CVE Vulnerability Database

Search and browse 394,758 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-40756HIGH8.1Unauthenticated PHP Object Injection in Zoya <= 1.4 versions.
CVE-2026-40752HIGH8.1Unauthenticated PHP Object Injection in Manufaktur Solutions <= 1.1.1 versions.
CVE-2026-40738HIGH8.1Unauthenticated PHP Object Injection in Eldon <= 1.4.1 versions.
CVE-2026-40733HIGH8.1Unauthenticated PHP Object Injection in ShiftUp <= 1.3 versions.
CVE-2026-40720HIGH7.1Unauthenticated Cross Site Scripting (XSS) in Royal Elementor Addons Pro < 1.7.1041 versions.
CVE-2026-39590HIGH8.1Unauthenticated Local File Inclusion in Atomlab <= 2.4.5 versions.
CVE-2026-39576HIGH8.1Unauthenticated PHP Object Injection in SingleMalt <= 1.5 versions.
CVE-2026-39560HIGH8.1Unauthenticated PHP Object Injection in Hiroshi <= 1.5.1 versions.
CVE-2026-39559HIGH8.1Unauthenticated Local File Inclusion in Uppercase < 1.2.2 versions.
CVE-2026-39556HIGH8.1Unauthenticated PHP Object Injection in Konsept <= 1.9 versions.
CVE-2026-39523HIGH8.1Unauthenticated Local File Inclusion in Solene Core <= 2.3.2 versions.
CVE-2026-39445HIGH8.1Unauthenticated PHP Object Injection in Alukas < 3.0.0 versions.
CVE-2026-39442HIGH8.1Unauthenticated PHP Object Injection in PressMart <= 1.2.26 versions.
CVE-2026-10641HIGH7.1Zephyr's Bluetooth Classic Hands-Free Profile (HFP) Hands-Free role parser (subsys/bluetooth/host/classic/hfp_hf.c) cont...
CVE-2025-69189HIGH7.3Missing Authorization vulnerability in EMV JobBank allows Exploiting Incorrectly Configured Access Control Security Leve...
CVE-2025-69175HIGH8.1Unauthenticated Local File Inclusion in Line Agency <= 1.3.1 versions.
CVE-2025-69174HIGH8.1Unauthenticated Local File Inclusion in Etude <= 1.6 versions.
CVE-2025-69170HIGH8.1Unauthenticated Local File Inclusion in Eventicity <= 1.5 versions.
CVE-2025-69166HIGH8.1Unauthenticated Local File Inclusion in Gunslinger <= 1.7 versions.
CVE-2025-69164HIGH8.1Unauthenticated Local File Inclusion in Skyward <= 1.10 versions.
CVE-2025-69158HIGH8.1Unauthenticated Local File Inclusion in Granola <= 1.13 versions.
CVE-2025-69157HIGH8.1Unauthenticated Local File Inclusion in Gamic <= 1.15 versions.
CVE-2025-69144HIGH8.1Unauthenticated Local File Inclusion in Preservation <= 1.10 versions.
CVE-2025-69140HIGH7.1Unauthenticated Cross Site Scripting (XSS) in SweetDate Core < 1.1.5 versions.
CVE-2025-69130HIGH8.8Deserialization of Untrusted Data vulnerability in Pixel Makers Creative INC. Entrepreneur - Booking for Small Businesse...