Export limit exceeded: 399925 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (399925 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-100276 | 2026-09-30 | 5.9 Medium | ||
| In JetBrains YouTrack before 2026.2.19197 guest users could remove a workflow action's visibility restriction and run the action | ||||
| CVE-2026-100275 | 2026-09-30 | 6.9 Medium | ||
| In JetBrains YouTrack before 2026.2.19197 stored XSS in the workflow error notification toast was possible | ||||
| CVE-2026-100274 | 2026-09-30 | 6.5 Medium | ||
| In JetBrains YouTrack before 2026.2.19197 project Admin could trigger DoS via a notification template | ||||
| CVE-2026-100273 | 2026-09-30 | 8.2 High | ||
| In JetBrains YouTrack before 2026.2.19197 authorisation bypass in the scripts debugger allowed arbitrary code execution | ||||
| CVE-2026-100272 | 2026-09-30 | 4.9 Medium | ||
| In JetBrains YouTrack before 2026.2.19197 missing authorisation in the notification template preview allowed Project Administrators to read restricted issues | ||||
| CVE-2026-100271 | 2026-09-30 | 2.7 Low | ||
| In JetBrains YouTrack before 2026.2.19197 missing authorisation on several endpoints allowed authenticated users to access information from other projects | ||||
| CVE-2026-100270 | 2026-09-30 | 3.3 Low | ||
| In JetBrains YouTrack before 2026.2.19197 low-level Admin Read permission users could disclose integration credentials via import configurations | ||||
| CVE-2026-100269 | 2026-09-30 | 4.3 Medium | ||
| In JetBrains YouTrack before 2026.2.19197 helpdesk project's Authorized Reporters list could be bypassed | ||||
| CVE-2026-100268 | 2026-09-30 | 7.7 High | ||
| In JetBrains YouTrack before 2026.2.19197 project administrators could read comments from other projects via notification templates | ||||
| CVE-2026-100267 | 2026-09-30 | 5.9 Medium | ||
| In JetBrains YouTrack before 2026.2.19197 reDoS attack was possible via mailbox regex mail-rule filters | ||||
| CVE-2026-100266 | 2026-09-30 | 7.7 High | ||
| In JetBrains Hub before 2026.2.52366 missing authorisation allowed authenticated users to send arbitrary emails from the server's trusted address | ||||
| CVE-2026-100265 | 2026-09-30 | 4.8 Medium | ||
| In JetBrains Rider before 2026.2.1 aI Assistant could auto-update third-party skills without user confirmation | ||||
| CVE-2026-100264 | 2026-09-30 | 2.7 Low | ||
| In JetBrains YouTrack before 2026.2.18991 stored SMTP server credentials could be disclosed by changing the server host | ||||
| CVE-2026-100263 | 2026-09-30 | 4.7 Medium | ||
| In JetBrains YouTrack before 2026.2.18991 stored HTML injection via the User-Agent header was possible | ||||
| CVE-2026-100262 | 2026-09-30 | 7.6 High | ||
| In JetBrains YouTrack before 2026.2.18991 missing authorisation allowed users with read-only project access to overwrite project notification templates | ||||
| CVE-2026-100261 | 2026-09-30 | 5.4 Medium | ||
| In JetBrains YouTrack before 2026.2.18991 changing article visibility settings was possible without update permission | ||||
| CVE-2026-100260 | 2026-09-30 | 5.3 Medium | ||
| In JetBrains YouTrack before 2026.2.18991 mailbox integration allowed authentication after a password reset | ||||
| CVE-2026-100259 | 2026-09-30 | 4.3 Medium | ||
| In JetBrains YouTrack before 2026.2.18991 improper access control on Gantt chart allowed edits by users with view-only access | ||||
| CVE-2026-100258 | 2026-09-30 | 4.3 Medium | ||
| In JetBrains YouTrack before 2026.2.18991 missing authorisation allowed read-only users to read project settings | ||||
| CVE-2026-100257 | 2026-09-30 | 4.3 Medium | ||
| In JetBrains YouTrack before 2026.2.18991 sSRF via stored XHTML injection was possible during PDF export | ||||