Browse CVEs

225 CVEs analyzed. 718 pending.

All Critical High Medium Low
CVE-2021-47918 8.1

Simple CMS 2.1 contains a remote SQL injection vulnerability in the users module that allows authenticated attackers to execute arbitrary SQL commands...

Feb 1, 2026
CVE-2021-47919 6.4

Simple CMS 2.1 contains a reflected cross-site scripting vulnerability in the preview.php file's id parameter. Attackers can craft malicious URLs cont...

Feb 1, 2026
CVE-2021-47920 5.4

WebMO Job Manager 20.0 contains a reflected cross-site scripting vulnerability in search parameters that allows attackers to inject malicious JavaScri...

Feb 1, 2026
CVE-2021-47921 6.5

Free Photo & Video Vault 0.0.2 contains a directory traversal vulnerability that allows remote attackers to manipulate web requests and access sensiti...

Feb 1, 2026
CVE-2022-50797 6.4

The Stripe Green Downloads WordPress plugin version 2.03 contains a persistent cross-site scripting (XSS) vulnerability in button label fields. Attack...

Feb 1, 2026
CVE-2021-47911 5.4

Affiliate Pro 1.7 contains reflected cross-site scripting vulnerabilities in index module input fields (fullname, username, email). Attackers can inje...

Feb 1, 2026
CVE-2021-47912 6.4

PHP Melody 3.0 contains multiple non-persistent cross-site scripting vulnerabilities in categories, import, and user import files. Attackers can injec...

Feb 1, 2026
CVE-2021-47913 6.4

PHP Melody 3.0 contains a persistent cross-site scripting vulnerability in the video editor's WYSIWYG component. Privileged users can inject malicious...

Feb 1, 2026
CVE-2021-47914 6.4

PHP Melody 3.0 contains a persistent cross-site scripting vulnerability in the edit-video.php submitted parameter that allows remote attackers to inje...

Feb 1, 2026
CVE-2021-47915 8.1

PHP Melody 3.0 contains a remote SQL injection vulnerability in the video edit module that allows authenticated attackers to execute arbitrary SQL com...

Feb 1, 2026
CVE-2021-47916 N/A

This CVE ID has been rejected or withdrawn by its CVE Numbering Authority, meaning it does not represent a valid security vulnerability. No systems ar...

Feb 1, 2026
CVE-2021-47856 6.4

Easy Cart Shopping Cart 2021 contains a non-persistent cross-site scripting vulnerability in the search module's keyword parameter. Remote attackers c...

Feb 1, 2026
CVE-2021-47885 6.4

Multiple payment terminal versions contain non-persistent cross-site scripting (XSS) vulnerabilities in billing and payment information input fields. ...

Feb 1, 2026
CVE-2021-47908 6.4

Ultimate POS 4.4 contains a persistent cross-site scripting vulnerability in the product name parameter that allows attackers to inject malicious scri...

Feb 1, 2026
CVE-2021-47909 8.1

Mult-E-Cart Ultimate 2.4 contains SQL injection vulnerabilities in multiple modules (inventory, customer, vendor, order) where attackers with vendor o...

Feb 1, 2026
CVE-2026-25069 N/A

SunFounder Pironman Dashboard versions 1.3.13 and earlier contain an unauthenticated path traversal vulnerability in log file API endpoints. Attackers...

Feb 1, 2026
CVE-2025-50537 5.5

A stack overflow vulnerability in ESLint versions before 9.26.0 allows denial of service when processing test cases with circular references. This aff...

Jan 26, 2026
CVE-2025-48782 9.8

This vulnerability allows remote attackers to upload malicious files to the Soar Cloud HRD Human Resource Management System, which can lead to arbitra...

Jun 6, 2025
CVE-2025-48783 7.5

This vulnerability allows remote attackers to delete arbitrary files on the Soar Cloud HRD Human Resource Management System by manipulating file paths...

Jun 6, 2025
CVE-2025-48784 7.5

A missing authorization vulnerability in Soar Cloud HRD Human Resource Management System allows remote attackers to modify system settings without pro...

Jun 6, 2025
CVE-2025-5192 7.5

This vulnerability allows remote attackers to bypass authentication in Soar Cloud HRD Human Resource Management System client applications. Attackers ...

Jun 6, 2025
CVE-2025-48781 7.5

This vulnerability allows remote attackers to read arbitrary files from the Soar Cloud HRD Human Resource Management System by manipulating file paths...

Jun 6, 2025
CVE-2025-48780 9.8

A critical deserialization vulnerability in Soar Cloud HRD Human Resource Management System allows remote attackers to execute arbitrary system comman...

Jun 6, 2025
CVE-2024-35280 5.4

This vulnerability allows attackers to perform reflected cross-site scripting (XSS) attacks against FortiDeceptor recovery endpoints. Attackers can in...

Jan 15, 2025
CVE-2024-45326 4.3

An authenticated attacker with no privileges can perform unauthorized operations on FortiDeceptor central management appliances by sending crafted req...

Jan 14, 2025