Vulnerability index

Browse CVEs

7,732 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
MEDIUM 5.3 CVE-2026-22645 The application discloses all used components, versions and license information to unauthenticated actors, giving attackers the opportunity to target… Incoming Goods Suite 1.2.1+ Fix from $1,6002026-01-15 HIGH 7.5 CVE-2026-22240 The vulnerability exists in BLUVOYIX due to an improper password storage implementation and subsequent exposure via unauthenticated APIs. An unauthen… Bluvoyix Mitigation only Fix from $1,9502026-01-14 CRITICAL 9.8 CVE-2026-22237 The vulnerability exists in BLUVOYIX due to the exposure of sensitive internal API documentation. An unauthenticated remote attacker could exploit th… Bluvoyix Mitigation only Fix from $2,3002026-01-14 MEDIUM 5.3 CVE-2026-0717 The LottieFiles – Lottie block for Gutenberg plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includin… Mitigation only Fix from $1,6002026-01-14 MEDIUM 5.3 CVE-2025-14464 The PDF Resume Parser plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.0. This is due to … Mitigation only Fix from $1,6002026-01-14 MEDIUM 5.5 CVE-2025-68965 Permission control vulnerability in the Notepad module. Impact: Successful exploitation of this vulnerability may affect service confidentiality. Harmonyos No fix yet Fix from $1,6002026-01-14 MEDIUM 5.5 CVE-2025-68966 Permission control vulnerability in the Notepad module. Impact: Successful exploitation of this vulnerability may affect service confidentiality. Harmonyos No fix yet Fix from $1,6002026-01-14 MEDIUM 5.5 CVE-2025-68959 Permission verification bypass vulnerability in the media library module. Impact: Successful exploitation of this vulnerability may affect service co… Emui No fix yet Fix from $1,6002026-01-14 MEDIUM 5.5 CVE-2026-20939 Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally. Windows 10 1607 10.0.14393.8783 / 10.0.17763.8276+ Fix from $1,6002026-01-13 MEDIUM 5.5 CVE-2026-20932 Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally. Windows 10 1607 10.0.14393.8783 / 10.0.17763.8276+ Fix from $1,6002026-01-13 MEDIUM 5.5 CVE-2026-20937 Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally. Windows 10 1607 10.0.14393.8783 / 10.0.17763.8276+ Fix from $1,6002026-01-13 MEDIUM 5.5 CVE-2026-20862 Exposure of sensitive information to an unauthorized actor in Windows Management Services allows an authorized attacker to disclose information local… Windows 10 1809 10.0.17763.8276 / 10.0.19044.6809+ Fix from $1,6002026-01-13 MEDIUM 6.5 CVE-2026-20847 Exposure of sensitive information to an unauthorized actor in Windows Shell allows an authorized attacker to perform spoofing over a network. Windows 10 1607 10.0.14393.8783 / 10.0.17763.8276+ Fix from $1,6002026-01-13 MEDIUM 5.5 CVE-2026-20827 Exposure of sensitive information to an unauthorized actor in Tablet Windows User Interface (TWINUI) Subsystem allows an authorized attacker to discl… Windows 10 1607 10.0.14393.8783 / 10.0.17763.8276+ Fix from $1,6002026-01-13 MEDIUM 6.2 CVE-2026-20821 Exposure of sensitive information to an unauthorized actor in Windows Remote Procedure Call allows an unauthorized attacker to disclose information l… Windows 10 1607 10.0.14393.8783 / 10.0.17763.8276+ Fix from $1,6002026-01-13 MEDIUM 5.5 CVE-2026-20823 Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally. Windows 10 1607 10.0.14393.8783 / 10.0.17763.8276+ Fix from $1,6002026-01-13 MEDIUM 5.5 CVE-2026-20805 KEVEPSS 5% Exposure of sensitive information to an unauthorized actor in Desktop Windows Manager allows an authorized attacker to disclose information locally. Windows 10 1607 10.0.14393.8783 / 10.0.17763.8276+ Fix from $1,6002026-01-13 HIGH 7.5 CVE-2025-37165 A vulnerability in the router mode configuration of HPE Instant On Access Points exposed certain network configuration details to unintended interfac… Mitigation only Fix from $1,9502026-01-13 CRITICAL 9.8 CVE-2025-47855 An exposure of sensitive information to an unauthorized actor [CWE-200] vulnerability in Fortinet FortiFone 7.0.0 through 7.0.1, FortiFone 3.0.13 thr… Mitigation only Fix from $2,3002026-01-13 MEDIUM 5.3 CVE-2026-0888 Information disclosure in the XML component. This vulnerability was fixed in Firefox 147 and Thunderbird 147. Firefox 147.0+ Fix from $1,6002026-01-13 MEDIUM 5.3 CVE-2026-0883 Information disclosure in the Networking component. This vulnerability was fixed in Firefox 147, Firefox ESR 140.7, Thunderbird 147, and Thunderbird … Firefox 140.7.0 / 147.0+ Fix from $1,6002026-01-13 MEDIUM 5.3 CVE-2025-14507 The EventPrime - Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, an… Mitigation only Fix from $1,6002026-01-13 MEDIUM 5.5 CVE-2026-22251 wlc is a Weblate command-line client using Weblate's REST API. Prior to 1.17.0, wlc supported providing unscoped API keys in the setting. This practi… Wlc 1.17.0+ Fix from $1,6002026-01-12 MEDIUM 5.3 CVE-2025-65090 XWiki Full Calendar Macro displays objects from the wiki on the calendar. Prior to version 2.4.6, users with the rights to view the Calendar.JSONServ… Full Calendar Macro 2.4.6+ Fix from $1,6002026-01-10 MEDIUM 5.3 CVE-2026-22604 OpenProject is an open-source, web-based project management software. For OpenProject versions from 11.2.1 to before 16.6.2, when sending a POST requ… Openproject 16.6.2+ Fix from $1,6002026-01-10 CRITICAL 9.1 CVE-2026-22600 OpenProject is an open-source, web-based project management software. A Local File Read (LFR) vulnerability exists in the work package PDF export fun… Openproject 16.6.4+ Fix from $2,3002026-01-10 MEDIUM 6.5 CVE-2025-14980 The BetterDocs plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.3.3 via the scripts() fun… Mitigation only Fix from $1,6002026-01-09 MEDIUM 5.3 CVE-2025-14574 The weDocs plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.1.15 via the `/wp-json/wp/v2/… Mitigation only Fix from $1,6002026-01-09 MEDIUM 5.4 CVE-2025-68718 KAYSUS KS-WR1200 routers with firmware 107 expose SSH and TELNET services on the LAN interface with hardcoded root credentials (root:12345678). The a… Ks Wr1200 Firmware No fix yet Fix from $1,6002026-01-08 HIGH 8.8 CVE-2025-68719 KAYSUS KS-WR3600 routers with firmware 1.0.5.9.1 mishandle configuration management. Once any user is logged in and maintains an active session, an a… Ks Wr3600 Firmware No fix yet Fix from $1,9502026-01-08