Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

163,503 CVEs · Medium severity

CVEs (163,503, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 476–500 of 163,503 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-86515 MEDIUM 4.3 2026-09-08 A security vulnerability has been detected in vgmstream up to r2117. Impacted is the function add_entry of the file src/meta/txtp_parser.c of the component txtp. Such manip…
CVE-2026-86514 MEDIUM 6.3 2026-09-08 A weakness has been identified in vgmstream up to r2117. This issue affects the function sscanf of the file src/meta/txth.c of the component txth-txtp. This manipulation ca…
CVE-2026-86513 MEDIUM 5.3 2026-09-08 A security flaw has been discovered in java-json-tools jackson-coreutils 2.0. This vulnerability affects the function TreePointer.tokensFromInput of the file src/main/java/…
CVE-2026-86512 MEDIUM 6.3 2026-09-08 A vulnerability was identified in java-json-tools json-patch up to 1.13. This affects the function CopyOperation.apply/MoveOperation.apply of the file src/main/java/com/git…
CVE-2026-86511 MEDIUM 5.3 2026-09-08 A vulnerability was found in java-json-tools jackson-coreutils 2.0. Affected by this vulnerability is the function BigDecimal.toPlainString of the file src/main/java/com/gi…
CVE-2026-86506 MEDIUM Patched 5.9 2026-09-07 In JetBrains GoLand before 2026.2.2.1 missing authentication on the GoLand profiler's injected pprof server exposed profiling data
CVE-2026-86500 MEDIUM Patched 5.5 2026-09-07 In JetBrains YouTrack before 2026.1.14047 a missing escalation check let a user with project update permissions grant themselves Project Admin
CVE-2026-8650 MEDIUM Patched 4.5 2026-07-08 Relative path traversal vulnerability in Progress MOVEit Transfer (Admin Settings module). This issue affects MOVEit Transfer: before 2025.0.7, from 2025.1.0 before 2025.1.3.
CVE-2026-86499 MEDIUM Patched 4.3 2026-09-07 In JetBrains YouTrack before 2026.1.14047 predefined search fields leaked all group names to any user, regardless of visibility permission
CVE-2026-86497 MEDIUM Patched 6.8 2026-09-07 In JetBrains YouTrack before 2026.2.18769 changing a mailbox host without re-authentication allowed a project administrator to exfiltrate stored mailbox credentials
CVE-2026-86496 MEDIUM Patched 4.3 2026-09-07 In JetBrains YouTrack before 2026.2.18769 missing access control on Helpdesk authorized reporters exposed reporter email addresses
CVE-2026-86495 MEDIUM Patched 6.5 2026-09-07 In JetBrains YouTrack before 2026.2.18687 missing permission checks allowed creating knowledge base articles in inaccessible projects
CVE-2026-86493 MEDIUM Patched 6.5 2026-09-07 In JetBrains YouTrack before 2026.2.18634 improper permission checks allowed read-only users to create and modify whiteboard cards
CVE-2026-86490 MEDIUM Patched 6.5 2026-09-07 In JetBrains YouTrack before 2026.2.18634 improper permission checks allowed overwriting of bundled apps via the app import endpoint
CVE-2026-8649 MEDIUM Patched 6.4 2026-07-08 Improper Neutralization of Special Elements in Data Query Logic vulnerability in Progress MOVEit Transfer (Custom Reports modules). This issue affects MOVEit Transfer: bef…
CVE-2026-86489 MEDIUM Patched 6.5 2026-09-07 In JetBrains YouTrack before 2026.2.18634 an IDOR in the user profile API disclosed private issues and starred folders across organizations
CVE-2026-86488 MEDIUM Patched 6.5 2026-09-07 In JetBrains YouTrack before 2026.2.18634 iDOR via the watchRules and issueListConfig endpoints exposed private saved searches
CVE-2026-86484 MEDIUM Patched 4.6 2026-09-07 In JetBrains YouTrack before 2026.2.18634 angularJS template injection in assignee names led to stored XSS
CVE-2026-86483 MEDIUM Patched 5.4 2026-09-07 In JetBrains YouTrack before 2026.2.18634 stored XSS via a custom field on Agile board cards was possible
CVE-2026-86481 MEDIUM Patched 4.3 2026-09-07 In JetBrains YouTrack before 2026.2.18634 signed URL reuse allowed disclosure of restricted project icons
CVE-2026-8647 MEDIUM 4.8 2026-05-26 Crypt::ScryptKDF versions through 0.010 for Perl uses insecure random number source when no CSPRNG module is available. The random_bytes function fell back to using the bu…
CVE-2026-86469 MEDIUM 5.3 2026-09-07 A flaw was found in GLib2. When g_file_replace() is used with G_FILE_CREATE_REPLACE_DESTINATION and creating the .goutputstream-XXXXXX temporary file fails, the library unl…
CVE-2026-86436 MEDIUM Patched 5.4 2026-09-07 Lara Dashboard before 1.3.2 fails to authorize access to the post-builder image and video upload endpoints, allowing authenticated accounts without content permissions to u…
CVE-2026-86432 MEDIUM Patched 5.3 2026-09-07 commonmark versions from 2.0.0 before 2.8.4 contain a denial of service vulnerability in XmlRenderer that emits depth-proportional indentation for every XML tag. Attackers …
CVE-2026-8643 MEDIUM Patched 5.5 2026-06-01 pip would treat console_scripts and gui_scripts as paths instead of file names without sanitizing the resolved absolute path to the installation directory, leading to entry…