CVE Vulnerability Database

Search and browse 397,943 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-46362HIGH7.1phpMyFAQ before 4.1.2 contains an authorization bypass vulnerability in AbstractAdministrationController::userHasPermiss...
CVE-2026-46361HIGH8.2phpMyFAQ before 4.1.2 contains a stored cross-site scripting vulnerability in search.twig where result.question and resu...
CVE-2026-46360MEDIUM5.4phpMyFAQ before 4.1.2 contains a stored cross-site scripting vulnerability in SvgSanitizer::decodeAllEntities() that lim...
CVE-2026-46359HIGH7.7phpMyFAQ before 4.1.2 contains a sql injection vulnerability in CurrentUser::setTokenData that allows authenticated atta...
CVE-2026-45800HIGH8.7Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.3...
CVE-2026-45622MEDIUM5.3Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.3...
CVE-2026-45616MEDIUM5.1Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.3...
CVE-2026-45010CRITICAL9.3phpMyFAQ before 4.1.2 contains an improper restriction of excessive authentication attempts vulnerability in the /admin/...
CVE-2026-45009MEDIUM5.3phpMyFAQ before 4.1.2 contains an insufficient authorization vulnerability in admin-api routes that allows authenticated...
CVE-2026-45008HIGH7phpMyFAQ before 4.1.2 contains a path traversal vulnerability in Client::deleteClientFolder that allows admins with INST...
CVE-2026-45007MEDIUM5.3phpMyFAQ before 4.1.2 contains missing permission checks in ConfigurationTabController.php where 12 endpoints use userIs...
CVE-2026-44826HIGH7.5Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.2...
CVE-2026-44719MEDIUM5.3Mathesar is a web application that makes working with PostgreSQL databases both simple and powerful. From 0.2.0 to befor...
CVE-2026-44718MEDIUM5.3Mathesar is a web application that makes working with PostgreSQL databases both simple and powerful. From 0.2.0 to befor...
CVE-2026-44366MEDIUM6.1Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.1...
CVE-2021-47968MEDIUM6.4Podcast Generator 3.1 is vulnerable to persistent cross-site scripting, allowing authenticated attackers to inject malic...
CVE-2021-47967MEDIUM6.1PHP Timeclock 1.04 contains multiple cross-site scripting vulnerabilities that allow unauthenticated attackers to inject...
CVE-2021-47966HIGH8.8PHP Timeclock 1.04 contains time-based and boolean-based blind SQL injection vulnerabilities in the login_userid paramet...
CVE-2021-47965CRITICAL9.8WordPress Plugin WP Super Edit 2.5.4 and earlier contains an unrestricted file upload vulnerability in the FCKeditor com...
CVE-2021-47964HIGH8.8Schlix CMS 2.2.6-6 contains a remote code execution vulnerability that allows authenticated attackers to execute arbitra...
CVE-2021-47963HIGH7.2Anote 1.0 contains a persistent cross-site scripting vulnerability that allows attackers to execute arbitrary code by in...
CVE-2021-47962MEDIUM6.4Savsoft Quiz 5.0 contains a persistent cross-site scripting vulnerability in the user account settings page that allows ...
CVE-2021-47959HIGH8.7WordPress Plugin WPGraphQL 1.3.5 contains a denial of service vulnerability that allows unauthenticated attackers to exh...
CVE-2021-47958MEDIUM5.3CouchCMS 2.2.1 contains a server-side request forgery vulnerability that allows authenticated attackers to make arbitrar...
CVE-2026-46474HIGH7.5Trog::TOTP versions before 1.006 for Perl generate secrets using rand. Secrets were generated using Perl's built-in ran...