SEPTEMBER 20, 2026
Live Feed
Vulnerability Register

CVE Database

Synced from NVD, cross-referenced against CISA KEV and EPSS · ordered by last update

148,122 records on file
Page 359 of 4,938
CVE ID Score Description
29d ago
7.5

Contributor Local File Inclusion in Vino <= 1.9 versions.

29d ago
7.5

Contributor Local File Inclusion in Tonda Core <= 2.1.2 versions.

29d ago
7.6

Administrator SQL Injection in Uncanny Automator <= 7.3.2 versions.

29d ago
8.5

Contributor SQL Injection in Quiz And Survey Master <= 11.2.0 versions.

29d ago
8.5

Contributor SQL Injection in MapSVG <= 8.14.0 versions.

29d ago
8.5

Contributor SQL Injection in MapSVG <= 8.14.0 versions.

29d ago
8.1

In JetBrains IntelliJ IDEA before 2026.2 arbitrary code injection was possible via UI Designer form files

29d ago
8.6

In JetBrains IntelliJ IDEA before 2026.2 unauthorized file access was possible in a Remote Development session

Exploit 29d ago
7.8

In JetBrains IntelliJ IDEA before 2026.2 arbitrary code execution was possible before granting project trust via development container configuration

Exploit 29d ago
8.4

In JetBrains PhpStorm before 2026.2 arbitrary code execution was possible before granting project trust via the configured interpreter

Exploit 29d ago
8.4

In JetBrains PhpStorm before 2026.2 arbitrary code execution was possible before granting project trust via project tooling

Exploit 29d ago
7.8

In JetBrains WebStorm before 2026.2 arbitrary code execution was possible via a project-supplied linter configuration

Exploit 29d ago
8.4

In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via the configured Node.js interpreter

Exploit 29d ago
8.4

In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via project-local package-manager tooling

Exploit 29d ago
8.4

In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via project-local linter tooling

Exploit 29d ago
7.8

In JetBrains GoLand before 2026.2 arbitrary code execution was possible before granting project trust via the configured Go SDK

Exploit 29d ago
7.8

In JetBrains GoLand before 2026.2 arbitrary code execution was possible before granting project trust in the Go Modules integration

29d ago
7.5

Unauthenticated Broken Access Control in PayU India <= 3.8.9 versions.

29d ago
7.1

Unauthenticated Cross Site Scripting (XSS) in Form Vibes – Database Manager for Forms <= 1.5.2 versions.

29d ago
7.1

Unauthenticated Cross Site Scripting (XSS) in Bookly <= 27.7 versions.

29d ago
7.5

Unauthenticated Broken Access Control in WPDM – Premium Packages <= 6.2.0 versions.

29d ago
7.5

Unauthenticated Broken Authentication in Ziina <= 1.2.21 versions.

29d ago
7.5

Unauthenticated Broken Access Control in Payment Gateway for PayPal on WooCommerce <= 9.1.4 versions.

29d ago
8.1

Unauthenticated Broken Authentication in miniOrange Discord Integration <= 2.2.4 versions.

29d ago
7.7

Subscriber Arbitrary File Deletion in Kali Forms <= 2.4.18 versions.

29d ago
8.8

Subscriber Privilege Escalation in WP BASE Booking <= 6.3.1 versions.

29d ago
7.1

Unauthenticated Cross Site Scripting (XSS) in Easy Form Builder <= 4.0.12 versions.

29d ago
7.1

Unauthenticated Cross Site Scripting (XSS) in Product Enquiry for WooCommerce <= 2.2.34.43 versions.

29d ago
7.1

Unauthenticated Cross Site Scripting (XSS) in AffiliateWP <= 2.34.0 versions.

29d ago
8.8

Unauthenticated Cross Site Request Forgery (CSRF) in ApusListing <= 1.2.63 versions.