CVE Browser
Search and filter CVEs by severity, ecosystem, EPSS score, and more.
Page 1
CVE-2026-14378 CRITICAL
DevKit Pro <= 2.3.0 - Unauthenticated Authentication Bypass to Administrator Account Takeover via 'original_user_id' Cookie in Frontend Revert Switch Flow
CVSS 9.8 EPSS n/a Oct 2, 2026
CVE-2026-14357 HIGH
DevKit Pro <= 2.3.0 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Theme Installation / Remote Code Execution via 'qqfile' Parameter
CVSS 8.8 EPSS 0.65% Sep 2, 2026
CVE-2021-24890 HIGH
Scripts Organizer < 3.0 - Unauthenticated Arbitrary File Upload
CVSS 8.8 EPSS 0.58% Sep 26, 2022
Showing 1 to 3 CVEs · page 1