CVE Vulnerability Database

Search and browse 397,943 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-8719HIGH8.8The AI Engine – The Chatbot, AI Framework & MCP for WordPress plugin for WordPress is vulnerable to Privilege Escalation...
CVE-2026-8725HIGH7.3A weakness has been identified in CoreWorxLab CAAL up to 1.6.0. The affected element is an unknown function of the file ...
CVE-2026-8724HIGH7.2A security flaw has been discovered in Dataease 2.10.20. Impacted is the function SqlparserUtils.transFilter of the file...
CVE-2026-8723MEDIUM6.3### Summary `qs.stringify` throws `TypeError` when called with `arrayFormat: 'comma'` and `encodeValuesOnly: true` on...
CVE-2026-6050——Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-46728HIGH8.8Das U-Boot before 2026.04 allows FIT (Flat Image Tree) signature verification bypass because hashed-nodes is omitted fro...
CVE-2021-47981MEDIUM5.4Quick.CMS 6.7 contains a cross-site scripting vulnerability in the sliders form that allows authenticated attackers to i...
CVE-2021-47980HIGH7.1Fuel CMS 1.4.13 contains a blind SQL injection vulnerability that allows authenticated attackers to manipulate database ...
CVE-2021-47979HIGH8.8WordPress Plugin Backup and Restore 1.0.3 contains an arbitrary file deletion vulnerability that allows authenticated at...
CVE-2021-47978MEDIUM6.9ProcessMaker 3.5.4 contains a local file inclusion vulnerability that allows unauthenticated attackers to read arbitrary...
CVE-2021-47977HIGH8.7WordPress Plugin Anti-Malware Security and Bruteforce Firewall 4.20.59 contains a directory traversal vulnerability that...
CVE-2021-47976HIGH8.8TextPattern CMS 4.9.0-dev contains a remote code execution vulnerability that allows authenticated attackers to upload a...
CVE-2021-47975HIGH7.2WP Learn Manager 1.1.2 contains a stored cross-site scripting vulnerability that allows unauthenticated attackers to inj...
CVE-2021-47974HIGH8.5VX Search 13.5.28 contains an unquoted service path vulnerability in both VX Search Server and VX Search Enterprise serv...
CVE-2021-47973HIGH8.7Sticky Notes Widget 3.0.6 contains a denial of service vulnerability that allows attackers to crash the application by p...
CVE-2021-47972HIGH8.7Sticky Notes & Color Widgets 1.4.2 contains a denial of service vulnerability that allows attackers to crash the applica...
CVE-2021-47971HIGH8.7My Notes Safe 5.3 contains a denial of service vulnerability that allows attackers to crash the application by pasting e...
CVE-2021-47970HIGH8.7Macaron Notes 5.5 contains a denial of service vulnerability that allows attackers to crash the application by creating ...
CVE-2021-47969HIGH8.7Color Notes 1.4 contains a denial of service vulnerability that allows attackers to crash the application by pasting exc...
CVE-2021-47957MEDIUM6.4Cookie Law Bar 1.2.1 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject ...
CVE-2021-47956HIGH8.8EgavilanMedia PHPCRUD 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate da...
CVE-2021-47955MEDIUM5.4CouchCMS 2.2.1 contains a cross-site scripting vulnerability that allows authenticated attackers to execute arbitrary Ja...
CVE-2021-47954HIGH8.8LayerBB 1.1.4 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queri...
CVE-2021-47952CRITICAL9.8python jsonpickle 2.0.0 contains a remote code execution vulnerability that allows attackers to execute arbitrary Python...
CVE-2021-47942HIGH8.7Home Assistant Community Store (HACS) prior to 1.10.0 contains a path traversal vulnerability that allows unauthenticate...