Vulnerability index

Browse CVEs

10,000+ matching
Filters
Severity

Filters apply as you choose them.

Unclassified MEDIUM 5.3
CVE-2026-65469

Unauthenticated Broken Access Control in AWP Classifieds <= 4.4.7 versions.

No fix yet
Fix from $1,600 2026-07-23
Unclassified MEDIUM 5.3
CVE-2026-65468

Unauthenticated Broken Access Control in JetBooking <= 4.1.2 versions.

No fix yet
Fix from $1,600 2026-07-23
Unclassified MEDIUM 6.5
CVE-2026-65465

Contributor Cross Site Scripting (XSS) in JetElements For Elementor <= 2.9.1.1 versions.

No fix yet
Fix from $1,600 2026-07-23
Unclassified MEDIUM 5.4
CVE-2026-65464

Unauthenticated Cross Site Request Forgery (CSRF) in GiveWP <= 4.16.3 versions.

No fix yet
Fix from $1,600 2026-07-23
Unclassified MEDIUM 5.4
CVE-2026-65463

Subscriber Insecure Direct Object References (IDOR) in Masteriyo - LMS <= 2.3.1 versions.

No fix yet
Fix from $1,600 2026-07-23
Unclassified HIGH 7.6
CVE-2026-65462

Administrator SQL Injection in Uncanny Automator <= 7.3.2 versions.

No fix yet
Fix from $1,950 2026-07-23
Unclassified CRITICAL 9.1
CVE-2026-65461

Administrator Arbitrary File Upload in Really Simple CSV Importer <= 1.3 versions.

Mitigation only
Fix from $2,300 2026-07-23
Unclassified CRITICAL 9.1
CVE-2026-65455

Administrator Arbitrary File Upload in MapSVG <= 8.14.0 versions.

No fix yet
Fix from $2,300 2026-07-23
Unclassified HIGH 8.5
CVE-2026-65454

Contributor SQL Injection in Quiz And Survey Master <= 11.2.0 versions.

No fix yet
Fix from $1,950 2026-07-23
Unclassified MEDIUM 5.3
CVE-2026-65453

Unauthenticated Broken Access Control in Ebook Store <= 6.19 versions.

No fix yet
Fix from $1,600 2026-07-23
Unclassified MEDIUM 5.3
CVE-2026-65452

Unauthenticated Broken Access Control in Ebook Store <= 6.19 versions.

No fix yet
Fix from $1,600 2026-07-23
Unclassified HIGH 8.5
CVE-2026-65451

Contributor SQL Injection in MapSVG <= 8.14.0 versions.

No fix yet
Fix from $1,950 2026-07-23
Unclassified HIGH 8.5
CVE-2026-65450

Contributor SQL Injection in MapSVG <= 8.14.0 versions.

No fix yet
Fix from $1,950 2026-07-23
Unclassified MEDIUM 6.5
CVE-2026-65449

Contributor Cross Site Scripting (XSS) in MapSVG <= 8.14.0 versions.

No fix yet
Fix from $1,600 2026-07-23
Intellij Idea CRITICAL 9.8
CVE-2026-64815

In JetBrains IntelliJ IDEA before 2026.2 arbitrary code injection was possible via UI Designer form files

Fix: 2026.2+
Fix from $2,300 2026-07-23
Intellij Idea HIGH 8.6
CVE-2026-64814

In JetBrains IntelliJ IDEA before 2026.2 unauthorized file access was possible in a Remote Development session

Fix: 2026.2+
Fix from $1,950 2026-07-23
Intellij Idea MEDIUM 6.1
CVE-2026-64810

In JetBrains IntelliJ IDEA before 2026.2 hTML injection was possible in an IDE notification, allowing silent user activity tracking

Fix: 2026.2+
Fix from $1,600 2026-07-23
Intellij Idea CRITICAL 10.0
CVE-2026-64813

In JetBrains IntelliJ IDEA before 2026.2 unauthorized settings modification was possible in a Remote Development session

Fix: 2026.2+
Fix from $2,300 2026-07-23
Intellij Idea CRITICAL 10.0
CVE-2026-64812

In JetBrains IntelliJ IDEA before 2026.2 unauthorized input injection was possible in a Remote Development session

Fix: 2026.2+
Fix from $2,300 2026-07-23
Intellij Idea HIGH 7.8
CVE-2026-64811

In JetBrains IntelliJ IDEA before 2026.2 arbitrary code execution was possible before granting project trust via development container configuration

Fix: 2026.2+
Fix from $1,950 2026-07-23
Phpstorm HIGH 8.4
CVE-2026-64809

In JetBrains PhpStorm before 2026.2 arbitrary code execution was possible before granting project trust via the configured interpreter

Fix: 2026.2.0+
Fix from $1,950 2026-07-23
Phpstorm HIGH 8.4
CVE-2026-64808

In JetBrains PhpStorm before 2026.2 arbitrary code execution was possible before granting project trust via project tooling

Fix: 2026.2.0+
Fix from $1,950 2026-07-23
Webstorm HIGH 7.8
CVE-2026-64807

In JetBrains WebStorm before 2026.2 arbitrary code execution was possible via a project-supplied linter configuration

Fix: 2026.2.0+
Fix from $1,950 2026-07-23
Webstorm HIGH 8.4
CVE-2026-64806

In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via the configured Node.js interpreter

Fix: 2026.2.0+
Fix from $1,950 2026-07-23
Goland MEDIUM 5.7
CVE-2026-64800

In JetBrains GoLand before 2026.2 sensitive configuration values written to log files by default

Fix: 2026.2+
Fix from $1,600 2026-07-23
Webstorm HIGH 8.4
CVE-2026-64805

In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via project-local package-manager tooling

Fix: 2026.2.0+
Fix from $1,950 2026-07-23
Webstorm HIGH 8.4
CVE-2026-64804

In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via project-local linter tooling

Fix: 2026.2.0+
Fix from $1,950 2026-07-23
Goland HIGH 7.8
CVE-2026-64803

In JetBrains GoLand before 2026.2 arbitrary code execution was possible before granting project trust via the configured Go SDK

Fix: 2026.2+
Fix from $1,950 2026-07-23
Goland HIGH 7.8
CVE-2026-64802

In JetBrains GoLand before 2026.2 arbitrary code execution was possible before granting project trust in the Go Modules integration

Fix: 2026.2+
Fix from $1,950 2026-07-23
Unclassified MEDIUM 5.4
CVE-2026-61981

Unauthenticated Cross Site Request Forgery (CSRF) in Simple Link Directory Pro <= 15.0.8 versions.

No fix yet
Fix from $1,600 2026-07-23