CVE Vulnerability Database

Search and browse 398,130 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-7475MEDIUM6.4The Sky Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `sky-custom-scripts` custom pos...
CVE-2026-6213CRITICAL10A vulnerability in Remote Spark SparkView before build 1122 allows an attacker to bypasses the local connection check an...
CVE-2026-5341MEDIUM6.4The NMR Strava activities plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `strava_nmr...
CVE-2026-7330HIGH7.2The Auto Affiliate Links plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includ...
CVE-2026-5127HIGH8.8The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordP...
CVE-2026-44928MEDIUM5.3In uriparser before 1.0.2, the function family EqualsUri can misclassify two unequal URIs as equal.
CVE-2026-44927MEDIUM5.3In uriparser before 1.0.2, there is pointer difference truncation to int in various places.
CVE-2026-43284HIGH8.8In the Linux kernel, the following vulnerability has been resolved: xfrm: esp: avoid in-place decrypt on shared skb fra...
CVE-2013-10075CRITICAL9.1Apache::Session versions through 1.94 for Perl re-creates deleted sessions. The session stores Apache::Session::Store::...
CVE-2026-8149MEDIUM5.1A vulnerability in Legion of the Bouncy Castle Inc. BC-LTS bcprov-lts8on on X86_64, AVX, AVX-512f, Linux, Legion of the ...
CVE-2026-8069HIGH7.8PredatorSense version 3.00.3136 to 3.00.3196 contain Local Privilege Escalation (LPE) vulnerability.The program exposes ...
CVE-2026-4935HIGH8.6The OttoKit: All-in-One Automation Platform WordPress plugin before 1.1.23 does not properly sanitize user input before ...
CVE-2026-44916LOW3In OpenStack Ironic before 35.0.2 (in a certain non-default configuration), instance_info['ks_template'] is rendered wit...
CVE-2025-69691CRITICAL9.9Netgate pfSense CE 2.8.0 allows code execution in the XMLRPC API via pfsense.exec_php. NOTE: the Supplier disputes this ...
CVE-2025-69690CRITICAL9.1Netgate pfSense CE 2.7.2 allows code execution by using the module installer with a backup file with a serialized PHP ob...
CVE-2025-69599CRITICAL9.8RayVentory Scan Engine through 12.6 Update 8 allows attackers to gain privileges if they control the value of the PATH e...
CVE-2025-67888HIGH7.3An issue was discovered in Control Web Panel (CWP) before 0.9.8.1209. User input passed via the "key" GET parameter to /...
CVE-2025-67887CRITICAL9.81C-Bitrix through 25.100.500 allows Remote Code Execution because an actor with SOURCE/WRITE permissions for the Transla...
CVE-2025-67886MEDIUM6.3Bitrix24 through 25.100.300 allows Remote Code Execution because an actor with SOURCE/WRITE permissions for the Translat...
CVE-2025-55449HIGH7.3AstrBotDevs AstrBot 3.5.15 has Advanced_System_for_Text_Response_and_Bot_Operations_Tool as the hardcoded private key us...
CVE-2023-46453CRITICAL9.8Certain GL.iNet devices with 4.x firmware allow authentication bypass (resulting in administrative control of the device...
CVE-2024-53326HIGH7.3LINQPad before 5.52.01 Pro edition is vulnerable to Unsafe Deserialization in LINQPad.AutoRefManager::PopulateFromCache(...
CVE-2024-51092CRITICAL9.1LibreNMS before 24.10.0 allows a remote attacker to execute arbitrary code via OS command injection involving AboutContr...
CVE-2024-46508HIGH7.5yeti-platform yeti before 2.1.12 allows attackers to generate valid JWT tokens is the secret is not changed (by setting ...
CVE-2024-46507HIGH7.3A SSTI (server side template injection) vulnerability in the custom template export function in yeti-platform yeti befor...