2026 CVE Vulnerabilities

53,405 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-64815CRITICAL9.8In JetBrains IntelliJ IDEA before 2026.2 arbitrary code injection was possible via UI Designer form files
CVE-2026-64814HIGH8.6In JetBrains IntelliJ IDEA before 2026.2 unauthorized file access was possible in a Remote Development session
CVE-2026-64813CRITICAL10In JetBrains IntelliJ IDEA before 2026.2 unauthorized settings modification was possible in a Remote Development session
CVE-2026-64812CRITICAL10In JetBrains IntelliJ IDEA before 2026.2 unauthorized input injection was possible in a Remote Development session
CVE-2026-64811HIGH7.8In JetBrains IntelliJ IDEA before 2026.2 arbitrary code execution was possible before granting project trust via develop...
CVE-2026-64810MEDIUM6.1In JetBrains IntelliJ IDEA before 2026.2 hTML injection was possible in an IDE notification, allowing silent user activi...
CVE-2026-64809HIGH8.4In JetBrains PhpStorm before 2026.2 arbitrary code execution was possible before granting project trust via the configur...
CVE-2026-64808HIGH8.4In JetBrains PhpStorm before 2026.2 arbitrary code execution was possible before granting project trust via project tool...
CVE-2026-64807HIGH7.8In JetBrains WebStorm before 2026.2 arbitrary code execution was possible via a project-supplied linter configuration
CVE-2026-64806HIGH8.4In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via the configur...
CVE-2026-64805HIGH8.4In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via project-loca...
CVE-2026-64804HIGH8.4In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via project-loca...
CVE-2026-64803HIGH7.8In JetBrains GoLand before 2026.2 arbitrary code execution was possible before granting project trust via the configured...
CVE-2026-64802HIGH7.8In JetBrains GoLand before 2026.2 arbitrary code execution was possible before granting project trust in the Go Modules ...
CVE-2026-64800MEDIUM5.7In JetBrains GoLand before 2026.2 sensitive configuration values written to log files by default
CVE-2026-61981MEDIUM5.4Unauthenticated Cross Site Request Forgery (CSRF) in Simple Link Directory Pro <= 15.0.8 versions.
CVE-2026-61973MEDIUM4.3Subscriber Broken Access Control in ShopLentor Pro <= 2.8.5 versions.
CVE-2026-61972MEDIUM5.3Unauthenticated Broken Access Control in ShopLentor Pro <= 2.8.5 versions.
CVE-2026-61954HIGH7.5Unauthenticated Broken Access Control in PayU India <= 3.8.9 versions.
CVE-2026-61951CRITICAL9.8Unauthenticated Privilege Escalation in TrueBooker <= 1.2.3 versions.
CVE-2026-61950CRITICAL9.3Unauthenticated SQL Injection in TrueBooker <= 1.2.3 versions.
CVE-2026-61949CRITICAL9.3Unauthenticated SQL Injection in Bookly <= 27.7 versions.
CVE-2026-61948CRITICAL9.3Unauthenticated SQL Injection in WPDM – Premium Packages <= 6.2.0 versions.
CVE-2026-61947HIGH7.1Unauthenticated Cross Site Scripting (XSS) in Form Vibes – Database Manager for Forms <= 1.5.2 versions.
CVE-2026-61946MEDIUM6.5Unauthenticated Insecure Direct Object References (IDOR) in Easy Appointments <= 3.12.27 versions.

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now