CVE Vulnerability Database

Search and browse 386,148 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-64805HIGH8.4In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via project-loca...
CVE-2026-64804HIGH8.4In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via project-loca...
CVE-2026-64803HIGH7.8In JetBrains GoLand before 2026.2 arbitrary code execution was possible before granting project trust via the configured...
CVE-2026-64802HIGH7.8In JetBrains GoLand before 2026.2 arbitrary code execution was possible before granting project trust in the Go Modules ...
CVE-2026-64800MEDIUM5.7In JetBrains GoLand before 2026.2 sensitive configuration values written to log files by default
CVE-2026-61981MEDIUM5.4Unauthenticated Cross Site Request Forgery (CSRF) in Simple Link Directory Pro <= 15.0.8 versions.
CVE-2026-61973MEDIUM4.3Subscriber Broken Access Control in ShopLentor Pro <= 2.8.5 versions.
CVE-2026-61972MEDIUM5.3Unauthenticated Broken Access Control in ShopLentor Pro <= 2.8.5 versions.
CVE-2026-61954HIGH7.5Unauthenticated Broken Access Control in PayU India <= 3.8.9 versions.
CVE-2026-61951CRITICAL9.8Unauthenticated Privilege Escalation in TrueBooker <= 1.2.3 versions.
CVE-2026-61950CRITICAL9.3Unauthenticated SQL Injection in TrueBooker <= 1.2.3 versions.
CVE-2026-61949CRITICAL9.3Unauthenticated SQL Injection in Bookly <= 27.7 versions.
CVE-2026-61948CRITICAL9.3Unauthenticated SQL Injection in WPDM – Premium Packages <= 6.2.0 versions.
CVE-2026-61947HIGH7.1Unauthenticated Cross Site Scripting (XSS) in Form Vibes – Database Manager for Forms <= 1.5.2 versions.
CVE-2026-61946MEDIUM6.5Unauthenticated Insecure Direct Object References (IDOR) in Easy Appointments <= 3.12.27 versions.
CVE-2026-61945MEDIUM6.5Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in MultiVendorX WooCommerce Pro...
CVE-2026-61944HIGH7.1Unauthenticated Cross Site Scripting (XSS) in Bookly <= 27.7 versions.
CVE-2026-61943HIGH7.5Unauthenticated Broken Access Control in WPDM – Premium Packages <= 6.2.0 versions.
CVE-2026-59555CRITICAL10Unauthenticated Arbitrary File Deletion in Participants Database <= 2.7.8.3 versions.
CVE-2026-59554HIGH7.5Unauthenticated Broken Authentication in Ziina <= 1.2.21 versions.
CVE-2026-59547HIGH7.5Unauthenticated Broken Access Control in Payment Gateway for PayPal on WooCommerce <= 9.1.4 versions.
CVE-2026-59545HIGH8.1Unauthenticated Broken Authentication in miniOrange Discord Integration <= 2.2.4 versions.
CVE-2026-59544CRITICAL9.8Unauthenticated PHP Object Injection in Thrive Quiz Builder <= 10.9.3.0 versions.
CVE-2026-59543CRITICAL9.9Subscriber Remote Code Execution (RCE) in Advanced Views <= 3.8.11 versions.
CVE-2026-59542HIGH7.7Subscriber Arbitrary File Deletion in Kali Forms <= 2.4.18 versions.