Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

4,825 CVEs · High severity

CVEs (4,825, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 1–25 of 4,825 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-9816 HIGH Patched 8.3 2026-08-17 Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21, 11.8.x <= 11.8.3 fail to validate BoardMember.Scheme* fields server-side on insert and archive-import paths which&hellip;
CVE-2026-9771 HIGH 8.8 2026-08-17 The flash_copy() system call is verified by z_vrfy_flash_copy() in drivers/flash/flash_util.c. On builds with CONFIG_USERSPACE enabled, this handler is the kernel-side trus&hellip;
CVE-2026-9769 HIGH Patched 7.5 2026-08-23 justhtml through 1.9.1 (fixed in 1.10.0) is vulnerable to uncontrolled recursion leading to denial of service. During JustHTML() construction, TreeBuilder.finish() uncondit&hellip;
CVE-2026-9331 HIGH 7.1 2026-09-08 The EDD Product Catalog Feed by PixelYourSite plugin for WordPress is vulnerable to unauthorized modification of data that can lead to a denial of service due to a missing &hellip;
CVE-2026-9317 HIGH Patched 8.1 2026-09-04 Nango before 0.71.6 contains a missing authentication vulnerability in the runner tRPC server that allows unauthenticated attackers to execute arbitrary JavaScript code by &hellip;
CVE-2026-8862 HIGH 7.5 2026-09-03 IBM Netezza Software 11.3.0.3 through Interim Fix 002 has credentials that are hardcoded in the application source code, allowing unauthorized access to the container regis&hellip;
CVE-2026-8718 HIGH 8.4 2026-08-10 tls_opt_dtls_peer_connection_id_value_get() in subsys/net/lib/sockets/sockets_tls.c, which handles getsockopt(SOL_TLS, TLS_DTLS_PEER_CID_VALUE), passed the caller-supplied &hellip;
CVE-2026-8712 HIGH Patched 8.3 2026-09-01 Wyoming before 1.10.2 contains a server-side request forgery vulnerability that allows unauthenticated attackers with network access to force outbound connections to arbitr&hellip;
CVE-2026-86544 HIGH Patched 8.1 2026-09-07 knowns versions before 0.30.0 contain an authorization bypass vulnerability where mutating code actions are incorrectly classified as read-only operations. Attackers with r&hellip;
CVE-2026-86541 HIGH Patched 8.3 2026-09-07 knowns versions before 0.30.0 contain a path traversal vulnerability in the handleCodeReplace() function that allows attackers to overwrite arbitrary files outside the proj&hellip;
CVE-2026-86540 HIGH Patched 7.8 2026-09-07 knowns versions before 0.30.0 fail to validate the settings.lsp.languages binary field in project configuration files, allowing attackers to execute arbitrary binaries by c&hellip;
CVE-2026-86539 HIGH 7.2 2026-09-07 knowns through 0.33.0 contains a server-side request forgery vulnerability in the POST /api/embedding-models/test endpoint that issues outbound requests to caller-supplied &hellip;
CVE-2026-86538 HIGH Patched 7.5 2026-09-07 knowns versions before 0.30.0 contain a path traversal vulnerability in the POST /api/templates/preview endpoint that allows unauthenticated attackers to read arbitrary fil&hellip;
CVE-2026-86504 HIGH Patched 7.8 2026-09-07 In JetBrains IntelliJ IDEA before 2026.2.2 missing project-trust confirmation before building a Dev Container allowed host-level code execution
CVE-2026-86502 HIGH Patched 8.4 2026-09-07 In JetBrains IntelliJ IDEA before 2026.2.2 missing TLS and authentication on the IJent gRPC server allowed local code execution on Remote Development hosts
CVE-2026-86498 HIGH Patched 7.7 2026-09-07 In JetBrains YouTrack before 2025.3.160480, 2026.1.14047 pUT requests on link sub-resources allowed modification linked entities without update permission
CVE-2026-86494 HIGH Patched 7.7 2026-09-07 In JetBrains YouTrack before 2026.2.18634 cloning a whiteboard allowed unauthorized changes to links on inaccessible issues
CVE-2026-86492 HIGH Patched 8.5 2026-09-07 In JetBrains YouTrack before 2026.2.18634 a shared token cache allowed cross-tenant theft of GitHub App installation tokens
CVE-2026-86482 HIGH Patched 8.8 2026-09-07 In JetBrains YouTrack before 2026.2.18634 unchecked group membership changes allowed privilege escalation
CVE-2026-86479 HIGH Patched 8.1 2026-09-07 In JetBrains YouTrack before 2026.2.18788, 2026.1.14055, 2025.3.161254 missing authorisation allowed access to restricted REST API resources via IDOR
CVE-2026-86439 HIGH Patched 8.8 2026-09-07 knowns versions before 0.30.0 fail to validate filesystem paths in MCP tool arguments, allowing attackers to read, create, overwrite and delete files outside the project di&hellip;
CVE-2026-86438 HIGH Patched 7.2 2026-09-07 Lara Dashboard before 1.3.2 fails to authorize the MarketplaceModuleBrowser installModule Livewire action, allowing non-Superadmin administrators to install modules. Attack&hellip;
CVE-2026-86437 HIGH Patched 7.2 2026-09-07 Lara Dashboard before 1.3.2 authorizes the POST /admin/settings/core-upgrades/upload endpoint with only the settings.edit permission, allowing non-Superadmin administrators&hellip;
CVE-2026-86435 HIGH Patched 7.5 2026-09-07 commonmark versions from 1.5.0 before 2.8.4 contain a denial of service vulnerability in the Footnote extension that fails to deduplicate footnote definitions. Attackers ca&hellip;
CVE-2026-86434 HIGH Patched 7.5 2026-09-07 league/commonmark versions >= 2.0.0 and < 2.8.4 (patched in 2.9.0) contain a denial of service vulnerability in UniqueSlugNormalizer::normalize(), which restarts its numeri&hellip;