CVE Vulnerability Database
Search and browse 397,790 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-25745 | HIGH | 8.8 | 0.3% | Jun 4, 2026 | WordPress Plugin Google Review Slider 6.1 contains a time-based blind SQL injection vulnerability that allows unauthenti... |
| CVE-2019-25744 | MEDIUM | 5.4 | 0.2% | Jun 4, 2026 | WordPress Popup Builder 3.49 contains a persistent cross-site scripting vulnerability that allows authenticated attacker... |
| CVE-2019-25743 | MEDIUM | 5.4 | 0.2% | Jun 4, 2026 | WordPress Soliloquy Lite 2.5.6 contains a persistent cross-site scripting vulnerability that allows authenticated attack... |
| CVE-2019-25742 | MEDIUM | 5.4 | 0.2% | Jun 4, 2026 | WordPress Theme Zoner Real Estate 4.1.1 contains a persistent cross-site scripting vulnerability that allows authenticat... |
| CVE-2019-25741 | CRITICAL | 9.8 | 0.6% | Jun 4, 2026 | Mobatek MobaXterm 12.1 contains a structured exception handling (SEH) based buffer overflow vulnerability in the usernam... |
| CVE-2019-25740 | HIGH | 7.1 | 0.3% | Jun 4, 2026 | Joomla com_jsjobs 1.2.6 contains an arbitrary file deletion vulnerability that allows authenticated attackers to delete ... |
| CVE-2019-25739 | MEDIUM | 5.4 | 0.2% | Jun 4, 2026 | GigToDo 1.3 contains a persistent cross-site scripting vulnerability that allows authenticated attackers to inject malic... |
| CVE-2019-25738 | CRITICAL | 9.8 | 0.3% | Jun 4, 2026 | WordPress Hybrid Composer 1.4.6 contains an unauthenticated settings change vulnerability that allows unauthenticated at... |
| CVE-2019-25737 | MEDIUM | 6.1 | 0.2% | Jun 4, 2026 | Live Chat Unlimited 2.8.3 contains a stored cross-site scripting vulnerability that allows unauthenticated attackers to ... |
| CVE-2019-25736 | HIGH | 8.6 | 0.1% | Jun 4, 2026 | LabF nfsAxe 3.7 Ping Client contains a buffer overflow vulnerability that allows local attackers to execute arbitrary co... |
| CVE-2019-25735 | HIGH | 8.6 | 0.1% | Jun 4, 2026 | AllPlayer 7.4 contains a local buffer overflow vulnerability in URL handling that allows attackers to overwrite structur... |
| CVE-2019-25734 | MEDIUM | 5.1 | 0.9% | Jun 4, 2026 | Contact Form by WD 1.13.1 contains a cross-site request forgery vulnerability combined with local file inclusion that al... |
| CVE-2019-25733 | HIGH | 8.6 | 0.1% | Jun 4, 2026 | NetShareWatcher 1.5.8.0 contains a structured exception handler buffer overflow vulnerability that allows local attacker... |
| CVE-2019-25732 | HIGH | 8.8 | 0.3% | Jun 4, 2026 | PHP EI-Tube Script 3 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary ... |
| CVE-2019-25731 | MEDIUM | 6.1 | 0.2% | Jun 4, 2026 | Zuz Music 2.1 contains a persistent cross-site scripting vulnerability that allows unauthenticated attackers to inject m... |
| CVE-2019-25730 | HIGH | 8.8 | 0.3% | Jun 4, 2026 | Listing Hub CMS 1.0 contains a SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQ... |
| CVE-2019-25729 | CRITICAL | 9.8 | 0.3% | Jun 4, 2026 | PDF Signer 3.0 contains a server-side template injection vulnerability that allows unauthenticated attackers to execute ... |
| CVE-2019-25728 | HIGH | 8.8 | 0.3% | Jun 4, 2026 | Care2x 2.7 contains multiple SQL injection vulnerabilities that allow unauthenticated attackers to execute arbitrary SQL... |
| CVE-2019-25727 | CRITICAL | 9.8 | 0.5% | Jun 4, 2026 | WordPress Plugin ad manager wd 1.0.11 contains an arbitrary file download vulnerability that allows unauthenticated atta... |
| CVE-2019-25726 | HIGH | 8.8 | 0.3% | Jun 4, 2026 | All in One Video Downloader 1.2 contains an SQL injection vulnerability that allows unauthenticated attackers to execute... |
| CVE-2026-4104 | CRITICAL | 9.8 | 0.3% | Jun 4, 2026 | Authorization bypass through User-Controlled SQL primary key vulnerability in Akmer Informatics Automation Industry and ... |
| CVE-2026-45432 | HIGH | 8.7 | 0.2% | Jun 4, 2026 | This vulnerability exists in GX Earth ONT models due to the transmission of user credentials in plaintext over HTTP in i... |
| CVE-2026-45431 | HIGH | 8.7 | 0.4% | Jun 4, 2026 | This vulnerability exists in GX Earth ONT models due to improper handling of user-supplied input in multiple diagnostic ... |
| CVE-2026-10843 | HIGH | 7.2 | 0.3% | Jun 4, 2026 | A flaw was found in the OpenShift Cloud Credential Operator Mint-mode IAM policies for AWS. Operator credentials are pro... |
| CVE-2026-10840 | HIGH | 7.1 | 0.2% | Jun 4, 2026 | A flaw was found in the OpenShift Pipelines operator. The tekton-scheduler-rolebinding ClusterRoleBinding grants the sys... |
