CVE Database

45572+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-64811
7.8 HIGH

In JetBrains IntelliJ IDEA before 2026.2 arbitrary code execution was possible before granting project trust via development container configuration

Jul 23, 2026
CVE-2026-64809
8.4 HIGH

In JetBrains PhpStorm before 2026.2 arbitrary code execution was possible before granting project trust via the configured interpreter

Jul 23, 2026
CVE-2026-64808
8.4 HIGH

In JetBrains PhpStorm before 2026.2 arbitrary code execution was possible before granting project trust via project tooling

Jul 23, 2026
CVE-2026-64807
7.8 HIGH

In JetBrains WebStorm before 2026.2 arbitrary code execution was possible via a project-supplied linter configuration

Jul 23, 2026
CVE-2026-64806
8.4 HIGH

In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via the configured Node.js interpreter

Jul 23, 2026
CVE-2026-64805
8.4 HIGH

In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via project-local package-manager tooling

Jul 23, 2026
CVE-2026-64804
8.4 HIGH

In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via project-local linter tooling

Jul 23, 2026
CVE-2026-64803
7.8 HIGH

In JetBrains GoLand before 2026.2 arbitrary code execution was possible before granting project trust via the configured Go SDK

Jul 23, 2026
CVE-2026-64802
7.8 HIGH

In JetBrains GoLand before 2026.2 arbitrary code execution was possible before granting project trust in the Go Modules integration

Jul 23, 2026
CVE-2026-61954
7.5 HIGH

Unauthenticated Broken Access Control in PayU India <= 3.8.9 versions.

Jul 23, 2026
CVE-2026-61947
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in Form Vibes – Database Manager for Forms <= 1.5.2 versions.

Jul 23, 2026
CVE-2026-61944
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in Bookly <= 27.7 versions.

Jul 23, 2026
CVE-2026-61943
7.5 HIGH

Unauthenticated Broken Access Control in WPDM – Premium Packages <= 6.2.0 versions.

Jul 23, 2026
CVE-2026-59554
7.5 HIGH

Unauthenticated Broken Authentication in Ziina <= 1.2.21 versions.

Jul 23, 2026
CVE-2026-59547
7.5 HIGH

Unauthenticated Broken Access Control in Payment Gateway for PayPal on WooCommerce <= 9.1.4 versions.

Jul 23, 2026
CVE-2026-59545
8.1 HIGH

Unauthenticated Broken Authentication in miniOrange Discord Integration <= 2.2.4 versions.

Jul 23, 2026
CVE-2026-59542
7.7 HIGH

Subscriber Arbitrary File Deletion in Kali Forms <= 2.4.18 versions.

Jul 23, 2026
CVE-2026-59541
8.8 HIGH

Subscriber Privilege Escalation in WP BASE Booking <= 6.3.1 versions.

Jul 23, 2026
CVE-2026-59517
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in Easy Form Builder <= 4.0.12 versions.

Jul 23, 2026
CVE-2026-59512
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in Product Enquiry for WooCommerce <= 2.2.34.43 versions.

Jul 23, 2026
CVE-2026-57809
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in AffiliateWP <= 2.34.0 versions.

Jul 23, 2026
CVE-2026-57785
8.8 HIGH

Unauthenticated Cross Site Request Forgery (CSRF) in ApusListing <= 1.2.63 versions.

Jul 23, 2026
CVE-2026-57769
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in Grand Photography <= 5.7.8 versions.

Jul 23, 2026
CVE-2026-57767
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in WP Google Maps Pro <= 10.1.02 versions.

Jul 23, 2026
CVE-2026-57735
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in Breakdance <= 2.7.1 versions.

Jul 23, 2026
CVE-2026-57704
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in Smart Manager <= 8.90.0 versions.

Jul 23, 2026
CVE-2026-57701
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in Real Estate Manager Pro <= 12.8.5 versions.

Jul 23, 2026
CVE-2026-57699
7.1 HIGH

Subscriber Cross Site Scripting (XSS) in Slider Pro <= 4.8.13 versions.

Jul 23, 2026
CVE-2026-57696
7.1 HIGH

Contributor Arbitrary File Deletion in Picture Gallery <= 1.6.5 versions.

Jul 23, 2026
CVE-2026-57626
7.1 HIGH

Cross-Site Request Forgery (CSRF) vulnerability in MailPoet allows Cross Site Request Forgery. This issue affects MailPoet: from 5.30.0 through 5.33.0.

Jul 23, 2026
CVE-2026-57428
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in Sprout Clients <= 3.2.3 versions.

Jul 23, 2026
CVE-2026-57427
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in Download Monitor - WPForms Lock <= 1.0.4 versions.

Jul 23, 2026
CVE-2026-57397
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in Coaching <= 3.9.2 versions.

Jul 23, 2026
CVE-2026-57374
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in Funnel Kit Funnel Builder PRO <= 3.15.0.7 versions.

Jul 23, 2026
CVE-2026-57370
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in Visitor Traffic Real Time Statistics Pro <= 11.9.1 versions.

Jul 23, 2026
CVE-2026-57367
7.1 HIGH

Subscriber Broken Access Control in WP Booking System < 5.12.8.1 versions.

Jul 23, 2026
CVE-2026-25405
8.5 HIGH

Contributor SQL Injection in eRoom <= 1.7.1 versions.

Jul 23, 2026
CVE-2026-24552
8.5 HIGH

Contributor SQL Injection in Create by Mediavine <= 2.5.3 versions.

Jul 23, 2026
CVE-2026-64611
7.5 HIGH

A flaw was found in libcupsfilters. The cfIEEE1284NormalizeMakeModel() function enters an infinite loop when processing a printer-advertised IEEE-1284 device ID with an empty model field, …

Jul 23, 2026
CVE-2026-16745
8.8 HIGH

A flaw was found in odh-dashboard, the web console component of Red Hat OpenShift AI (RHOAI). Due to incorrect network binding, a malicious actor within …

Jul 23, 2026
CVE-2026-65757
8.1 HIGH

Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in Modules Anywhere extension - The editor popup could expose restricted module data …

Jul 23, 2026
CVE-2026-65755
7.5 HIGH

Joomla Extension - regularlabs.com - Date-sensitive query-cache leakage in Articles Anywhere and Users Anywhere extension - Date-sensitive query cache keys did not retain a bounded …

Jul 23, 2026
CVE-2026-65754
7.5 HIGH

Joomla Extension - regularlabs.com - Insecure path handling in ReReplacer Pro extension - ReReplacer XML include paths could read files outside the site directory.

Jul 23, 2026
CVE-2026-65430
7.5 HIGH

Joomla Extension - regularlabs.com - MaxMind Credential leakage in GeoIP extension - MaxMind credentials where leaked in request URLs, causing a credential leakage vulnerability.

Jul 23, 2026
CVE-2026-64876
8.8 HIGH

Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in GeoIP extension - Database-update requests lacked consistent token and Super User checks, …

Jul 23, 2026
CVE-2026-64799
7.5 HIGH

Joomla Extension - regularlabs.com - SSRF via remote image downloads in Articles Anywhere and Users Anywhere extensions - Content-controlled image URLs could request private or …

Jul 23, 2026
CVE-2026-15017
8.8 HIGH

The MDJM Event Management plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.7.8.4. This is due to missing …

Jul 23, 2026
CVE-2026-52688
7.5 HIGH

RRSIGs with too few labels can lead to bypass of DNSSEC wildcard validation

Jul 23, 2026
CVE-2026-16287
7.8 HIGH

Improper neutralization of special elements used in an OS command ('OS command injection') vulnerability in TUBITAK BILGEM Software Technologies Research Institute pardus-update allows OS Command …

Jul 23, 2026
CVE-2024-58330
7.5 HIGH

A missing authentication check in Bosch IP cameras of families CPP13 and CPP14 allows an unauthenticated attacker to retrieve video analytics event data.

Jul 23, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.