Export limit exceeded: 387293 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (387293 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-86485 | 1 Jetbrains | 1 Youtrack | 2026-09-07 | 3.5 Low |
| In JetBrains YouTrack before 2026.2.18634 iP spoofing via HTTP headers allowed forged Bitbucket webhooks | ||||
| CVE-2026-86487 | 1 Jetbrains | 1 Youtrack | 2026-09-07 | 3.1 Low |
| In JetBrains YouTrack before 2026.2.18634 a crafted WebSocket message allowed read-only whiteboard users to modify canvas content | ||||
| CVE-2026-86488 | 1 Jetbrains | 1 Youtrack | 2026-09-07 | 6.5 Medium |
| In JetBrains YouTrack before 2026.2.18634 iDOR via the watchRules and issueListConfig endpoints exposed private saved searches | ||||
| CVE-2026-86490 | 1 Jetbrains | 1 Youtrack | 2026-09-07 | 6.5 Medium |
| In JetBrains YouTrack before 2026.2.18634 improper permission checks allowed overwriting of bundled apps via the app import endpoint | ||||
| CVE-2026-86491 | 2026-09-07 | 3.5 Low | ||
| In JetBrains YouTrack before 2026.2.18634 stored XSS was possible via project and organization icon uploads | ||||
| CVE-2026-86492 | 2026-09-07 | 8.5 High | ||
| In JetBrains YouTrack before 2026.2.18634 a shared token cache allowed cross-tenant theft of GitHub App installation tokens | ||||
| CVE-2026-86496 | 2026-09-07 | 4.3 Medium | ||
| In JetBrains YouTrack before 2026.2.18769 missing access control on Helpdesk authorized reporters exposed reporter email addresses | ||||
| CVE-2026-86497 | 2026-09-07 | 6.8 Medium | ||
| In JetBrains YouTrack before 2026.2.18769 changing a mailbox host without re-authentication allowed a project administrator to exfiltrate stored mailbox credentials | ||||
| CVE-2026-86498 | 2026-09-07 | 7.7 High | ||
| In JetBrains YouTrack before 2025.3.160480, 2026.1.14047 pUT requests on link sub-resources allowed modification linked entities without update permission | ||||
| CVE-2026-80176 | 2026-09-07 | 4.7 Medium | ||
| Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Plaintext Storage of a Password vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to information disclosure. | ||||
| CVE-2026-80166 | 2026-09-07 | 7.8 High | ||
| Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Privilege Management vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability, leading to elevation of privileges. | ||||
| CVE-2026-86478 | 1 Jetbrains | 1 Youtrack | 2026-09-07 | 9.8 Critical |
| In JetBrains YouTrack before 2025.3.161254, 2026.1.14042 improper authentication in YouTrack Helpdesk allowed unauthenticated account takeover via a self-asserted email address | ||||
| CVE-2026-86479 | 1 Jetbrains | 1 Youtrack | 2026-09-07 | 8 High |
| In JetBrains YouTrack before 2026.2.18788, 2026.1.14055, 2025.3.161254 missing authorisation allowed access to restricted REST API resources via IDOR | ||||
| CVE-2026-86480 | 1 Jetbrains | 1 Hub | 2026-09-07 | 9.8 Critical |
| In JetBrains Hub before 2026.2.52442 an unauthenticated attacker could register a trusted service and gain superuser privileges | ||||
| CVE-2026-86482 | 1 Jetbrains | 1 Youtrack | 2026-09-07 | 8.8 High |
| In JetBrains YouTrack before 2026.2.18634 unchecked group membership changes allowed privilege escalation | ||||
| CVE-2026-86484 | 1 Jetbrains | 1 Youtrack | 2026-09-07 | 4.6 Medium |
| In JetBrains YouTrack before 2026.2.18634 angularJS template injection in assignee names led to stored XSS | ||||
| CVE-2026-86489 | 1 Jetbrains | 1 Youtrack | 2026-09-07 | 6.5 Medium |
| In JetBrains YouTrack before 2026.2.18634 an IDOR in the user profile API disclosed private issues and starred folders across organizations | ||||
| CVE-2026-80054 | 2026-09-07 | 5.5 Medium | ||
| Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Incorrect Permission Assignment for Critical Resource vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to unauthorized access. | ||||
| CVE-2026-8279 | 2 Masteriyo, Wordpress | 2 Masteriyo Lms – Lms Course Builder, Quizzes & Certificates, Wordpress | 2026-09-07 | 5.3 Medium |
| The Masteriyo LMS plugin for WordPress is vulnerable to unauthorized data deletion due to a missing capability check on the 'delete_item_permissions_check' function in the CourseProgressItemsController in all versions up to, and including, 2.2.0. This makes it possible for unauthenticated attackers to delete arbitrary course progress records belonging to any student. | ||||
| CVE-2022-51010 | 1 Pmmp | 1 Pocketmine-mp | 2026-09-07 | 6.5 Medium |
| PocketMine-MP versions before 4.4.2 fail to properly validate item IDs received from clients in itemstack NBT data. Attackers can send crafted item IDs outside the valid range to trigger an uncaught exception that crashes the server. | ||||