CVE Vulnerability Database

Search and browse 394,851 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-5079HIGH7.5Impact: multer versions 1.0.0 through 2.1.1 and 3.0.0-alpha.1 are vulnerable to a Denial of Service via deeply nested fi...
CVE-2026-52704CRITICAL10Improper Control of Generation of Code ('Code Injection') vulnerability in Edgar Rojas WooCommerce PDF Invoice Builder a...
CVE-2026-49111HIGH8.8Incorrect Privilege Assignment vulnerability in ThemeGrill Masteriyo - LMS allows Privilege Escalation. This issue affe...
CVE-2026-49064HIGH7.5Insertion of Sensitive Information Into Sent Data vulnerability in Stiofan GetPaid allows Retrieve Embedded Sensitive Da...
CVE-2026-49062HIGH8.8Authentication Bypass Using an Alternate Path or Channel vulnerability in WP Engine Faust.Js allows Password Recovery Ex...
CVE-2026-48969MEDIUM6.5Subscriber Broken Access Control in Really Simple SSL <= 9.5.9 versions.
CVE-2025-64215MEDIUM6.5Missing Authorization vulnerability in StylemixThemes MasterStudy LMS Pro allows Accessing Functionality Not Properly Co...
CVE-2019-25746HIGH7.1WordPress Sliced Invoices 3.8.2 contains an authenticated SQL injection vulnerability that allows authenticated attacker...
CVE-2018-25437HIGH8.7WordPress CherryFramework Themes 3.1.4 contains an information disclosure vulnerability that allows unauthenticated atta...
CVE-2018-25436CRITICAL9.8WordPress Plugin Baggage Freight Shipping Australia 0.1.0 contains an unrestricted file upload vulnerability that allows...
CVE-2016-20084HIGH7.2WordPress appointment-booking-calendar 1.1.24 contains multiple privilege escalation vulnerabilities that allow unauthen...
CVE-2016-20083MEDIUM6.9WordPress More Fields Plugin 2.1 contains a cross-site request forgery vulnerability that allows attackers to perform un...
CVE-2016-20082MEDIUM6.9WordPress Plugin Abtest contains a local file inclusion vulnerability that allows unauthenticated attackers to include a...
CVE-2016-20081HIGH8.7WordPress Plugin HB Audio Gallery Lite 1.0.0 contains a path traversal vulnerability that allows unauthenticated attacke...
CVE-2016-20080MEDIUM6.9WordPress Brandfolder plugin version 3.0 and earlier contains a local file inclusion vulnerability in callback.php that ...
CVE-2016-20079MEDIUM6.9WordPress Dharma Booking 2.28.3 and earlier contains a local file inclusion vulnerability that allows unauthenticated at...
CVE-2016-20078MEDIUM6.9WordPress IMDb Profile Widget 1.0.8 contains a local file inclusion vulnerability that allows unauthenticated attackers ...
CVE-2016-20077MEDIUM6.9WordPress Plugin Photocart Link 1.6 contains a local file inclusion vulnerability that allows unauthenticated attackers ...
CVE-2016-20076HIGH8.7WordPress Simple-Backup 2.7.11 contains multiple vulnerabilities that allow unauthenticated attackers to delete arbitrar...
CVE-2016-20075HIGH8.8WordPress Ultimate Product Catalog 3.8.6 contains an arbitrary file upload vulnerability that allows authenticated users...
CVE-2016-20074MEDIUM5.3WordPress Lazy Content Slider Plugin 3.4 contains a cross-site request forgery vulnerability that allows attackers to pe...
CVE-2016-20073HIGH8.8Answer My Question 1.3 plugin for WordPress contains an SQL injection vulnerability that allows unauthenticated attacker...
CVE-2016-20072HIGH8.8BBS e-Franchise 1.1.1 plugin for WordPress contains an SQL injection vulnerability that allows unauthenticated attackers...
CVE-2016-20071HIGH8.8The 404 Redirection Manager plugin version 1.0 for WordPress contains an unauthenticated SQL injection vulnerability tha...
CVE-2016-20070MEDIUM6.4WordPress Booking Calendar Contact Form 1.0.23 contains privilege escalation and stored cross-site scripting vulnerabili...