CVE Vulnerability Database
Search and browse 396,750 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-20250 | HIGH | 8.7 | 0.6% | Jun 9, 2026 | Mac Photo Gallery 3.0 contains a path traversal vulnerability that allows unauthenticated attackers to download arbitrar... |
| CVE-2017-20249 | HIGH | 8.8 | 0.3% | Jun 9, 2026 | Apptha Slider Gallery 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbit... |
| CVE-2017-20248 | HIGH | 8.7 | 0.6% | Jun 9, 2026 | Apptha Slider Gallery 1.0 contains a path traversal vulnerability that allows unauthenticated attackers to download arbi... |
| CVE-2017-20247 | HIGH | 8.8 | 0.3% | Jun 9, 2026 | WordPress Plugin PICA Photo Gallery 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to... |
| CVE-2017-20246 | HIGH | 8.8 | 0.3% | Jun 9, 2026 | KittyCatfish 2.2 plugin for WordPress contains an SQL injection vulnerability that allows unauthenticated attackers to r... |
| CVE-2017-20245 | HIGH | 8.8 | 0.3% | Jun 9, 2026 | Wow Viral Signups 2.1 WordPress plugin contains an SQL injection vulnerability that allows unauthenticated attackers to ... |
| CVE-2017-20244 | HIGH | 8.8 | 0.3% | Jun 9, 2026 | Wow Forms WordPress Plugin version 2.1 contains an SQL injection vulnerability that allows unauthenticated attackers to ... |
| CVE-2017-20243 | HIGH | 8.8 | 0.3% | Jun 9, 2026 | WordPress Car Park Booking Plugin version 13 October 17 contains a time-based SQL injection vulnerability that allows un... |
| CVE-2016-20065 | HIGH | 8.8 | 0.3% | Jun 9, 2026 | Product Catalog 8 1.2 plugin for WordPress contains an SQL injection vulnerability that allows unauthenticated attackers... |
| CVE-2016-20064 | MEDIUM | 6.9 | 0.7% | Jun 9, 2026 | WP Vault 0.8.6.6 contains a local file inclusion vulnerability that allows unauthenticated attackers to read arbitrary f... |
| CVE-2016-20063 | HIGH | 7.1 | 0.2% | Jun 9, 2026 | Single Personal Message 1.0.3 contains an SQL injection vulnerability that allows authenticated users to execute arbitra... |
| CVE-2016-20062 | HIGH | 8.8 | 0.3% | Jun 9, 2026 | Simply Poll 1.4.1 plugin for WordPress contains an SQL injection vulnerability that allows unauthenticated attackers to ... |
| CVE-2026-49742 | HIGH | 7.1 | 0.3% | Jun 9, 2026 | Backend users with file download permissions were able to download files from the fallback storage of the file abstracti... |
| CVE-2026-49741 | HIGH | 8.7 | 0.2% | Jun 9, 2026 | Backend users with write access to the form_definition database table were able to directly create, update, or delete fo... |
| CVE-2026-49740 | MEDIUM | 6.3 | 0.2% | Jun 9, 2026 | TYPO3's cache frontend (VariableFrontend) and persistent key-value store (Registry) deserialized PHP payloads without in... |
| CVE-2026-49738 | LOW | 2.1 | 0.4% | Jun 9, 2026 | The path allowance check in GeneralUtility::isAllowedAbsPath() performed a plain string prefix comparison without requir... |
| CVE-2026-47352 | MEDIUM | 5.3 | 0.2% | Jun 9, 2026 | Authenticated backend users were able to retrieve file metadata via several Backend API routes without proper permission... |
| CVE-2026-47351 | MEDIUM | 5.3 | 0.2% | Jun 9, 2026 | Backend users were able to insert arbitrary records and files into the TYPO3 clipboard without proper read permission ch... |
| CVE-2026-47350 | MEDIUM | 5.3 | 0.2% | Jun 9, 2026 | Backend users were able to move records to a different page without having edit permissions on the source page. This iss... |
| CVE-2026-47349 | MEDIUM | 5.3 | 0.2% | Jun 9, 2026 | Backend users with access to the Recycler module were able to restore soft-deleted records on pages or for tables they w... |
| CVE-2026-47348 | MEDIUM | 5.1 | 0.3% | Jun 9, 2026 | Editors with access to create or modify page content were able to include HTML markup in page titles that were stored in... |
| CVE-2026-47347 | MEDIUM | 5.3 | 0.3% | Jun 9, 2026 | Applications that use GeneralUtility::sanitizeLocalUrl to allow only local URLs are vulnerable to open redirect attacks ... |
| CVE-2026-47346 | HIGH | 7.6 | 0.3% | Jun 9, 2026 | Backend users with file write permissions were able to upload form definition files with mixed-case extensions (e.g., .F... |
| CVE-2026-47343 | HIGH | 7.2 | 0.2% | Jun 9, 2026 | Non-privileged backend users with file mount access were able to perform write operations (move, delete, rename) on fold... |
| CVE-2026-11607 | HIGH | 7.6 | 0.2% | Jun 9, 2026 | Backend users with access to the Form Framework were able to use files not ending in .form.yaml as form definitions, whi... |
