CVE Vulnerability Database

Search and browse 394,827 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2025-31013HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themify Folo allow...
CVE-2025-15642MEDIUM6.8Netskope is notified about a potential gap in its Netskoped Client for Windows systems where a malicious insider with ad...
CVE-2025-15641MEDIUM6.8Netskope was notified about a potential gap in its Netskope Client for Windows systems where a malicious insider with ad...
CVE-2024-52488CRITICAL9.9Subscriber Arbitrary File Upload in Grip <= 1.0.9 versions.
CVE-2024-49269HIGH7.1Unauthenticated Cross Site Scripting (XSS) in my flatonica <= 0.0.8 versions.
CVE-2024-37496MEDIUM4.3Missing Authorization vulnerability in Rara Themes Metro Magazine allows Exploiting Incorrectly Configured Access Contro...
CVE-2024-37210MEDIUM6.5Missing Authorization vulnerability in ali2woo AliNext allows Exploiting Incorrectly Configured Access Control Security ...
CVE-2024-35690MEDIUM6.5Insertion of sensitive information into sent data vulnerability in MarketingFire Widget Options allows Retrieve Embedded...
CVE-2024-35648MEDIUM4.3Cross-Site request forgery (CSRF) vulnerability in Andy Moyle Emergency Password Reset allows Cross Site Request Forgery...
CVE-2024-34810MEDIUM4.3Cross-Site request forgery (CSRF) vulnerability in Extend Themes Skyline WP allows Cross Site Request Forgery. This iss...
CVE-2024-33909MEDIUM5.3Missing Authorization vulnerability in Avirtum iPages Flipbook allows Exploiting Incorrectly Configured Access Control S...
CVE-2024-33685MEDIUM4.3Missing Authorization vulnerability in Jegstudio Startupzy startupzy allows Exploiting Incorrectly Configured Access Con...
CVE-2024-32949HIGH8.3Missing Authorization vulnerability in Prince Integrate Google Drive allows Exploiting Incorrectly Configured Access Con...
CVE-2024-32729HIGH7.5Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in QuantumCloud Conversatio...
CVE-2024-31435MEDIUM4.3: Missing Authorization vulnerability in Inisev Social Media & Share Icons allows Exploiting Incorrectly Configured Acce...
CVE-2024-24709MEDIUM4.3Missing Authorization vulnerability in Shareaholic allows Exploiting Incorrectly Configured Access Control Security Leve...
CVE-2026-48776CRITICAL9.1LangGraph Python SDK is used to connect to running LangGraph API servers, manage assistants, threads and stream runs fro...
CVE-2026-48294HIGH7.4Adobe Acrobat PDF Extension (Chrome) versions 26.5.2.2 and earlier are affected by a UXSS-class cross-origin data disclo...
CVE-2026-46979MEDIUM6.5Vulnerability in the PeopleSoft Enterprise CS Campus Community product of Oracle PeopleSoft (component: Integration and ...
CVE-2026-46978CRITICAL10Vulnerability in the Oracle Solaris product of Oracle Systems (component: Remote Administration Daemon). The supported...
CVE-2026-46977LOW3.2Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: VMSVGA device). The supported v...
CVE-2026-46976HIGH7.2Vulnerability in the Oracle Public Sector Payroll product of Oracle E-Business Suite (component: Internal Operations). ...
CVE-2026-46974HIGH7.5Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version th...
CVE-2026-46973HIGH8.8Vulnerability in the Oracle Outsourced Mfg for Discrete Industries product of Oracle E-Business Suite (component: Intern...
CVE-2026-46972HIGH8.8Vulnerability in the Oracle Outsourced Mfg for Discrete Industries product of Oracle E-Business Suite (component: Intern...