CVE Vulnerability Database

Search and browse 394,852 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2016-20070MEDIUM6.4WordPress Booking Calendar Contact Form 1.0.23 contains privilege escalation and stored cross-site scripting vulnerabili...
CVE-2016-20069HIGH8.8WordPress Booking Calendar Contact Form 1.0.23 contains an unauthenticated blind SQL injection vulnerability in the shor...
CVE-2016-20068HIGH8.8WordPress Booking Calendar Contact Form version 1.0.23 contains an unauthenticated blind SQL injection vulnerability tha...
CVE-2016-20067MEDIUM5.3WordPress CP Polls 1.0.8 contains a cross-site request forgery vulnerability that allows attackers to perform unauthoriz...
CVE-2016-20066HIGH7.2WordPress CP Polls 1.0.8 contains a persistent cross-site scripting vulnerability that allows attackers to inject malici...
CVE-2026-5482CRITICAL9.3Responsive FileManager's allows an unauthenticated attacker to upload files of any type and extension without restrictio...
CVE-2026-49757CRITICAL9.2Authentication Bypass by Spoofing vulnerability in team-alembic AshAuthentication allows account takeover of local users...
CVE-2026-34030MEDIUM6.9The Wertheim SafeController Software, AssemblyVersion 6.15.8328.28014, does not sufficiently validate the branch code wh...
CVE-2026-34029MEDIUM6.8The Wertheim SafeController Software, AssemblyVersion 6.15.8328.28014, contains a hard-coded cryptographic key in the Sa...
CVE-2026-34028MEDIUM6.9The Wertheim SafeController Software, AssemblyVersion 6.15.8328.28014, exposes web-accessible file paths that are not pr...
CVE-2026-34027MEDIUM5.3The Wertheim SafeController Software, AssemblyVersion 6.15.8328.28014, contains insufficient server-side file type valid...
CVE-2026-34026HIGH7.1Wertheim SafeController Software, AssemblyVersion 6.15.8328.28014, contains a path traversal vulnerability in the docume...
CVE-2026-34025MEDIUM5.3The Wertheim SafeController Software, AssemblyVersion 6.15.8328.28014, contains an IP restriction bypass vulnerability i...
CVE-2026-34024HIGH8.6The Wertheim SafeController Software, AssemblyVersion 6.15.8328.28014, contains missing authorization checks on multiple...
CVE-2026-34023HIGH7.1The Wertheim SafeController Software, AssemblyVersion 6.15.8328.28014, contains an incorrect authorization vulnerability...
CVE-2026-34022HIGH7.1The Wertheim SafeController Family 65000, Controller 65000 - AssemblyVersion 6.11.8130.22319, uses weak custom cryptogra...
CVE-2026-34021HIGH8.6The Wertheim SafeController 5400, Controller 5400 - AssemblyVersion 6.11.8130.22320, uses RS-485 communication between t...
CVE-2026-12057HIGH7.8When the application executes the JavaScript script embedded in the PDF within the sandbox, it fails to intercept some d...
CVE-2026-50100HIGH8.5Multiple printer drivers provided by Ricoh Company, Ltd. and KONICA MINOLTA JAPAN, INC. contain a privilege escalation v...
CVE-2026-44188MEDIUM5.3A flaw was found in Ansible Lightspeed. This vulnerability, related to insufficient session expiration, allows a remote ...
CVE-2026-11860HIGH7.5Quick.CMS deserializes user-controlled data received over plaintext HTTP without ensuring integrity or authenticity. Thi...
CVE-2026-9278MEDIUM5.4The Form Builder CP WordPress plugin before 1.2.47 does not properly sanitize a form configuration value before storing ...
CVE-2026-8935CRITICAL9.8The WP MAPS PRO WordPress plugin before 6.1.1 registers an unauthenticated AJAX action which, given a valid nonce that i...
CVE-2026-8386MEDIUM5.3The WP Go Maps WordPress plugin before 10.0.10 does not perform any approval-state filtering on its public single-marke...
CVE-2026-8385MEDIUM5.3The WP Go Maps WordPress plugin before 10.0.10 does not properly enforce the marker approval filter on the admin-ajax f...