Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

133,513 CVEs · High severity

CVEs (133,513, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 76–100 of 133,513 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-64805 HIGH Patched 8.4 2026-07-23 In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via project-local package-manager tooling
CVE-2026-61944 HIGH 7.1 2026-07-23 Unauthenticated Cross Site Scripting (XSS) in Bookly <= 27.7 versions.
CVE-2026-61947 HIGH 7.1 2026-07-23 Unauthenticated Cross Site Scripting (XSS) in Form Vibes – Database Manager for Forms <= 1.5.2 versions.
CVE-2026-59542 HIGH 7.7 2026-07-23 Subscriber Arbitrary File Deletion in Kali Forms <= 2.4.18 versions.
CVE-2026-59545 HIGH 8.1 2026-07-23 Unauthenticated Broken Authentication in miniOrange Discord Integration <= 2.2.4 versions.
CVE-2026-59547 HIGH 7.5 2026-07-23 Unauthenticated Broken Access Control in Payment Gateway for PayPal on WooCommerce <= 9.1.4 versions.
CVE-2026-59554 HIGH 7.5 2026-07-23 Unauthenticated Broken Authentication in Ziina <= 1.2.21 versions.
CVE-2026-61943 HIGH 7.5 2026-07-23 Unauthenticated Broken Access Control in WPDM – Premium Packages <= 6.2.0 versions.
CVE-2026-59517 HIGH 7.1 2026-07-23 Unauthenticated Cross Site Scripting (XSS) in Easy Form Builder <= 4.0.12 versions.
CVE-2026-59541 HIGH 8.8 2026-07-23 Subscriber Privilege Escalation in WP BASE Booking <= 6.3.1 versions.
CVE-2026-59512 HIGH 7.1 2026-07-23 Unauthenticated Cross Site Scripting (XSS) in Product Enquiry for WooCommerce <= 2.2.34.43 versions.
CVE-2026-57735 HIGH 7.1 2026-07-23 Unauthenticated Cross Site Scripting (XSS) in Breakdance <= 2.7.1 versions.
CVE-2026-57767 HIGH 7.1 2026-07-23 Unauthenticated Cross Site Scripting (XSS) in WP Google Maps Pro <= 10.1.02 versions.
CVE-2026-57769 HIGH 7.1 2026-07-23 Unauthenticated Cross Site Scripting (XSS) in Grand Photography <= 5.7.8 versions.
CVE-2026-57785 HIGH 8.8 2026-07-23 Unauthenticated Cross Site Request Forgery (CSRF) in ApusListing <= 1.2.63 versions.
CVE-2026-57809 HIGH 7.1 2026-07-23 Unauthenticated Cross Site Scripting (XSS) in AffiliateWP <= 2.34.0 versions.
CVE-2026-57626 HIGH 7.1 2026-07-23 Cross-Site Request Forgery (CSRF) vulnerability in MailPoet allows Cross Site Request Forgery. This issue affects MailPoet: from 5.30.0 through 5.33.0.
CVE-2026-57696 HIGH 7.1 2026-07-23 Contributor Arbitrary File Deletion in Picture Gallery <= 1.6.5 versions.
CVE-2026-57699 HIGH 7.1 2026-07-23 Subscriber Cross Site Scripting (XSS) in Slider Pro <= 4.8.13 versions.
CVE-2026-57701 HIGH 7.1 2026-07-23 Unauthenticated Cross Site Scripting (XSS) in Real Estate Manager Pro <= 12.8.5 versions.
CVE-2026-57704 HIGH 7.1 2026-07-23 Unauthenticated Cross Site Scripting (XSS) in Smart Manager <= 8.90.0 versions.
CVE-2026-57370 HIGH 7.1 2026-07-23 Unauthenticated Cross Site Scripting (XSS) in Visitor Traffic Real Time Statistics Pro <= 11.9.1 versions.
CVE-2026-57374 HIGH 7.1 2026-07-23 Unauthenticated Cross Site Scripting (XSS) in Funnel Kit Funnel Builder PRO <= 3.15.0.7 versions.
CVE-2026-57397 HIGH 7.1 2026-07-23 Unauthenticated Cross Site Scripting (XSS) in Coaching <= 3.9.2 versions.
CVE-2026-57427 HIGH 7.1 2026-07-23 Unauthenticated Cross Site Scripting (XSS) in Download Monitor - WPForms Lock <= 1.0.4 versions.