CVE Vulnerability Database

Search and browse 394,613 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-56330MEDIUM4.8Capgo before 12.128.2 contains an open redirect vulnerability in stripe_portal and stripe_checkout endpoints that accept...
CVE-2026-56325LOW3.1Capgo before 12.128.2 uses ILIKE pattern matching instead of exact matching for app_id lookup in the preview subdomain r...
CVE-2026-56319MEDIUM5.3Capgo before 12.128.2 contains an information disclosure vulnerability in the GET /statistics/app/:app_id endpoint that ...
CVE-2026-56317MEDIUM6.1Nuxt before 4.4.7 (and the 3.x branch before 3.21.7) contains a cross-site scripting vulnerability in the NoScript compo...
CVE-2026-56307MEDIUM5.3Cap-go before 12.128.12 contains a broken cursor pagination vulnerability in the /private/devices endpoint on the Cloudf...
CVE-2026-56304MEDIUM6.9picklescan before 1.0.1 contains an unsafe pickle deserialization vulnerability allowing unauthenticated attackers to cr...
CVE-2026-56295MEDIUM6.3Capgo before 12.128.2 contains an authorization bypass vulnerability in webhook management endpoints that allows non-exp...
CVE-2026-56294MEDIUM4.8capacitor-native-biometric before 12.128.2 contains an authentication bypass vulnerability where the onAuthenticationSuc...
CVE-2026-56282MEDIUM6.9Capgo before 12.128.2 contains an information disclosure vulnerability in the unauthenticated /replication endpoint that...
CVE-2026-56276MEDIUM6Flowise before 3.1.2 contains a mass assignment vulnerability in the PUT /api/v1/user endpoint that allows authenticated...
CVE-2026-56267MEDIUM6.9Flowise before 3.0.13 contains an information exposure vulnerability in the POST /api/v1/account/forgot-password endpoin...
CVE-2026-56235MEDIUM6.9Cap-go capgo before 12.128.2 contains an authorization bypass in several Supabase PostgREST RPC functions (get_app_metri...
CVE-2026-56228MEDIUM6.9Capgo before 12.128.2 fails to enforce a maximum value on the minimum password length field in its password policy confi...
CVE-2026-56227MEDIUM5.4Capgo before 12.128.2 contains a server-side request forgery vulnerability in webhook URL validation that allows loopbac...
CVE-2026-56218MEDIUM6.9Capgo before 12.128.2 fails to strip EXIF metadata including GPS geolocation data from uploaded images, allowing informa...
CVE-2025-71331MEDIUM6.1Flowise before 3.0.8 contains a cross-site scripting (XSS) vulnerability caused by insufficient input filtering in chat ...
CVE-2024-58351CRITICAL9.8Flowise before 2.1.4 allows configuration to be injected into the Chainflow during execution via the overrideConfig opti...
CVE-2026-12673MEDIUM5.9Liquidfiles versions before 4.2.12 are affected by a broken access control vulnerability resulting in privilege escalati...
CVE-2022-50972CRITICAL9.8WooCommerce 7.1.0 contains a remote code execution vulnerability that allows attackers to execute arbitrary PHP code by ...
CVE-2020-37255HIGH8.7WordPress Time Capsule Plugin 1.21.16 contains an authentication bypass vulnerability that allows unauthenticated attack...
CVE-2019-25763CRITICAL9.8WordPress Ultimate Addons for Beaver Builder 1.2.4.1 contains an authentication bypass vulnerability that allows attacke...
CVE-2026-48939CRITICAL9.8A vulnerability in the iCagenda extension for Joomla allows the upload of arbitrary files in the file attachment feature...
CVE-2026-48909CRITICAL9.5SP LMS (com_splms) < 4.1.4 by JoomShaper deserializes user-controlled cookie data without validation, enabling an unauth...
CVE-2026-48908CRITICAL9.8A vulnerability in SP Page Builder for Joomla allows unauthenticated users to upload arbitrary files, ultimately resulti...
CVE-2026-12119MEDIUM6.5The Simple File List plugin for WordPress is vulnerable to unauthorized file operations due to a missing authorization c...