CVE search
401,034 resultsCVE-2026-7175MEDIUMMultiple vulnerabilities in Entradium by CrocanticketsEPSS 0.2%CVE-2026-7174MEDIUMMultiple vulnerabilities in Entradium by CrocanticketsEPSS 0.3%CVE-2026-7173MEDIUMMultiple vulnerabilities in Entradium by CrocanticketsEPSS 0.3%CVE-2026-75786HIGHSQL Injection in Grafana Integration Endpoint (query.php)EPSS 0.2%CVE-2026-64950HIGHStored Cross-Site Scripting via Directory Name in File Manager Create DirectoryEPSS 0.2%CVE-2026-64949HIGHUnrestricted File Upload Leading to Remote Code Execution in Admin Tools File ManagerEPSS 0.3%CVE-2026-64948HIGHMissing Authorization in get_module_detail AJAX Endpoint Allows Cross-Group Module Data DisclosureEPSS 0.2%CVE-2026-64947HIGHCSRF Bypass Leading to Remote Code Execution via Unrestricted File Upload in Plugin File ManagerEPSS 0.3%CVE-2026-92144HIGHForminator Forms <= 1.57.2 - Unauthenticated Stored Cross-Site Scripting via 'postdata-1[post-custom]' ParameterEPSS 0.5%CVE-2026-96256MEDIUMGutenberg Essential Blocks <= 6.4.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'marker' AttributeEPSS 0.3%CVE-2026-64946HIGHCSRF Bypass Leading to Stored Cross-Site Scripting via Unrestricted SVG Upload in File ManagerEPSS 0.2%CVE-2026-34190MEDIUMCSRF in Alert Command DeletionEPSS 0.2%CVE-2026-34189MEDIUMCSRF in Event Response DeletionEPSS 0.2%CVE-2026-96577HIGHOc-mirror__release-4.21: embedded local cache registry listens on all interfaces without authentication, with delete enabledEPSS 0.2%CVE-2026-83589MEDIUMOauth-proxy: open redirect via /\ and /\t bypass in post-login redirectEPSS 0.2%CVE-2026-103497MEDIUMIn JetBrains YouTrack before 2026.2.19422 sSRF was possible via the GitHub VCS integrationEPSS 0.2%CVE-2026-103496MEDIUMIn JetBrains YouTrack before 2026.2.19422 iDOR in inbox threads allowed reading other users' notificationsEPSS 0.1%CVE-2026-103495MEDIUMIn JetBrains YouTrack before 2026.2.19422 missing authorisation allowed reloading of translation catalogsEPSS 0.2%CVE-2026-103494MEDIUMIn JetBrains YouTrack before 2026.2.19422 privilege escalation was possible via user group membership changesEPSS 0.2%CVE-2026-103493HIGHIn JetBrains YouTrack before 2026.2.19422 stored XSS via Mermaid and LaTeX content was possibleEPSS 0.2%