CVE & CISA-KEV Catalog

395,283 CVEs1,715 actively exploited (KEV)
Active:
  • CVSS 6.5 v3·EPSS -·No fix yet

    IBM QRadar 7.5.0 through 7.5.0 UP15 Interim Fix 006 could allow an authenticated user to obtain sensitive information from backup files due to incorrect permissions assignment.

    Published 2026-09-18

  • CVSS 6.5 v3·EPSS -·No fix yet

    A low-privileged remote attacker can manipulate the schema path parameter in the /index.php/diagnostics_tab/ajax_diag_table_rows endpoint using a valid user cookie allowing disclosure of all user password hashes.

    Published 2026-09-16

  • CVSS 8.1 v3·EPSS 0.3%·No fix yet

    The endpoint on the iDirect iQ200 VSAT terminal returns the complete device configuration as JSON, including the SECURITY section which contains MD5-crypt password hashes for the root SSH and web administration accounts. Any user with valid web credentials can extract these hashes and crack them offline using commodity hardware.

    Published 2026-09-11

  • CVSS 4.3 v3·EPSS 0.2%·Fix available

    An issue was discovered in Cyrus IMAP before 3.12.4. There is a Sieve mailbox existence oracle. An authenticated user could install a Sieve script that probed whether another user's private mailbox existed, or read the value of shared mailbox annotations, by observing which fileinto branch fired during LMTP delivery.

    Published 2026-09-09

  • CVSS 5.5 v3·EPSS 0.4%·Fix available

    Exposure of sensitive system information to an unauthorized control sphere in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

    Published 2026-09-08

  • CVSS 5.5 v3·EPSS 0.4%·Fix available

    Exposure of sensitive system information to an unauthorized control sphere in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

    Published 2026-09-08

  • CVSS 7.5 v3·EPSS 0.8%·Fix available

    Exposure of sensitive system information to an unauthorized control sphere in Windows Services for NFS ONCRPC XDR Driver allows an unauthorized attacker to disclose information over a network.

    Published 2026-09-08

  • CVSS 5.6 v3·EPSS 0.4%·Fix available

    Exposure of sensitive system information to an unauthorized control sphere in Windows Win32K allows an authorized attacker to disclose information locally.

    Published 2026-09-08

  • CVSS 5.7 v3·EPSS 1.0%·Fix available

    Exposure of sensitive system information to an unauthorized control sphere in Windows Kernel allows an authorized attacker to disclose information over a network.

    Published 2026-09-08

  • CVSS 5.5 v3·EPSS 0.5%·Fix available

    Exposure of sensitive system information to an unauthorized control sphere in Windows Kernel allows an authorized attacker to disclose information locally.

    Published 2026-09-08

  • CVSS 5.5 v3·EPSS 0.5%·Fix available

    Exposure of sensitive system information to an unauthorized control sphere in Windows MIDI Service Module allows an authorized attacker to disclose information locally.

    Published 2026-09-08

  • CVSS 5.5 v3·EPSS 0.5%·Fix available

    Exposure of sensitive system information to an unauthorized control sphere in Windows License Manager allows an authorized attacker to disclose information locally.

    Published 2026-09-08

  • CVSS 5.5 v3·EPSS 0.4%·Fix available

    Exposure of sensitive system information to an unauthorized control sphere in Windows MIDI Service Module allows an authorized attacker to disclose information locally.

    Published 2026-09-08

  • CVSS 5.7 v4·EPSS 0.1%·No fix yet

    Exposure of Sensitive System Information to an Unauthorized Control Sphere in Armoury Crate driver allows a local user to obtain kernel virtual addresses via a crafted IOCTL request by bypassing the driver's verification, potentially providing further insight into the kernel memory layout.Refer to the ' Security Update for Armoury Crate App ' section on the ASUS Security Advisory for more information.

    Published 2026-09-08

  • CVSS 6.5 v3·EPSS 0.2%·No fix yet

    SAP Web Dispatcher, Internet Communication Manager and SAP Content Server allows an authenticated low-privileged attacker to access certain administrative functionality or interface and obtain sensitive information about the system state, resulting in information disclosure. This disclosed information could potentially be used to facilitate further attacks. This vulnerability has a high impact on the confidentiality of the application, with no impact on integrity or availability.

    Published 2026-09-08

  • CVSS 7.8 v3·EPSS 0.1%·No fix yet

    PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 build 1016 contain an information disclosure vulnerability in DirectIo64.sys that allows unauthenticated local attackers to dump complete physical memory contents by supplying a caller-controlled file path to an exposed IOCTL. Attackers can issue a single IOCTL call to trigger the driver to iterate all physical memory ranges via MmGetPhysicalMemoryRanges and map each page through ZwMapViewOfSection on the PhysicalMemory section object, writing a full RAM image to an attacker-specified path in the SYSTEM context, bypassing user-mode ACLs and exposing LSASS working set, process memory, and cryptographic material from all running processes.

    Published 2026-09-04

  • CVSS 7.1 v3·EPSS 0.1%·No fix yet

    PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 build 1016 contain an unauthenticated physical memory disclosure in DirectIo64.sys, reachable by unprivileged local users through a single IOCTL with no caller-identity check. The handler writes a crash-dump-format (PAGEDU64) image of all physical memory to a caller-supplied file path in the SYSTEM context, allowing a standard user to create files in locations they cannot otherwise write and to recover memory belonging to processes of other users. The image is preceded by a header that exposes the kernel loaded-module list, active-process list and PFN database pointers, defeating KASLR. The same handler also dereferences the return value of an internal kernel-structure locator wi

    Published 2026-09-04

  • CVSS 7.5 v3·EPSS 0.3%·No fix yet

    XING CPTrans-ME-X contains an Exposure of Sensitive System Information to an Unauthorized Control Sphere (CWE-497). Sensitive system information may be leaked.

    Published 2026-09-04

  • CVSS 7.5 v3·EPSS 0.3%·No fix yet

    Unauthenticated Sensitive Data Exposure in WooCommerce Product Attachment <= 2.3.3 versions.

    Published 2026-09-02

  • CVSS 7.5 v3·EPSS 0.3%·No fix yet

    Unauthenticated Sensitive Data Exposure in Lead Generation Contact Widget & AI Chatbot: Chat Button, Phone Call, Telegram, Email – SiteLeads <= 1.2.0 versions.

    Published 2026-08-24

  • CVSS 5.3 v3·EPSS 0.4%·No fix yet

    The Brushfire platform's video content streaming application (https://online.brushfire.com) exposes database path in requests to users, allowing a remote, unauthenticated attacker to read information about other users. Fixed February 2026.

    Published 2026-08-21

  • CVSS 5.5 v3·EPSS 0.1%·Fix available

    Dell Command Update (DCU), versions prior to 5.7.1, contain an Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information disclosure.

    Published 2026-08-19

  • CVSS 5.3 v3·EPSS 0.2%·No fix yet

    Unauthenticated Sensitive Data Exposure in 3D FlipBook – PDF Flipbook Viewer, Flipbook Image Gallery <= 1.16.20 versions.

    Published 2026-08-18

  • CVSS 7.5 v3·EPSS 0.3%·No fix yet

    Unauthenticated Sensitive Data Exposure in Duitku Payment Gateway <= 2.11.14 versions.

    Published 2026-08-18

  • CVSS 7.5 v3·EPSS 0.3%·No fix yet

    OpenTofu versions 1.8.0 through 1.8.2 do not properly restrict sensitive variables and locals when users have opted into static evaluation of module sources, versions, and backend configurations. As a result, values marked as sensitive may be exposed through these configuration elements instead of producing an error. This is fixed in OpenTofu 1.8.3, which adds explicit errors to prevent the use of sensitive values in these contexts.

    Published 2026-08-16

  • CVSS 7.5 v3·EPSS 0.3%·No fix yet

    Unauthenticated Sensitive Data Exposure in WooCommerce Appointments <= 5.3.8 versions.

    Published 2026-08-13

  • CVSS 6.5 v3·EPSS 0.4%·No fix yet

    Subscriber Sensitive Data Exposure in Payment Forms for Paystack <= 4.0.5 versions.

    Published 2026-08-13

  • CVSS 2.4 v4·EPSS 0.2%·No fix yet

    TBEA TLogger V2.1.0.0B0.0.0.0 exposes a UART interface on the device's circuit board without sufficient protection. A physically proximate attacker can connect to the UART interface and observe the device boot process and runtime debug output. The disclosed information includes operating system details, software versions, network configuration, filesystem paths, and other implementation and debugging information that may assist an attacker in further compromising the device.

    Published 2026-08-10

  • CVSS 6.5 v3·EPSS 0.2%·No fix yet

    Exposure of sensitive system information to an unauthorized control sphere vulnerability in Zyxel Networks WAH7601 allows Web Application Fingerprinting. This issue affects WAH7601: through 20072026.

    Published 2026-08-10

  • CVSS 6.9 v4·EPSS 0.3%·No fix yet

    Kirby is an open-source content management system. Prior to 4.9.5 and from 5.0.0 through 5.5.1, the REST API error handler can return unsanitized PHP error messages that expose the full filesystem path of the Kirby installation to unauthenticated API users. This vulnerability affects all Kirby sites that have not disabled the REST API with the 'api' => false option. This issue is fixed in versions 4.9.5 and 5.5.2.

    Published 2026-08-07

  • CVSS 5.3 v4·EPSS 0.3%·No fix yet

    Nexus Repository 3 did not fully sandbox JEXL expressions used in Content Selectors. An account holding the nexus:selectors:create permission could construct an expression that read Java object properties not intended to be exposed to the expression engine, disclosing internal JVM class metadata such as class and classloader names. This issue does not permit method invocation, object construction, or arbitrary code execution. This has been fixed by restricting property access in the JEXL sandbox to the intended data types.

    Published 2026-08-07

  • CVSS 5.3 v3·EPSS 0.2%·No fix yet

    Unauthenticated Sensitive Data Exposure in YITH WooCommerce Zoom Magnifier <= 2.52.0 versions.

    Published 2026-08-06

  • CVSS 9.1 v3·EPSS 0.4%·No fix yet

    A privilege escalation vulnerability exists in Rancher's impersonation middleware (pkg/auth/requests/impersonate.go). An authenticated Rancher user with the default user global role can gain full administrative access to the Rancher control plane and transitively to all downstream clusters it manages. This issue affects Rancher: from 2.11.0 before 2.11.16, from 2.12.0 before 2.12.12, from 2.13.0 before 2.13.8, and from 2.14.0 before 2.14.2.

    Published 2026-08-05

  • CVSS 4.0 v3·EPSS 0.1%·No fix yet

    HCL iControl was affected by Sensitive Data Exposure vulnerabilities. It involves the public exposure of internal configuration files due to improper web server or application hardening.

    Published 2026-07-31

  • CVSS 4.3 v3·EPSS 0.1%·No fix yet

    SAP NetWeaver Application Server for ABAP and ABAP Platform writes sensitive session identifier information into a diagnostic trace when the trace is activated by a privileged user. An attacker with access to the resulting trace data could obtain identifiers that allow impersonation of legitimate users during their validity period. This leads to high impact on confidentiality. Integrity and availability are not impacted.

    Published 2026-07-28

  • CVSS 5.3 v3·EPSS 0.2%·No fix yet

    Unauthenticated Sensitive Data Exposure in Exclusive Addons Elementor <= 2.8.0 versions.

    Published 2026-07-27

  • CVSS 5.3 v3·EPSS 0.2%·No fix yet

    Unauthenticated Sensitive Data Exposure in MapPress Maps for WordPress <= 2.97.6 versions.

    Published 2026-07-27

  • CVSS 7.5 v3·EPSS 0.3%·No fix yet

    Unauthenticated Sensitive Data Exposure in Byteflows Travel & Hotel Booking <= 1.0.0 versions.

    Published 2026-07-27

  • CVSS 7.5 v3·EPSS 0.4%·No fix yet

    Subscriber Sensitive Data Exposure in ShipTime: Discounted Shipping Rates <= 1.1.1 versions.

    Published 2026-07-27

  • CVSS 4.8 v4·EPSS 0.1%·No fix yet

    Ericsson Packet Core Controller (PCC) versions prior to 1.39 contain an Exposure of Sensitive System Information vulnerability in Configuration Management allowing an attacker to enumerate other users on the system.

    Published 2026-07-27

  • CVSS 5.3 v3·EPSS 0.3%·No fix yet

    Pronetiqs IntraVUE versions 3.2.1a14 and prior have an exposure of sensitive system information to an unauthorized control sphere vulnerability which could allow for asset discovery by unauthenticated users.

    Published 2026-07-23

  • CVSS 8.6 v3·EPSS 0.4%·No fix yet

    Pronetiqs IntraVUE versions 3.2.1a14 and prior have an exposure of sensitive system information to an unauthorized control sphere vulnerability which could expose the underlying host/share filesystem.

    Published 2026-07-23

  • CVSS 4.3 v3·EPSS 0.3%·No fix yet

    Contributor Sensitive Data Exposure in TinyMCE Templates <= 4.8.1 versions.

    Published 2026-07-23

  • CVSS 5.3 v3·EPSS 0.3%·No fix yet

    Unauthenticated Sensitive Data Exposure in WP Social Ninja <= 4.3.0 versions.

    Published 2026-07-23

  • CVSS 5.3 v3·EPSS 0.3%·No fix yet

    Unauthenticated Sensitive Data Exposure in Ultimate Store Kit Elementor Addons <= 3.0.5 versions.

    Published 2026-07-23

  • CVSS 5.3 v3·EPSS 0.3%·No fix yet

    Unauthenticated Sensitive Data Exposure in Complianz <= 7.5.0 versions.

    Published 2026-07-23

  • CVSS 5.3 v3·EPSS 0.3%·No fix yet

    Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in John-Michael L'Allier Create mediavine-create allows Retrieve Embedded Sensitive Data.This issue affects Create: from n/a through 2.6.0.

    Published 2026-07-23

  • CVSS 5.3 v3·EPSS 0.3%·No fix yet

    Unauthenticated Sensitive Data Exposure in Ninja Tables <= 5.2.10 versions.

    Published 2026-07-23

  • CVSS 4.3 v3·EPSS 0.3%·No fix yet

    Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Chouby Polylang and Chouby Polylang Pro allows Retrieve Embedded Sensitive Data. This issue affects Polylang: through 3.8.5; Polylang Pro: through 3.8.5.

    Published 2026-07-23

  • CVSS 6.5 v3·EPSS 0.4%·No fix yet

    Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in MultiVendorX WooCommerce Product Stock Alert allows Retrieve Embedded Sensitive Data. This issue affects WooCommerce Product Stock Alert: from n/a through 3.0.6.

    Published 2026-07-23

Free CVE lookup by TridentStack Control, automated patching for Windows, macOS, and Linux fleets. Learn more·Uses NVD data but is not endorsed or certified by the NVD. EPSS scores courtesy of FIRST.org (https://www.first.org/epss). Source: CISA KEV Catalog.