fix from $1,6002026-04-05 HIGH 7.5 CVE-2026-5585 A vulnerability was found in Tencent AI-Infra-Guard 4.0. The affected element is an unknown function of the file common/websocket/task_manager.go of … Ai Infra Guard No fix yet Fix from $1,9502026-04-05 HIGH 7.5 CVE-2026-5571 A vulnerability was identified in Technostrobe HI-LED-WR120-G2 5.5.0.1R6.03.30. The impacted element is an unknown function of the file /fs of the co… Hi Led Wr120 G2 Firmware No fix yet Fix from $1,9502026-04-05 MEDIUM 5.3 CVE-2026-34947 Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to before 2026.2.2, and 2026.3.0-l… Discourse after 2026.2.1 Fix from $1,6002026-04-03 MEDIUM 5.3 CVE-2026-27481 Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to before 2026.2.2, and 2026.3.0-l… Discourse after 2026.2.1 Fix from $1,6002026-04-03 MEDIUM 6.5 CVE-2026-35038 Signal K Server is a server application that runs on a central hub in a boat. Prior to version 2.24.0, there is an arbitrary prototype read vulnerabi… Signal K Server 2.24.0+ Fix from $1,6002026-04-02 HIGH 7.5 CVE-2026-34785 Rack is a modular Ruby web server interface. Prior to versions 2.2.23, 3.1.21, and 3.2.6, Rack::Static determines whether a request should be served … Rack 2.2.23 / 3.1.21+ Fix from $1,9502026-04-02 HIGH 7.5 CVE-2026-5032 The W3 Total Cache plugin for WordPress is vulnerable to information exposure in all versions up to, and including, 2.9.3. This is due to the plugin … Mitigation only Fix from $1,9502026-04-02 MEDIUM 5.3 CVE-2026-34518 AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, when following redirects to a different orig… Aiohttp 3.13.4+ Fix from $1,6002026-04-01 HIGH 7.5 CVE-2025-67805 A non-default configuration in Sage DPW 2025_06_004 allows unauthenticated access to diagnostic endpoints within the Database Monitor feature, exposi… Sage Dpw Mitigation only Fix from $1,9502026-04-01 MEDIUM 5.3 CVE-2026-2696 The Export All URLs WordPress plugin before 5.1 generates CSV filenames containing posts URLS (including private posts) in a predictable pattern usin… Mitigation only Fix from $1,6002026-04-01 MEDIUM 6.5 CVE-2026-5291 Inappropriate implementation in WebGL in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to obtain potentially sensitive information … Chrome 146.0.7680.177+ Fix from $1,6002026-04-01 HIGH 7.5 CVE-2026-3774 The application allows PDF JavaScript and document/print actions (such as WillPrint/DidPrint) to update form fields, annotations, or optional content… Pdf Editor after 2025.3.0.35737 Fix from $1,9502026-04-01 MEDIUM 5.5 CVE-2025-71280 XenForo before 2.3.7 allows information disclosure via local account page caching on shared systems. On systems where multiple users share a browser … Xenforo 2.3.7+ Fix from $1,6002026-04-01 MEDIUM 6.5 CVE-2026-34215 Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.63 and 9.7.0-alpha.7, t… Parse Server 8.6.63 / 9.7.0+ Fix from $1,6002026-03-31 MEDIUM 6.5 CVE-2026-33300 Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to before 2026.2.2, and 2026.3.0-l… Discourse 2026.1.3 / 2026.2.2+ Fix from $1,6002026-03-31 MEDIUM 5.3 CVE-2026-33073 Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to before 2026.2.2, and 2026.3.0-l… Discourse 2026.1.3 / 2026.2.2+ Fix from $1,6002026-03-31 MEDIUM 6.5 CVE-2026-32143 Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to before 2026.2.2, and 2026.3.0-l… Discourse 2026.1.3 / 2026.2.2+ Fix from $1,6002026-03-31 HIGH 7.5 CVE-2026-4020EPSS 42% The Gravity SMTP plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.1.4. This is due to a R… Mitigation only Fix from $1,9502026-03-31 HIGH 8.2 CVE-2026-29872 A cross-session information disclosure vulnerability exists in the awesome-llm-apps project in commit e46690f99c3f08be80a9877fab52acacf7ab8251 (2026-… Awesome Llm Apps No fix yet Fix from $1,9502026-03-30 HIGH 7.1 CVE-2026-34472EPSS 9% Unauthenticated credential disclosure in the wizard interface in ZTE ZXHN H188A V6.0.10P2_TE and V6.0.10P3N3_TE allows unauthenticated attackers on t… Zxhn H188a Firmware Mitigation only Fix from $1,9502026-03-30 MEDIUM 5.3 CVE-2026-5003 A vulnerability was found in PromtEngineer localGPT up to 4d41c7d1713b16b216d8e062e51a5dd88b20b054. This affects the function handle_index of the fil… Mitigation only Fix from $1,6002026-03-28 MEDIUM 6.5 CVE-2026-1307 The Ninja Forms - The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions u… Mitigation only Fix from $1,6002026-03-28 MEDIUM 6.5 CVE-2026-33981 changedetection.io is a free open source web page change detection tool. Prior to 0.54.7, the `jq:` and `jqraw:` include filter expressions allow use… Changedetection 0.54.7+ Fix from $1,6002026-03-27 MEDIUM 6.5 CVE-2026-33886 Statamic is a Laravel and Git powered content management system (CMS). Starting in version 5.7.12 and prior to versions 5.73.16 and 6.7.2, a control … Statamic 5.73.16 / 6.7.2+ Fix from $1,6002026-03-27 MEDIUM 6.5 CVE-2026-33882 Statamic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.16 and 6.7.2, the markdown preview endpoint could be ma… Statamic 5.73.16 / 6.7.2+ Fix from $1,6002026-03-27 MEDIUM 5.7 CVE-2026-31951 LibreChat is a ChatGPT clone with additional features. In versions 0.8.2-rc1 through 0.8.3-rc1, user-created MCP (Model Context Protocol) servers can… Librechat 0.8.3+ Fix from $1,6002026-03-27 HIGH 7.1 CVE-2025-15381 In the latest version of mlflow/mlflow, when the `basic-auth` app is enabled, tracing and assessment endpoints are not protected by permission valida… Mlflow No fix yet Fix from $1,9502026-03-27 MEDIUM 5.3 CVE-2026-33761 WWBN AVideo is an open source video platform. In versions up to and including 26.0, three `list.json.php` endpoints in the Scheduler plugin lack any … Avideo after 26.0 Fix from $1,6002026-03-27 HIGH 7.4 CVE-2026-33745 cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.39.0, the cpp-httplib HTTP client forwards stored Basic … Cpp Httplib 0.39.0+ Fix from $1,9502026-03-27