Vulnerability index

Browse CVEs

7,732 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
HIGH 7.5 CVE-2025-8590 Exposure of Sensitive Information to an Unauthorized Actor vulnerability in AKCE Software Technology R&D Industry and Trade Inc. SKSPro allows Direct… Mitigation only Fix from $1,9502026-02-03 MEDIUM 5.3 CVE-2026-1371 The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and … Mitigation only Fix from $1,6002026-02-03 MEDIUM 5.3 CVE-2026-0950 The Spectra Gutenberg Blocks – Website Builder for the Block Editor plugin for WordPress is vulnerable to Information Disclosure in all versions up t… Mitigation only Fix from $1,6002026-02-03 HIGH 7.5 CVE-2026-25222 PolarLearn is a free and open-source learning program. In 0-PRERELEASE-15 and earlier, a timing attack vulnerability in the sign-in process allows un… Polarlearn Patch available Fix from $1,9502026-02-02 HIGH 7.5 CVE-2026-23743 Discourse is an open source discussion platform. In versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0, permalinks pointing to access-restri… Discourse 3.5.4 / 2025.11.2+ Fix from $1,9502026-01-28 MEDIUM 5.3 CVE-2026-1060 The WP Adminify plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.0.7.7 via the /wp-json/a… Mitigation only Fix from $1,6002026-01-28 MEDIUM 6.5 CVE-2025-54373 OpenEMR is a free and open source electronic health records and medical practice management application. Versions prior to 7.0.4 have a vulnerability… Openemr Patch available Fix from $1,6002026-01-28 MEDIUM 5.3 CVE-2026-24473 Hono is a Web application framework that provides support for any JavaScript runtime. Prior to version 4.11.7, Serve static Middleware for the Cloudf… Hono 4.11.7+ Fix from $1,6002026-01-27 HIGH 7.5 CVE-2026-24870 Exposure of Sensitive Information to an Unauthorized Actor vulnerability in ixray-team ixray-1.6-stcop.This issue affects ixray-1.6-stcop: before 1.3. Ix Ray Engine 1.6 1.3+ Fix from $1,9502026-01-27 HIGH 7.5 CVE-2025-67274 An issue in continuous.software aangine v.2025.2 allows a remote attacker to obtain sensitive information via the excel-integration-service template … Aangine Mitigation only Fix from $1,9502026-01-26 MEDIUM 5.3 CVE-2025-13920 The WP Directory Kit plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.4.9 via the wdk_pub… Mitigation only Fix from $1,6002026-01-24 HIGH 7.5 CVE-2026-24422 phpMyFAQ is an open source FAQ web application. In versions 4.0.16 and below, multiple public API endpoints improperly expose sensitive user informat… Phpmyfaq 4.0.17+ Fix from $1,9502026-01-24 HIGH 7.5 CVE-2025-52026 An information disclosure vulnerability exists in the /srvs/membersrv/getCashiers endpoint of the Aptsys gemscms backend platform thru 2025-05-28. Th… Gemscms Backend after 2025-05-28 Fix from $1,9502026-01-23 HIGH 7.5 CVE-2026-0789 ALGO 8180 IP Audio Alerter Web UI Inclusion of Authentication Cookie in Response Body Information Disclosure Vulnerability. This vulnerability allows… 8180 Ip Audio Alerter Firmware Mitigation only Fix from $1,9502026-01-23 HIGH 7.4 CVE-2026-21524 Exposure of sensitive information to an unauthorized actor in Azure Data Explorer allows an unauthorized attacker to disclose information over a netw… Azure Data Explorer No fix yet Fix from $1,9502026-01-22 MEDIUM 6.5 CVE-2026-20800 Gitea's notification API does not re-validate repository access permissions when returning notification details. After a user's access to a private r… Gitea 1.25.4+ Fix from $1,6002026-01-22 HIGH 7.4 CVE-2025-69822 An issue in Atomberg Atomberg Erica Smart Fan Firmware Version: V1.0.36 allows an attacker to obtain sensitive information and escalate privileges vi… Erica Smart Fan Firmware No fix yet Fix from $1,9502026-01-22 HIGH 7.4 CVE-2025-65098 Typebot is an open-source chatbot builder. In versions prior to 3.13.2, client-side script execution in Typebot allows stealing all stored credential… Typebot 3.13.2+ Fix from $1,9502026-01-22 MEDIUM 5.3 CVE-2026-21974 Vulnerability in the Oracle Life Sciences Central Designer product of Oracle Health Sciences Applications (component: Platform). The supported vers… Life Sciences Central Designer Mitigation only Fix from $1,6002026-01-20 HIGH 7.5 CVE-2026-21940 Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: User and User Group). The supported version that is affected is 9.… Supply Chain Products Suite Mitigation only Fix from $1,9502026-01-20 MEDIUM 5.3 CVE-2026-21928 Vulnerability in the Oracle Solaris product of Oracle Systems (component: Kernel). The supported version that is affected is 11. Easily exploitable… Solaris Mitigation only Fix from $1,6002026-01-20 CRITICAL 9.8 CVE-2026-0905 Insufficient policy enforcement in Network in Google Chrome prior to 144.0.7559.59 allowed an attack who obtained a network log file to potentially o… Chrome 144.0.7559.59 / 144.0.7559.60+ Fix from $2,3002026-01-20 MEDIUM 5.3 CVE-2026-1196 A security vulnerability has been detected in MineAdmin 1.x/2.x. Affected is an unknown function of the file /system/getFileInfoById. Such manipulati… Mineadmin No fix yet Fix from $1,6002026-01-20 HIGH 7.5 CVE-2026-1194 A security flaw has been discovered in MineAdmin 1.x/2.x. This affects an unknown function of the component Swagger. The manipulation results in info… Mineadmin No fix yet Fix from $1,9502026-01-20 HIGH 7.5 CVE-2026-1175 A vulnerability was identified in birkir prime up to 0.4.0.beta.0. This impacts an unknown function of the file /graphql of the component GraphQL Dir… Prime after 0.4.0 Fix from $1,9502026-01-19 MEDIUM 5.3 CVE-2026-1170 A vulnerability was detected in birkir prime up to 0.4.0.beta.0. This issue affects some unknown processing of the file /graphql of the component Gra… Prime after 0.4.0 Fix from $1,6002026-01-19 MEDIUM 5.3 CVE-2025-12129 The CubeWP – All-in-One Dynamic Content Framework plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.… Mitigation only Fix from $1,6002026-01-17 MEDIUM 5.3 CVE-2025-14075 The WP Hotel Booking plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.2.7. This is due to… Mitigation only Fix from $1,6002026-01-17 MEDIUM 5.3 CVE-2025-24089 A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 18.3 and iPadOS 18.3. An app may be able to enumerate a us… Ipados 18.3+ Fix from $1,6002026-01-16 HIGH 7.5 CVE-2025-68438 In Apache Airflow versions before 3.1.6, when rendered template fields in a Dag exceed [core] max_templated_field_length, sensitive values could be e… Airflow 3.1.6+ Fix from $1,9502026-01-16