CVE search
369,363 resultsCVE-2026-14647MEDIUMonnx onnxruntime old.cc convPoolShapeInference_opset19 out-of-boundsEPSS 0.3%CVE-2026-14642MEDIUMSourceCodester Class and Exam Timetabling System edit_class2.php sql injectionEPSS 0.4%CVE-2026-14641MEDIUMSourceCodester Class and Exam Timetabling System edit_course.php sql injectionEPSS 0.4%CVE-2026-14640MEDIUMCodeAstro Apartment Visitor Management System Login index.php sql injectionEPSS 0.3%CVE-2026-14639MEDIUMCodeAstro Ecommerce Website my_account.php sql injectionEPSS 0.2%CVE-2026-12740HIGHPlack::Middleware::OAuth versions through 0.10 for Perl do not support the OAuth 2.0 state parameterEPSS 0.2%CVE-2026-12746HIGHDancer2::Plugin::Auth::OAuth::Provider versions before 0.23 for Perl do not support the OAuth 2.0 state parameterEPSS 0.2%CVE-2026-14638MEDIUMitsourcecode Hospital Management System patient.php sql injectionEPSS 0.2%CVE-2026-14637HIGHkirilkirkov Ecommerce-CodeIgniter-Bootstrap ShoppingCart.php getCartItems deserializationEPSS 0.6%CVE-2026-14636MEDIUMkirilkirkov Ecommerce-CodeIgniter-Bootstrap Vendor Image Manager AddProduct.php do_upload_others_images path traversalEPSS 0.3%CVE-2026-14635MEDIUMkirilkirkov Ecommerce-CodeIgniter-Bootstrap Vendor Multi-Image Endpoint AddProduct.php path traversalEPSS 0.4%CVE-2026-14634MEDIUMkirilkirkov Ecommerce-CodeIgniter-Bootstrap Subscribed Emails Admin MY_Controller.php checkForPostRequests cross site scriptingEPSS 0.3%CVE-2026-14633MEDIUMkirilkirkov Ecommerce-CodeIgniter-Bootstrap Hidden REST API Endpoint set cross site scriptingEPSS 0.3%CVE-2026-14632MEDIUMkirilkirkov Ecommerce-CodeIgniter-Bootstrap Trusted Backend MY_Controller.php setReferrer redirectEPSS 0.3%CVE-2026-14630LOWForceInjection AI-fundermentals Memory Recall smart_customer_service.py get_conversation_history weak hashEPSS 0.2%CVE-2026-14535HIGHFickling MLAllowlist analysis pass rendered inoperative by shared mutable state in AnalysisContext.shorten_code()EPSS 0.3%CVE-2026-14534HIGHFickling check_safety() bypass via unlisted standard library modules (_posixsubprocess, site, atexit)EPSS 0.3%CVE-2026-14629MEDIUMRT-Thread Parameter lwp_syscall.c sys_ioctl divide by zeroEPSS 0.3%CVE-2026-14628MEDIUMNousResearch hermes-agent Live Webhook Endpoint base.py extract_media path traversalEPSS 0.6%CVE-2025-13475LOWCross-Tenant Access via Application Consent Mismanagement in Multiple WSO2 Products Allows Unauthorized Data ExposureEPSS 0.2%