Search
163,503 CVEs · Medium severity
CVEs (163,503, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 26–50 of 163,503 (capped at 500)
| CVE ID | Severity ↑ | Patch | CVSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-86436 | MEDIUM | Patched | 5.4 | 2026-09-07 | Lara Dashboard before 1.3.2 fails to authorize access to the post-builder image and video upload endpoints, allowing authenticated accounts without content permissions to u… |
| CVE-2026-86506 | MEDIUM | Patched | 5.9 | 2026-09-07 | In JetBrains GoLand before 2026.2.2.1 missing authentication on the GoLand profiler's injected pprof server exposed profiling data |
| CVE-2026-86497 | MEDIUM | Patched | 6.8 | 2026-09-07 | In JetBrains YouTrack before 2026.2.18769 changing a mailbox host without re-authentication allowed a project administrator to exfiltrate stored mailbox credentials |
| CVE-2026-86499 | MEDIUM | Patched | 4.3 | 2026-09-07 | In JetBrains YouTrack before 2026.1.14047 predefined search fields leaked all group names to any user, regardless of visibility permission |
| CVE-2026-86500 | MEDIUM | Patched | 5.5 | 2026-09-07 | In JetBrains YouTrack before 2026.1.14047 a missing escalation check let a user with project update permissions grant themselves Project Admin |
| CVE-2026-86488 | MEDIUM | Patched | 6.5 | 2026-09-07 | In JetBrains YouTrack before 2026.2.18634 iDOR via the watchRules and issueListConfig endpoints exposed private saved searches |
| CVE-2026-86489 | MEDIUM | Patched | 6.5 | 2026-09-07 | In JetBrains YouTrack before 2026.2.18634 an IDOR in the user profile API disclosed private issues and starred folders across organizations |
| CVE-2026-86490 | MEDIUM | Patched | 6.5 | 2026-09-07 | In JetBrains YouTrack before 2026.2.18634 improper permission checks allowed overwriting of bundled apps via the app import endpoint |
| CVE-2026-86493 | MEDIUM | Patched | 6.5 | 2026-09-07 | In JetBrains YouTrack before 2026.2.18634 improper permission checks allowed read-only users to create and modify whiteboard cards |
| CVE-2026-86495 | MEDIUM | Patched | 6.5 | 2026-09-07 | In JetBrains YouTrack before 2026.2.18687 missing permission checks allowed creating knowledge base articles in inaccessible projects |
| CVE-2026-86496 | MEDIUM | Patched | 4.3 | 2026-09-07 | In JetBrains YouTrack before 2026.2.18769 missing access control on Helpdesk authorized reporters exposed reporter email addresses |
| CVE-2026-86481 | MEDIUM | Patched | 4.3 | 2026-09-07 | In JetBrains YouTrack before 2026.2.18634 signed URL reuse allowed disclosure of restricted project icons |
| CVE-2026-86483 | MEDIUM | Patched | 5.4 | 2026-09-07 | In JetBrains YouTrack before 2026.2.18634 stored XSS via a custom field on Agile board cards was possible |
| CVE-2026-86484 | MEDIUM | Patched | 4.6 | 2026-09-07 | In JetBrains YouTrack before 2026.2.18634 angularJS template injection in assignee names led to stored XSS |
| CVE-2026-79975 | MEDIUM | 5.5 | 2026-09-07 | Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Certificate Validation vulnerability. A … | |
| CVE-2026-80058 | MEDIUM | 5.5 | 2026-09-07 | Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Cleartext Storage of Sensitive Information vulnera… | |
| CVE-2026-80125 | MEDIUM | 5.9 | 2026-09-07 | Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Certificate Validation vulnerability. An… | |
| CVE-2026-80126 | MEDIUM | 6.5 | 2026-09-07 | Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Locking vulnerability. A low privileged … | |
| CVE-2026-80167 | MEDIUM | 5.5 | 2026-09-07 | Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Use of Hard-coded Cryptographic Key vulnerability… | |
| CVE-2026-80176 | MEDIUM | 4.7 | 2026-09-07 | Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Plaintext Storage of a Password vulnerability. A l… | |
| CVE-2026-86321 | MEDIUM | 5.3 | 2026-09-07 | A vulnerability was found in java-json-tools jackson-coreutils 2.0. Affected by this issue is the function JsonLoader.fromURL of the file src/main/java/com/github/fge/jacks… | |
| CVE-2026-86469 | MEDIUM | 5.3 | 2026-09-07 | A flaw was found in GLib2. When g_file_replace() is used with G_FILE_CREATE_REPLACE_DESTINATION and creating the .goutputstream-XXXXXX temporary file fails, the library unl… | |
| CVE-2026-79642 | MEDIUM | 5.6 | 2026-09-07 | Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Certificate Validation vulnerability. An… | |
| CVE-2026-79943 | MEDIUM | 4.8 | 2026-09-07 | Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Validation of Certificate with Host Mism… | |
| CVE-2026-80054 | MEDIUM | 5.5 | 2026-09-07 | Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Incorrect Permission Assignment for Critical Reso… |