CVE Vulnerability Database
Search and browse 397,974 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-6473 | HIGH | 8.8 | 1.0% | May 14, 2026 | Integer wraparound in multiple PostgreSQL server features allows an unprivileged database user to cause the server to un... |
| CVE-2026-6472 | MEDIUM | 5.4 | 0.2% | May 14, 2026 | Missing authorization in PostgreSQL CREATE TYPE allows an object creator to hijack other queries that use search_path to... |
| CVE-2026-1630 | MEDIUM | 5.1 | 0.4% | May 14, 2026 | WEBCON BPS is vulnerable to Reflected XSS via one of parameters used by "/openinmobileapp" endpoint. An attacker can sen... |
| CVE-2025-15025 | HIGH | 8.8 | 0.3% | May 14, 2026 | Authorization bypass through User-Controlled key vulnerability in Yordam Information Technology Consulting, Training and... |
| CVE-2026-6008 | MEDIUM | 6.8 | 0.2% | May 14, 2026 | Authorization bypass through User-Controlled key vulnerability in Im Park Information Technology, Electronics, Press, Pu... |
| CVE-2026-5798 | HIGH | 7.1 | 0.2% | May 14, 2026 | Unsafe object reference (IDOR) in Stel Order v3.25.1 and earlier versions, specifically in the ‘/app/FrontController’ en... |
| CVE-2026-5790 | MEDIUM | 5.1 | 0.3% | May 14, 2026 | Stored Cross-Site Scripting (XSS) in Stel Order v3.25.1 and earlier, located at the ‘/app/FrontController’ endpoint via ... |
| CVE-2026-4031 | HIGH | 7.5 | 0.5% | May 14, 2026 | The Database Backup for WordPress plugin for WordPress is vulnerable to authorization bypass in all versions up to, and ... |
| CVE-2026-4030 | HIGH | 8.1 | 0.5% | May 14, 2026 | The Database Backup for WordPress plugin for WordPress is vulnerable to unauthorized arbitrary file read and deletion in... |
| CVE-2026-4029 | HIGH | 7.5 | 0.4% | May 14, 2026 | The Database Backup for WordPress plugin for WordPress is vulnerable to unauthorized database export in all versions up ... |
| CVE-2026-43644 | MEDIUM | 6.1 | 0.2% | May 14, 2026 | podinfo through 6.11.2 contains a reflected cross-site scripting vulnerability in the /echo and /api/echo endpoints wher... |
| CVE-2025-12008 | HIGH | 8.8 | 0.2% | May 14, 2026 | Authorization bypass through User-Controlled key vulnerability in APPYAP Technology and Information Inc. Yaay Social Med... |
| CVE-2026-45205 | MEDIUM | 5.3 | 0.5% | May 14, 2026 | Uncontrolled Recursion vulnerability in Apache Commons. When processing an untrusted configuration file, Commons Config... |
| CVE-2026-8468 | HIGH | 8.2 | 0.6% | May 14, 2026 | Allocation of Resources Without Limits or Throttling vulnerability in plug_project plug allows denial of service via unb... |
| CVE-2026-8295 | MEDIUM | 6.9 | 0.3% | May 14, 2026 | An integer overflow vulnerability in the simdjson document-builder API allows incorrect buffer size calculations in "str... |
| CVE-2025-68421 | HIGH | 8.7 | 0.2% | May 14, 2026 | Comarch ERP Optima client makes use of a hard-coded password for a database user. These credentials cannot be changed. I... |
| CVE-2025-68420 | HIGH | 7.5 | 0.1% | May 14, 2026 | Comarch ERP Optima client connects to a database using a high privileged account regardless of an application account to... |
| CVE-2026-2347 | CRITICAL | 9.8 | 0.4% | May 14, 2026 | Authorization bypass through User-Controlled key vulnerability in Akilli Commerce Software Technologies Ltd. Co. E-Comme... |
| CVE-2025-11024 | CRITICAL | 9.8 | 0.4% | May 14, 2026 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Akilli Commerce So... |
| CVE-2026-6514 | HIGH | 7.5 | 0.3% | May 14, 2026 | The InfusedWoo Pro plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 5.1.2... |
| CVE-2026-6512 | CRITICAL | 9.1 | 0.3% | May 14, 2026 | The InfusedWoo Pro plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.1.... |
| CVE-2026-6504 | MEDIUM | 6.4 | 0.3% | May 14, 2026 | The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'titl... |
| CVE-2026-6206 | MEDIUM | 5.3 | 0.4% | May 14, 2026 | The MW WP Form plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 5.1.2 vi... |
| CVE-2026-6174 | MEDIUM | 6.4 | 0.2% | May 14, 2026 | The CC Child Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'more' parameter in all ver... |
| CVE-2026-6145 | MEDIUM | 5.3 | 0.4% | May 14, 2026 | The User Registration & Membership plugin for WordPress is vulnerable to Missing Authorization in all versions up to, an... |
