CVE Vulnerability Database

Search and browse 394,250 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-54824HIGH7.5Unauthenticated Sensitive Data Exposure in Ads by WPQuads <= 3.0.3 versions.
CVE-2026-54820CRITICAL9.3Unauthenticated SQL Injection in JetBooking <= 4.0.4.1 versions.
CVE-2026-52701MEDIUM6.5Unauthenticated Broken Access Control in User Registration <= 5.2.2 versions.
CVE-2026-4339MEDIUM6.5Mattermost versions 10.11.x <= 10.11.18, 11.6.x <= 11.6.3, 11.5.x <= 11.5.6 fail to validate attachment URLs against int...
CVE-2026-45257HIGH7.8The KTLS receive path decrypted each record in place, assuming that the mbufs holding received data were anonymous and s...
CVE-2026-45256MEDIUM5.5When used to deliver a signal to a specific thread, thr_kill2(2) called p_cansignal() to determine whether the operation...
CVE-2026-3472LOW3.5Mattermost versions 10.11.x <= 10.11.18, 11.6.x <= 11.6.3, 11.5.x <= 11.5.6 fail to properly apply markdown image render...
CVE-2026-30041HIGH7.5An integer overflow in the PSD parser compnent of FastStone Image Viewer v8.3 allows attackers to execute arbitrary code...
CVE-2026-30040MEDIUM6.5A heap overflow in the FSViewer.exe process of FastStone Image Viewer v8.3 allows attackers to cause a execute arbitrary...
CVE-2026-24547MEDIUM5.3Unauthenticated Broken Access Control in SiteGround Email Marketing <= 1.7.5 versions.
CVE-2025-68075MEDIUM6.5Contributor Cross Site Scripting (XSS) in BNE Testimonials <= 2.0.8 versions.
CVE-2025-68074MEDIUM6.5Contributor Cross Site Scripting (XSS) in Image Carousel <= 1.0.0.41 versions.
CVE-2025-68064HIGH7.5Contributor Local File Inclusion in Goya Core < 1.0.9.4 versions.
CVE-2025-68063HIGH7.5Contributor Local File Inclusion in Splash - Sport Club WordPress Theme for Basketball, Football, Hockey <= 4.4.3 versio...
CVE-2025-68052HIGH8.8Unauthenticated Cross Site Request Forgery (CSRF) in Eagle Booking <= 1.3.4.3 versions.
CVE-2025-66123MEDIUM5.3Unauthenticated Insecure Direct Object References (IDOR) in BookPro <= 1.1.0 versions.
CVE-2025-64637MEDIUM5.3Unauthenticated Content Injection in Auros Core <= 5.3.1 versions.
CVE-2025-64636MEDIUM5.3Unauthenticated Broken Access Control in Donation Thermometer <= 2.2.7 versions.
CVE-2025-63079MEDIUM4.3Contributor Broken Access Control in Live Copy Paste for Elementor <= 1.5.3 versions.
CVE-2025-63078MEDIUM4.3Subscriber Broken Access Control in Restaurant Menu by MotoPress <= 2.4.11 versions.
CVE-2025-63041MEDIUM5.4Contributor Broken Access Control in Forget About Shortcode Buttons <= 2.1.3 versions.
CVE-2026-57940LOW2.1HTMLy 3.1.1 contains a Server-Side Request Forgery (SSRF) vulnerability in the RSS feed import functionality. The functi...
CVE-2026-57926CRITICAL9.8In JetBrains YouTrack before 2026.2.16593 the websandbox bridge was vulnerable to a prototype pollution attack
CVE-2026-57925MEDIUM5.3In JetBrains YouTrack before 2026.2.16593 improper access control allowed reading saved queries and tags
CVE-2026-57924MEDIUM5.3In JetBrains YouTrack before 2026.2.16593 default role configuration exposed excessive user profile details