Search
2,372 CVEs
CVEs (2,372, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 176–200 of 2,372 (capped at 500)
| CVE ID | Severity | Patch | CVSS | Published ↓ | Description |
|---|---|---|---|---|---|
| CVE-2026-86439 | HIGH | Patched | 8.8 | 2026-09-07 | knowns versions before 0.30.0 fail to validate filesystem paths in MCP tool arguments, allowing attackers to read, create, overwrite and delete files outside the project di… |
| CVE-2026-82758 | NONE | Patched | — | 2026-09-07 | Improper Authentication vulnerability in ash-project ash_authentication_oauth2_server allows an unauthenticated attacker to register OAuth clients even when Dynamic Client … |
| CVE-2026-82757 | NONE | Patched | — | 2026-09-07 | Server-Side Request Forgery (SSRF) vulnerability in ash-project ash_authentication_oauth2_server allows an attacker who controls a client metadata URL and its DNS to make t… |
| CVE-2026-82756 | NONE | Patched | — | 2026-09-07 | Improper Encoding or Escaping of Output vulnerability in ash-project ash_authentication_oauth2_server allows an unauthenticated attacker to inject arbitrary authentication … |
| CVE-2026-82755 | NONE | Patched | — | 2026-09-07 | Use of Cache Containing Sensitive Information vulnerability in ash-project ash_authentication_oauth2_server allows a shared HTTP cache to serve one tenant's OAuth discovery… |
| CVE-2026-82754 | NONE | Patched | — | 2026-09-07 | Improper Protection of Alternate Path vulnerability in ash-project ash_authentication_oauth2_server exposes the state-changing OAuth endpoints under an unintended URL prefi… |
| CVE-2026-82753 | NONE | Patched | — | 2026-09-07 | Allocation of Resources Without Limits or Throttling vulnerability in ash-project ash_authentication_oauth2_server allows an unauthenticated attacker to exhaust database st… |
| CVE-2026-82586 | NONE | Patched | — | 2026-09-07 | Improper Protection of Alternate Path vulnerability in ash-project ash_lua allows a user-supplied Lua script to read attributes that are not on the exposed-field allow-list… |
| CVE-2026-82584 | NONE | Patched | — | 2026-09-07 | Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in ash-project igniter allows a malicious package publisher to forge the mix igniter.install con… |
| CVE-2026-81638 | NONE | Patched | — | 2026-09-07 | Improper Handling of Alternate Encoding vulnerability in ash-project ash_double_entry allows an attacker to submit several distinct string spellings of the same identifier.… |
| CVE-2026-86438 | HIGH | Patched | 7.2 | 2026-09-07 | Lara Dashboard before 1.3.2 fails to authorize the MarketplaceModuleBrowser installModule Livewire action, allowing non-Superadmin administrators to install modules. Attack… |
| CVE-2026-86437 | HIGH | Patched | 7.2 | 2026-09-07 | Lara Dashboard before 1.3.2 authorizes the POST /admin/settings/core-upgrades/upload endpoint with only the settings.edit permission, allowing non-Superadmin administrators… |
| CVE-2026-86436 | MEDIUM | Patched | 5.4 | 2026-09-07 | Lara Dashboard before 1.3.2 fails to authorize access to the post-builder image and video upload endpoints, allowing authenticated accounts without content permissions to u… |
| CVE-2026-75650 | CRITICAL | 10.0 | 2026-09-07 | Adobe Commerce is affected by an Improper Neutralization of Special Elements Used in a Template Engine vulnerability that could result in arbitrary code execution in the co… | |
| CVE-2026-86287 | NONE | Patched | — | 2026-09-07 | Net::IP::LPM versions before 1.12 for Perl accept malformed prefix lengths. Non-numeric and non-ASCII prefix lengths are accepted and treated as 0. Integers over 31 bits a… |
| CVE-2026-16028 | NONE | Patched | — | 2026-09-07 | Protocol::HTTP2 versions before 1.14 for Perl allow memory exhaustion via closed streams that stream_state never removes from the connection stream table. When a stream re… |
| CVE-2026-86506 | MEDIUM | Patched | 5.9 | 2026-09-07 | In JetBrains GoLand before 2026.2.2.1 missing authentication on the GoLand profiler's injected pprof server exposed profiling data |
| CVE-2026-86505 | LOW | Patched | 3.3 | 2026-09-07 | In JetBrains IntelliJ IDEA before 2026.2.2 missing project-trust check leaked project metadata to JetBrains Marketplace |
| CVE-2026-86504 | HIGH | Patched | 7.8 | 2026-09-07 | In JetBrains IntelliJ IDEA before 2026.2.2 missing project-trust confirmation before building a Dev Container allowed host-level code execution |
| CVE-2026-86503 | LOW | Patched | 3.3 | 2026-09-07 | In JetBrains IntelliJ IDEA before 2026.2.2 opening an untrusted project could trigger SSRF via Kubernetes spec-source URL fetching |
| CVE-2026-86502 | HIGH | Patched | 8.4 | 2026-09-07 | In JetBrains IntelliJ IDEA before 2026.2.2 missing TLS and authentication on the IJent gRPC server allowed local code execution on Remote Development hosts |
| CVE-2026-86501 | LOW | Patched | 2.8 | 2026-09-07 | In JetBrains IntelliJ IDEA before 2026.2.2 terminal command input could be written to idea.log |
| CVE-2026-86500 | MEDIUM | Patched | 5.5 | 2026-09-07 | In JetBrains YouTrack before 2026.1.14047 a missing escalation check let a user with project update permissions grant themselves Project Admin |
| CVE-2026-86499 | MEDIUM | Patched | 4.3 | 2026-09-07 | In JetBrains YouTrack before 2026.1.14047 predefined search fields leaked all group names to any user, regardless of visibility permission |
| CVE-2026-86498 | HIGH | Patched | 7.7 | 2026-09-07 | In JetBrains YouTrack before 2025.3.160480, 2026.1.14047 pUT requests on link sub-resources allowed modification linked entities without update permission |