CVE search

401,007 results
CVE-2026-10026HIGHCTX Feed Pro <= 7.6.12 - Authenticated (Administrator+) Remote Code ExecutionEPSS 0.3%CVE-2026-19660CRITICALDivi Membership <= 2.3.0 - Unauthenticated Authentication Bypass via 'paypal_param' ParameterEPSS 0.4%CVE-2026-93367HIGHVisitors Traffic Real Time Statistics Pro <= 11.22 - Unauthenticated Stored Cross-Site Scripting via ahcpro_track_visitor (page_title)EPSS 0.2%CVE-2026-14378CRITICALDevKit Pro <= 2.3.0 - Unauthenticated Authentication Bypass to Administrator Account Takeover via 'original_user_id' Cookie in Frontend Revert Switch FlowEPSS 0.5%CVE-2026-104123MEDIUMSourceCodester Online Reviewer Management System btn_functions.php activity sql injectionEPSS 0.3%CVE-2026-104120MEDIUMmodelcontextprotocol mcp-server-fetch/mcp-server-everything Fetch Tool server.py fetch_url server-side request forgeryEPSS 0.3%CVE-2026-104054MEDIUMcalcom cal.diy PBAC Permission BookingAccessService.ts doesUserIdHaveAccessToBooking authorizationEPSS 0.2%CVE-2026-104053MEDIUMitsourcecode Pet Shop Management System admin_reservefilter.php sql injectionEPSS 0.2%CVE-2026-21140MEDIUMImproper access control in ManagedProvisioning prior to SMR Sep-2026 Release 1 allows local attackers to install arbitrary applications.EPSS 0.1%CVE-2026-104052MEDIUMitsourcecode Pet Shop Management System admin_reject_completed.php sql injectionEPSS 0.2%CVE-2026-104480CRITICALImproper MLS Welcome roster validation in Discord libdave allows unauthorized group membershipEPSS 0.4%CVE-2026-103098HIGHGV-Eye Sensitive information exposure in URL query parameter VulnerabilityEPSS 0.2%CVE-2026-103097HIGHGV-Eye Relay Payment API Key VulnerabilityEPSS 0.2%CVE-2026-103096HIGHGV-Eye Hardcoded API Key VulnerabilityEPSS 0.2%CVE-2026-51898—sinaptik-ai pandas-ai 3.0.0 is vulnerable to Code Injection in CodeExecutor.execute.EPSS —CVE-2026-51917—FinRobot v1.0.0 is vulnerable to Code Injection in CodingUtils.modify_code.EPSS —CVE-2026-51911—vanna v2.0.2 contains a code injection vulnerability in VannaBase.get_plotly_figure (src/vanna/legacy/base/base.py). Depending on the exposeEPSS —CVE-2026-51901—SuperAGI up to 0.0.14 is vulnerable to Incorrect Access Control. The agent execution controller endpoint /api/agentexecutions/schedule allowEPSS —CVE-2026-51918—FinRobot 1.0.0 contains code injection in CodingUtils.create_file_with_code ().EPSS —CVE-2026-51914—TransformerOptimus SuperAGI v0.0.14 is vulnerable to Incorrect Access Control in the agent template controller. In affected source snapshotsEPSS —