CVE Browser
Search and filter CVEs by severity, ecosystem, EPSS score, and more.
Page 1 (more results available)
CTX Feed Pro <= 7.6.12 - Authenticated (Administrator+) Remote Code Execution
Divi Membership <= 2.3.0 - Unauthenticated Authentication Bypass via 'paypal_param' Parameter
Visitors Traffic Real Time Statistics Pro <= 11.22 - Unauthenticated Stored Cross-Site Scripting via ahcpro_track_visitor (page_title)
DevKit Pro <= 2.3.0 - Unauthenticated Authentication Bypass to Administrator Account Takeover via 'original_user_id' Cookie in Frontend Revert Switch Flow
SourceCodester Online Reviewer Management System btn_functions.php activity sql injection
modelcontextprotocol mcp-server-fetch/mcp-server-everything Fetch Tool server.py fetch_url server-side request forgery
calcom cal.diy PBAC Permission BookingAccessService.ts doesUserIdHaveAccessToBooking authorization
Transmission of a sensitive key in the URL over an unencrypted HTTP connection. The request is sent over HTTP rather than HTTPS, meaning the key is transmitted…
An API key is hardcoded and retrievable from the application package. Since Android applications can be reverse engineered, embedding sensitive API credentials…
API key is hardcoded and retrievable from the application package. Since Android applications can be reverse engineered, embedding sensitive API credentials di…
itsourcecode Pet Shop Management System admin_reservefilter.php sql injection
Improper access control in ManagedProvisioning prior to SMR Sep-2026 Release 1 allows local attackers to install arbitrary applications.
itsourcecode Pet Shop Management System admin_reject_completed.php sql injection
Improper MLS Welcome roster validation in Discord libdave allows unauthorized group membership
389-ds-base: 389-ds-base: starttls plaintext-buffer retention allows on-path attacker to forge an ldap client's authentication result
ClipBucket v5 through 5.5.3-#197 SQL Injection via ads_manager.php delete Parameter
Mooncake through 0.3.13.post1 Missing Authentication in HTTP Metadata Server
Mooncake transfer engine before 0.3.13 Unauthenticated Arbitrary Memory Read/Write via TCP Transport
Mooncake transfer engine through 0.3.13.post1 Memory Exhaustion via Unbounded Notify Queue
Mooncake transfer engine through 0.3.13.post1 Denial of Service via P2P Handshake Daemon Response Write
Office-PowerPoint-MCP-Server through 2.0.7 Path Traversal via save_presentation and manage_image
SConnect: Native Host Unauthenticated Remote Code Execution Vulnerability
389-ds-base: 389-ds-base: unauthenticated worker-thread-pool exhaustion via completed-operation-then-incomplete-pdu connection requeue
- Use of Hard-coded Credentials vulnerability in Johnson Controls EasyIO FG allows - Pasword Spraying. This issue affects EasyIO FG: before 2.0b52.
- Cleartext Transmission of Sensitive Information vulnerability in Johnson Controls EasyIO NEO allows - Man In the Middle Attack. This issue affects EasyIO NEO…
Showing 1 to 25 CVEs · page 1 (more available)