CVE search

401,046 results
CVE-2026-101148CRITICALBackupSheep <= 1.8 - Unauthenticated Arbitrary File Deletion and Backup Exfiltration via Empty Integration KeyEPSS 0.3%CVE-2026-101147HIGHFeatured Image from URL (FIFU) Free & Premium - Administrator Account Creation via CSRFEPSS 0.1%CVE-2026-103543MEDIUMitsourcecode Leave Management System controller.php sql injectionEPSS 0.2%CVE-2026-80275HIGHComelit 1456B gateway allows low priviledge user to overwrite installer password via unauthorized endpointEPSS 0.2%CVE-2026-80276HIGHComelit 1456B gateway exposes remote configuration password via unauthenticated management interfaceEPSS 0.4%CVE-2026-103542MEDIUMformtools.org Form Tools AJAX Endpoint actions.php smart_fill server-side request forgeryEPSS 0.2%CVE-2026-88999MEDIUMRedux Framework <= 4.5.14 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Attachment Deletion via 'attachment_id' ParameterEPSS 0.3%CVE-2026-85679HIGHExtendify <= 3.1.6 - Unauthenticated Stored Cross-Site Scripting via 'styles.blocks' Block Type KeyEPSS 0.3%CVE-2026-103541MEDIUMformtools.org Form Tools Ajax actions.php uploadFile unrestricted uploadEPSS 0.2%CVE-2026-67075MEDIUMHCL Digital Experience is affected by improper input sanitationEPSS 0.2%CVE-2026-103540MEDIUMformtools.org Form Tools Client Settings Clients.class.php updateClientSettingsTab special elements in template engineEPSS 0.2%CVE-2026-103539MEDIUMZongXR SuperMarket Instant Buy InstantBuyController.java startBuy missing authenticationEPSS 0.3%CVE-2026-82824CRITICALPath traversal may allow arbitrary files to be viewed, created, modified, or deletedEPSS 0.4%CVE-2026-82825CRITICALMissing proper authentication for critical APIs may allow sensitive information to be obtained or modified, or unauthorized operations to be performedEPSS 0.3%CVE-2026-82826HIGHAuthentication information or sensitive data may be intercepted in transitEPSS 0.2%CVE-2026-82827CRITICALA hard-coded JWT signing secret key may allow administrative functions to be abused using fraudulently generated Bearer tokensEPSS 0.3%CVE-2026-82828HIGHImproper authorization may allow a general user to perform operations equivalent to those available with administrator privilegesEPSS 0.2%CVE-2026-82829CRITICALHidden accounts or hard-coded credentials may permit unauthorized access without the legitimate authentication processEPSS 0.3%CVE-2026-76147MEDIUMGenians, Inc Genian NAC/ZTNA Remote Code ExecutionEPSS 0.4%CVE-2026-76146HIGHGenians, Inc Genian SSL PNS OS Command InjectionEPSS 1.9%