CVE Vulnerability Database

Search and browse 386,148 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-65464MEDIUM5.4Unauthenticated Cross Site Request Forgery (CSRF) in GiveWP <= 4.16.3 versions.
CVE-2026-65463MEDIUM5.4Subscriber Insecure Direct Object References (IDOR) in Masteriyo - LMS <= 2.3.1 versions.
CVE-2026-65462HIGH7.6Administrator SQL Injection in Uncanny Automator <= 7.3.2 versions.
CVE-2026-65461CRITICAL9.1Administrator Arbitrary File Upload in Really Simple CSV Importer <= 1.3 versions.
CVE-2026-65460MEDIUM4.3Unauthenticated Cross Site Request Forgery (CSRF) in Zarinpal Gateway <= 5.1.0 versions.
CVE-2026-65458MEDIUM4.3Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Chouby Polylang and Chouby P...
CVE-2026-65457MEDIUM4.3Subscriber Broken Access Control in ЮKassa для WooCommerce <= 2.16.1 versions.
CVE-2026-65456MEDIUM4.3Contributor Insecure Direct Object References (IDOR) in Product Slider for WooCommerce <= 1.13.62 versions.
CVE-2026-65455CRITICAL9.1Administrator Arbitrary File Upload in MapSVG <= 8.14.0 versions.
CVE-2026-65454HIGH8.5Contributor SQL Injection in Quiz And Survey Master <= 11.2.0 versions.
CVE-2026-65453MEDIUM5.3Unauthenticated Broken Access Control in Ebook Store <= 6.19 versions.
CVE-2026-65452MEDIUM5.3Unauthenticated Broken Access Control in Ebook Store <= 6.19 versions.
CVE-2026-65451HIGH8.5Contributor SQL Injection in MapSVG <= 8.14.0 versions.
CVE-2026-65450HIGH8.5Contributor SQL Injection in MapSVG <= 8.14.0 versions.
CVE-2026-65449MEDIUM6.5Contributor Cross Site Scripting (XSS) in MapSVG <= 8.14.0 versions.
CVE-2026-64815CRITICAL9.8In JetBrains IntelliJ IDEA before 2026.2 arbitrary code injection was possible via UI Designer form files
CVE-2026-64814HIGH8.6In JetBrains IntelliJ IDEA before 2026.2 unauthorized file access was possible in a Remote Development session
CVE-2026-64813CRITICAL10In JetBrains IntelliJ IDEA before 2026.2 unauthorized settings modification was possible in a Remote Development session
CVE-2026-64812CRITICAL10In JetBrains IntelliJ IDEA before 2026.2 unauthorized input injection was possible in a Remote Development session
CVE-2026-64811HIGH7.8In JetBrains IntelliJ IDEA before 2026.2 arbitrary code execution was possible before granting project trust via develop...
CVE-2026-64810MEDIUM6.1In JetBrains IntelliJ IDEA before 2026.2 hTML injection was possible in an IDE notification, allowing silent user activi...
CVE-2026-64809HIGH8.4In JetBrains PhpStorm before 2026.2 arbitrary code execution was possible before granting project trust via the configur...
CVE-2026-64808HIGH8.4In JetBrains PhpStorm before 2026.2 arbitrary code execution was possible before granting project trust via project tool...
CVE-2026-64807HIGH7.8In JetBrains WebStorm before 2026.2 arbitrary code execution was possible via a project-supplied linter configuration
CVE-2026-64806HIGH8.4In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via the configur...