CVE Vulnerability Database
Search and browse 397,873 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-9512 | MEDIUM | 6.3 | 1.1% | May 25, 2026 | A security flaw has been discovered in Totolink CA750-PoE 6.2c.510. This vulnerability affects the function setPasswordC... |
| CVE-2026-48837 | HIGH | 8.5 | 0.4% | May 25, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Unlimited Elements... |
| CVE-2026-45438 | HIGH | 7.5 | 0.3% | May 25, 2026 | Missing Authorization vulnerability in WebToffee Smart Coupons for WooCommerce allows Exploiting Incorrectly Configured ... |
| CVE-2026-45435 | MEDIUM | 6.5 | 0.2% | May 25, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Melapress WP Activ... |
| CVE-2026-45217 | MEDIUM | 6.5 | 0.4% | May 25, 2026 | Authentication Bypass Using an Alternate Path or Channel vulnerability in ThemeHigh Stripe Payment Gateway for WooCommer... |
| CVE-2026-45216 | HIGH | 8.8 | 0.4% | May 25, 2026 | Incorrect Privilege Assignment vulnerability in StoreApps Smart Manager allows Privilege Escalation. This issue affects... |
| CVE-2026-45209 | HIGH | 7.5 | 0.3% | May 25, 2026 | Missing Authorization vulnerability in edward_plainview MyCryptoCheckout allows Exploiting Incorrectly Configured Access... |
| CVE-2026-42776 | MEDIUM | 6.3 | 0.2% | May 25, 2026 | Missing Authorization vulnerability in WP Sunshine Sunshine Photo Cart allows Exploiting Incorrectly Configured Access C... |
| CVE-2026-42774 | CRITICAL | 9.3 | 0.4% | May 25, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Crocoblock JetEngi... |
| CVE-2026-42773 | CRITICAL | 9.3 | 0.4% | May 25, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in eMagicOne eMagicOn... |
| CVE-2026-42763 | MEDIUM | 6.5 | 0.3% | May 25, 2026 | Missing Authorization vulnerability in SePay team SePay Gateway allows Retrieve Embedded Sensitive Data. This issue aff... |
| CVE-2026-39436 | HIGH | 7.1 | 0.1% | May 25, 2026 | Cross-Site Request Forgery (CSRF) vulnerability in bgermann CformsII allows Cross Site Request Forgery. This issue affe... |
| CVE-2026-32389 | MEDIUM | 5.4 | 0.2% | May 25, 2026 | Missing Authorization vulnerability in Linethemes NanoCare allows Exploiting Incorrectly Configured Access Control Secur... |
| CVE-2026-24937 | HIGH | 7.2 | 0.4% | May 25, 2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in VideoWhisper.Com Broadcast Live Video allows ... |
| CVE-2026-9511 | MEDIUM | 6.3 | 1.1% | May 25, 2026 | A vulnerability was identified in Totolink CA750-PoE 6.2c.510. This affects the function setWebWlanIdx of the file /cgi-... |
| CVE-2026-9504 | LOW | 3.3 | 0.2% | May 25, 2026 | A weakness has been identified in GNU LibreDWG up to 0.14. Affected is the function bit_convert_TU of the file programs/... |
| CVE-2026-27398 | MEDIUM | 5.3 | 0.2% | May 25, 2026 | Missing Authorization vulnerability in WP Chill RSVP and Event Management allows Exploiting Incorrectly Configured Acces... |
| CVE-2026-27357 | MEDIUM | 5.3 | 0.2% | May 25, 2026 | Missing Authorization vulnerability in Cornel Raiu WP Search Analytics allows Exploiting Incorrectly Configured Access C... |
| CVE-2026-27346 | MEDIUM | 4.9 | 0.3% | May 25, 2026 | Missing Authorization vulnerability in Kings Plugins B2BKing allows Exploiting Incorrectly Configured Access Control Sec... |
| CVE-2026-24592 | MEDIUM | 5.3 | 0.2% | May 25, 2026 | Missing Authorization vulnerability in Lucian Apostol Auto Affiliate Links allows Exploiting Incorrectly Configured Acce... |
| CVE-2026-24586 | MEDIUM | 5.4 | 0.3% | May 25, 2026 | Missing Authorization vulnerability in Themeansar Newses allows Exploiting Incorrectly Configured Access Control Securit... |
| CVE-2026-24582 | MEDIUM | 4.3 | 0.2% | May 25, 2026 | Missing Authorization vulnerability in WPPOOL FlexTable allows Exploiting Incorrectly Configured Access Control Security... |
| CVE-2026-24554 | MEDIUM | 4.3 | 0.1% | May 25, 2026 | Cross-Site Request Forgery (CSRF) vulnerability in Convers Lab WPSubscription allows Cross Site Request Forgery. This i... |
| CVE-2026-24527 | MEDIUM | 4.3 | 0.2% | May 25, 2026 | Missing Authorization vulnerability in Patterns in the cloud Autoship Cloud for WooCommerce Subscription Products allows... |
| CVE-2025-62745 | MEDIUM | 6.5 | 0.2% | May 25, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PickPlugins Team S... |
