Search
30,217 CVEs
CVEs (30,217, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 401–425 of 30,217 (capped at 500)
| CVE ID ↓ | Severity | Patch | CVSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-86498 | HIGH | Patched | 7.7 | 2026-09-07 | In JetBrains YouTrack before 2025.3.160480, 2026.1.14047 pUT requests on link sub-resources allowed modification linked entities without update permission |
| CVE-2026-86497 | MEDIUM | Patched | 6.8 | 2026-09-07 | In JetBrains YouTrack before 2026.2.18769 changing a mailbox host without re-authentication allowed a project administrator to exfiltrate stored mailbox credentials |
| CVE-2026-86496 | MEDIUM | Patched | 4.3 | 2026-09-07 | In JetBrains YouTrack before 2026.2.18769 missing access control on Helpdesk authorized reporters exposed reporter email addresses |
| CVE-2026-86495 | MEDIUM | Patched | 6.5 | 2026-09-07 | In JetBrains YouTrack before 2026.2.18687 missing permission checks allowed creating knowledge base articles in inaccessible projects |
| CVE-2026-86494 | HIGH | Patched | 7.7 | 2026-09-07 | In JetBrains YouTrack before 2026.2.18634 cloning a whiteboard allowed unauthorized changes to links on inaccessible issues |
| CVE-2026-86493 | MEDIUM | Patched | 6.5 | 2026-09-07 | In JetBrains YouTrack before 2026.2.18634 improper permission checks allowed read-only users to create and modify whiteboard cards |
| CVE-2026-86492 | HIGH | Patched | 8.5 | 2026-09-07 | In JetBrains YouTrack before 2026.2.18634 a shared token cache allowed cross-tenant theft of GitHub App installation tokens |
| CVE-2026-86491 | LOW | Patched | 3.5 | 2026-09-07 | In JetBrains YouTrack before 2026.2.18634 stored XSS was possible via project and organization icon uploads |
| CVE-2026-86490 | MEDIUM | Patched | 6.5 | 2026-09-07 | In JetBrains YouTrack before 2026.2.18634 improper permission checks allowed overwriting of bundled apps via the app import endpoint |
| CVE-2026-8649 | MEDIUM | Patched | 6.4 | 2026-07-08 | Improper Neutralization of Special Elements in Data Query Logic vulnerability in Progress MOVEit Transfer (Custom Reports modules). This issue affects MOVEit Transfer: bef… |
| CVE-2026-86489 | MEDIUM | Patched | 6.5 | 2026-09-07 | In JetBrains YouTrack before 2026.2.18634 an IDOR in the user profile API disclosed private issues and starred folders across organizations |
| CVE-2026-86488 | MEDIUM | Patched | 6.5 | 2026-09-07 | In JetBrains YouTrack before 2026.2.18634 iDOR via the watchRules and issueListConfig endpoints exposed private saved searches |
| CVE-2026-86487 | LOW | Patched | 3.1 | 2026-09-07 | In JetBrains YouTrack before 2026.2.18634 a crafted WebSocket message allowed read-only whiteboard users to modify canvas content |
| CVE-2026-86486 | LOW | Patched | 3.7 | 2026-09-07 | In JetBrains YouTrack before 2026.2.18634 the generic VCS webhook handler failed open when its secret was blank |
| CVE-2026-86485 | LOW | Patched | 3.3 | 2026-09-07 | In JetBrains YouTrack before 2026.2.18634 iP spoofing via HTTP headers allowed forged Bitbucket webhooks |
| CVE-2026-86484 | MEDIUM | Patched | 4.6 | 2026-09-07 | In JetBrains YouTrack before 2026.2.18634 angularJS template injection in assignee names led to stored XSS |
| CVE-2026-86483 | MEDIUM | Patched | 5.4 | 2026-09-07 | In JetBrains YouTrack before 2026.2.18634 stored XSS via a custom field on Agile board cards was possible |
| CVE-2026-86482 | HIGH | Patched | 8.8 | 2026-09-07 | In JetBrains YouTrack before 2026.2.18634 unchecked group membership changes allowed privilege escalation |
| CVE-2026-86481 | MEDIUM | Patched | 4.3 | 2026-09-07 | In JetBrains YouTrack before 2026.2.18634 signed URL reuse allowed disclosure of restricted project icons |
| CVE-2026-86480 | CRITICAL | Patched | 9.8 | 2026-09-07 | In JetBrains Hub before 2026.2.52442 an unauthenticated attacker could register a trusted service and gain superuser privileges |
| CVE-2026-86479 | HIGH | Patched | 8.1 | 2026-09-07 | In JetBrains YouTrack before 2026.2.18788, 2026.1.14055, 2025.3.161254 missing authorisation allowed access to restricted REST API resources via IDOR |
| CVE-2026-86478 | CRITICAL | Patched | 9.8 | 2026-09-07 | In JetBrains YouTrack before 2025.3.161254, 2026.1.14042 improper authentication in YouTrack Helpdesk allowed unauthenticated account takeover via a self-asserted email address |
| CVE-2026-86469 | MEDIUM | 5.3 | 2026-09-07 | A flaw was found in GLib2. When g_file_replace() is used with G_FILE_CREATE_REPLACE_DESTINATION and creating the .goutputstream-XXXXXX temporary file fails, the library unl… | |
| CVE-2026-8646 | HIGH | Patched | 7.4 | 2026-06-22 | IBM WebSphere Application Server 9.0 and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 are vulnerable to HTTP request smuggling. A remote att… |
| CVE-2026-86452 | NONE | — | 2026-09-07 | Affected versions of MISP permit unauthenticated or weakly constrained request paths to perform persistent work without adequate input bounds or rate limiting. The users/… |