Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
4.3 MEDIUM
CVE-2026-65458 — WordPress Polylang plugin <= 3.8.5 - Sensitive Data Exposure vulnerability

Contributor Sensitive Data Exposure in Polylang <= 3.8.5 versions.

Remote | Information Disclosure
Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
4.3 MEDIUM
CVE-2026-65457 — WordPress ЮKassa для WooCommerce plugin <= 2.16.1 - Broken Access Control vulnerability

Subscriber Broken Access Control in ЮKassa для WooCommerce <= 2.16.1 versions.

Remote | Authorization
Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
4.3 MEDIUM
CVE-2026-65456 — WordPress Product Slider for WooCommerce plugin <= 1.13.62 - Insecure Direct Object Refer…

Contributor Insecure Direct Object References (IDOR) in Product Slider for WooCommerce <= 1.13.62 versions.

product_slider_for_woocommerce | Remote | Authorization
Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
9.1 CRITICAL
CVE-2026-65455 — WordPress MapSVG plugin <= 8.14.0 - Arbitrary File Upload vulnerability

Administrator Arbitrary File Upload in MapSVG <= 8.14.0 versions.

Remote | Authentication
Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
8.5 HIGH
CVE-2026-65454 — WordPress Quiz And Survey Master plugin <= 11.2.0 - SQL Injection vulnerability

Contributor SQL Injection in Quiz And Survey Master <= 11.2.0 versions.

quiz_and_survey_master | Remote | Injection
Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
5.3 MEDIUM
CVE-2026-65453 — WordPress Ebook Store plugin <= 6.19 - Broken Access Control vulnerability

Unauthenticated Broken Access Control in Ebook Store <= 6.19 versions.

Remote | Authorization
Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
5.3 MEDIUM
CVE-2026-65452 — WordPress Ebook Store plugin <= 6.19 - Broken Access Control vulnerability

Unauthenticated Broken Access Control in Ebook Store <= 6.19 versions.

Remote | Authorization
Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
8.5 HIGH
CVE-2026-65451 — WordPress MapSVG plugin <= 8.14.0 - SQL Injection vulnerability

Contributor SQL Injection in MapSVG <= 8.14.0 versions.

Remote | Injection
Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
8.5 HIGH
CVE-2026-65450 — WordPress MapSVG plugin <= 8.14.0 - SQL Injection vulnerability

Contributor SQL Injection in MapSVG <= 8.14.0 versions.

Remote | Injection
Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
6.5 MEDIUM
CVE-2026-65449 — WordPress MapSVG plugin <= 8.14.0 - Cross Site Scripting (XSS) vulnerability

Contributor Cross Site Scripting (XSS) in MapSVG <= 8.14.0 versions.

Remote | Cross-Site Scripting
Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
8.1 HIGH
CVE-2026-64815 — JetBrains IntelliJ IDEA UI Designer Arbitrary Code Injection

In JetBrains IntelliJ IDEA before 2026.2 arbitrary code injection was possible via UI Designer form files

intellij_idea | Remote | Injection
Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
8.6 HIGH
CVE-2026-64814 — JetBrains IntelliJ IDEA Unauthorized File Access Vulnerability

In JetBrains IntelliJ IDEA before 2026.2 unauthorized file access was possible in a Remote Development session

intellij_idea | Remote | Path Traversal
Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
10.0 CRITICAL
CVE-2026-64813 — JetBrains IntelliJ IDEA Unauthorized Settings Modification Vulnerability

In JetBrains IntelliJ IDEA before 2026.2 unauthorized settings modification was possible in a Remote Development session

intellij_idea | Remote | Authorization
Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
10.0 CRITICAL
CVE-2026-64812 — JetBrains IntelliJ IDEA Input Injection Vulnerability

In JetBrains IntelliJ IDEA before 2026.2 unauthorized input injection was possible in a Remote Development session

intellij_idea | Remote | Injection
Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
7.8 HIGH
CVE-2026-64811 — JetBrains IntelliJ IDEA Arbitrary Code Execution Vulnerability

In JetBrains IntelliJ IDEA before 2026.2 arbitrary code execution was possible before granting project trust via development container configuration

intellij_idea | Misconfiguration
Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
4.3 MEDIUM
CVE-2026-64810 — JetBrains IntelliJ IDEA HTML Injection Vulnerability

In JetBrains IntelliJ IDEA before 2026.2 hTML injection was possible in an IDE notification, allowing silent user activity tracking

intellij_idea | Remote | Information Disclosure
Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
8.4 HIGH
CVE-2026-64809 — JetBrains PhpStorm Arbitrary Code Execution Vulnerability

In JetBrains PhpStorm before 2026.2 arbitrary code execution was possible before granting project trust via the configured interpreter

phpstorm | Authentication
Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
8.4 HIGH
CVE-2026-64808 — JetBrains PhpStorm Arbitrary Code Execution Vulnerability

In JetBrains PhpStorm before 2026.2 arbitrary code execution was possible before granting project trust via project tooling

phpstorm | Misconfiguration
Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
7.8 HIGH
CVE-2026-64807 — JetBrains WebStorm Arbitrary Code Execution

In JetBrains WebStorm before 2026.2 arbitrary code execution was possible via a project-supplied linter configuration

webstorm | Misconfiguration
Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
8.4 HIGH
CVE-2026-64806 — JetBrains WebStorm Arbitrary Code Execution

In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via the configured Node.js interpreter

webstorm | Misconfiguration
Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
Showing 20 of 9822 Results