45572+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.
In JetBrains IntelliJ IDEA before 2026.2 arbitrary code execution was possible before granting project trust via development container configuration
In JetBrains PhpStorm before 2026.2 arbitrary code execution was possible before granting project trust via the configured interpreter
In JetBrains PhpStorm before 2026.2 arbitrary code execution was possible before granting project trust via project tooling
In JetBrains WebStorm before 2026.2 arbitrary code execution was possible via a project-supplied linter configuration
In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via the configured Node.js interpreter
In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via project-local package-manager tooling
In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via project-local linter tooling
In JetBrains GoLand before 2026.2 arbitrary code execution was possible before granting project trust via the configured Go SDK
In JetBrains GoLand before 2026.2 arbitrary code execution was possible before granting project trust in the Go Modules integration
Unauthenticated Broken Access Control in PayU India <= 3.8.9 versions.
Unauthenticated Cross Site Scripting (XSS) in Form Vibes – Database Manager for Forms <= 1.5.2 versions.
Unauthenticated Cross Site Scripting (XSS) in Bookly <= 27.7 versions.
Unauthenticated Broken Access Control in WPDM – Premium Packages <= 6.2.0 versions.
Unauthenticated Broken Authentication in Ziina <= 1.2.21 versions.
Unauthenticated Broken Access Control in Payment Gateway for PayPal on WooCommerce <= 9.1.4 versions.
Unauthenticated Broken Authentication in miniOrange Discord Integration <= 2.2.4 versions.
Subscriber Arbitrary File Deletion in Kali Forms <= 2.4.18 versions.
Subscriber Privilege Escalation in WP BASE Booking <= 6.3.1 versions.
Unauthenticated Cross Site Scripting (XSS) in Easy Form Builder <= 4.0.12 versions.
Unauthenticated Cross Site Scripting (XSS) in Product Enquiry for WooCommerce <= 2.2.34.43 versions.
Unauthenticated Cross Site Scripting (XSS) in AffiliateWP <= 2.34.0 versions.
Unauthenticated Cross Site Request Forgery (CSRF) in ApusListing <= 1.2.63 versions.
Unauthenticated Cross Site Scripting (XSS) in Grand Photography <= 5.7.8 versions.
Unauthenticated Cross Site Scripting (XSS) in WP Google Maps Pro <= 10.1.02 versions.
Unauthenticated Cross Site Scripting (XSS) in Breakdance <= 2.7.1 versions.
Unauthenticated Cross Site Scripting (XSS) in Smart Manager <= 8.90.0 versions.
Unauthenticated Cross Site Scripting (XSS) in Real Estate Manager Pro <= 12.8.5 versions.
Subscriber Cross Site Scripting (XSS) in Slider Pro <= 4.8.13 versions.
Contributor Arbitrary File Deletion in Picture Gallery <= 1.6.5 versions.
Cross-Site Request Forgery (CSRF) vulnerability in MailPoet allows Cross Site Request Forgery. This issue affects MailPoet: from 5.30.0 through 5.33.0.
Unauthenticated Cross Site Scripting (XSS) in Sprout Clients <= 3.2.3 versions.
Unauthenticated Cross Site Scripting (XSS) in Download Monitor - WPForms Lock <= 1.0.4 versions.
Unauthenticated Cross Site Scripting (XSS) in Coaching <= 3.9.2 versions.
Unauthenticated Cross Site Scripting (XSS) in Funnel Kit Funnel Builder PRO <= 3.15.0.7 versions.
Unauthenticated Cross Site Scripting (XSS) in Visitor Traffic Real Time Statistics Pro <= 11.9.1 versions.
Subscriber Broken Access Control in WP Booking System < 5.12.8.1 versions.
Contributor SQL Injection in eRoom <= 1.7.1 versions.
Contributor SQL Injection in Create by Mediavine <= 2.5.3 versions.
A flaw was found in libcupsfilters. The cfIEEE1284NormalizeMakeModel() function enters an infinite loop when processing a printer-advertised IEEE-1284 device ID with an empty model field, …
A flaw was found in odh-dashboard, the web console component of Red Hat OpenShift AI (RHOAI). Due to incorrect network binding, a malicious actor within …
Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in Modules Anywhere extension - The editor popup could expose restricted module data …
Joomla Extension - regularlabs.com - Date-sensitive query-cache leakage in Articles Anywhere and Users Anywhere extension - Date-sensitive query cache keys did not retain a bounded …
Joomla Extension - regularlabs.com - Insecure path handling in ReReplacer Pro extension - ReReplacer XML include paths could read files outside the site directory.
Joomla Extension - regularlabs.com - MaxMind Credential leakage in GeoIP extension - MaxMind credentials where leaked in request URLs, causing a credential leakage vulnerability.
Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in GeoIP extension - Database-update requests lacked consistent token and Super User checks, …
Joomla Extension - regularlabs.com - SSRF via remote image downloads in Articles Anywhere and Users Anywhere extensions - Content-controlled image URLs could request private or …
The MDJM Event Management plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.7.8.4. This is due to missing …
RRSIGs with too few labels can lead to bypass of DNSSEC wildcard validation
Improper neutralization of special elements used in an OS command ('OS command injection') vulnerability in TUBITAK BILGEM Software Technologies Research Institute pardus-update allows OS Command …
A missing authentication check in Bosch IP cameras of families CPP13 and CPP14 allows an unauthenticated attacker to retrieve video analytics event data.
Free website and port scanning — find vulnerabilities before attackers do.