CVE Vulnerability Database
Search and browse 398,082 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-50945 | MEDIUM | 6.4 | 0.2% | May 10, 2026 | WordPress 3dady Real-Time Web Stats plugin 1.0 contains a stored cross-site scripting vulnerability that allows authenti... |
| CVE-2022-50944 | HIGH | 8.8 | 0.3% | May 10, 2026 | Aero CMS 0.0.1 contains a PHP code injection vulnerability that allows authenticated attackers to execute arbitrary PHP ... |
| CVE-2022-50943 | MEDIUM | 6.1 | 0.3% | May 10, 2026 | Moodle LMS 4.0 contains a cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious s... |
| CVE-2021-47953 | MEDIUM | 5.3 | 0.1% | May 10, 2026 | OpenCart 3.0.3.7 contains a cross-site request forgery vulnerability that allows attackers to change user passwords by s... |
| CVE-2021-47951 | MEDIUM | 6.4 | 0.2% | May 10, 2026 | WordPress Picture Gallery 1.4.2 contains a stored cross-site scripting vulnerability that allows authenticated attackers... |
| CVE-2021-47950 | MEDIUM | 6.4 | 0.2% | May 10, 2026 | Advanced Guestbook 2.4.4 contains a persistent cross-site scripting vulnerability in the smilies administration interfac... |
| CVE-2021-47949 | HIGH | 8.8 | 0.5% | May 10, 2026 | CyberPanel 2.1 contains a command execution vulnerability that allows authenticated attackers to read arbitrary files an... |
| CVE-2021-47948 | MEDIUM | 5.4 | 0.2% | May 10, 2026 | WordPress GetPaid Plugin 2.4.6 contains an HTML injection vulnerability that allows authenticated attackers to inject ar... |
| CVE-2021-47947 | MEDIUM | 6.4 | 0.2% | May 10, 2026 | Projectsend r1295 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject mal... |
| CVE-2021-47946 | MEDIUM | 6.9 | 0.2% | May 10, 2026 | OpenCart 3.0.3.6 contains a cross-site request forgery vulnerability in the /account/edit endpoint that allows unauthent... |
| CVE-2021-47945 | HIGH | 8.5 | 0.1% | May 10, 2026 | Argus Surveillance DVR 4.0 contains an unquoted service path vulnerability in the DVRWatchdog service that allows local ... |
| CVE-2021-47944 | HIGH | 8.7 | 0.3% | May 10, 2026 | memono Notepad 4.2 contains a denial of service vulnerability that allows attackers to crash the application by pasting ... |
| CVE-2021-47943 | HIGH | 8.8 | 0.6% | May 10, 2026 | TextPattern CMS 4.8.7 contains a remote code execution vulnerability that allows authenticated attackers to execute arbi... |
| CVE-2021-47941 | HIGH | 8.8 | 0.3% | May 10, 2026 | WordPress Plugin Survey & Poll 1.5.7.3 contains an SQL injection vulnerability that allows unauthenticated attackers to ... |
| CVE-2021-47940 | CRITICAL | 9.8 | 0.4% | May 10, 2026 | WordPress Plugin Download From Files version 1.48 and earlier contains an arbitrary file upload vulnerability that allow... |
| CVE-2021-47939 | HIGH | 8.8 | 0.6% | May 10, 2026 | Evolution CMS 3.1.6 contains a remote code execution vulnerability that allows authenticated users with module creation ... |
| CVE-2021-47938 | HIGH | 8.8 | 0.6% | May 10, 2026 | ImpressCMS 1.4.2 contains a remote code execution vulnerability in the autotasks administrative interface that allows au... |
| CVE-2021-47937 | HIGH | 8.8 | 0.6% | May 10, 2026 | e107 CMS 2.3.0 contains a remote code execution vulnerability that allows authenticated users with theme installation pe... |
| CVE-2021-47936 | CRITICAL | 9.8 | 0.7% | May 10, 2026 | OpenCATS 0.9.4 contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary... |
| CVE-2021-47935 | HIGH | 8.8 | 0.9% | May 10, 2026 | Sentry 8.2.0 contains a remote code execution vulnerability that allows authenticated superusers to execute arbitrary co... |
| CVE-2021-47933 | CRITICAL | 9.8 | 0.6% | May 10, 2026 | WordPress MStore API 2.0.6 contains an arbitrary file upload vulnerability that allows unauthenticated attackers to uplo... |
| CVE-2021-47932 | CRITICAL | 9.8 | 0.4% | May 10, 2026 | WordPress TheCartPress 1.5.3.6 contains an unauthenticated privilege escalation vulnerability that allows attackers to c... |
| CVE-2021-47931 | MEDIUM | 6.4 | 0.2% | May 10, 2026 | Exponent CMS 2.6 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject mali... |
| CVE-2021-47930 | HIGH | 8.8 | 0.3% | May 10, 2026 | Balbooa Joomla Forms Builder 2.0.6 contains an unauthenticated SQL injection vulnerability in the form submission handle... |
| CVE-2021-47929 | MEDIUM | 6.4 | 0.2% | May 10, 2026 | Filterable Portfolio Gallery 1.0 contains a stored cross-site scripting vulnerability that allows authenticated attacker... |
