CVE Vulnerability Database

Search and browse 377,421 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-19348CRITICAL9.8A security flaw has been discovered in Shenzhen Aitemi M300 Wi-Fi Repeater r0-ea7890a. Impacted is the function sprintf ...
CVE-2026-19347MEDIUM6.3A vulnerability was identified in itsourcecode Hospital Management System 1.0. This issue affects some unknown processin...
CVE-2026-19346HIGH8.8A vulnerability was determined in Tenda CH22 1.0.0.1. This vulnerability affects the function formCertListInfo of the fi...
CVE-2026-19345MEDIUM6.5A vulnerability was found in code-projects Task Management System 1.0. This affects an unknown part of the file /user/Up...
CVE-2026-19344HIGH7.3A vulnerability has been found in code-projects Task Management System 1.0. Affected by this issue is some unknown funct...
CVE-2026-19343HIGH7.3A flaw has been found in code-projects Task Management System 1.0. Affected by this vulnerability is an unknown function...
CVE-2026-19342HIGH7.3A vulnerability was detected in code-projects Task Management System 1.0. Affected is an unknown function of the file /i...
CVE-2026-19341HIGH8.8A security vulnerability has been detected in UTT HiPER 1200GW up to 2.5.3-170306. This impacts the function strcpy of t...
CVE-2026-19340MEDIUM6.3A weakness has been identified in anubissbe ProjectHub-Mcp up to 5.0.0. This affects an unknown function of the file bac...
CVE-2026-19339MEDIUM6.3A security flaw has been discovered in aliyun alibabacloud-dataworks-mcp-server up to 1.0.43. The impacted element is th...
CVE-2026-19338MEDIUM5.3A vulnerability was identified in automateyournetwork MCPyATS up to 0.1.4. The affected element is the function processG...
CVE-2026-19337MEDIUM5.3A vulnerability was determined in adenot mcp-google-search up to 0.3.1. Impacted is an unknown function of the file src/...
CVE-2026-19336MEDIUM5.3A vulnerability was found in Pimzino spec-workflow-mcp up to 2.2.6. This issue affects the function ApprovalStorage.crea...
CVE-2026-19335MEDIUM5.3A vulnerability has been found in Jane-xiaoer skill-vision-control up to 1.3.0. This vulnerability affects the function ...
CVE-2026-18603MEDIUM6.5The PiWeb Cancel order / Refund request for WooCommerce WordPress plugin before 1.3.4.34 does not have authorization or ...
CVE-2026-18473CRITICAL9.1The WP Directory Kit WordPress plugin before 1.5.5 does not properly sanitise and escape a parameter before using it in ...
CVE-2026-18465MEDIUM6.5The WP MAPS PRO WordPress plugin before 6.1.3 does not perform a capability check in one of its AJAX actions, which is a...
CVE-2026-18464HIGH7.5The WP MAPS PRO WordPress plugin before 6.1.3 does not perform a capability check in one of its AJAX actions, which is a...
CVE-2026-18357HIGH7.5The WPC Order Tip for WooCommerce WordPress plugin before 3.3.1 does not perform authorisation or nonce checks in one of...
CVE-2026-18037MEDIUM6.5The Create WordPress plugin before 2.5.4 does not perform an authorization check before rendering content over one of it...
CVE-2026-18032HIGH7.5The WP Data Access WordPress plugin before 5.5.79 does not validate the column names it accepts on one of its unauthent...
CVE-2026-17044HIGH8.6The Iptanus File Upload WordPress plugin before 5.1.8 does not properly sanitise and escape a parameter before using it ...
CVE-2026-17017HIGH8.1The CubeWP Framework WordPress plugin before 1.1.31 does not properly sanitize and escape a parameter before using it in...
CVE-2026-17014MEDIUM5.3The WP Photo Album Plus WordPress plugin before 9.2.07.002 does not perform any capability or nonce check on one of its ...
CVE-2026-17011LOW3.8The Nexter Blocks WordPress plugin before 5.0.2 does not restrict who can save global CSS through one of its REST endpo...