Vulnerability index

Browse CVEs

7,732 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
MEDIUM 6.4 CVE-2026-28682 Gokapi is a self-hosted file sharing server with automatic expiration and encryption support. Prior to version 2.2.3, the upload status SSE implement… Gokapi 2.2.3+ Fix from $1,6002026-03-06 MEDIUM 5.3 CVE-2026-28675 OpenSift is an AI study tool that sifts through large datasets using semantic search and generative AI. Prior to version 1.6.3-alpha, some endpoints … Opensift 1.6.3+ Fix from $1,6002026-03-06 MEDIUM 5.3 CVE-2026-2589 The Greenshift – animation and page builder blocks plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and in… Mitigation only Fix from $1,6002026-03-06 MEDIUM 6.5 CVE-2026-28492 File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename and edit files. Pr… Filebrowser 2.61.0+ Fix from $1,6002026-03-05 MEDIUM 5.3 CVE-2026-28434 cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.35.0, when a request handler throws a C++ exception and … Cpp Httplib 0.35.0+ Fix from $1,6002026-03-04 MEDIUM 6.5 CVE-2026-3058 The Seraphinite Accelerator plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.28.14 via th… Seraphinite Accelerator 2.28.15+ Fix from $1,6002026-03-04 HIGH 7.5 CVE-2026-2747 SEPPmail Secure Email Gateway before version 15.0.1 decrypts inline PGP messages without isolating them from surrounding unencrypted content, allowin… Seppmail 15.0.1+ Fix from $1,9502026-03-04 HIGH 7.5 CVE-2026-2025 The Mail Mint WordPress plugin before 1.19.5 does not have authorization in one of its REST API endpoint, allowing unauthenticated users to call it … Mitigation only Fix from $1,9502026-03-04 MEDIUM 5.3 CVE-2026-1980 The WPBookit plugin for WordPress is vulnerable to unauthorized data disclosure due to a missing authorization check on the 'get_customer_list' route… Mitigation only Fix from $1,6002026-03-04 HIGH 8.1 CVE-2026-25146 OpenEMR is a free and open source electronic health records and medical practice management application. From 5.0.2 to before 8.0.0, there are (at le… Openemr 8.0.0+ Fix from $1,9502026-03-03 HIGH 8.4 CVE-2026-0025 In hasImage of Notification.java, there is a possible way to reveal information across users due to a permissions bypass. This could lead to local es… Android Mitigation only Fix from $1,9502026-03-02 MEDIUM 6.2 CVE-2026-0005 In onServiceDisconnected of KeyguardServiceDelegate.java, there is a possible partial bypass of app pinning allowing limited interaction with other a… Android Mitigation only Fix from $1,6002026-03-02 MEDIUM 5.5 CVE-2025-48642 In jump_to_payload of payload.rs, there is a possible information disclosure due to a logic error in the code. This could lead to local information d… Android Mitigation only Fix from $1,6002026-03-02 HIGH 7.7 CVE-2025-48635 In multiple functions of TaskFragmentOrganizerController.java, there is a possible activity token leak due to a logic error in the code. This could l… Android Mitigation only Fix from $1,9502026-03-02 MEDIUM 6.5 CVE-2025-64427 ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In version 1.5.0 and prior, due to insufficient valida… Zimaos after 1.5.0 Fix from $1,6002026-03-02 MEDIUM 5.3 CVE-2026-28559 wpForo Forum 2.4.14 contains an information disclosure vulnerability that allows unauthenticated users to retrieve private and unapproved forum topic… Wpforo Forum 2.4.16+ Fix from $1,6002026-02-28 MEDIUM 6.7 CVE-2025-9908 A flaw was found in the Red Hat Ansible Automation Platform, Event-Driven Ansible (EDA) Event Streams. This vulnerability allows an authenticated use… Ansible Automation Platform 2.6+ Fix from $1,6002026-02-27 MEDIUM 6.7 CVE-2025-9907 A flaw was found in the Red Hat Ansible Automation Platform, Event-Driven Ansible (EDA) Event Stream API. This vulnerability allows exposure of sensi… Ansible Automation Platform 2.6+ Fix from $1,6002026-02-27 HIGH 7.5 CVE-2026-24498 Exposure of Sensitive Information to an Unauthorized Actor vulnerability in EFM-Networks, Inc. IpTIME T5008, EFM-Networks, Inc. IpTIME AX2004M, EFM-N… T5008 Firmware 15.27.2+ Fix from $1,9502026-02-27 HIGH 7.5 CVE-2026-28276 Initiative is a self-hosted project management platform. An access control vulnerability exists in Initiative versions prior to 0.32.2 where uploaded… Initiative 0.32.2+ Fix from $1,9502026-02-26 CRITICAL 9.8 CVE-2026-28213 EverShop is a TypeScript-first eCommerce platform. Versions prior to 2.1.1 have a vulnerability in the "Forgot Password" functionality. When specifyi… Evershop 2.1.1+ Fix from $2,3002026-02-26 HIGH 8.4 CVE-2026-2244 A vulnerability in Google Cloud Vertex AI Workbench from 7/21/2025 to 01/30/2026 allows an attacker to exfiltrate valid Google Cloud access tokens of… Mitigation only Fix from $1,9502026-02-26 MEDIUM 6.5 CVE-2026-24487 OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0, an authorization byp… Openemr 8.0.0+ Fix from $1,6002026-02-25 HIGH 7.5 CVE-2026-20133 KEVEPSS 31% A vulnerability in Cisco Catalyst SD-WAN Software could allow an unauthenticated, remote attacker to view sensitive information on an affected system… Catalyst Sd Wan Manager 20.9.8.2 / 20.12.5.3+ Fix from $1,9502026-02-25 MEDIUM 6.5 CVE-2026-27611 FileBrowser Quantum is a free, self-hosted, web-based file manager. Prior to versions 1.1.3-stable and 1.2.6-beta, when users share password-protecte… Filebrowser Quantum 1.1.3 / 1.2.6+ Fix from $1,6002026-02-25 MEDIUM 6.5 CVE-2026-3131 Improper access control in multiple DVLS REST API endpoints in Devolutions Server 2025.3.14.0 and earlier allows an authenticated user with view-on… Devolutions Server 2025.3.15.0+ Fix from $1,6002026-02-24 HIGH 7.5 CVE-2026-2803 Information disclosure, mitigation bypass in the Settings UI component. This vulnerability was fixed in Firefox 148 and Thunderbird 148. Firefox 148.0+ Fix from $1,9502026-02-24 HIGH 7.5 CVE-2026-2783 Information disclosure due to JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 148, Firefox ESR 14… Firefox 140.8.0 / 148.0+ Fix from $1,9502026-02-24 MEDIUM 6.5 CVE-2026-23983 A Sensitive Data Exposure vulnerability exists in Apache Superset allowing authenticated users to retrieve sensitive user information. The Tag endpoi… Superset 6.0.0+ Fix from $1,6002026-02-24 MEDIUM 6.5 CVE-2026-2976 A weakness has been identified in FastApiAdmin up to 2.2.0. Affected by this issue is the function download_controller of the file /backend/app/api/v… Fastapiadmin after 2.2.0 Fix from $1,6002026-02-23