CVE Vulnerability Database

Search and browse 377,706 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-18597HIGH8.5The PDF creation feature of Foxit PDF Services API supports referencing external files. Although local file access is re...
CVE-2026-0637MEDIUM4.4When an Event Publisher output adapter is configured with irrelevant properties, the affected products log these propert...
CVE-2025-15039CRITICAL9.4The Conditional Authentication (Adaptive Authentication) script does not correctly enforce the completion of all require...
CVE-2025-14779LOW3.8The Secret Type Management REST API does not correctly isolate access controls when deleting a secret type. The on-delet...
CVE-2025-13909MEDIUM4.3The system accepts authentication requests without sufficient validation to enforce tenant isolation when using Email OT...
CVE-2025-13736LOW3.7When Multi-Attribute Login is enabled, the login interface fails to consistently mask the existence of user accounts. Fo...
CVE-2025-13394MEDIUM5.4The Ajax processor within the Carbon console fails to adequately protect state-changing operations from Cross-Site Reque...
CVE-2025-12627LOW2.4The user impersonation flow in WSO2 Identity Server fails to properly manage refresh tokens associated with impersonated...
CVE-2025-11850MEDIUM4.3When secondary user stores are configured, the implicit-association resolver incorrectly initializes from a secondary us...
CVE-2024-8995MEDIUM4.9Unused authorization codes issued to deleted users are not being properly invalidated or removed from the system. This a...
CVE-2024-6832HIGH7.5The account locking mechanism fails to trigger when secondary user stores are inaccessible. The software does not mainta...
CVE-2024-10302MEDIUM5.8The user self-signup flow in multiple WSO2 products fails to adequately validate user-supplied input. This weakness allo...
CVE-2023-7355Rejected reason: Erroneously reserved under wrong year by automation defect; never assigned.
CVE-2023-7354Rejected reason: Erroneously reserved under wrong year by automation defect; never assigned.
CVE-2023-7353Rejected reason: Erroneously reserved under wrong year by automation defect; never assigned.
CVE-2026-19007MEDIUM6.3A vulnerability was determined in mf-yang openclaw-cn up to 0.2.1. This vulnerability affects the function isApprovedEle...
CVE-2026-19006MEDIUM6.3A vulnerability was found in mf-yang openclaw-cn 2026.2.5. This affects an unknown part of the file src/agents/bash-tool...
CVE-2026-19005MEDIUM6.3A vulnerability was detected in nanocoai NanoClaw up to 2.0.64. Affected is the function handleCreateAgent of the file s...
CVE-2026-18967HIGH8.1A flaw was found in the SAML broker component of Keycloak, an identity and access management solution. When configured a...
CVE-2026-18510HIGH7.2The TranslatePress – Translate Multilingual sites with AI Translation plugin for WordPress is vulnerable to Stored Cross...
CVE-2026-18400MEDIUM6.4The Slider, Gallery, and Carousel by MetaSlider – Image Slider, Video Slider plugin for WordPress is vulnerable to Store...
CVE-2026-18395MEDIUM5.4The Child Pages Card WordPress plugin before 1.09 does not sanitise and escape some of its shortcode attributes before o...
CVE-2026-18050HIGH7.5The Events Manager WordPress plugin before 7.4 does not perform any authorization check on a REST route that serves tem...
CVE-2026-16954MEDIUM6.5The AI Engine WordPress plugin before 3.6.4 does not redact secret configuration values before exposing them in an admi...
CVE-2026-16734HIGH7.5The Stripe Payment Forms by WP Full Pay WordPress plugin before 8.5.2 does not verify that the caller owns the Stripe p...