CVE Vulnerability Database

Search and browse 397,943 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2021-47934MEDIUM6.9MyBB Timeline Plugin 1.0 contains cross-site scripting vulnerabilities that allow attackers to inject malicious scripts ...
CVE-2020-37247HIGH8.5Kite 4.2.0.1 U1 contains an unquoted service path vulnerability in the KiteService Windows service that allows local att...
CVE-2020-37246MEDIUM6.9Supsystic Backup 2.3.9 contains a local file inclusion vulnerability that allows unauthenticated attackers to read and d...
CVE-2020-37245HIGH8.7Supsystic Digital Publications 1.6.9 contains a path traversal vulnerability in the Folder input field that allows attac...
CVE-2020-37244HIGH8.8Supsystic Membership 1.4.7 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbi...
CVE-2020-37243HIGH8.8Supsystic Pricing Table 1.8.7 contains an SQL injection vulnerability in the 'sidx' GET parameter that allows unauthenti...
CVE-2020-37242HIGH8.8Supsystic Ultimate Maps 1.1.12 contains an SQL injection vulnerability that allows unauthenticated attackers to execute ...
CVE-2020-37241MEDIUM6.9bloofoxCMS 0.5.2.1 contains a cross-site request forgery vulnerability that allows attackers to perform administrative a...
CVE-2020-37240MEDIUM6.4Queue Management System 4.0.0 contains a stored cross-site scripting vulnerability that allows authenticated administrat...
CVE-2020-37239CRITICAL9.8libbabl 0.1.62 contains a broken double free detection vulnerability that allows attackers to bypass memory safety check...
CVE-2020-37238MEDIUM6.4CMS Made Simple 2.2.15 contains a stored cross-site scripting vulnerability that allows authenticated users with Content...
CVE-2020-37237MEDIUM6.4Composr CMS 10.0.34 contains a persistent cross-site scripting vulnerability that allows authenticated administrators to...
CVE-2020-37236MEDIUM6.4NewsLister contains an authenticated persistent cross-site scripting vulnerability that allows authenticated administrat...
CVE-2020-37235MEDIUM6.4WordPress Theme Wibar 1.1.8 contains a stored cross-site scripting vulnerability in the Brand component that allows auth...
CVE-2020-37234MEDIUM6.9Internet Download Manager 6.38.12 contains a buffer overflow vulnerability in the Scheduler component that allows local ...
CVE-2020-37233MEDIUM6.4WordPress Plugin Buddypress 6.2.0 contains a persistent cross-site scripting vulnerability that allows authenticated att...
CVE-2020-37232HIGH8.5Advanced System Care Service 13.0.0.157 contains an unquoted service path vulnerability in the AdvancedSystemCareService...
CVE-2020-37231HIGH8.5Privacy Drive 3.17.0 contains an unquoted service path vulnerability in the pdsvc.exe service binary that allows local a...
CVE-2020-37230HIGH8.5Syncplify.me Server! 5.0.37 contains an unquoted service path vulnerability in the SMWebRestServicev5 service that allow...
CVE-2020-37229HIGH8.5OKI sPSV Port Manager 1.0.41 contains an unquoted service path vulnerability in the sPSVOpLclSrv service that allows loc...
CVE-2020-37228CRITICAL9.8iDS6 DSSPro Digital Signage System 6.2 contains a CAPTCHA security bypass vulnerability that allows attackers to bypass ...
CVE-2020-37227HIGH8.8HS Brand Logo Slider 2.1 contains an unrestricted file upload vulnerability that allows authenticated users to bypass cl...
CVE-2026-46719MEDIUM6.5Net::Statsd::Lite versions before 0.9.0 for Perl allowed metric injections. The metric names were not checked for newli...
CVE-2025-4202MEDIUM4.3The Multicollab: Content Team Collaboration and Editorial Workflow plugin for WordPress is vulnerable to unauthorized mo...
CVE-2026-8657HIGH8.2Versions of the package jsondiffpatch before 0.7.6 are vulnerable to Prototype Pollution via the jsondiffpatch.patch() a...