CVE Vulnerability Database

Search and browse 397,790 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2019-25745HIGH8.8WordPress Plugin Google Review Slider 6.1 contains a time-based blind SQL injection vulnerability that allows unauthenti...
CVE-2019-25744MEDIUM5.4WordPress Popup Builder 3.49 contains a persistent cross-site scripting vulnerability that allows authenticated attacker...
CVE-2019-25743MEDIUM5.4WordPress Soliloquy Lite 2.5.6 contains a persistent cross-site scripting vulnerability that allows authenticated attack...
CVE-2019-25742MEDIUM5.4WordPress Theme Zoner Real Estate 4.1.1 contains a persistent cross-site scripting vulnerability that allows authenticat...
CVE-2019-25741CRITICAL9.8Mobatek MobaXterm 12.1 contains a structured exception handling (SEH) based buffer overflow vulnerability in the usernam...
CVE-2019-25740HIGH7.1Joomla com_jsjobs 1.2.6 contains an arbitrary file deletion vulnerability that allows authenticated attackers to delete ...
CVE-2019-25739MEDIUM5.4GigToDo 1.3 contains a persistent cross-site scripting vulnerability that allows authenticated attackers to inject malic...
CVE-2019-25738CRITICAL9.8WordPress Hybrid Composer 1.4.6 contains an unauthenticated settings change vulnerability that allows unauthenticated at...
CVE-2019-25737MEDIUM6.1Live Chat Unlimited 2.8.3 contains a stored cross-site scripting vulnerability that allows unauthenticated attackers to ...
CVE-2019-25736HIGH8.6LabF nfsAxe 3.7 Ping Client contains a buffer overflow vulnerability that allows local attackers to execute arbitrary co...
CVE-2019-25735HIGH8.6AllPlayer 7.4 contains a local buffer overflow vulnerability in URL handling that allows attackers to overwrite structur...
CVE-2019-25734MEDIUM5.1Contact Form by WD 1.13.1 contains a cross-site request forgery vulnerability combined with local file inclusion that al...
CVE-2019-25733HIGH8.6NetShareWatcher 1.5.8.0 contains a structured exception handler buffer overflow vulnerability that allows local attacker...
CVE-2019-25732HIGH8.8PHP EI-Tube Script 3 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary ...
CVE-2019-25731MEDIUM6.1Zuz Music 2.1 contains a persistent cross-site scripting vulnerability that allows unauthenticated attackers to inject m...
CVE-2019-25730HIGH8.8Listing Hub CMS 1.0 contains a SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQ...
CVE-2019-25729CRITICAL9.8PDF Signer 3.0 contains a server-side template injection vulnerability that allows unauthenticated attackers to execute ...
CVE-2019-25728HIGH8.8Care2x 2.7 contains multiple SQL injection vulnerabilities that allow unauthenticated attackers to execute arbitrary SQL...
CVE-2019-25727CRITICAL9.8WordPress Plugin ad manager wd 1.0.11 contains an arbitrary file download vulnerability that allows unauthenticated atta...
CVE-2019-25726HIGH8.8All in One Video Downloader 1.2 contains an SQL injection vulnerability that allows unauthenticated attackers to execute...
CVE-2026-4104CRITICAL9.8Authorization bypass through User-Controlled SQL primary key vulnerability in Akmer Informatics Automation Industry and ...
CVE-2026-45432HIGH8.7This vulnerability exists in GX Earth ONT models due to the transmission of user credentials in plaintext over HTTP in i...
CVE-2026-45431HIGH8.7This vulnerability exists in GX Earth ONT models due to improper handling of user-supplied input in multiple diagnostic ...
CVE-2026-10843HIGH7.2A flaw was found in the OpenShift Cloud Credential Operator Mint-mode IAM policies for AWS. Operator credentials are pro...
CVE-2026-10840HIGH7.1A flaw was found in the OpenShift Pipelines operator. The tekton-scheduler-rolebinding ClusterRoleBinding grants the sys...