Vulnerability index

Browse CVEs

7,720 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
MEDIUM 5.3 CVE-2026-67339 guzzlehttp/guzzle versions before 7.14.2 fail to properly isolate Proxy-Authorization headers from origin servers in cURL handlers. Attackers can cap… No fix yet Fix from $1,6002026-08-01 HIGH 8.3 CVE-2026-67320 axios in a Node.js deployment using the HTTP adapter can route requests through an attacker-controlled proxy. axios hardens merged request configurat… No fix yet Fix from $1,9502026-08-01 HIGH 7.5 CVE-2026-67322 GitPython before 3.1.52 is vulnerable to environment-variable exfiltration in Repo.clone_from(). The caller-supplied remote URL is passed through Git… No fix yet Fix from $1,9502026-08-01 MEDIUM 5.3 CVE-2026-18059 The PixelYourSite – Your smart PIXEL (TAG) & API Manager plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, … No fix yet Fix from $1,6002026-08-01 HIGH 7.5 CVE-2026-14839 The Mapster WP Maps WordPress plugin before 1.24.0 does not perform any authorization or post-status check on a public REST endpoint, allowing unauth… No fix yet Fix from $1,9502026-08-01 MEDIUM 6.2 CVE-2026-54785 gemini-bridge is a lightweight MCP server bridging AI agents to Google's Gemini AI via the official CLI. From 1.0.0 until 1.3.1, consult_gemini_with_… No fix yet Fix from $1,6002026-07-31 MEDIUM 6.5 CVE-2026-45377 Decidim is a participatory democracy framework. Prior to 0.30.9, from 0.31.0 before 0.31.5, and in 0.32.0.rc1 before 0.32.0.rc2, the normal download_… No fix yet Fix from $1,6002026-07-31 CRITICAL 9.9 CVE-2026-52855 Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to 1.12.3, {{config.}} placeholders in egg… No fix yet Fix from $2,3002026-07-31 MEDIUM 6.5 CVE-2026-14928 The JS Help Desk WordPress plugin before 3.1.4 does not perform authorization or ownership checks before returning support-ticket content in a nonce… No fix yet Fix from $1,6002026-07-31 MEDIUM 6.5 CVE-2026-14931 The JS Help Desk WordPress plugin before 3.1.4 grants a support-agent capability to the Contributor role on activation and does not perform a capabi… No fix yet Fix from $1,6002026-07-31 HIGH 7.5 CVE-2026-15048 The Geeky Bot WordPress plugin before 1.2.8 does not perform an authorization check on one of its AJAX actions, allowing unauthenticated users to re… No fix yet Fix from $1,9502026-07-31 HIGH 7.5 CVE-2026-14319 The GiveWP WordPress plugin before 4.16.3 does not properly restrict access to a REST API endpoint that returns recurring-donation records, allowing… No fix yet Fix from $1,9502026-07-31 CRITICAL 9.3 CVE-2026-48499 Activepieces is an open source AI workflow automation platform. Prior to 0.84.0, an unsanitized path segment in the Code piece sandbox can let an aut… No fix yet Fix from $2,3002026-07-30 HIGH 7.5 CVE-2026-41186 When Calico's shared debug server is enabled (disabled by default), the Calico kube-controllers and Goldmane components bind their Go pprof debug lis… Calico 3.21.7 / 3.22.4+ Fix from $1,9502026-07-30 MEDIUM 6.5 CVE-2026-18005 Inappropriate implementation in WebXR in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to obtain potentially sensitive information f… Chrome 151.0.7922.72+ Fix from $1,6002026-07-30 MEDIUM 6.5 CVE-2026-18001 Inappropriate implementation in WebGL in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to obtain potentially sensitive information f… Chrome 151.0.7922.72+ Fix from $1,6002026-07-30 MEDIUM 6.5 CVE-2026-17975 Inappropriate implementation in IME in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker to obtain potentially sensitive informat… Chrome 151.0.7922.72+ Fix from $1,6002026-07-30 MEDIUM 6.2 CVE-2026-17966 Inappropriate implementation in Views in Google Chrome on Mac prior to 151.0.7922.72 allowed a local attacker to obtain potentially sensitive informa… Chrome 151.0.7922.72+ Fix from $1,6002026-07-30 MEDIUM 5.5 CVE-2026-17973 Inappropriate implementation in Views in Google Chrome on Mac prior to 151.0.7922.72 allowed a local attacker to obtain potentially sensitive informa… Chrome 151.0.7922.72+ Fix from $1,6002026-07-30 MEDIUM 6.5 CVE-2026-17892 Inappropriate implementation in WebXR in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to obtain potentially sensitive information f… Chrome 151.0.7922.72+ Fix from $1,6002026-07-30 MEDIUM 6.5 CVE-2026-17683 Inappropriate implementation in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to obtain potentially sensitive information f… Chrome 151.0.7922.72+ Fix from $1,6002026-07-30 MEDIUM 6.0 CVE-2026-67435 linuxfabrik-lib provides Python modules for database access, caching, shell execution, and API integrations. Prior to version 6.0.0, lib.url.fetch() … No fix yet Fix from $1,6002026-07-29 HIGH 8.3 CVE-2026-67436 Linuxfabrik monitoring-plugins provides Python monitoring plugins for Icinga, Nagios, and related monitoring systems. In 6.0.0 and earlier, the redfi… No fix yet Fix from $1,9502026-07-29 CRITICAL 9.1 CVE-2026-13697 undici's cache interceptor mishandles malformed Cache-Control private directives. In undici 7.0.0 up to before 7.29.0 and 8.0.0 up to before 8.9.0, a… Undici 7.29.0 / 8.9.0+ Fix from $2,3002026-07-29 HIGH 7.4 CVE-2026-54660 swagger-typescript-api generates API clients for Fetch or Axios from OpenAPI specifications. Prior to 13.12.2, src/resolved-swagger-schema.ts getRemo… No fix yet Fix from $1,9502026-07-29 MEDIUM 5.3 CVE-2026-66489 Joomla Extension - balbooa.com - Various unauthenticated file system disclosure in Gridbox < 2.20.2 Gridbox 2.20.2+ Fix from $1,6002026-07-29 HIGH 8.7 CVE-2026-58157 Apache Traffic Server can reuse server sessions and tunnels improperly, exposing data across client connections. This issue affects Apache Traffic S… Traffic Server 9.2.15 / 10.1.4+ Fix from $1,9502026-07-29 MEDIUM 5.3 CVE-2026-11351 The ShinyStat Analytics WordPress plugin before 1.0.17 does not perform any authorization check on one of its REST API endpoints, allowing unauthenti… No fix yet Fix from $1,6002026-07-29 MEDIUM 6.9 CVE-2026-54659 Pagy is agnostic pagination in plain Ruby. From 43.0.0 until 43.5.6, Pagy::I18n.locale= in gem/lib/pagy/modules/i18n/i18n.rb stored locale values ver… No fix yet Fix from $1,6002026-07-28 HIGH 7.5 CVE-2026-55389 datamodel-code-generator generates Pydantic v2 models, dataclasses, TypedDict, and msgspec.Struct from OpenAPI, JSON Schema, GraphQL, Avro, Protobuf,… Datamodel Code Generator 0.62.0+ Fix from $1,9502026-07-28