SEPTEMBER 5, 2026
Live Feed
Vulnerability Register

CVE Database

Synced from NVD, cross-referenced against CISA KEV and EPSS · ordered by last update

369,240 records on file
Page 569 of 12,308
CVE ID Score Description
13d ago
8.5

Contributor SQL Injection in MapSVG <= 8.14.0 versions.

13d ago
6.5

Contributor Cross Site Scripting (XSS) in MapSVG <= 8.14.0 versions.

13d ago
8.1

In JetBrains IntelliJ IDEA before 2026.2 arbitrary code injection was possible via UI Designer form files

13d ago
8.6

In JetBrains IntelliJ IDEA before 2026.2 unauthorized file access was possible in a Remote Development session

13d ago
10

In JetBrains IntelliJ IDEA before 2026.2 unauthorized settings modification was possible in a Remote Development session

13d ago
10

In JetBrains IntelliJ IDEA before 2026.2 unauthorized input injection was possible in a Remote Development session

Exploit 13d ago
7.8

In JetBrains IntelliJ IDEA before 2026.2 arbitrary code execution was possible before granting project trust via development container configuration

13d ago
4.3

In JetBrains IntelliJ IDEA before 2026.2 hTML injection was possible in an IDE notification, allowing silent user activity tracking

Exploit 13d ago
8.4

In JetBrains PhpStorm before 2026.2 arbitrary code execution was possible before granting project trust via the configured interpreter

Exploit 13d ago
8.4

In JetBrains PhpStorm before 2026.2 arbitrary code execution was possible before granting project trust via project tooling

Exploit 13d ago
7.8

In JetBrains WebStorm before 2026.2 arbitrary code execution was possible via a project-supplied linter configuration

Exploit 13d ago
8.4

In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via the configured Node.js interpreter

Exploit 13d ago
8.4

In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via project-local package-manager tooling

Exploit 13d ago
8.4

In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via project-local linter tooling

Exploit 13d ago
7.8

In JetBrains GoLand before 2026.2 arbitrary code execution was possible before granting project trust via the configured Go SDK

Exploit 13d ago
7.8

In JetBrains GoLand before 2026.2 arbitrary code execution was possible before granting project trust in the Go Modules integration

13d ago
3.5

In JetBrains GoLand before 2026.2 sensitive configuration values written to log files by default

13d ago
5.4

Unauthenticated Cross Site Request Forgery (CSRF) in Simple Link Directory Pro <= 15.0.8 versions.

13d ago
4.3

Subscriber Broken Access Control in ShopLentor Pro <= 2.8.5 versions.

13d ago
5.3

Unauthenticated Broken Access Control in ShopLentor Pro <= 2.8.5 versions.

13d ago
7.5

Unauthenticated Broken Access Control in PayU India <= 3.8.9 versions.

13d ago
9.8

Unauthenticated Privilege Escalation in TrueBooker <= 1.2.3 versions.

13d ago
9.3

Unauthenticated SQL Injection in TrueBooker <= 1.2.3 versions.

13d ago
9.3

Unauthenticated SQL Injection in Bookly <= 27.7 versions.

13d ago
9.3

Unauthenticated SQL Injection in WPDM – Premium Packages <= 6.2.0 versions.

13d ago
7.1

Unauthenticated Cross Site Scripting (XSS) in Form Vibes – Database Manager for Forms <= 1.5.2 versions.

13d ago
6.5

Unauthenticated Insecure Direct Object References (IDOR) in Easy Appointments <= 3.12.27 versions.

13d ago
6.5

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in MultiVendorX WooCommerce Product Stock Alert allows Retrieve Embedded Sensitive Data. This issue affects WooCommerce Product Stock Alert: from n/a through 3.0.6.

13d ago
7.1

Unauthenticated Cross Site Scripting (XSS) in Bookly <= 27.7 versions.

13d ago
7.5

Unauthenticated Broken Access Control in WPDM – Premium Packages <= 6.2.0 versions.