CVE Database

121173+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-65473
6.5 MEDIUM

Contributor Cross Site Scripting (XSS) in Virtue/Ascend/Pinnacle Toolkit <= 4.9.12 versions.

Jul 23, 2026
CVE-2026-65472
5.3 MEDIUM

Unauthenticated Broken Access Control in Kit (formerly ConvertKit) <= 3.3.5 versions.

Jul 23, 2026
CVE-2026-65471
9.6 CRITICAL

Unauthenticated Cross Site Request Forgery (CSRF) in Avada Core <= 5.15.6 versions.

Jul 23, 2026
CVE-2026-65470
6.5 MEDIUM

Contributor Cross Site Scripting (XSS) in Fluent Support <= 2.3.0 versions.

Jul 23, 2026
CVE-2026-65469
5.3 MEDIUM

Unauthenticated Broken Access Control in AWP Classifieds <= 4.4.7 versions.

Jul 23, 2026
CVE-2026-65468
5.3 MEDIUM

Unauthenticated Broken Access Control in JetBooking <= 4.1.2 versions.

Jul 23, 2026
CVE-2026-65467
4.9 MEDIUM

Contributor Server Side Request Forgery (SSRF) in JetEngine <= 3.8.11 versions.

Jul 23, 2026
CVE-2026-65466
4.9 MEDIUM

Custom role Server Side Request Forgery (SSRF) in JetBooking <= 4.1.2 versions.

Jul 23, 2026
CVE-2026-65465
6.5 MEDIUM

Contributor Cross Site Scripting (XSS) in JetElements For Elementor <= 2.9.1.1 versions.

Jul 23, 2026
CVE-2026-65464
5.4 MEDIUM

Unauthenticated Cross Site Request Forgery (CSRF) in GiveWP <= 4.16.3 versions.

Jul 23, 2026
CVE-2026-65463
5.4 MEDIUM

Subscriber Insecure Direct Object References (IDOR) in Masteriyo - LMS <= 2.3.1 versions.

Jul 23, 2026
CVE-2026-65462
7.6 HIGH

Administrator SQL Injection in Uncanny Automator <= 7.3.2 versions.

Jul 23, 2026
CVE-2026-65461
9.1 CRITICAL

Administrator Arbitrary File Upload in Really Simple CSV Importer <= 1.3 versions.

Jul 23, 2026
CVE-2026-65460
4.3 MEDIUM

Unauthenticated Cross Site Request Forgery (CSRF) in Zarinpal Gateway <= 5.1.0 versions.

Jul 23, 2026
CVE-2026-65458
4.3 MEDIUM

Contributor Sensitive Data Exposure in Polylang <= 3.8.5 versions.

Jul 23, 2026
CVE-2026-65457
4.3 MEDIUM

Subscriber Broken Access Control in ЮKassa для WooCommerce <= 2.16.1 versions.

Jul 23, 2026
CVE-2026-65456
4.3 MEDIUM

Contributor Insecure Direct Object References (IDOR) in Product Slider for WooCommerce <= 1.13.62 versions.

Jul 23, 2026
CVE-2026-65455
9.1 CRITICAL

Administrator Arbitrary File Upload in MapSVG <= 8.14.0 versions.

Jul 23, 2026
CVE-2026-65454
8.5 HIGH

Contributor SQL Injection in Quiz And Survey Master <= 11.2.0 versions.

Jul 23, 2026
CVE-2026-65453
5.3 MEDIUM

Unauthenticated Broken Access Control in Ebook Store <= 6.19 versions.

Jul 23, 2026
CVE-2026-65452
5.3 MEDIUM

Unauthenticated Broken Access Control in Ebook Store <= 6.19 versions.

Jul 23, 2026
CVE-2026-65451
8.5 HIGH

Contributor SQL Injection in MapSVG <= 8.14.0 versions.

Jul 23, 2026
CVE-2026-65450
8.5 HIGH

Contributor SQL Injection in MapSVG <= 8.14.0 versions.

Jul 23, 2026
CVE-2026-65449
6.5 MEDIUM

Contributor Cross Site Scripting (XSS) in MapSVG <= 8.14.0 versions.

Jul 23, 2026
CVE-2026-64815
8.1 HIGH

In JetBrains IntelliJ IDEA before 2026.2 arbitrary code injection was possible via UI Designer form files

Jul 23, 2026
CVE-2026-64814
8.6 HIGH

In JetBrains IntelliJ IDEA before 2026.2 unauthorized file access was possible in a Remote Development session

Jul 23, 2026
CVE-2026-64813
10.0 CRITICAL

In JetBrains IntelliJ IDEA before 2026.2 unauthorized settings modification was possible in a Remote Development session

Jul 23, 2026
CVE-2026-64812
10.0 CRITICAL

In JetBrains IntelliJ IDEA before 2026.2 unauthorized input injection was possible in a Remote Development session

Jul 23, 2026
CVE-2026-64811
7.8 HIGH

In JetBrains IntelliJ IDEA before 2026.2 arbitrary code execution was possible before granting project trust via development container configuration

Jul 23, 2026
CVE-2026-64810
4.3 MEDIUM

In JetBrains IntelliJ IDEA before 2026.2 hTML injection was possible in an IDE notification, allowing silent user activity tracking

Jul 23, 2026
CVE-2026-64809
8.4 HIGH

In JetBrains PhpStorm before 2026.2 arbitrary code execution was possible before granting project trust via the configured interpreter

Jul 23, 2026
CVE-2026-64808
8.4 HIGH

In JetBrains PhpStorm before 2026.2 arbitrary code execution was possible before granting project trust via project tooling

Jul 23, 2026
CVE-2026-64807
7.8 HIGH

In JetBrains WebStorm before 2026.2 arbitrary code execution was possible via a project-supplied linter configuration

Jul 23, 2026
CVE-2026-64806
8.4 HIGH

In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via the configured Node.js interpreter

Jul 23, 2026
CVE-2026-64805
8.4 HIGH

In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via project-local package-manager tooling

Jul 23, 2026
CVE-2026-64804
8.4 HIGH

In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via project-local linter tooling

Jul 23, 2026
CVE-2026-64803
7.8 HIGH

In JetBrains GoLand before 2026.2 arbitrary code execution was possible before granting project trust via the configured Go SDK

Jul 23, 2026
CVE-2026-64802
7.8 HIGH

In JetBrains GoLand before 2026.2 arbitrary code execution was possible before granting project trust in the Go Modules integration

Jul 23, 2026
CVE-2026-64800
3.5 LOW

In JetBrains GoLand before 2026.2 sensitive configuration values written to log files by default

Jul 23, 2026
CVE-2026-61981
5.4 MEDIUM

Unauthenticated Cross Site Request Forgery (CSRF) in Simple Link Directory Pro <= 15.0.8 versions.

Jul 23, 2026
CVE-2026-61973
4.3 MEDIUM

Subscriber Broken Access Control in ShopLentor Pro <= 2.8.5 versions.

Jul 23, 2026
CVE-2026-61972
5.3 MEDIUM

Unauthenticated Broken Access Control in ShopLentor Pro <= 2.8.5 versions.

Jul 23, 2026
CVE-2026-61954
7.5 HIGH

Unauthenticated Broken Access Control in PayU India <= 3.8.9 versions.

Jul 23, 2026
CVE-2026-61951
9.8 CRITICAL

Unauthenticated Privilege Escalation in TrueBooker <= 1.2.3 versions.

Jul 23, 2026
CVE-2026-61950
9.3 CRITICAL

Unauthenticated SQL Injection in TrueBooker <= 1.2.3 versions.

Jul 23, 2026
CVE-2026-61949
9.3 CRITICAL

Unauthenticated SQL Injection in Bookly <= 27.7 versions.

Jul 23, 2026
CVE-2026-61948
9.3 CRITICAL

Unauthenticated SQL Injection in WPDM – Premium Packages <= 6.2.0 versions.

Jul 23, 2026
CVE-2026-61947
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in Form Vibes – Database Manager for Forms <= 1.5.2 versions.

Jul 23, 2026
CVE-2026-61946
6.5 MEDIUM

Unauthenticated Insecure Direct Object References (IDOR) in Easy Appointments <= 3.12.27 versions.

Jul 23, 2026
CVE-2026-61945
6.5 MEDIUM

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in MultiVendorX WooCommerce Product Stock Alert allows Retrieve Embedded Sensitive Data. This issue affects …

Jul 23, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.