Total CVEs

150,920

Critical Severity

5,034

High Severity

17,670

Last 7 Days

2,106
Quick preset (or use dates below)
Clear Filters
Showing 2,361 - 2,380 of 150,920 CVEs
CVE-2026-64812 CRITICAL - 10.0

In JetBrains IntelliJ IDEA before 2026.2 unauthorized input injection was possible in a Remote Development session

Vendor: JetBrains
Product: IntelliJ IDEA
Published: Jul 23, 2026
Source: NVD
CVE-2026-64811 HIGH - 7.8

In JetBrains IntelliJ IDEA before 2026.2 arbitrary code execution was possible before granting project trust via development container configuration

Vendor: JetBrains
Product: IntelliJ IDEA
Published: Jul 23, 2026
Source: NVD
CVE-2026-64810 MEDIUM - 4.3

In JetBrains IntelliJ IDEA before 2026.2 hTML injection was possible in an IDE notification, allowing silent user activity tracking

Vendor: JetBrains
Product: IntelliJ IDEA
Published: Jul 23, 2026
Source: NVD
CVE-2026-64809 HIGH - 8.4

In JetBrains PhpStorm before 2026.2 arbitrary code execution was possible before granting project trust via the configured interpreter

Vendor: JetBrains
Product: PhpStorm
Published: Jul 23, 2026
Source: NVD
CVE-2026-64808 HIGH - 8.4

In JetBrains PhpStorm before 2026.2 arbitrary code execution was possible before granting project trust via project tooling

Vendor: JetBrains
Product: PhpStorm
Published: Jul 23, 2026
Source: NVD
CVE-2026-64807 HIGH - 7.8

In JetBrains WebStorm before 2026.2 arbitrary code execution was possible via a project-supplied linter configuration

Vendor: JetBrains
Product: WebStorm
Published: Jul 23, 2026
Source: NVD
CVE-2026-64806 HIGH - 8.4

In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via the configured Node.js interpreter

Vendor: JetBrains
Product: WebStorm
Published: Jul 23, 2026
Source: NVD
CVE-2026-64805 HIGH - 8.4

In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via project-local package-manager tooling

Vendor: JetBrains
Product: WebStorm
Published: Jul 23, 2026
Source: NVD
CVE-2026-64804 HIGH - 8.4

In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via project-local linter tooling

Vendor: JetBrains
Product: WebStorm
Published: Jul 23, 2026
Source: NVD
CVE-2026-64803 HIGH - 7.8

In JetBrains GoLand before 2026.2 arbitrary code execution was possible before granting project trust via the configured Go SDK

Vendor: JetBrains
Product: GoLand
Published: Jul 23, 2026
Source: NVD
CVE-2026-64802 HIGH - 7.8

In JetBrains GoLand before 2026.2 arbitrary code execution was possible before granting project trust in the Go Modules integration

Vendor: JetBrains
Product: GoLand
Published: Jul 23, 2026
Source: NVD

In JetBrains GoLand before 2026.2 sensitive configuration values written to log files by default

Vendor: JetBrains
Product: GoLand
Published: Jul 23, 2026
Source: NVD
CVE-2026-61981 MEDIUM - 5.4

Unauthenticated Cross Site Request Forgery (CSRF) in Simple Link Directory Pro <= 15.0.8 versions.

Vendor: QuantumCloud
Product: Simple Link Directory Pro
Published: Jul 23, 2026
Source: NVD
CVE-2026-61973 MEDIUM - 4.3

Subscriber Broken Access Control in ShopLentor Pro <= 2.8.5 versions.

Vendor: WooLentor
Product: ShopLentor Pro
Published: Jul 23, 2026
Source: NVD
CVE-2026-61972 MEDIUM - 5.3

Unauthenticated Broken Access Control in ShopLentor Pro <= 2.8.5 versions.

Vendor: WooLentor
Product: ShopLentor Pro
Published: Jul 23, 2026
Source: NVD
CVE-2026-61954 HIGH - 7.5

Unauthenticated Broken Access Control in PayU India <= 3.8.9 versions.

Vendor: PayU India
Product: PayU India
Published: Jul 23, 2026
Source: NVD
CVE-2026-61951 CRITICAL - 9.8

Unauthenticated Privilege Escalation in TrueBooker <= 1.2.3 versions.

Vendor: themetechmount
Product: TrueBooker
Published: Jul 23, 2026
Source: NVD
CVE-2026-61950 CRITICAL - 9.3

Unauthenticated SQL Injection in TrueBooker <= 1.2.3 versions.

Vendor: themetechmount
Product: TrueBooker
Published: Jul 23, 2026
Source: NVD
CVE-2026-61949 CRITICAL - 9.3

Unauthenticated SQL Injection in Bookly <= 27.7 versions.

Vendor: Bookly
Product: Bookly
Published: Jul 23, 2026
Source: NVD
CVE-2026-61948 CRITICAL - 9.3

Unauthenticated SQL Injection in WPDM โ€“ Premium Packages <= 6.2.0 versions.

Vendor: Shahjada
Product: WPDM โ€“ Premium Packages
Published: Jul 23, 2026
Source: NVD