| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| Contributor Arbitrary File Deletion in Picture Gallery <= 1.6.5 versions. |
| Unauthenticated Broken Access Control in Knit Pay <= 9.6.0.0 versions. |
| Subscriber Arbitrary Content Deletion in WP EasyPay <= 4.5.0 versions. |
| Unauthenticated Arbitrary File Deletion in Broadcast Live Video <= 7.2.4 versions. |
| Unauthenticated Sensitive Data Exposure in Ninja Tables <= 5.2.10 versions. |
| In JetBrains GoLand before 2026.2 arbitrary code execution was possible before granting project trust in the Go Modules integration |
| In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via the configured Node.js interpreter |
| In JetBrains WebStorm before 2026.2 arbitrary code execution was possible via a project-supplied linter configuration |
| In JetBrains IntelliJ IDEA before 2026.2 arbitrary code injection was possible via UI Designer form files |
| In JetBrains PyCharm before 2026.1.4, 2026.2 arbitrary code execution via malicious Python executable was possible on untrusted project open |
| Subscriber Broken Access Control in WP ERP <= 1.17.5 versions. |
| Unauthenticated SQL Injection in Bookly <= 27.7 versions. |
| Unauthenticated Cross Site Request Forgery (CSRF) in Simple Link Directory Pro <= 15.0.8 versions. |
| Contributor SQL Injection in Quiz And Survey Master <= 11.2.0 versions. |
| Contributor Server Side Request Forgery (SSRF) in JetEngine <= 3.8.11 versions. |
| Unauthenticated Sensitive Data Exposure in Complianz <= 7.5.0 versions. |
| Contributor Cross Site Scripting (XSS) in Accept Donations with PayPal & Stripe <= 1.5.5 versions. |
| Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). |
| Contributor SQL Injection in Visualizer <= 4.0.6 versions. |
| Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). |