Vulnerability index

Browse CVEs

7,720 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
MEDIUM 5.3 CVE-2026-72549 An information disclosure vulnerability in OpenSignLabs OpenSign through 2.37.0 allows unauthenticated remote attackers to map any email address or u… No fix yet Fix from $4,0002026-08-11 MEDIUM 6.5 CVE-2026-72539 An information disclosure vulnerability in Windmill Labs Windmill through 1.783.0 allows any authenticated workspace member to read legacy ownerless … No fix yet Fix from $4,0002026-08-11 HIGH 7.5 CVE-2026-72915 Mastodon is a free, open-source social network server based on ActivityPub. From 4.6.0-beta.1 until 4.6.4 and 4.7.0-beta.1, any logged-in local user … No fix yet Fix from $4,9002026-08-10 MEDIUM 6.5 CVE-2026-72873 Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, application.one in apps/dokploy/server/api/routers/application.ts re… No fix yet Fix from $4,0002026-08-10 MEDIUM 6.5 CVE-2026-72726 Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, an authenticated user could eavesdrop on privat… No fix yet Fix from $4,0002026-08-10 MEDIUM 5.3 CVE-2026-72760 Affected versions of MISP cti-transmute disclose users' email addresses through the account following-list endpoint. When an authenticated user follo… No fix yet Fix from $4,0002026-08-10 HIGH 7.5 CVE-2026-61899 Vulnerability in tapestry-core in Apache Tapestry 5.5.0+ on all platforms allows attackers to download clsspath assets via specially crafted URLs. Us… Tapestry No fix yet Fix from $4,9002026-08-10 MEDIUM 5.3 CVE-2026-19074 The Advanced Classifieds & Directory Pro Advanced Classifieds & Directory Pro WordPress plugin before 3.4.3 (<= 3.4.2) is vulnerable to unauthenticat… No fix yet Fix from $4,0002026-08-10 HIGH 7.5 CVE-2026-18470 The Login & Register Forms WordPress plugin before 4.0.2 does not verify that a password reset request comes from the account's owner, and does not … No fix yet Fix from $4,9002026-08-10 HIGH 7.5 CVE-2026-18946 The Contact Form to Any API WordPress plugin before 3.0.7 does not use a random filename when copying files uploaded through contact forms into a pub… No fix yet Fix from $4,9002026-08-10 HIGH 7.5 CVE-2026-17022 The Salon Booking System WordPress plugin before 10.30.34 does not properly validate a booking's ownership token before loading it in its booking-wi… No fix yet Fix from $4,9002026-08-10 HIGH 7.5 CVE-2026-17541 The File Manager WordPress plugin before 6.9.1 does not have authorisation checks on one of its REST API routes, allowing unauthenticated users to re… No fix yet Fix from $4,9002026-08-10 HIGH 7.5 CVE-2026-17542 The File Manager WordPress plugin before 6.9.1 does not perform any capability check on one of its file manager connector endpoints, allowing any aut… No fix yet Fix from $4,9002026-08-10 HIGH 7.5 CVE-2026-14206 The HT Contact Form WordPress plugin before 2.9.3 does not perform any authorization check on the endpoint that returns a saved form draft, allowing… No fix yet Fix from $4,9002026-08-10 MEDIUM 5.3 CVE-2026-19363 A vulnerability was found in lmammino oidc-authorizer up to 0.4.0. Impacted is an unknown function of the file src/handler.rs of the component Lambda… No fix yet Fix from $4,0002026-08-09 MEDIUM 5.3 CVE-2026-19357 A security flaw has been discovered in MingSoft MCMS up to 3.0.6. Affected is an unknown function of the file /mdiy/form/get of the component ms-mdiy… No fix yet Fix from $4,0002026-08-09 MEDIUM 5.3 CVE-2026-19356 A vulnerability was identified in MingSoft MCMS up to 3.0.6. This impacts an unknown function of the file /mdiy/form/data/list of the component ms-md… No fix yet Fix from $4,0002026-08-09 HIGH 7.5 CVE-2026-18357 The WPC Order Tip for WooCommerce WordPress plugin before 3.3.1 does not perform authorisation or nonce checks in one of its reporting features, allo… No fix yet Fix from $4,9002026-08-09 HIGH 7.5 CVE-2026-18032 The WP Data Access WordPress plugin before 5.5.79 does not validate the column names it accepts on one of its unauthenticated AJAX actions, and the … No fix yet Fix from $4,9002026-08-09 HIGH 7.5 CVE-2026-16988 The GeoDirectory WordPress plugin before 2.8.169 does not perform any authorization check when returning map marker data for a single requested list… No fix yet Fix from $4,9002026-08-09 MEDIUM 6.5 CVE-2026-16595 The WP Directory Kit WordPress plugin before 1.5.5 does not perform authorization or nonce checks on one of its authenticated AJAX actions, allowing … No fix yet Fix from $1,6002026-08-08 MEDIUM 6.5 CVE-2026-16562 The WP Statistics WordPress plugin before 14.16.10 does not perform a capability check on a set of dashboard analytics AJAX handlers, relying only o… No fix yet Fix from $1,6002026-08-08 HIGH 7.5 CVE-2026-16578 The Admin Safety Guard — Login Security, Limit Logins, 2FA & Brute Force Protection WordPress plugin before 1.4.0 does not perform any capability che… No fix yet Fix from $1,9502026-08-08 MEDIUM 6.5 CVE-2026-16590 The WP Directory Kit WordPress plugin before 1.5.5 does not perform authorization or nonce checks on one of its authenticated AJAX actions, allowing … No fix yet Fix from $1,6002026-08-08 HIGH 7.5 CVE-2026-16594 The WP Directory Kit WordPress plugin before 1.5.5 does not perform authorization or nonce checks on one of its authenticated AJAX actions, allowing … No fix yet Fix from $1,9502026-08-08 HIGH 8.6 CVE-2026-48007 Element Call is a native Matrix video conferencing application. Versions 0.5.17 through 0.19.3 report analytics data to a PostHog server, when config… No fix yet Fix from $1,9502026-08-07 MEDIUM 6.5 CVE-2026-47364 In versions of the Datadog Android application prior to v545-5.9.2, the app tags Crashlytics data with the user's Datadog UUID, with no user-facing o… No fix yet Fix from $1,6002026-08-07 MEDIUM 5.3 CVE-2026-19229 A vulnerability was determined in SourceCodester Online Clothing Store. Affected by this issue is some unknown functionality of the file /_notes/ of … No fix yet Fix from $1,6002026-08-07 CRITICAL 9.2 CVE-2026-54203 Memory Leak to an Unauthorized Actor vulnerability in Tobit Laboratories AG TeamDavid's Webbox allows reading of sensitive information. When accessin… No fix yet Fix from $2,3002026-08-07 HIGH 7.5 CVE-2026-14943 The Password Protected — Lock Entire Site, Pages, Posts, Categories, and Partial Content WordPress plugin before 2.8.4 does not restrict REST API acc… No fix yet Fix from $1,9502026-08-07