CVE Vulnerability Database

Search and browse 398,082 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2022-50945MEDIUM6.4WordPress 3dady Real-Time Web Stats plugin 1.0 contains a stored cross-site scripting vulnerability that allows authenti...
CVE-2022-50944HIGH8.8Aero CMS 0.0.1 contains a PHP code injection vulnerability that allows authenticated attackers to execute arbitrary PHP ...
CVE-2022-50943MEDIUM6.1Moodle LMS 4.0 contains a cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious s...
CVE-2021-47953MEDIUM5.3OpenCart 3.0.3.7 contains a cross-site request forgery vulnerability that allows attackers to change user passwords by s...
CVE-2021-47951MEDIUM6.4WordPress Picture Gallery 1.4.2 contains a stored cross-site scripting vulnerability that allows authenticated attackers...
CVE-2021-47950MEDIUM6.4Advanced Guestbook 2.4.4 contains a persistent cross-site scripting vulnerability in the smilies administration interfac...
CVE-2021-47949HIGH8.8CyberPanel 2.1 contains a command execution vulnerability that allows authenticated attackers to read arbitrary files an...
CVE-2021-47948MEDIUM5.4WordPress GetPaid Plugin 2.4.6 contains an HTML injection vulnerability that allows authenticated attackers to inject ar...
CVE-2021-47947MEDIUM6.4Projectsend r1295 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject mal...
CVE-2021-47946MEDIUM6.9OpenCart 3.0.3.6 contains a cross-site request forgery vulnerability in the /account/edit endpoint that allows unauthent...
CVE-2021-47945HIGH8.5Argus Surveillance DVR 4.0 contains an unquoted service path vulnerability in the DVRWatchdog service that allows local ...
CVE-2021-47944HIGH8.7memono Notepad 4.2 contains a denial of service vulnerability that allows attackers to crash the application by pasting ...
CVE-2021-47943HIGH8.8TextPattern CMS 4.8.7 contains a remote code execution vulnerability that allows authenticated attackers to execute arbi...
CVE-2021-47941HIGH8.8WordPress Plugin Survey & Poll 1.5.7.3 contains an SQL injection vulnerability that allows unauthenticated attackers to ...
CVE-2021-47940CRITICAL9.8WordPress Plugin Download From Files version 1.48 and earlier contains an arbitrary file upload vulnerability that allow...
CVE-2021-47939HIGH8.8Evolution CMS 3.1.6 contains a remote code execution vulnerability that allows authenticated users with module creation ...
CVE-2021-47938HIGH8.8ImpressCMS 1.4.2 contains a remote code execution vulnerability in the autotasks administrative interface that allows au...
CVE-2021-47937HIGH8.8e107 CMS 2.3.0 contains a remote code execution vulnerability that allows authenticated users with theme installation pe...
CVE-2021-47936CRITICAL9.8OpenCATS 0.9.4 contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary...
CVE-2021-47935HIGH8.8Sentry 8.2.0 contains a remote code execution vulnerability that allows authenticated superusers to execute arbitrary co...
CVE-2021-47933CRITICAL9.8WordPress MStore API 2.0.6 contains an arbitrary file upload vulnerability that allows unauthenticated attackers to uplo...
CVE-2021-47932CRITICAL9.8WordPress TheCartPress 1.5.3.6 contains an unauthenticated privilege escalation vulnerability that allows attackers to c...
CVE-2021-47931MEDIUM6.4Exponent CMS 2.6 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject mali...
CVE-2021-47930HIGH8.8Balbooa Joomla Forms Builder 2.0.6 contains an unauthenticated SQL injection vulnerability in the form submission handle...
CVE-2021-47929MEDIUM6.4Filterable Portfolio Gallery 1.0 contains a stored cross-site scripting vulnerability that allows authenticated attacker...