CVE Vulnerability Database
Search and browse 397,943 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-46362 | HIGH | 7.1 | 0.3% | May 15, 2026 | phpMyFAQ before 4.1.2 contains an authorization bypass vulnerability in AbstractAdministrationController::userHasPermiss... |
| CVE-2026-46361 | HIGH | 8.2 | 0.2% | May 15, 2026 | phpMyFAQ before 4.1.2 contains a stored cross-site scripting vulnerability in search.twig where result.question and resu... |
| CVE-2026-46360 | MEDIUM | 5.4 | 0.2% | May 15, 2026 | phpMyFAQ before 4.1.2 contains a stored cross-site scripting vulnerability in SvgSanitizer::decodeAllEntities() that lim... |
| CVE-2026-46359 | HIGH | 7.7 | 0.2% | May 15, 2026 | phpMyFAQ before 4.1.2 contains a sql injection vulnerability in CurrentUser::setTokenData that allows authenticated atta... |
| CVE-2026-45800 | HIGH | 8.7 | 0.3% | May 15, 2026 | Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.3... |
| CVE-2026-45622 | MEDIUM | 5.3 | 0.3% | May 15, 2026 | Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.3... |
| CVE-2026-45616 | MEDIUM | 5.1 | 0.2% | May 15, 2026 | Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.3... |
| CVE-2026-45010 | CRITICAL | 9.3 | 0.3% | May 15, 2026 | phpMyFAQ before 4.1.2 contains an improper restriction of excessive authentication attempts vulnerability in the /admin/... |
| CVE-2026-45009 | MEDIUM | 5.3 | 0.2% | May 15, 2026 | phpMyFAQ before 4.1.2 contains an insufficient authorization vulnerability in admin-api routes that allows authenticated... |
| CVE-2026-45008 | HIGH | 7 | 0.3% | May 15, 2026 | phpMyFAQ before 4.1.2 contains a path traversal vulnerability in Client::deleteClientFolder that allows admins with INST... |
| CVE-2026-45007 | MEDIUM | 5.3 | 0.2% | May 15, 2026 | phpMyFAQ before 4.1.2 contains missing permission checks in ConfigurationTabController.php where 12 endpoints use userIs... |
| CVE-2026-44826 | HIGH | 7.5 | 0.2% | May 15, 2026 | Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.2... |
| CVE-2026-44719 | MEDIUM | 5.3 | 0.3% | May 15, 2026 | Mathesar is a web application that makes working with PostgreSQL databases both simple and powerful. From 0.2.0 to befor... |
| CVE-2026-44718 | MEDIUM | 5.3 | 0.3% | May 15, 2026 | Mathesar is a web application that makes working with PostgreSQL databases both simple and powerful. From 0.2.0 to befor... |
| CVE-2026-44366 | MEDIUM | 6.1 | 0.3% | May 15, 2026 | Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.1... |
| CVE-2021-47968 | MEDIUM | 6.4 | 0.2% | May 15, 2026 | Podcast Generator 3.1 is vulnerable to persistent cross-site scripting, allowing authenticated attackers to inject malic... |
| CVE-2021-47967 | MEDIUM | 6.1 | 0.2% | May 15, 2026 | PHP Timeclock 1.04 contains multiple cross-site scripting vulnerabilities that allow unauthenticated attackers to inject... |
| CVE-2021-47966 | HIGH | 8.8 | 0.3% | May 15, 2026 | PHP Timeclock 1.04 contains time-based and boolean-based blind SQL injection vulnerabilities in the login_userid paramet... |
| CVE-2021-47965 | CRITICAL | 9.8 | 0.6% | May 15, 2026 | WordPress Plugin WP Super Edit 2.5.4 and earlier contains an unrestricted file upload vulnerability in the FCKeditor com... |
| CVE-2021-47964 | HIGH | 8.8 | 0.7% | May 15, 2026 | Schlix CMS 2.2.6-6 contains a remote code execution vulnerability that allows authenticated attackers to execute arbitra... |
| CVE-2021-47963 | HIGH | 7.2 | 0.5% | May 15, 2026 | Anote 1.0 contains a persistent cross-site scripting vulnerability that allows attackers to execute arbitrary code by in... |
| CVE-2021-47962 | MEDIUM | 6.4 | 0.2% | May 15, 2026 | Savsoft Quiz 5.0 contains a persistent cross-site scripting vulnerability in the user account settings page that allows ... |
| CVE-2021-47959 | HIGH | 8.7 | 0.5% | May 15, 2026 | WordPress Plugin WPGraphQL 1.3.5 contains a denial of service vulnerability that allows unauthenticated attackers to exh... |
| CVE-2021-47958 | MEDIUM | 5.3 | 0.2% | May 15, 2026 | CouchCMS 2.2.1 contains a server-side request forgery vulnerability that allows authenticated attackers to make arbitrar... |
| CVE-2026-46474 | HIGH | 7.5 | 0.3% | May 15, 2026 | Trog::TOTP versions before 1.006 for Perl generate secrets using rand. Secrets were generated using Perl's built-in ran... |
