CVE Vulnerability Database

Search and browse 389,982 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-57387HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in picu picu picu all...
CVE-2026-57386HIGH8.8Incorrect Privilege Assignment vulnerability in Kodezen LLC aBlocks ablocks allows Privilege Escalation.This issue affec...
CVE-2026-57385HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in appsbd Vitepos vit...
CVE-2026-57383HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in eyecix JobSearch w...
CVE-2026-57382HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Mitchell Bennis Si...
CVE-2026-57381HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Property Hive Prop...
CVE-2026-57380HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in hupe13 Extensions ...
CVE-2026-57379HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPPOOL FormyChat s...
CVE-2026-57378HIGH7.5Missing Authorization vulnerability in Phil Kurth Advanced Forms advanced-forms allows Exploiting Incorrectly Configured...
CVE-2026-57377MEDIUM6.5Missing Authorization vulnerability in WPXPO WowAddons product-addons allows Exploiting Incorrectly Configured Access Co...
CVE-2026-57376HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Element Invader El...
CVE-2026-57375MEDIUM6.5Missing Authorization vulnerability in FluxBuilder MStore API mstore-api allows Exploiting Incorrectly Configured Access...
CVE-2026-57372HIGH7.2Server-Side Request Forgery (SSRF) vulnerability in denishua WPJAM Basic wpjam-basic allows Server Side Request Forgery....
CVE-2026-57371HIGH8.8Deserialization of Untrusted Data vulnerability in denishua WPJAM Basic wpjam-basic allows Object Injection.This issue a...
CVE-2026-57369HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in themifyme Themify ...
CVE-2026-57368HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NooTheme Jobmonste...
CVE-2026-57365MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Hitesh Chandwani r...
CVE-2026-57364MEDIUM6.5Improper Validation of Specified Quantity in Input vulnerability in WPDeveloper Better Payment – Instant Payments, Donat...
CVE-2026-57363HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in QuantumCloud ChatB...
CVE-2026-49876MEDIUM6.5Authenticated SSRF in Gravitino JobManager allows server-side HTTP requests to internal network and cloud metadata endpo...
CVE-2026-41041CRITICAL9.1URL path injection via unencoded user-supplied identifiers vulnerability in Apache Gravitino. This issue affects Apache...
CVE-2026-22103CRITICAL9.3The NPC start endpoint on the web server at port 8090 is vulnerable to command injection.
CVE-2026-22102CRITICAL9.3A POST request sent to a specific webserver endpoint can be used to write to arbitrary file locations. The endpoint acce...
CVE-2026-22100HIGH8.6The OCPP DataTransfer message `ReserveLogin` is vulnerable to command injection. By manipulating the data value, arbitra...
CVE-2026-22099HIGH8.7The charging station does not require authentication for Bluetooth commands to perform actions. The functionality expose...