Vulnerability index

Browse CVEs

7,732 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
HIGH 7.5 CVE-2026-32609 Glances is an open-source system cross-platform monitoring tool. The GHSA-gh4x fix (commit 5d3de60) addressed unauthenticated configuration secrets e… Glances 4.5.2+ Fix from $1,9502026-03-18 HIGH 7.5 CVE-2026-32596 Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.2, Glances web server runs without authentication by default when start… Glances 4.5.2+ Fix from $1,9502026-03-18 MEDIUM 6.9 CVE-2026-32265 The Amazon S3 for Craft CMS plugin provides an Amazon S3 integration for Craft CMS. In versions 2.0.2 through 2.2.4, unauthenticated users can view a… Patch available Fix from $1,6002026-03-18 MEDIUM 6.5 CVE-2026-1267 IBM Planning Analytics Local 2.1.0 through 2.1.17 could allow an unauthorized access to sensitive application data and administrative functionalities… Planning Analytics Local 2.1.18+ Fix from $1,6002026-03-17 MEDIUM 5.3 CVE-2025-52649 HCL AION is affected by a vulnerability where certain identifiers may be predictable in nature. Predictable identifiers may allow an attacker to infe… Aion 2.1.2+ Fix from $1,6002026-03-16 MEDIUM 6.5 CVE-2026-32237 Backstage is an open framework for building developer portals. Prior to 3.1.5, authenticated users with permission to execute scaffolder dry-runs can… Backstage\/plugin Scaffolder Backend 3.1.5+ Fix from $1,6002026-03-12 MEDIUM 5.3 CVE-2026-32142 Shopware is an open commerce platform. /api/_info/config route exposes information about licenses. This vulnerability is fixed in 7.8.1 and 6.10.15. Mitigation only Fix from $1,6002026-03-12 MEDIUM 5.3 CVE-2026-32100 Shopware is an open commerce platform. /api/_info/config route exposes information about active security fixes. This vulnerability is fixed in 2.0.16… Mitigation only Fix from $1,6002026-03-12 MEDIUM 6.2 CVE-2026-29066 Tina is a headless content management system. Prior to 2.1.8, the TinaCMS CLI dev server configures Vite with server.fs.strict: false, which disables… Tinacms\/cli 2.1.8+ Fix from $1,6002026-03-12 MEDIUM 5.5 CVE-2026-4040 A vulnerability was identified in OpenClaw up to 2026.2.17. This issue affects the function tools.exec.safeBins of the component File Existence Handl… Openclaw 2026.2.19+ Fix from $1,6002026-03-12 HIGH 7.5 CVE-2026-32098 Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.9 and 8.6.35, an attacke… Parse Server 8.6.35 / 9.6.0+ Fix from $1,9502026-03-11 MEDIUM 6.5 CVE-2026-32094 Shescape is a simple shell escape library for JavaScript. Prior to 2.1.10, Shescape#escape() does not escape square-bracket glob syntax for Bash, Bus… Shescape 2.1.10+ Fix from $1,6002026-03-11 MEDIUM 5.4 CVE-2026-20166 In Splunk Enterprise versions below 10.2.1 and 10.0.4, and Splunk Cloud Platform versions below 10.2.2510.5, 10.1.2507.16, and 10.0.2503.12, a low-pr… Splunk 10.0.4 / 10.0.2503.12+ Fix from $1,6002026-03-11 MEDIUM 6.5 CVE-2026-20164 In Splunk Enterprise versions below 10.2.0, 10.0.3, 9.4.9, and 9.3.10, and Splunk Cloud Platform versions below 10.2.2510.5, 10.1.2507.16, 10.0.2503.… Splunk 9.3.10 / 9.3.2411.123+ Fix from $1,6002026-03-11 MEDIUM 5.9 CVE-2026-1867 The Guest posting / Frontend Posting / Front Editor WordPress plugin before 5.0.6 allows passing a URL parameter to regenerate a .json file based on… Mitigation only Fix from $1,6002026-03-11 HIGH 7.5 CVE-2026-31837 Istio is an open platform to connect, manage, and secure microservices. Prior to 1.29.1, 1.28.5, and 1.27.8, a user of Istio is impacted if the JWKS … Istio 1.27.8 / 1.28.5+ Fix from $1,9502026-03-10 MEDIUM 6.5 CVE-2025-66413 Git for Windows is the Windows port of Git. Prior to 2.53.0(2), it is possible to obtain a user's NTLM hash by tricking them into cloning from a mali… Git after 2.53.0 Fix from $1,6002026-03-10 HIGH 7.5 CVE-2026-30933 FileBrowser Quantum is a free, self-hosted, web-based file manager. Prior to 1.3.1-beta and 1.2.2-stable, the remediation for CVE-2026-27611 is incom… Filebrowser after 1.2.9 Fix from $1,9502026-03-10 HIGH 7.5 CVE-2026-30928 Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.1, the /api/4/config REST API endpoint returns the entire parsed Glance… Glances 4.5.1+ Fix from $1,9502026-03-10 MEDIUM 5.5 CVE-2026-25186 Exposure of sensitive information to an unauthorized actor in Windows Accessibility Infrastructure (ATBroker.exe) allows an authorized attacker to di… Windows 10 1607 10.0.14393.8957 / 10.0.17763.8511+ Fix from $1,6002026-03-10 MEDIUM 5.3 CVE-2026-25185 Exposure of sensitive information to an unauthorized actor in Windows Shell Link Processing allows an unauthorized attacker to perform spoofing over … Windows 10 1607 10.0.14393.8957 / 10.0.17763.8511+ Fix from $1,6002026-03-10 HIGH 7.5 CVE-2026-30852 Caddy is an extensible server platform that uses TLS by default. From version 2.7.5 to before version 2.11.2, the vars_regexp matcher in vars.go:337 … Caddy 2.11.2+ Fix from $1,9502026-03-07 MEDIUM 5.3 CVE-2026-29787 mcp-memory-service is an open-source memory backend for multi-agent systems. Prior to version 10.21.0, the /api/health/detailed endpoint returns deta… Mcp Memory Service 10.21.0+ Fix from $1,6002026-03-07 HIGH 7.5 CVE-2026-29779 UptimeFlare is a serverless uptime monitoring & status page solution, powered by Cloudflare Workers. Prior to commit 377a596, configuration file upti… Uptimeflare 2026-03-04+ Fix from $1,9502026-03-07 MEDIUM 5.3 CVE-2026-30829 Checkmate is an open-source, self-hosted tool designed to track and monitor server hardware, uptime, response times, and incidents in real-time with … Checkmate 3.4.0+ Fix from $1,6002026-03-07 HIGH 7.5 CVE-2026-27796 Homarr is an open-source dashboard. Prior to version 1.54.0, the integration.all tRPC endpoint in Homarr is exposed as a publicProcedure, allowing un… Homarr 1.54.0+ Fix from $1,9502026-03-07 HIGH 7.5 CVE-2026-30244 Plane is an an open-source project management tool. Prior to version 1.2.2, unauthenticated attackers can enumerate workspace members and extract sen… Plane 1.2.2+ Fix from $1,9502026-03-06 HIGH 8.2 CVE-2026-30845 Wekan is an open source kanban tool built with Meteor. In versions 8.31.0 through 8.33, the board composite publication in Wekan publishes all integr… Wekan 8.33+ Fix from $1,9502026-03-06 HIGH 7.5 CVE-2026-30846 Wekan is an open source kanban tool built with Meteor. In versions 8.31.0 through 8.33, the globalwebhooks publication exposes all global webhook int… Wekan 8.33+ Fix from $1,9502026-03-06 MEDIUM 6.5 CVE-2026-30847 Wekan is an open source kanban tool built with Meteor. In versions 8.31.0 through 8.33, the notificationUsers publication in Wekan publishes user doc… Wekan 8.33+ Fix from $1,6002026-03-06