CVE Vulnerability Database

Search and browse 397,974 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-6473HIGH8.8Integer wraparound in multiple PostgreSQL server features allows an unprivileged database user to cause the server to un...
CVE-2026-6472MEDIUM5.4Missing authorization in PostgreSQL CREATE TYPE allows an object creator to hijack other queries that use search_path to...
CVE-2026-1630MEDIUM5.1WEBCON BPS is vulnerable to Reflected XSS via one of parameters used by "/openinmobileapp" endpoint. An attacker can sen...
CVE-2025-15025HIGH8.8Authorization bypass through User-Controlled key vulnerability in Yordam Information Technology Consulting, Training and...
CVE-2026-6008MEDIUM6.8Authorization bypass through User-Controlled key vulnerability in Im Park Information Technology, Electronics, Press, Pu...
CVE-2026-5798HIGH7.1Unsafe object reference (IDOR) in Stel Order v3.25.1 and earlier versions, specifically in the ‘/app/FrontController’ en...
CVE-2026-5790MEDIUM5.1Stored Cross-Site Scripting (XSS) in Stel Order v3.25.1 and earlier, located at the ‘/app/FrontController’ endpoint via ...
CVE-2026-4031HIGH7.5The Database Backup for WordPress plugin for WordPress is vulnerable to authorization bypass in all versions up to, and ...
CVE-2026-4030HIGH8.1The Database Backup for WordPress plugin for WordPress is vulnerable to unauthorized arbitrary file read and deletion in...
CVE-2026-4029HIGH7.5The Database Backup for WordPress plugin for WordPress is vulnerable to unauthorized database export in all versions up ...
CVE-2026-43644MEDIUM6.1podinfo through 6.11.2 contains a reflected cross-site scripting vulnerability in the /echo and /api/echo endpoints wher...
CVE-2025-12008HIGH8.8Authorization bypass through User-Controlled key vulnerability in APPYAP Technology and Information Inc. Yaay Social Med...
CVE-2026-45205MEDIUM5.3Uncontrolled Recursion vulnerability in Apache Commons. When processing an untrusted configuration file, Commons Config...
CVE-2026-8468HIGH8.2Allocation of Resources Without Limits or Throttling vulnerability in plug_project plug allows denial of service via unb...
CVE-2026-8295MEDIUM6.9An integer overflow vulnerability in the simdjson document-builder API allows incorrect buffer size calculations in "str...
CVE-2025-68421HIGH8.7Comarch ERP Optima client makes use of a hard-coded password for a database user. These credentials cannot be changed. I...
CVE-2025-68420HIGH7.5Comarch ERP Optima client connects to a database using a high privileged account regardless of an application account to...
CVE-2026-2347CRITICAL9.8Authorization bypass through User-Controlled key vulnerability in Akilli Commerce Software Technologies Ltd. Co. E-Comme...
CVE-2025-11024CRITICAL9.8Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Akilli Commerce So...
CVE-2026-6514HIGH7.5The InfusedWoo Pro plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 5.1.2...
CVE-2026-6512CRITICAL9.1The InfusedWoo Pro plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.1....
CVE-2026-6504MEDIUM6.4The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'titl...
CVE-2026-6206MEDIUM5.3The MW WP Form plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 5.1.2 vi...
CVE-2026-6174MEDIUM6.4The CC Child Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'more' parameter in all ver...
CVE-2026-6145MEDIUM5.3The User Registration & Membership plugin for WordPress is vulnerable to Missing Authorization in all versions up to, an...