CVE Vulnerability Database

Search and browse 381,631 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-65890CRITICAL9.8Joomla Extension - balbooa.com - Unauthenticated SQL injection in Gridbox < 2.20.2 - Multiple SQLi vectors allow unauthe...
CVE-2026-65889HIGH7.5Joomla Extension - balbooa.com - Unauthenticated recursive directory deletion < 2.20.2 - The generateNewApp method allow...
CVE-2026-55995HIGH8.7A Double Free vulnerability in open-iscsi allows an unauthenticated MITM attacker to cause DoS. This issue affects...
CVE-2026-18174MEDIUM5.3@fastify/forwarded resolves client addresses from the X-Forwarded-For header. In versions before 3.0.2, when the header ...
CVE-2026-16751MEDIUM6.5Authorization Bypass in the emergency recovery approval component in Ente Technologies Ente Museum Server allows an auth...
CVE-2026-65946MEDIUM6.1Joomla Extension - rolandd.com - XSS vectors in AJAX endpoint handlers RO CSVI < 9.11.0
CVE-2026-65944HIGH8.8Joomla Extension - rolandd.com - CSRF vectors in AJAX endpoint handlers RO CSVI < 9.11.0
CVE-2026-65943HIGH7.5Joomla Extension - rolandd.com - Unauthenticated directory creation RO CSVI < 9.11.0
CVE-2026-65891MEDIUM6.5Joomla Extension - joomlacontenteditor.net - Creation of hidden files and unintended file overwrite via rename function ...
CVE-2026-65885HIGH8.8Joomla Extension - balbooa.com - Authenticated arbitrary file upload in Gridbox < 2.20.2 - File upload methods allows au...
CVE-2026-65884CRITICAL9.8Joomla Extension - balbooa.com - Privilege Escalation in Gridbox < 2.20.2 - The registration method allows users provide...
CVE-2026-50641HIGH7.1Streamsoft Business Intelligence (BI) stores users' passwords in plaintext form in the database This issue was fixed in...
CVE-2026-44944HIGH8.5An Incorrect Authorization vulnerability in open-iscsi allows unprivilidged local users to use the isscsiuio control soc...
CVE-2026-44943MEDIUM6.9An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in open-iscsi allows rem...
CVE-2026-33385MEDIUM5.1A Blind SQL injection vulnerability has been identified in Quick.CMS. Improper neutralization of input provided by a hig...
CVE-2026-14354HIGH8.7CWE-522 Insufficiently Protected Credentials vulnerability exists that could cause authentication bypass and unauthorize...
CVE-2026-12927HIGH8.4CWE-787 Out-of-bounds write vulnerability exists that could cause loss of data or potentially risk arbitrary code execut...
CVE-2026-0667CRITICAL9.3CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability that could cause arbitrary code execution, d...
CVE-2026-14270HIGH8.8The Extra Checkout Options (addon for Extra Product Options & Add-Ons for WooCommerce) plugin for WordPress is vulnerabl...
CVE-2026-8791MEDIUM6.4The Booking System Trafft plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `bookingWebsiteUrl` ...
CVE-2026-7436MEDIUM6.4The WPC Badge Management for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'text...
CVE-2026-6089MEDIUM4.9The WP CTA plugin for WordPress is vulnerable to Server-Side Request Forgery via the 'sticky_s_media' parameter in impor...
CVE-2026-65883CRITICAL9.8Joomla Extension - aimy-extensions.com - RCE via PHP object injection in Aimy Captcha-Less Form Guard 18.0 - 20.0 - A fo...
CVE-2026-5060MEDIUM6.5The MasterStudy LMS WordPress Plugin – for Online Courses and Education plugin for WordPress is vulnerable to Insecure D...
CVE-2026-56390MEDIUM6.3GNU Bison improperly handles grammar‑defined output paths. Grammar directives such as %output and %header allow specifyi...