CVE search

401,046 results
CVE-2026-76145HIGHGenians, Inc Genian SSL PNS Improper Privilege ManagementEPSS 0.2%CVE-2026-76144LOWGenians, Inc Genian SSL PNS Unrestricted File UploadEPSS 0.1%CVE-2026-76143HIGHGenians, Inc Genian SSL PNS Multi Factor Authentication BypassEPSS 0.3%CVE-2026-76142CRITICALGenians, Inc. Genian NAC/ZTNA Improper Access Control on the Internal InterfaceEPSS 0.3%CVE-2026-78210HIGHIn affected versions of Octopus Server, users with certain scoped permission sets could execute arbitrary scripts in an environment without EPSS 0.3%CVE-2026-103538MEDIUMZongXR SuperMarket Order Deletion Endpoint OrderController.java OrderController.deleteOrder missing authenticationEPSS 0.4%CVE-2026-92966CRITICALAppointment Booking Plugin <= 5.7.0 - Unauthenticated Arbitrary Shortcode Execution via First/Last Name FieldEPSS 0.4%CVE-2026-12241MEDIUMAdvanced Woo Labels – Product Labels & Badges for WooCommerce <= 2.51 - Improper Authorization to Authenticated (Subscriber+) Stored Cross-Site ScriptingEPSS 0.2%CVE-2026-92548MEDIUMWP Popular Posts <= 7.4.2 - Unauthenticated Information Disclosure in 'post_type' and 'context' ParametersEPSS 0.3%CVE-2026-103536MEDIUMZongXR Supermarket save Endpoint OrderController.java OrderController.addOrder missing authenticationEPSS 0.4%CVE-2026-103641MEDIUMGegl: gegl04: gegl: out-of-bounds read in the radiance hdr uncompressed scanline decoderEPSS 0.1%CVE-2026-103534MEDIUMDavid-Crty databasement Snapshot Model snapshots SnapshotPolicy.view access controlEPSS 0.2%CVE-2026-91109MEDIUMSimply Schedule Appointments <= 1.6.12.31 - Insecure Direct Object Reference to Authenticated (Subscriber+) Sensitive Information Disclosure via 'complete_group' ParameterEPSS 0.3%CVE-2026-96561HIGHAI Engine <= 3.8.0 - Unauthenticated Stored Cross-Site Scripting via 'model_' Parameter → PHP Error-Log Injection → Advisor Indirect Prompt InjectionEPSS 0.3%CVE-2026-92245HIGHSimply Schedule Appointments <= 1.6.12.32 - Missing Authorization to Unauthenticated Sensitive Information Exposure and Arbitrary Appointment Deletion via 'recursive' Parameter on the appointment_types REST Endpoint via Public NonceEPSS 0.4%CVE-2026-103533LOWDavid-Crty databasement database-servers API Endpoint RestoreRequest.php 511 path traversalEPSS 0.3%CVE-2026-101887LOWBlueALSA bluealsad LC3plus Decoder Division-by-Zero DoSEPSS 0.2%CVE-2026-92537MEDIUMNewsletter <= 9.3.9 - Unauthenticated Insufficiently Protected Credentials via '/tnp/l/' Click-Tracking REST Endpoint (Raw Subscriber Token Cookie Disclosure)EPSS 0.3%CVE-2026-13313HIGHAn Active Debug Code vulnerability in certain ASUS router models allows a remote authenticated user, via a crafted HTTP request, to bypass sEPSS 0.7%CVE-2026-14157CRITICALUse of an Externally Controlled Format String in the ASUS Router modules allow a remote authenticated user to execute arbitrary commands viaEPSS 0.8%