CVE Database

138188+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-37344
7.2 HIGH

SourceCodester Vehicle Parking Area Management System v1.0 is vulnerable to SQL Injection in the file /parking/manage_location.php.

Apr 16, 2026
CVE-2026-37343
7.2 HIGH

SourceCodester Vehicle Parking Area Management System v1.0 is vulnerable to SQL Injection in the file /parking/manage_user.php.

Apr 16, 2026
CVE-2026-37342
7.2 HIGH

SourceCodester Vehicle Parking Area Management System v1.0 is vulnerable to SQL Injection in the file /parking/view_parked_details.php.

Apr 16, 2026
CVE-2026-37341
7.2 HIGH

SourceCodester Vehicle Parking Area Management System v1.0 is vulnerable to SQL Injection in the file /parking/manage_category.php.

Apr 16, 2026
CVE-2026-37340
9.8 CRITICAL

SourceCodester Simple Music Cloud Community System v1.0 is vulnerable to SQL Injection in the file /music/edit_music.php.

Apr 16, 2026
CVE-2026-37339
9.8 CRITICAL

SourceCodester Simple Music Cloud Community System v1.0 is vulnerable to SQL Injection in the file /music/view_genre.php.

Apr 16, 2026
CVE-2026-37338
9.4 CRITICAL

SourceCodester Simple Music Cloud Community System v1.0 is vulnerable to SQL Injection in the file /music/view_user.php.

Apr 16, 2026
CVE-2026-37337
7.3 HIGH

SourceCodester Simple Music Cloud Community System v1.0 is vulnerable to SQL Injection in the file /music/view_playlist.php.

Apr 16, 2026
CVE-2026-37336
7.3 HIGH

SourceCodester Simple Music Cloud Community System v1.0 is vulnerable to SQL Injection in the file /music/view_music.php.

Apr 16, 2026
CVE-2026-33804
7.4 HIGH

@fastify/middie versions 9.3.1 and earlier are vulnerable to middleware bypass when the deprecated Fastify ignoreDuplicateSlashes option is enabled. The middleware path matching logic does not …

Apr 16, 2026
CVE-2026-30656
7.5 HIGH

A NULL pointer dereference vulnerability exists in fio (Flexible I/O Tester) v3.41 when parsing job files containing the fdp_pli option. The callback function str_fdp_pli_cb() does …

Apr 16, 2026
CVE-2026-30459
7.1 HIGH

An issue in the Forgot Password feature of Daylight Studio FuelCMS v1.5.2 allows unauthenticated attackers to obtain the password reset token of a victim user …

Apr 16, 2026
CVE-2026-2840
6.4 MEDIUM

The Email Encoder – Protect Email Addresses and Phone Numbers plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'eeb_mailto' shortcode in all …

Apr 16, 2026
CVE-2026-6410
5.3 MEDIUM

@fastify/static versions 8.0.0 through 9.1.0 allow path traversal when directory listing is enabled via the list option. The dirList.path() function resolves directories outside the configured …

Apr 16, 2026
CVE-2026-6270
9.1 CRITICAL

@fastify/middie versions 9.3.1 and earlier do not register inherited middleware directly on child plugin engine instances. When a Fastify application registers authentication middleware in a …

Apr 16, 2026
CVE-2026-5785
8.1 HIGH

Zohocorp ManageEngine PAM360 versions before 8531 and ManageEngine Password Manager Pro versions from 8600 to 13230 are vulnerable to Authenticated SQL injection in the query …

Apr 16, 2026
CVE-2026-4160
5.3 MEDIUM

The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Insecure Direct Object Reference via the …

Apr 16, 2026
CVE-2026-31987
7.5 HIGH

JWT Tokens used by tasks were exposed in logs. This could allow UI users to act as Dag Authors. Users are advised to upgrade to …

Apr 16, 2026
CVE-2026-6414
5.9 MEDIUM

@fastify/static versions 8.0.0 through 9.1.0 decode percent-encoded path separators (%2F) before filesystem resolution, while Fastify's router treats them as literal characters. This mismatch allows attackers …

Apr 16, 2026
CVE-2026-31843
9.8 CRITICAL

The goodoneuz/pay-uz Laravel package (<= 2.2.24) contains a critical vulnerability in the /payment/api/editable/update endpoint that allows unauthenticated attackers to overwrite existing PHP payment hook files. …

Apr 16, 2026
CVE-2025-15621

Insufficiently Protected Credentials in Sparx Systems Pty Ltd. Sparx Enterprise Architect. Client does not verify the receiver of OAuth2 credentials during OpenID authentication

Apr 16, 2026
CVE-2026-3489
7.5 HIGH

The DirectoryPress – Business Directory And Classified Ad Listing plugin for WordPress is vulnerable to SQL Injection via the 'packages' parameter in versions up to, …

Apr 16, 2026
CVE-2026-3369
5.4 MEDIUM

The Better Find and Replace – AI-Powered Suggestions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via uploaded image title in versions up to, …

Apr 16, 2026
CVE-2026-3155
3.1 LOW

The OneSignal – Web Push Notifications plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 3.8.0. This is due to …

Apr 16, 2026
CVE-2025-12624
6.0 MEDIUM

Active access tokens are not revoked or invalidated when a user account is locked within WSO2 Identity Server. This failure to enforce revocation allows previously …

Apr 16, 2026
CVE-2025-6024
6.1 MEDIUM

The authentication endpoint fails to encode user-supplied input before rendering it in the web page, allowing for script injection. An attacker can leverage this by …

Apr 16, 2026
CVE-2024-8010
3.5 LOW

The component accepts XML input through the publisher without disabling external entity resolution. This allows malicious actors to submit a crafted XML payload that exploits …

Apr 16, 2026
CVE-2024-4867
5.4 MEDIUM

The WSO2 API Manager developer portal accepts user-supplied input without enforcing expected validation constraints or proper output encoding. This deficiency allows a malicious actor to …

Apr 16, 2026
CVE-2024-10242
6.1 MEDIUM

The authentication endpoint fails to adequately validate user-supplied input before reflecting it back in the response. This allows an attacker to inject malicious script payloads …

Apr 16, 2026
CVE-2025-67711
6.1 MEDIUM

There is a stored cross site scripting issue in Esri ArcGIS Server 11.4 and earlier on Windows and Linux that in some configurations allows a …

Dec 31, 2025
CVE-2025-67710
6.1 MEDIUM

There is a stored cross site scripting issue in Esri ArcGIS Server 11.4 and earlier on Windows and Linux that in some configurations allows a …

Dec 31, 2025
CVE-2025-67709
6.1 MEDIUM

There is a stored cross site scripting issue in Esri ArcGIS Server 11.4 and earlier on Windows and Linux that in some configurations allows a …

Dec 31, 2025
CVE-2025-67708
6.1 MEDIUM

There is a stored cross site scripting issue in Esri ArcGIS Server 11.4 and earlier on Windows and Linux that in some configurations allows a …

Dec 31, 2025
CVE-2025-67707
5.6 MEDIUM

ArcGIS Server versions 11.5 and earlier on Windows and Linux do not sufficiently validate uploaded files, enabling a remote unauthenticated attacker to upload arbitrary files …

Dec 31, 2025
CVE-2025-67706
5.6 MEDIUM

ArcGIS Server versions 11.5 and earlier on Windows and Linux do not sufficiently validate uploaded files, enabling a remote unauthenticated attacker to upload arbitrary files …

Dec 31, 2025
CVE-2025-67705
6.1 MEDIUM

There is a stored cross site scripting issue in Esri ArcGIS Server 11.4 and earlier on Windows and Linux that in some configurations allows a …

Dec 31, 2025
CVE-2025-67704
6.1 MEDIUM

There is a stored cross site scripting issue in Esri ArcGIS Server 11.4 and earlier on Windows and Linux that in some configurations allows a …

Dec 31, 2025
CVE-2025-67703
6.1 MEDIUM

There is a stored cross site scripting issue in Esri ArcGIS Server 11.4 and earlier on Windows and Linux that in some configurations allows a …

Dec 31, 2025
CVE-2025-69288
9.1 CRITICAL

Titra is open source project time tracking software. Prior to version 0.99.49, Titra allows any authenticated Admin user to modify the timeEntryRule in the database. …

Dec 31, 2025
CVE-2025-69286
9.8 CRITICAL

RAGFlow is an open-source RAG (Retrieval-Augmented Generation) engine. In versions prior to 0.22.0, the use of an insecure key generation algorithm in the API key …

Dec 31, 2025
CVE-2025-68700
8.8 HIGH

RAGFlow is an open-source RAG (Retrieval-Augmented Generation) engine. In versions prior to 0.23.0, a low-privileged authenticated user (normal login account) can execute arbitrary system commands …

Dec 31, 2025
CVE-2025-34469
7.5 HIGH

Cowrie versions prior to 2.9.0 contain a server-side request forgery (SSRF) vulnerability in the emulated shell implementation of wget and curl. In the default emulated …

Dec 31, 2025
CVE-2025-15398
3.7 LOW

A security vulnerability has been detected in Uasoft badaso up to 2.9.7. Affected is the function forgetPassword of the file src/Controllers/BadasoAuthController.php of the component Token …

Dec 31, 2025
CVE-2023-7332

PocketMine-MP versions prior to 4.18.1 contain an improper input validation vulnerability in inventory transaction handling. A remote attacker with a valid player session can request …

Dec 31, 2025
CVE-2025-53235
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in osuthorpe Easy Social easy-social-media allows Reflected XSS.This issue affects Easy Social: from n/a …

Dec 31, 2025
CVE-2023-7331
4.7 MEDIUM

A vulnerability was detected in PKrystian Full-Stack-Bank up to bf73a0179e3ff07c0d7dc35297cea0be0e5b1317. This vulnerability affects unknown code of the component User Handler. Performing manipulation results in sql …

Dec 31, 2025
CVE-2015-10145
8.8 HIGH

Gargoyle router management utility versions 1.5.x contain an authenticated OS command execution vulnerability in /utility/run_commands.sh. The application fails to properly restrict or validate input supplied …

Dec 31, 2025
CVE-2025-66148
5.4 MEDIUM

Missing Authorization vulnerability in merkulove Conformer for Elementor conformer-elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Conformer for Elementor: from n/a through …

Dec 31, 2025
CVE-2025-66146
5.4 MEDIUM

Missing Authorization vulnerability in merkulove Logger for Elementor logger-elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Logger for Elementor: from n/a through …

Dec 31, 2025
CVE-2025-66145
5.4 MEDIUM

Missing Authorization vulnerability in merkulove Worker for WPBakery worker-wpbakery allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Worker for WPBakery: from n/a through …

Dec 31, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.