CVE Browser

Search and filter CVEs by severity, ecosystem, EPSS score, and more.

More filters

Page 1 (more results available)

CVE-2026-10026 HIGH

CTX Feed Pro <= 7.6.12 - Authenticated (Administrator+) Remote Code Execution

CVSS 7.2 EPSS n/a Oct 2, 2026
CVE-2026-19660 CRITICAL

Divi Membership <= 2.3.0 - Unauthenticated Authentication Bypass via 'paypal_param' Parameter

CVSS 9.8 EPSS n/a Oct 2, 2026
CVE-2026-93367 HIGH

Visitors Traffic Real Time Statistics Pro <= 11.22 - Unauthenticated Stored Cross-Site Scripting via ahcpro_track_visitor (page_title)

CVSS 7.2 EPSS n/a Oct 2, 2026
CVE-2026-14378 CRITICAL

DevKit Pro <= 2.3.0 - Unauthenticated Authentication Bypass to Administrator Account Takeover via 'original_user_id' Cookie in Frontend Revert Switch Flow

CVSS 9.8 EPSS n/a Oct 2, 2026
CVE-2026-104123 MEDIUM

SourceCodester Online Reviewer Management System btn_functions.php activity sql injection

CVSS 6.9 EPSS n/a Oct 2, 2026
CVE-2026-104120 MEDIUM

modelcontextprotocol mcp-server-fetch/mcp-server-everything Fetch Tool server.py fetch_url server-side request forgery

CVSS 6.9 EPSS n/a Oct 2, 2026
CVE-2026-104054 MEDIUM

calcom cal.diy PBAC Permission BookingAccessService.ts doesUserIdHaveAccessToBooking authorization

CVSS 5.3 EPSS n/a Oct 2, 2026
CVE-2026-103098 HIGH

Transmission of a sensitive key in the URL over an unencrypted HTTP connection. The request is sent over HTTP rather than HTTPS, meaning the key is transmitted…

CVSS 7.5 EPSS n/a Oct 2, 2026
CVE-2026-103097 HIGH

An API key is hardcoded and retrievable from the application package. Since Android applications can be reverse engineered, embedding sensitive API credentials…

CVSS 7.5 EPSS n/a Oct 2, 2026
CVE-2026-103096 HIGH

API key is hardcoded and retrievable from the application package. Since Android applications can be reverse engineered, embedding sensitive API credentials di…

CVSS 7.5 EPSS n/a Oct 2, 2026
CVE-2026-104053 MEDIUM

itsourcecode Pet Shop Management System admin_reservefilter.php sql injection

CVSS 5.3 EPSS n/a Oct 2, 2026
CVE-2026-21140 MEDIUM

Improper access control in ManagedProvisioning prior to SMR Sep-2026 Release 1 allows local attackers to install arbitrary applications.

CVSS 6.9 EPSS n/a Oct 2, 2026
CVE-2026-104052 MEDIUM

itsourcecode Pet Shop Management System admin_reject_completed.php sql injection

CVSS 5.3 EPSS n/a Oct 2, 2026
CVE-2026-104480 CRITICAL

Improper MLS Welcome roster validation in Discord libdave allows unauthorized group membership

CVSS 9.4 EPSS n/a Oct 2, 2026
CVE-2026-86345 CRITICAL

389-ds-base: 389-ds-base: starttls plaintext-buffer retention allows on-path attacker to forge an ldap client's authentication result

CVSS 9.0 EPSS n/a Oct 1, 2026
CVE-2026-103766 HIGH

ClipBucket v5 through 5.5.3-#197 SQL Injection via ads_manager.php delete Parameter

CVSS 8.6 EPSS n/a Oct 1, 2026
CVE-2026-103765 HIGH

Mooncake through 0.3.13.post1 Missing Authentication in HTTP Metadata Server

CVSS 8.8 EPSS n/a Oct 1, 2026
CVE-2026-103764 CRITICAL

Mooncake transfer engine before 0.3.13 Unauthenticated Arbitrary Memory Read/Write via TCP Transport

CVSS 9.3 EPSS n/a Oct 1, 2026
CVE-2026-103761 HIGH

Mooncake transfer engine through 0.3.13.post1 Memory Exhaustion via Unbounded Notify Queue

CVSS 8.7 EPSS n/a Oct 1, 2026
CVE-2026-103760 HIGH

Mooncake transfer engine through 0.3.13.post1 Denial of Service via P2P Handshake Daemon Response Write

CVSS 8.2 EPSS n/a Oct 1, 2026
CVE-2025-71427 HIGH

Office-PowerPoint-MCP-Server through 2.0.7 Path Traversal via save_presentation and manage_image

CVSS 7.6 EPSS n/a Oct 1, 2026
CVE-2026-18397 CRITICAL

SConnect: Native Host Unauthenticated Remote Code Execution Vulnerability

CVSS 9.4 EPSS n/a Oct 1, 2026
CVE-2026-86344 HIGH

389-ds-base: 389-ds-base: unauthenticated worker-thread-pool exhaustion via completed-operation-then-incomplete-pdu connection requeue

CVSS 7.5 EPSS n/a Oct 1, 2026
CVE-2026-27873 MEDIUM

- Use of Hard-coded Credentials vulnerability in Johnson Controls EasyIO FG allows - Pasword Spraying. This issue affects EasyIO FG: before 2.0b52.

CVSS 5.6 EPSS n/a Oct 1, 2026
CVE-2026-64893 HIGH

- Cleartext Transmission of Sensitive Information vulnerability in Johnson Controls EasyIO NEO allows - Man In the Middle Attack. This issue affects EasyIO NEO…

CVSS 7.3 EPSS n/a Oct 1, 2026

Showing 1 to 25 CVEs · page 1 (more available)