Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 5.3
CVE-2026-65469
Unauthenticated Broken Access Control in AWP Classifieds <= 4.4.7 versions.
No fix yet
MEDIUM 5.3
CVE-2026-65468
Unauthenticated Broken Access Control in JetBooking <= 4.1.2 versions.
No fix yet
MEDIUM 6.5
CVE-2026-65465
Contributor Cross Site Scripting (XSS) in JetElements For Elementor <= 2.9.1.1 versions.
No fix yet
MEDIUM 5.4
CVE-2026-65464
Unauthenticated Cross Site Request Forgery (CSRF) in GiveWP <= 4.16.3 versions.
No fix yet
MEDIUM 5.4
CVE-2026-65463
Subscriber Insecure Direct Object References (IDOR) in Masteriyo - LMS <= 2.3.1 versions.
No fix yet
HIGH 7.6
CVE-2026-65462
Administrator SQL Injection in Uncanny Automator <= 7.3.2 versions.
No fix yet
CRITICAL 9.1
CVE-2026-65461
Administrator Arbitrary File Upload in Really Simple CSV Importer <= 1.3 versions.
Mitigation only
CRITICAL 9.1
CVE-2026-65455
Administrator Arbitrary File Upload in MapSVG <= 8.14.0 versions.
No fix yet
HIGH 8.5
CVE-2026-65454
Contributor SQL Injection in Quiz And Survey Master <= 11.2.0 versions.
No fix yet
MEDIUM 5.3
CVE-2026-65453
Unauthenticated Broken Access Control in Ebook Store <= 6.19 versions.
No fix yet
MEDIUM 5.3
CVE-2026-65452
Unauthenticated Broken Access Control in Ebook Store <= 6.19 versions.
No fix yet
HIGH 8.5
CVE-2026-65451
Contributor SQL Injection in MapSVG <= 8.14.0 versions.
No fix yet
HIGH 8.5
CVE-2026-65450
Contributor SQL Injection in MapSVG <= 8.14.0 versions.
No fix yet
MEDIUM 6.5
CVE-2026-65449
Contributor Cross Site Scripting (XSS) in MapSVG <= 8.14.0 versions.
No fix yet
CRITICAL 9.8
CVE-2026-64815
In JetBrains IntelliJ IDEA before 2026.2 arbitrary code injection was possible via UI Designer form files
Intellij Idea
2026.2+
HIGH 8.6
CVE-2026-64814
In JetBrains IntelliJ IDEA before 2026.2 unauthorized file access was possible in a Remote Development session
Intellij Idea
2026.2+
MEDIUM 6.1
CVE-2026-64810
In JetBrains IntelliJ IDEA before 2026.2 hTML injection was possible in an IDE notification, allowing silent user activity tracking
Intellij Idea
2026.2+
CRITICAL 10.0
CVE-2026-64813
In JetBrains IntelliJ IDEA before 2026.2 unauthorized settings modification was possible in a Remote Development session
Intellij Idea
2026.2+
CRITICAL 10.0
CVE-2026-64812
In JetBrains IntelliJ IDEA before 2026.2 unauthorized input injection was possible in a Remote Development session
Intellij Idea
2026.2+
HIGH 7.8
CVE-2026-64811
In JetBrains IntelliJ IDEA before 2026.2 arbitrary code execution was possible before granting project trust via development container configuration
Intellij Idea
2026.2+
HIGH 8.4
CVE-2026-64809
In JetBrains PhpStorm before 2026.2 arbitrary code execution was possible before granting project trust via the configured interpreter
Phpstorm
2026.2.0+
HIGH 8.4
CVE-2026-64808
In JetBrains PhpStorm before 2026.2 arbitrary code execution was possible before granting project trust via project tooling
Phpstorm
2026.2.0+
HIGH 7.8
CVE-2026-64807
In JetBrains WebStorm before 2026.2 arbitrary code execution was possible via a project-supplied linter configuration
Webstorm
2026.2.0+
HIGH 8.4
CVE-2026-64806
In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via the configured Node.js interpreter
Webstorm
2026.2.0+
MEDIUM 5.7
CVE-2026-64800
In JetBrains GoLand before 2026.2 sensitive configuration values written to log files by default
Goland
2026.2+
HIGH 8.4
CVE-2026-64805
In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via project-local package-manager tooling
Webstorm
2026.2.0+
HIGH 8.4
CVE-2026-64804
In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via project-local linter tooling
Webstorm
2026.2.0+
HIGH 7.8
CVE-2026-64803
In JetBrains GoLand before 2026.2 arbitrary code execution was possible before granting project trust via the configured Go SDK
Goland
2026.2+
HIGH 7.8
CVE-2026-64802
In JetBrains GoLand before 2026.2 arbitrary code execution was possible before granting project trust in the Go Modules integration
Goland
2026.2+
MEDIUM 5.4
CVE-2026-61981
Unauthenticated Cross Site Request Forgery (CSRF) in Simple Link Directory Pro <= 15.0.8 versions.
No fix yet