Search
2,372 CVEs
CVEs (2,372, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 76–100 of 2,372 (capped at 500)
| CVE ID ↓ | Severity | Patch | CVSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-86481 | MEDIUM | Patched | 4.3 | 2026-09-07 | In JetBrains YouTrack before 2026.2.18634 signed URL reuse allowed disclosure of restricted project icons |
| CVE-2026-86480 | CRITICAL | Patched | 9.8 | 2026-09-07 | In JetBrains Hub before 2026.2.52442 an unauthenticated attacker could register a trusted service and gain superuser privileges |
| CVE-2026-86479 | HIGH | Patched | 8.1 | 2026-09-07 | In JetBrains YouTrack before 2026.2.18788, 2026.1.14055, 2025.3.161254 missing authorisation allowed access to restricted REST API resources via IDOR |
| CVE-2026-86478 | CRITICAL | Patched | 9.8 | 2026-09-07 | In JetBrains YouTrack before 2025.3.161254, 2026.1.14042 improper authentication in YouTrack Helpdesk allowed unauthenticated account takeover via a self-asserted email address |
| CVE-2026-86469 | MEDIUM | 5.3 | 2026-09-07 | A flaw was found in GLib2. When g_file_replace() is used with G_FILE_CREATE_REPLACE_DESTINATION and creating the .goutputstream-XXXXXX temporary file fails, the library unl… | |
| CVE-2026-86452 | NONE | — | 2026-09-07 | Affected versions of MISP permit unauthenticated or weakly constrained request paths to perform persistent work without adequate input bounds or rate limiting. The users/… | |
| CVE-2026-86451 | NONE | — | 2026-09-07 | Affected versions of MISP allow authenticated users to retrieve object-reference records by UUID through EventGraphTool::get_reference_data() without first checking whether… | |
| CVE-2026-86441 | NONE | — | 2026-09-07 | Affected versions of MISP contain inconsistent authorization checks across dashboard widgets that display organisation information. Several organisation-related widgets d… | |
| CVE-2026-86440 | NONE | — | 2026-09-07 | Affected versions of MISP insufficiently validate URLs used by dashboard widgets, particularly the Button widget. The widget's URL is stored configuration controlled by a… | |
| CVE-2026-86439 | HIGH | Patched | 8.8 | 2026-09-07 | knowns versions before 0.30.0 fail to validate filesystem paths in MCP tool arguments, allowing attackers to read, create, overwrite and delete files outside the project di… |
| CVE-2026-86438 | HIGH | Patched | 7.2 | 2026-09-07 | Lara Dashboard before 1.3.2 fails to authorize the MarketplaceModuleBrowser installModule Livewire action, allowing non-Superadmin administrators to install modules. Attack… |
| CVE-2026-86437 | HIGH | Patched | 7.2 | 2026-09-07 | Lara Dashboard before 1.3.2 authorizes the POST /admin/settings/core-upgrades/upload endpoint with only the settings.edit permission, allowing non-Superadmin administrators… |
| CVE-2026-86436 | MEDIUM | Patched | 5.4 | 2026-09-07 | Lara Dashboard before 1.3.2 fails to authorize access to the post-builder image and video upload endpoints, allowing authenticated accounts without content permissions to u… |
| CVE-2026-86435 | HIGH | Patched | 7.5 | 2026-09-07 | commonmark versions from 1.5.0 before 2.8.4 contain a denial of service vulnerability in the Footnote extension that fails to deduplicate footnote definitions. Attackers ca… |
| CVE-2026-86434 | HIGH | Patched | 7.5 | 2026-09-07 | league/commonmark versions >= 2.0.0 and < 2.8.4 (patched in 2.9.0) contain a denial of service vulnerability in UniqueSlugNormalizer::normalize(), which restarts its numeri… |
| CVE-2026-86433 | HIGH | Patched | 7.5 | 2026-09-07 | commonmark versions from 1.5.0 before 2.8.4 contain a denial of service vulnerability in the Attributes extension where AttributesListener::findTargetAndDirection() perform… |
| CVE-2026-86432 | MEDIUM | Patched | 5.3 | 2026-09-07 | commonmark versions from 2.0.0 before 2.8.4 contain a denial of service vulnerability in XmlRenderer that emits depth-proportional indentation for every XML tag. Attackers … |
| CVE-2026-86431 | HIGH | Patched | 7.2 | 2026-09-07 | league/commonmark (thephpleague/commonmark) versions >= 2.7.0 and < 2.9.1 contain a cross-site scripting vulnerability in the AttributesExtension. Prefixing an attribute na… |
| CVE-2026-86430 | HIGH | Patched | 7.5 | 2026-09-07 | league/commonmark versions before 2.9.1 contain multiple denial of service vulnerabilities in fenced code block detection, reference link label lookup, and emphasis delimit… |
| CVE-2026-86429 | HIGH | Patched | 7.5 | 2026-09-07 | The league/commonmark (thephpleague/commonmark) library in versions >= 1.5.0 and < 2.9.1 contains quadratic parsing complexity in its SmartPunctExtension and AttributesExte… |
| CVE-2026-86428 | HIGH | Patched | 7.5 | 2026-09-07 | commonmark versions from 1.5.0 before 2.10.0 contain a denial of service vulnerability in the AttributesExtension when processing distinctly-named attributes. Attackers can… |
| CVE-2026-86427 | HIGH | Patched | 8.8 | 2026-09-07 | LibreNMS before 26.8.0 contains an argument injection vulnerability in the graph_title parameter that allows authenticated attackers to inject arbitrary rrdtool arguments b… |
| CVE-2026-86426 | NONE | Patched | — | 2026-09-07 | LibreNMS before 26.8.0 contains an authentication bypass vulnerability in the REST API that allows unauthenticated attackers to access protected endpoints by sending numeri… |
| CVE-2026-86425 | LOW | Patched | 3.3 | 2026-09-07 | ImageMagick before 7.1.2-30 and 6.9.x before 6.9.13-55 contains a heap-use-after-free vulnerability in the Layer method of PerlMagick. An attacker who supplies a crafted li… |
| CVE-2026-86424 | LOW | Patched | 2.5 | 2026-09-07 | ImageMagick before 7.1.2-30 and 6.9.13-55 contains a time-of-check-time-of-use (TOCTOU) vulnerability in the video decoder that allows attackers to bypass path policy write… |