SEPTEMBER 4, 2026
Live Feed
Vulnerability Register

CVE Database

Synced from NVD, cross-referenced against CISA KEV and EPSS · ordered by last update

368,781 records on file
Page 553 of 12,293
CVE ID Score Description
13d ago
5.3

Unauthenticated Broken Access Control in Kit (formerly ConvertKit) <= 3.3.5 versions.

13d ago
9.6

Unauthenticated Cross Site Request Forgery (CSRF) in Avada Core <= 5.15.6 versions.

13d ago
6.5

Contributor Cross Site Scripting (XSS) in Fluent Support <= 2.3.0 versions.

13d ago
5.3

Unauthenticated Broken Access Control in AWP Classifieds <= 4.4.7 versions.

13d ago
5.3

Unauthenticated Broken Access Control in JetBooking <= 4.1.2 versions.

13d ago
4.9

Contributor Server Side Request Forgery (SSRF) in JetEngine <= 3.8.11 versions.

13d ago
4.9

Custom role Server Side Request Forgery (SSRF) in JetBooking <= 4.1.2 versions.

13d ago
6.5

Contributor Cross Site Scripting (XSS) in JetElements For Elementor <= 2.9.1.1 versions.

13d ago
5.4

Unauthenticated Cross Site Request Forgery (CSRF) in GiveWP <= 4.16.3 versions.

13d ago
5.4

Subscriber Insecure Direct Object References (IDOR) in Masteriyo - LMS <= 2.3.1 versions.

13d ago
7.6

Administrator SQL Injection in Uncanny Automator <= 7.3.2 versions.

13d ago
9.1

Administrator Arbitrary File Upload in Really Simple CSV Importer <= 1.3 versions.

13d ago
4.3

Unauthenticated Cross Site Request Forgery (CSRF) in Zarinpal Gateway <= 5.1.0 versions.

13d ago
4.3

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Chouby Polylang and Chouby Polylang Pro allows Retrieve Embedded Sensitive Data. This issue affects Polylang: through 3.8.5; Polylang Pro: through 3.8.5.

13d ago
4.3

Subscriber Broken Access Control in ЮKassa для WooCommerce <= 2.16.1 versions.

13d ago
4.3

Contributor Insecure Direct Object References (IDOR) in Product Slider for WooCommerce <= 1.13.62 versions.

13d ago
9.1

Administrator Arbitrary File Upload in MapSVG <= 8.14.0 versions.

13d ago
8.5

Contributor SQL Injection in Quiz And Survey Master <= 11.2.0 versions.

13d ago
5.3

Unauthenticated Broken Access Control in Ebook Store <= 6.19 versions.

13d ago
5.3

Unauthenticated Broken Access Control in Ebook Store <= 6.19 versions.

13d ago
8.5

Contributor SQL Injection in MapSVG <= 8.14.0 versions.

13d ago
8.5

Contributor SQL Injection in MapSVG <= 8.14.0 versions.

13d ago
6.5

Contributor Cross Site Scripting (XSS) in MapSVG <= 8.14.0 versions.

13d ago
8.1

In JetBrains IntelliJ IDEA before 2026.2 arbitrary code injection was possible via UI Designer form files

13d ago
8.6

In JetBrains IntelliJ IDEA before 2026.2 unauthorized file access was possible in a Remote Development session

13d ago
10

In JetBrains IntelliJ IDEA before 2026.2 unauthorized settings modification was possible in a Remote Development session

13d ago
10

In JetBrains IntelliJ IDEA before 2026.2 unauthorized input injection was possible in a Remote Development session

Exploit 13d ago
7.8

In JetBrains IntelliJ IDEA before 2026.2 arbitrary code execution was possible before granting project trust via development container configuration

13d ago
4.3

In JetBrains IntelliJ IDEA before 2026.2 hTML injection was possible in an IDE notification, allowing silent user activity tracking

Exploit 13d ago
8.4

In JetBrains PhpStorm before 2026.2 arbitrary code execution was possible before granting project trust via the configured interpreter