Vulnerability index

Browse CVEs

7,732 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
MEDIUM 6.5 CVE-2026-1556 Information disclosure in the file URI processing of File (Field) Paths in Drupal File (Field) Paths 7.x prior to 7.1.3 on Drupal 7.x allows authenti… Filefield Paths 7.x-1.3+ Fix from $1,6002026-03-26 MEDIUM 5.3 CVE-2025-55276 HCL Aftermarket DPC is affected by Internal IP Disclosure vulnerability will give attackers a clearer map of the organization’s network layout. Aftermarket Cloud Mitigation only Fix from $1,6002026-03-26 MEDIUM 5.3 CVE-2025-55272 HCL Aftermarket DPC is affected by Banner Disclosure vulnerability where attackers gain insights into the system’s software and version details which… Aftermarket Cloud Mitigation only Fix from $1,6002026-03-26 HIGH 7.5 CVE-2025-55265 HCL Aftermarket DPC is affected by File Discovery which allows attacker could exploit this issue to read sensitive files present in the system and ma… Aftermarket Cloud Mitigation only Fix from $1,9502026-03-26 HIGH 7.2 CVE-2025-14915 IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.3 IBM WebSphere Application Server Liberty is affected by privilege escalation. A … Websphere Application Server 26.0.0.4+ Fix from $1,9502026-03-25 MEDIUM 5.5 CVE-2026-28877 An authorization issue was addressed with improved state management. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.4 and iPadOS 26.4, m… Ipados 15.7.5 / 26.4+ Fix from $1,6002026-03-25 MEDIUM 6.5 CVE-2026-28878 A privacy issue was addressed by removing sensitive data. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Sequoi… Ipados 14.8.5 / 18.7.7+ Fix from $1,6002026-03-25 MEDIUM 5.3 CVE-2026-28820 This issue was addressed with improved checks. This issue is fixed in macOS Tahoe 26.4. An app may be able to access sensitive user data. macOS 26.4+ Fix from $1,6002026-03-25 MEDIUM 6.5 CVE-2026-33353 Soft Serve is a self-hostable Git server for the command line. From version 0.6.0 to before version 0.11.6, an authorization flaw in repo import allo… Soft Serve 0.11.6+ Fix from $1,6002026-03-24 MEDIUM 6.5 CVE-2026-33627 Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.61 and 9.6.0-alpha.55, … Parse Server 8.6.61 / 9.6.0+ Fix from $1,6002026-03-24 MEDIUM 6.5 CVE-2026-33677 Vikunja is an open-source self-hosted task management platform. Prior to version 2.2.1, the `GET /api/v1/projects/:project/webhooks` endpoint returns… Vikunja 2.2.1+ Fix from $1,6002026-03-24 HIGH 7.5 CVE-2026-4712 Information disclosure in the Widget: Cocoa component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbi… Firefox 140.9.0 / 149.0+ Fix from $1,9502026-03-24 MEDIUM 5.3 CVE-2026-4733 Exposure of Sensitive Information to an Unauthorized Actor vulnerability in ixray-team ixray-1.6-stcop.This issue affects ixray-1.6-stcop: before 1.3. Patch available Fix from $1,6002026-03-24 HIGH 7.5 CVE-2025-60949 Census CSWeb 8.0.1 allows "app/config" to be reachable via HTTP in some deployments. A remote, unauthenticated attacker could send requests to config… Csweb Patch available Fix from $1,9502026-03-23 MEDIUM 5.3 CVE-2026-23486 Blinko is an AI-powered card note-taking project. Prior to version 1.8.4, a publicly accessible endpoint exposes all user information, including user… Blinko 1.8.4+ Fix from $1,6002026-03-23 MEDIUM 5.5 CVE-2026-27131 The Sprig Plugin for Craft CMS is a reactive Twig component framework for Craft CMS. Starting in version 2.0.0 and prior to versions 2.15.2 and 3.15.… Patch available Fix from $1,6002026-03-23 MEDIUM 5.3 CVE-2025-13997 The King Addons for Elementor – 4,000+ ready Elementor sections, 650+ templates, 70+ FREE widgets for Elementor plugin for WordPress is vulnerable to… Mitigation only Fix from $1,6002026-03-23 HIGH 7.5 CVE-2026-33180 HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to version 6.9.0, when setting headers… Mitigation only Fix from $1,9502026-03-20 MEDIUM 5.3 CVE-2026-33041 WWBN AVideo is an open source video platform. In versions 25.0 and below, /objects/encryptPass.json.php exposes the application's password hashing al… Avideo 26.0+ Fix from $1,6002026-03-20 MEDIUM 6.5 CVE-2026-32938 SiYuan is a personal knowledge management system. In versions 3.6.0 and below, the /api/lute/html2BlockDOM on the desktop copies local files pointed … Siyuan 3.6.1+ Fix from $1,6002026-03-20 CRITICAL 9.6 CVE-2026-32890 Anchorr is a Discord bot for requesting movies and TV shows and receiving notifications when items are added to a media server. In versions 1.4.1 and… Anchorr after 1.4.1 Fix from $2,3002026-03-20 MEDIUM 6.5 CVE-2026-30891 Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, a user could access another user's priv… Discourse 2026.1.2 / 2026.2.1+ Fix from $1,6002026-03-20 MEDIUM 6.5 CVE-2026-29108 SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versions 8.9.3, an authenticated A… Suitecrm 8.9.3+ Fix from $1,6002026-03-20 MEDIUM 6.5 CVE-2026-33355 Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, the `/private-posts` endpoint did not a… Discourse 2026.1.2 / 2026.2.1+ Fix from $1,6002026-03-19 MEDIUM 6.5 CVE-2026-32099 Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, when a user has `hide_profile` enabled,… Discourse 2026.1.2 / 2026.2.1+ Fix from $1,6002026-03-19 MEDIUM 6.5 CVE-2026-32002 OpenClaw versions prior to 2026.2.23 contain a sandbox bypass vulnerability in the sandboxed image tool that fails to enforce tools.fs.workspaceOnly … Openclaw 2026.2.23+ Fix from $1,6002026-03-19 HIGH 7.5 CVE-2026-23659 Exposure of sensitive information to an unauthorized actor in Azure Data Factory allows an unauthorized attacker to disclose information over a netwo… Azure Data Factory No fix yet Fix from $1,9502026-03-19 CRITICAL 9.8 CVE-2026-32865 OPEXUS eComplaint and eCASE before version 10.1.0.0 include the secret verification code in the HTTP response when requesting a password reset via 'F… Ecase Ecomplaint 10.1.0.0+ Fix from $2,3002026-03-19 MEDIUM 6.5 CVE-2026-33163 Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.35 and 8.6.50, when a `P… Parse Server 8.6.50 / 9.6.0+ Fix from $1,6002026-03-18 CRITICAL 9.1 CVE-2026-32633 Glances is an open-source system cross-platform monitoring tool. Prior to version 4.5.2, in Central Browser mode, the `/api/4/serverslist` endpoint r… Glances 4.5.2+ Fix from $2,3002026-03-18