CVE Vulnerability Database

Search and browse 390,085 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-14809HIGH8.7Prog Management System developed by PROG MIS has a SQL Injection vulnerability, allowing unauthenticated remote attacker...
CVE-2026-6382CRITICAL9.1The FileOrganizer WordPress plugin before 1.1.9, Advanced File Manager WordPress plugin before 5.4.12, File Manager Pr...
CVE-2026-14808CRITICAL9.8Prog Management System developed by PROG MIS has a Exposure of Sensitive Information vulnerability, allowing unauthe...
CVE-2026-14807CRITICAL9.8ERP App developed by PROG MIS has a Use of Hard-coded Credentials vulnerability, allowing unauthenticated remote attacke...
CVE-2026-14802HIGH7.3A vulnerability was detected in react create-react-app up to 5.0.1 on macOS. This affects the function startBrowserProce...
CVE-2026-14801MEDIUM4.8A security vulnerability has been detected in GPAC 26.03-DEV-rev342-g80071f700-master. The impacted element is the funct...
CVE-2026-14800MEDIUM4.3A weakness has been identified in imhamzaazam ecommerceFlask up to cb7d9e24c30a99379651b7493b32048126ef402b. The affecte...
CVE-2026-12083HIGH8.1The Admin and Site Enhancements (ASE) WordPress plugin before 8.8.4, admin-site-enhancements-pro WordPress plugin before...
CVE-2026-11962HIGH8.8The FileOrganizer WordPress plugin before 1.2.0 does not validate the file type on several of its file-management opera...
CVE-2026-11855HIGH8.8The Simple Membership WordPress plugin before 4.7.5 does not verify the authenticity of Stripe webhook requests when no ...
CVE-2026-11766HIGH8The Ultimate Member WordPress plugin before 2.12.0 does not properly sanitise and escape the value of custom textarea p...
CVE-2026-10830HIGH8.8The AllCoach WordPress plugin before 1.0.2 does not verify that an email address submitted to a public account-registra...
CVE-2024-6228HIGH7.5The Notifications for Forms & WordPress Actions WordPress plugin before 2.6 does not validate a user-supplied value befo...
CVE-2026-14799MEDIUM6.3A security flaw has been discovered in CodeAstro Ecommerce Website 1.0. Impacted is an unknown function of the file /cus...
CVE-2026-14798MEDIUM6.3A vulnerability was identified in CodeAstro Apartment Visitor Management System 1.0. This issue affects some unknown pro...
CVE-2026-14797MEDIUM6.3A vulnerability was determined in CodeAstro Apartment Visitor Management System 1.0. This vulnerability affects unknown ...
CVE-2026-14796MEDIUM6.3A vulnerability was found in CodeAstro Apartment Visitor Management System 1.0. This affects an unknown part of the file...
CVE-2026-14795MEDIUM6.3A vulnerability has been found in CodeAstro Apartment Visitor Management System 1.0. Affected by this issue is some unkn...
CVE-2026-14794MEDIUM5.3A flaw has been found in Craft CMS up to 4.18.0.1. Affected by this vulnerability is the function actionGetNewUsersData ...
CVE-2026-14793MEDIUM5.3A vulnerability was detected in Craft CMS up to 4.18.0.1. Affected is the function actionReorderSets of the file src/con...
CVE-2026-14792MEDIUM6.9A security vulnerability has been detected in Formbricks 5.0.0. This impacts an unknown function of the file apps/web/mo...
CVE-2026-14791LOW3.5A weakness has been identified in crater-invoice-inc crater up to 6.0.6. This affects the function getFormattedString of...
CVE-2026-14790LOW3.3A flaw has been found in GPAC 26.02.0. This affects the function nhmldump_send_frame of the file src/filters/write_nhml....
CVE-2026-14789HIGH7.8A vulnerability was detected in radareorg radare2 up to 6.1.6. Affected by this issue is some unknown functionality of t...
CVE-2026-14803MEDIUM6.5Mojo::JSON versions before 9.47 for Perl allow memory exhaustion via unbounded recursion in the pure-Perl decoder. The ...