CVE Vulnerability Database

Search and browse 388,932 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-64794MEDIUM6.5Joomla Extension - regularlabs.com - restricted user-data exposure in Users Anywhere and Articles Anywhere extensions - ...
CVE-2026-64793CRITICAL9.1Joomla Extension - regularlabs.com - Content access and publication bypass in Articles Anywhere and Modules Anywhere ext...
CVE-2026-64792HIGH7.5Joomla Extension - regularlabs.com - disclosure of restricted content via search index in various Regular Labs extension...
CVE-2026-64791HIGH8.8Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in Regular Labs Extension Manager...
CVE-2026-63685HIGH8.8Joomla Extension - regularlabs.com - Authorization bypass in DB Replacer extension - Administrator routes and replacemen...
CVE-2026-63684HIGH8.8Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in various admin/import/export ac...
CVE-2026-63683HIGH7.5Joomla Extension - regularlabs.com - Client IP spoofing vulnerability in Regular Labs conditions manager - IP and GeoIP ...
CVE-2026-63281MEDIUM4.8Joomla Extension - regularlabs.com - XSS vulnerability in Regular Labs conditions manager - Stored condition values coul...
CVE-2026-63280HIGH8.8Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in Regular Labs conditions manage...
CVE-2026-63265HIGH8Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in various Regular Labs extension...
CVE-2026-13089HIGH7.5OIDC::Lite versions through 0.12.1 for Perl allow ID Token signature verification bypass via a token-controlled algorith...
CVE-2025-60835HIGH7.8An issue in the unrar.dll component of IZArc v4.6 allows attackers to execute a path traversal.
CVE-2025-50330HIGH8.8An issue in ZipGenius Team ZipGenius v.6.3.2.3116 and before allows a remote attacker to escalate privileges and execute...
CVE-2025-50329CRITICAL9.8An issue in ConeXware, Inc Power Archiver v.22.00.11 and before allows a remote attacker to escalate privileges and exec...
CVE-2025-50327HIGH8.8An issue in Franco Corbelli ZPAQFRANZ v.61.3 and before allows a remote attacker to escalate privileges and execute arbi...
CVE-2025-50325MEDIUM5.4BandiZip v.7.37 is affected by a Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypa...
CVE-2025-50324HIGH8.8An issue in Milos Paripovic OneCommander v.3.96.0.0 allows a remote attacker to execute arbitrary code via the OneComman...
CVE-2025-44090HIGH8.8An issue in OhSoft CoffeeZip v4.8.0.0 allows attackers to execute arbitrary code via downloading and executing a crafted...
CVE-2025-44089HIGH8.8An issue in NCH Software ExpressZip v11.29 allows attackers to execute arbitrary code via downloading and executing a cr...
CVE-2026-9737HIGH7.1During query planning when reading the sort pattern in raw BSONObj form, in some places we don’t explicitly handle the m...
CVE-2026-64829CRITICAL9.1Question2Answer through 1.8.8 contains a session invalidation vulnerability that allows attackers with a previously obta...
CVE-2026-14899HIGH7.5The code to parse MIME headers for display when forwarding a message (if the setting to view all headers was enabled) ha...
CVE-2026-14881HIGH8.4When importing connections in Compass it is possible to override some connection options that are otherwise can't be cha...
CVE-2026-13078HIGH7.7A vulnerability was discovered in MongoDB Server where the server-side MozJS scripting engine unconditionally registered...
CVE-2026-13077HIGH7.1A missing bounds check in the BSON CodeWScope element accessors allows an attacker to trigger an out-of-bounds heap read...