CVE Vulnerability Database

Search and browse 397,845 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2018-25397MEDIUM6.9PHP-SHOP 1.0 contains a cross-site request forgery vulnerability that allows unauthenticated attackers to add administra...
CVE-2018-25396HIGH8.7Heatmiser Wifi Thermostat 1.7 contains a credential disclosure vulnerability that allows unauthenticated attackers to re...
CVE-2018-25395HIGH8.8Kados R10 GreenBee contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQ...
CVE-2018-25394HIGH8.8Kados R10 GreenBee contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQ...
CVE-2018-25393HIGH7.1Navigate CMS 2.8.5 contains a path traversal vulnerability that allows authenticated users to download arbitrary files b...
CVE-2018-25392HIGH7.1MaxOn ERP Software 8.x-9.x contains an SQL injection vulnerability that allows authenticated users to execute arbitrary ...
CVE-2018-25391HIGH8.7HaPe PKH 1.1 fails to enforce authorization on its record deletion endpoints, allowing unauthenticated attackers to dele...
CVE-2018-25390HIGH8.8HaPe PKH 1.1 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database querie...
CVE-2018-25389HIGH8.8HaPe PKH 1.1 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database querie...
CVE-2018-25388HIGH8.8HaPe PKH 1.1 contains an arbitrary file upload vulnerability that allows authenticated attackers to upload malicious fil...
CVE-2018-25387MEDIUM6.9HaPe PKH 1.1 contains a cross-site request forgery vulnerability that allows attackers to change administrator passwords...
CVE-2018-25386HIGH8.8HaPe PKH 1.1 contains multiple SQL injection vulnerabilities in admin/media.php that allow attackers to manipulate datab...
CVE-2018-25385HIGH8.8E-Registrasi Pencak Silat 18.10 contains an SQL injection vulnerability that allows unauthenticated attackers to execute...
CVE-2018-25384MEDIUM5.4Wikidforum 2.20 contains a cross-site scripting vulnerability that allows authenticated attackers to inject malicious sc...
CVE-2018-25383HIGH8.6Free MP3 CD Ripper 2.8 contains a stack-based buffer overflow vulnerability in WMA file processing that allows local att...
CVE-2018-25382HIGH8.8Zechat 1.5 contains an SQL injection vulnerability that allows unauthenticated attackers to extract database information...
CVE-2026-4290CRITICAL9.1The WP Travel Pro plugin for WordPress is vulnerable to arbitrary user deletion via the /wp-json/wp-travel/v1/travel-gui...
CVE-2026-45609MEDIUM6.5mcp-security provides Security and Authorization support for Model Context Protocol in Spring AI. Prior to 0.1.9, the mc...
CVE-2026-41159MEDIUM5.3Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. Prior to 10.9.6 ...
CVE-2026-41150MEDIUM5.3Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. Prior to 10.9.6 ...
CVE-2026-39292HIGH7.3Falco Solutions PHPPageBuilder v0.31.0 contains an unrestricted file upload vulnerability in the pagemanager/pagebuilder...
CVE-2026-10063CRITICAL9.8A vulnerability was identified in TRENDnet TEW-432BRP 3.10B20. Affected by this issue is the function formWPS of the fil...
CVE-2026-10062CRITICAL9.8A vulnerability was determined in TRENDnet TEW-432BRP 3.10B20. Affected by this vulnerability is the function formSetRou...
CVE-2026-10042CRITICAL9.8manga-image-translator contains a remote code execution vulnerability in the shared API server mode due to unsafe deseri...
CVE-2026-49325MEDIUM4.6Improper handling of physical conditions in the bike-shutdown control of the Indian Motorcycle Scout Bobber + Tech 2025 ...