CVE Vulnerability Database

Search and browse 396,750 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2017-20250HIGH8.7Mac Photo Gallery 3.0 contains a path traversal vulnerability that allows unauthenticated attackers to download arbitrar...
CVE-2017-20249HIGH8.8Apptha Slider Gallery 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbit...
CVE-2017-20248HIGH8.7Apptha Slider Gallery 1.0 contains a path traversal vulnerability that allows unauthenticated attackers to download arbi...
CVE-2017-20247HIGH8.8WordPress Plugin PICA Photo Gallery 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to...
CVE-2017-20246HIGH8.8KittyCatfish 2.2 plugin for WordPress contains an SQL injection vulnerability that allows unauthenticated attackers to r...
CVE-2017-20245HIGH8.8Wow Viral Signups 2.1 WordPress plugin contains an SQL injection vulnerability that allows unauthenticated attackers to ...
CVE-2017-20244HIGH8.8Wow Forms WordPress Plugin version 2.1 contains an SQL injection vulnerability that allows unauthenticated attackers to ...
CVE-2017-20243HIGH8.8WordPress Car Park Booking Plugin version 13 October 17 contains a time-based SQL injection vulnerability that allows un...
CVE-2016-20065HIGH8.8Product Catalog 8 1.2 plugin for WordPress contains an SQL injection vulnerability that allows unauthenticated attackers...
CVE-2016-20064MEDIUM6.9WP Vault 0.8.6.6 contains a local file inclusion vulnerability that allows unauthenticated attackers to read arbitrary f...
CVE-2016-20063HIGH7.1Single Personal Message 1.0.3 contains an SQL injection vulnerability that allows authenticated users to execute arbitra...
CVE-2016-20062HIGH8.8Simply Poll 1.4.1 plugin for WordPress contains an SQL injection vulnerability that allows unauthenticated attackers to ...
CVE-2026-49742HIGH7.1Backend users with file download permissions were able to download files from the fallback storage of the file abstracti...
CVE-2026-49741HIGH8.7Backend users with write access to the form_definition database table were able to directly create, update, or delete fo...
CVE-2026-49740MEDIUM6.3TYPO3's cache frontend (VariableFrontend) and persistent key-value store (Registry) deserialized PHP payloads without in...
CVE-2026-49738LOW2.1The path allowance check in GeneralUtility::isAllowedAbsPath() performed a plain string prefix comparison without requir...
CVE-2026-47352MEDIUM5.3Authenticated backend users were able to retrieve file metadata via several Backend API routes without proper permission...
CVE-2026-47351MEDIUM5.3Backend users were able to insert arbitrary records and files into the TYPO3 clipboard without proper read permission ch...
CVE-2026-47350MEDIUM5.3Backend users were able to move records to a different page without having edit permissions on the source page. This iss...
CVE-2026-47349MEDIUM5.3Backend users with access to the Recycler module were able to restore soft-deleted records on pages or for tables they w...
CVE-2026-47348MEDIUM5.1Editors with access to create or modify page content were able to include HTML markup in page titles that were stored in...
CVE-2026-47347MEDIUM5.3Applications that use GeneralUtility::sanitizeLocalUrl to allow only local URLs are vulnerable to open redirect attacks ...
CVE-2026-47346HIGH7.6Backend users with file write permissions were able to upload form definition files with mixed-case extensions (e.g., .F...
CVE-2026-47343HIGH7.2Non-privileged backend users with file mount access were able to perform write operations (move, delete, rename) on fold...
CVE-2026-11607HIGH7.6Backend users with access to the Form Framework were able to use files not ending in .form.yaml as form definitions, whi...