CVE Vulnerability Database
Search and browse 397,845 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-25397 | MEDIUM | 6.9 | 0.2% | May 29, 2026 | PHP-SHOP 1.0 contains a cross-site request forgery vulnerability that allows unauthenticated attackers to add administra... |
| CVE-2018-25396 | HIGH | 8.7 | 0.3% | May 29, 2026 | Heatmiser Wifi Thermostat 1.7 contains a credential disclosure vulnerability that allows unauthenticated attackers to re... |
| CVE-2018-25395 | HIGH | 8.8 | 0.3% | May 29, 2026 | Kados R10 GreenBee contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQ... |
| CVE-2018-25394 | HIGH | 8.8 | 0.3% | May 29, 2026 | Kados R10 GreenBee contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQ... |
| CVE-2018-25393 | HIGH | 7.1 | 0.6% | May 29, 2026 | Navigate CMS 2.8.5 contains a path traversal vulnerability that allows authenticated users to download arbitrary files b... |
| CVE-2018-25392 | HIGH | 7.1 | 0.3% | May 29, 2026 | MaxOn ERP Software 8.x-9.x contains an SQL injection vulnerability that allows authenticated users to execute arbitrary ... |
| CVE-2018-25391 | HIGH | 8.7 | 0.3% | May 29, 2026 | HaPe PKH 1.1 fails to enforce authorization on its record deletion endpoints, allowing unauthenticated attackers to dele... |
| CVE-2018-25390 | HIGH | 8.8 | 0.3% | May 29, 2026 | HaPe PKH 1.1 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database querie... |
| CVE-2018-25389 | HIGH | 8.8 | 0.3% | May 29, 2026 | HaPe PKH 1.1 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database querie... |
| CVE-2018-25388 | HIGH | 8.8 | 0.5% | May 29, 2026 | HaPe PKH 1.1 contains an arbitrary file upload vulnerability that allows authenticated attackers to upload malicious fil... |
| CVE-2018-25387 | MEDIUM | 6.9 | 0.2% | May 29, 2026 | HaPe PKH 1.1 contains a cross-site request forgery vulnerability that allows attackers to change administrator passwords... |
| CVE-2018-25386 | HIGH | 8.8 | 0.3% | May 29, 2026 | HaPe PKH 1.1 contains multiple SQL injection vulnerabilities in admin/media.php that allow attackers to manipulate datab... |
| CVE-2018-25385 | HIGH | 8.8 | 0.3% | May 29, 2026 | E-Registrasi Pencak Silat 18.10 contains an SQL injection vulnerability that allows unauthenticated attackers to execute... |
| CVE-2018-25384 | MEDIUM | 5.4 | 0.2% | May 29, 2026 | Wikidforum 2.20 contains a cross-site scripting vulnerability that allows authenticated attackers to inject malicious sc... |
| CVE-2018-25383 | HIGH | 8.6 | 0.2% | May 29, 2026 | Free MP3 CD Ripper 2.8 contains a stack-based buffer overflow vulnerability in WMA file processing that allows local att... |
| CVE-2018-25382 | HIGH | 8.8 | 0.3% | May 29, 2026 | Zechat 1.5 contains an SQL injection vulnerability that allows unauthenticated attackers to extract database information... |
| CVE-2026-4290 | CRITICAL | 9.1 | 0.3% | May 29, 2026 | The WP Travel Pro plugin for WordPress is vulnerable to arbitrary user deletion via the /wp-json/wp-travel/v1/travel-gui... |
| CVE-2026-45609 | MEDIUM | 6.5 | 0.2% | May 29, 2026 | mcp-security provides Security and Authorization support for Model Context Protocol in Spring AI. Prior to 0.1.9, the mc... |
| CVE-2026-41159 | MEDIUM | 5.3 | 0.4% | May 29, 2026 | Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. Prior to 10.9.6 ... |
| CVE-2026-41150 | MEDIUM | 5.3 | 0.4% | May 29, 2026 | Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. Prior to 10.9.6 ... |
| CVE-2026-39292 | HIGH | 7.3 | 0.5% | May 29, 2026 | Falco Solutions PHPPageBuilder v0.31.0 contains an unrestricted file upload vulnerability in the pagemanager/pagebuilder... |
| CVE-2026-10063 | CRITICAL | 9.8 | 0.9% | May 29, 2026 | A vulnerability was identified in TRENDnet TEW-432BRP 3.10B20. Affected by this issue is the function formWPS of the fil... |
| CVE-2026-10062 | CRITICAL | 9.8 | 0.8% | May 29, 2026 | A vulnerability was determined in TRENDnet TEW-432BRP 3.10B20. Affected by this vulnerability is the function formSetRou... |
| CVE-2026-10042 | CRITICAL | 9.8 | 0.6% | May 29, 2026 | manga-image-translator contains a remote code execution vulnerability in the shared API server mode due to unsafe deseri... |
| CVE-2026-49325 | MEDIUM | 4.6 | 0.2% | May 29, 2026 | Improper handling of physical conditions in the bike-shutdown control of the Indian Motorcycle Scout Bobber + Tech 2025 ... |
