Vulnerability index

Browse CVEs

7,732 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
MEDIUM 5.3 CVE-2024-26478 An issue in Statping-ng v.0.91.0 allows an attacker to obtain sensitive information via a crafted request to the /api/users endpoint. Statping Ng No fix yet Fix from $1,6002026-02-11 MEDIUM 5.3 CVE-2024-26479 An issue in Statping-ng v.0.91.0 allows an attacker to obtain sensitive information via a crafted request to the Command execution function. Statping Ng No fix yet Fix from $1,6002026-02-11 HIGH 7.5 CVE-2024-26480 An issue in Statping-ng v.0.91.0 allows an attacker to obtain sensitive information via a crafted request to the admin parameter. Statping Ng No fix yet Fix from $1,9502026-02-11 HIGH 7.5 CVE-2024-26477 An issue in Statping-ng v.0.91.0 allows an attacker to obtain sensitive information via a crafted request to the api parameter of the oauth, amazon_s… Statping Ng No fix yet Fix from $1,9502026-02-11 MEDIUM 6.5 CVE-2026-2317 Inappropriate implementation in Animation in Google Chrome prior to 145.0.7632.45 allowed a remote attacker to leak cross-origin data via a crafted H… Chrome 145.0.7632.45+ Fix from $1,6002026-02-11 MEDIUM 5.3 CVE-2026-2295 The WPZOOM Addons for Elementor – Starter Templates & Widgets plugin for WordPress is vulnerable to unauthorized access of data due to a missing capa… Mitigation only Fix from $1,6002026-02-11 HIGH 7.5 CVE-2026-21260 Exposure of sensitive information to an unauthorized actor in Microsoft Office Outlook allows an unauthorized attacker to perform spoofing over a net… 365 Apps 16.0.19127.20518+ Fix from $1,9502026-02-10 MEDIUM 5.9 CVE-2025-68686 KEV An Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE-200] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.1, FortiOS … Fortios 7.4.7 / 7.6.2+ Fix from $1,6002026-02-10 HIGH 7.5 CVE-2026-2268 The Ninja Forms plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.14.0. This is due to the… Mitigation only Fix from $1,9502026-02-10 MEDIUM 6.5 CVE-2026-24098 Apache Airflow versions 3.0.0 - 3.1.7, has vulnerability that allows authenticated UI users with permission to one or more specific Dags to view impo… Airflow 3.1.7+ Fix from $1,6002026-02-09 HIGH 7.5 CVE-2026-2148 A security vulnerability has been detected in Tenda AC21 16.03.08.16. Affected is an unknown function of the file /cgi-bin/DownloadFlash of the compo… Ac21 Firmware No fix yet Fix from $1,9502026-02-08 MEDIUM 5.3 CVE-2026-2147 A weakness has been identified in Tenda AC21 16.03.08.16. This impacts an unknown function of the file /cgi-bin/DownloadLog of the component Web Mana… Ac21 Firmware No fix yet Fix from $1,6002026-02-08 MEDIUM 5.3 CVE-2026-2207 A weakness has been identified in WeKan up to 8.20. This issue affects some unknown processing of the file server/publications/activities.js of the c… Wekan 8.21+ Fix from $1,6002026-02-08 CRITICAL 9.1 CVE-2026-1727 The Agentspace service was affected by a vulnerability that exposed sensitive information due to the use of predictable Google Cloud Storage bucket n… Mitigation only Fix from $2,3002026-02-06 HIGH 7.5 CVE-2026-25650 MCP Salesforce Connector is a Model Context Protocol (MCP) server implementation for Salesforce integration. Prior to 0.1.10, arbitrary attribute acc… Mcp Salesforce Connector 0.1.10+ Fix from $1,9502026-02-06 HIGH 7.6 CVE-2025-70963 Gophish <=0.12.1 is vulnerable to Incorrect Access Control. The administrative dashboard exposes each user’s long-lived API key directly inside the r… Gophish after 0.12.1 Fix from $1,9502026-02-06 HIGH 7.5 CVE-2026-2056 A security vulnerability has been detected in D-Link DIR-605L and DIR-619L 2.06B01/2.13B01. The impacted element is an unknown function of the file /… Dir 605l Firmware No fix yet Fix from $1,9502026-02-06 HIGH 7.5 CVE-2026-2054 A security flaw has been discovered in D-Link DIR-605L and DIR-619L 2.06B01/2.13B01. Impacted is an unknown function of the component Wifi Setting Ha… Dir 605l Firmware No fix yet Fix from $1,9502026-02-06 HIGH 7.5 CVE-2026-2055 A weakness has been identified in D-Link DIR-605L and DIR-619L 2.06B01/2.13B01. The affected element is an unknown function of the component DHCP Cli… Dir 605l Firmware No fix yet Fix from $1,9502026-02-06 MEDIUM 5.5 CVE-2026-24916 Identity authentication bypass vulnerability in the window module. Impact: Successful exploitation of this vulnerability may affect service confident… Harmonyos No fix yet Fix from $1,6002026-02-06 HIGH 7.5 CVE-2026-21626 Access control settings for forum post custom fields are not applied to the JSON output type, leading to an ACL violation vector an information discl… Easydiscuss after 5.0.15 Fix from $1,9502026-02-06 HIGH 8.2 CVE-2026-21532 Azure Function Information Disclosure Vulnerability Azure Functions No fix yet Fix from $1,9502026-02-05 MEDIUM 5.3 CVE-2026-25523 Magento-lts is a long-term support alternative to Magento Community Edition (CE). Prior to version 20.16.1, the admin url can be discovered without p… Magento after 20.16.0 Fix from $1,6002026-02-04 MEDIUM 6.5 CVE-2026-25475 OpenClaw is a personal AI assistant. Prior to version 2026.1.30, the isValidMedia() function in src/media/parse.ts allows arbitrary file paths includ… Openclaw 2026.1.30+ Fix from $1,6002026-02-04 HIGH 7.7 CVE-2025-61917 n8n is an open source workflow automation platform. From version 1.65.0 to before 1.114.3, the use of Buffer.allocUnsafe() and Buffer.allocUnsafeSlow… N8n 1.114.3+ Fix from $1,9502026-02-04 MEDIUM 5.3 CVE-2025-15482 The Chapa Payment Gateway Plugin for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and incl… Mitigation only Fix from $1,6002026-02-04 MEDIUM 5.3 CVE-2025-15508 The Magic Import Document Extractor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.0.4 … Mitigation only Fix from $1,6002026-02-04 HIGH 8.1 CVE-2025-52631 HCL AION is affected by a Missing or Insecure HTTP Strict-Transport-Security (HSTS) Header vulnerability. This can allow insecure connections, potent… Aion Mitigation only Fix from $1,9502026-02-03 MEDIUM 6.5 CVE-2020-37114 GUnet OpenEclass 1.7.3 allows unauthenticated and authenticated users to access sensitive information, including system information, application vers… Open Eclass Platform No fix yet Fix from $1,6002026-02-03 MEDIUM 6.5 CVE-2025-65017 Decidim is a participatory democracy framework. In versions from 0.30.0 to before 0.30.4 and from 0.31.0.rc1 to before 0.31.0, the private data expor… Decidim 0.30.4+ Fix from $1,6002026-02-03