CVE search

401,037 results
CVE-2026-96173MEDIUMPayments for Hubtel < 1.0.2 - Unauthenticated Order Key Disclosure via IDOREPSS 0.2%CVE-2026-92412HIGHFive Star Restaurant Reviews < 2.3.14 - Reflected XSSEPSS 0.2%CVE-2026-90974MEDIUMWP Fusion Lite 3.37.14 - 3.47.14 - Unauthenticated CRM Integration Settings UpdateEPSS 0.2%CVE-2026-90972MEDIUMWP Fusion Lite < 3.48.0 - Subscriber+ User Email Disclosure and Cross-User CRM Data DeletionEPSS 0.1%CVE-2026-89296HIGHPro Like Button < 2.0 - Unauthenticated SQLi via 'postid' ParameterEPSS 0.3%CVE-2026-87973LOWIf-So Dynamic Content 1.9.9 - 1.10.1 - Editor+ Stored XSS via Conversion NameEPSS 0.1%CVE-2026-87970MEDIUMIf-So Dynamic Content 1.8 - 1.10.1 - Reflected XSS via render_ifso_shortcodesEPSS 0.2%CVE-2026-86610MEDIUMDownload Manager < 3.3.71 - Author+ Stored XSS via Package IconEPSS 0.2%CVE-2026-81809HIGHPaytm Payment Gateway < 2.8.9 - Unauthenticated SQLi via Payment CallbackEPSS 0.2%CVE-2026-81739HIGHPaytm Payment Gateway < 2.8.9 - Unauthenticated Stored XSS via Payment CallbackEPSS 0.2%CVE-2026-19253HIGHCache Enabler < 1.8.17 - Unauthenticated Arbitrary File and Directory Deletion via cache_enabler_clear_page_cache_by_urlEPSS 0.2%CVE-2026-101148CRITICALBackupSheep <= 1.8 - Unauthenticated Arbitrary File Deletion and Backup Exfiltration via Empty Integration KeyEPSS 0.3%CVE-2026-101147HIGHFeatured Image from URL (FIFU) Free & Premium - Administrator Account Creation via CSRFEPSS 0.1%CVE-2026-103543MEDIUMitsourcecode Leave Management System controller.php sql injectionEPSS 0.2%CVE-2026-80275HIGHComelit 1456B gateway allows low priviledge user to overwrite installer password via unauthorized endpointEPSS 0.2%CVE-2026-80276HIGHComelit 1456B gateway exposes remote configuration password via unauthenticated management interfaceEPSS 0.4%CVE-2026-103542MEDIUMformtools.org Form Tools AJAX Endpoint actions.php smart_fill server-side request forgeryEPSS 0.2%CVE-2026-88999MEDIUMRedux Framework <= 4.5.14 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Attachment Deletion via 'attachment_id' ParameterEPSS 0.3%CVE-2026-85679HIGHExtendify <= 3.1.6 - Unauthenticated Stored Cross-Site Scripting via 'styles.blocks' Block Type KeyEPSS 0.3%CVE-2026-103541MEDIUMformtools.org Form Tools Ajax actions.php uploadFile unrestricted uploadEPSS 0.2%