SEPTEMBER 4, 2026
Live Feed
Vulnerability Register

CVE Database

Synced from NVD, cross-referenced against CISA KEV and EPSS · ordered by last update

368,781 records on file
Page 554 of 12,293
CVE ID Score Description
Exploit 13d ago
8.4

In JetBrains PhpStorm before 2026.2 arbitrary code execution was possible before granting project trust via project tooling

Exploit 13d ago
7.8

In JetBrains WebStorm before 2026.2 arbitrary code execution was possible via a project-supplied linter configuration

Exploit 13d ago
8.4

In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via the configured Node.js interpreter

Exploit 13d ago
8.4

In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via project-local package-manager tooling

Exploit 13d ago
8.4

In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via project-local linter tooling

Exploit 13d ago
7.8

In JetBrains GoLand before 2026.2 arbitrary code execution was possible before granting project trust via the configured Go SDK

Exploit 13d ago
7.8

In JetBrains GoLand before 2026.2 arbitrary code execution was possible before granting project trust in the Go Modules integration

13d ago
3.5

In JetBrains GoLand before 2026.2 sensitive configuration values written to log files by default

13d ago
5.4

Unauthenticated Cross Site Request Forgery (CSRF) in Simple Link Directory Pro <= 15.0.8 versions.

13d ago
4.3

Subscriber Broken Access Control in ShopLentor Pro <= 2.8.5 versions.

13d ago
5.3

Unauthenticated Broken Access Control in ShopLentor Pro <= 2.8.5 versions.

13d ago
7.5

Unauthenticated Broken Access Control in PayU India <= 3.8.9 versions.

13d ago
9.8

Unauthenticated Privilege Escalation in TrueBooker <= 1.2.3 versions.

13d ago
9.3

Unauthenticated SQL Injection in TrueBooker <= 1.2.3 versions.

13d ago
9.3

Unauthenticated SQL Injection in Bookly <= 27.7 versions.

13d ago
9.3

Unauthenticated SQL Injection in WPDM – Premium Packages <= 6.2.0 versions.

13d ago
7.1

Unauthenticated Cross Site Scripting (XSS) in Form Vibes – Database Manager for Forms <= 1.5.2 versions.

13d ago
6.5

Unauthenticated Insecure Direct Object References (IDOR) in Easy Appointments <= 3.12.27 versions.

13d ago
6.5

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in MultiVendorX WooCommerce Product Stock Alert allows Retrieve Embedded Sensitive Data. This issue affects WooCommerce Product Stock Alert: from n/a through 3.0.6.

13d ago
7.1

Unauthenticated Cross Site Scripting (XSS) in Bookly <= 27.7 versions.

13d ago
7.5

Unauthenticated Broken Access Control in WPDM – Premium Packages <= 6.2.0 versions.

13d ago
10

Unauthenticated Arbitrary File Deletion in Participants Database <= 2.7.8.3 versions.

13d ago
7.5

Unauthenticated Broken Authentication in Ziina <= 1.2.21 versions.

13d ago
7.5

Unauthenticated Broken Access Control in Payment Gateway for PayPal on WooCommerce <= 9.1.4 versions.

13d ago
8.1

Unauthenticated Broken Authentication in miniOrange Discord Integration <= 2.2.4 versions.

13d ago
9.8

Unauthenticated PHP Object Injection in Thrive Quiz Builder <= 10.9.3.0 versions.

Exploit 13d ago
9.9

Subscriber Remote Code Execution (RCE) in Advanced Views <= 3.8.11 versions.

13d ago
7.7

Subscriber Arbitrary File Deletion in Kali Forms <= 2.4.18 versions.

13d ago
8.8

Subscriber Privilege Escalation in WP BASE Booking <= 6.3.1 versions.

13d ago
9.8

Unauthenticated Privilege Escalation in SMS Alert Order Notifications <= 3.9.6 versions.