CVE Vulnerability Database

Search and browse 390,226 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-53909MEDIUM6.5MCO does not correctly validate types of uploaded files. File upload validation functionality relies only on client-side...
CVE-2026-53908MEDIUM4.3MCO is vulnerable to User Enumeration through authentication-related functionalities. The application returns distinguis...
CVE-2026-53907MEDIUM5.4MCO is vulnerable to Stored Cross‑Site Scripting (XSS) via the application logo upload functionality. An attacker with t...
CVE-2026-53906HIGH8.2MCO is vulnerable to Path Disclosure and Path Traversal in file handling functionality related to data export and upload...
CVE-2026-53905HIGH7.1MCO does not properly enforce authorization checks in the /customer/servlet/mco/webapi/admin-view-hierarchy/get-acl-tree...
CVE-2026-53904HIGH7.1MCO is vulnerable to Account Denial of Service due to improper implementation of password reset functionality. Each pass...
CVE-2026-53903HIGH8.1MCO is vulnerable to an Insecure Direct Object Reference (IDOR) vulnerability in the /customer/servlet/mco/webapi/tradin...
CVE-2026-53902MEDIUM6.5MCO does not properly enforce authorization checks in the /customer/servlet/mco/webapi/profile-sections/group-membership...
CVE-2026-14198CRITICAL9.1@fastify/middie versions 9.1.0 through 9.3.2 decode the encoded slash %2F inside path parameter values before matching m...
CVE-2026-14181HIGH7.5@fastify/middie versions 9.1.0 through 9.3.2 fail to guard the URL normalization step used by the standalone engine when...
CVE-2026-13323HIGH8.7In Open VSX Registry before 1.0.2, the /vscode/unpkg/ endpoint serves user-supplied HTML files with Content-Type: text/h...
CVE-2026-14258MEDIUM6.5A flaw was found in dhcpcd's IPv6 Neighbor Discovery Router Advertisement processing. A specially crafted IPv6 Router Ad...
CVE-2026-13228HIGH8.8The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Privilege Esca...
CVE-2026-12142HIGH7.2The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting vi...
CVE-2026-10095MEDIUM6.4The WP Photo Album Plus plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'subtext' parameter in...
CVE-2026-27435MEDIUM5.3Missing Authorization vulnerability in WofficeIO Woffice allows Exploiting Incorrectly Configured Access Control Securit...
CVE-2026-13454MEDIUM6.5The MotoPress Appointment Booking plugin for WordPress is vulnerable to generic SQL Injection via the 's' parameter in a...
CVE-2026-12754MEDIUM6.1The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the '...
CVE-2026-56016MEDIUM5.9CGI::Session::ID::md5 versions before 4.49 for Perl generate predictable session ids from low-entropy sources. The gene...
CVE-2026-50043HIGH8.6Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in SkyBridge MB-...
CVE-2026-13733MEDIUM6.4The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'no_data_msg' Shortcode Attri...
CVE-2026-12732MEDIUM6.4The LearnPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'class_wrapper_form' shortcode ...
CVE-2026-12577HIGH8.7DVP80ES3 with Improperly Implemented Security Check for Standard vulnerability.
CVE-2026-12576HIGH7.5DVP80ES3 with Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability.
CVE-2026-12575HIGH7.5DVP80ES3 with  Improper Resource Shutdown or Release vulnerability.