Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

674 CVEs · High severity

CVEs (674, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 1–25 of 674 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-9331 HIGH 7.1 2026-09-08 The EDD Product Catalog Feed by PixelYourSite plugin for WordPress is vulnerable to unauthorized modification of data that can lead to a denial of service due to a missing …
CVE-2026-9317 HIGH Patched 8.1 2026-09-04 Nango before 0.71.6 contains a missing authentication vulnerability in the runner tRPC server that allows unauthenticated attackers to execute arbitrary JavaScript code by …
CVE-2026-8862 HIGH 7.5 2026-09-03 IBM Netezza Software 11.3.0.3 through Interim Fix 002 has credentials that are hardcoded in the application source code, allowing unauthorized access to the container regis…
CVE-2026-8712 HIGH Patched 8.3 2026-09-01 Wyoming before 1.10.2 contains a server-side request forgery vulnerability that allows unauthenticated attackers with network access to force outbound connections to arbitr…
CVE-2026-86544 HIGH Patched 8.1 2026-09-07 knowns versions before 0.30.0 contain an authorization bypass vulnerability where mutating code actions are incorrectly classified as read-only operations. Attackers with r…
CVE-2026-86541 HIGH Patched 8.3 2026-09-07 knowns versions before 0.30.0 contain a path traversal vulnerability in the handleCodeReplace() function that allows attackers to overwrite arbitrary files outside the proj…
CVE-2026-86540 HIGH Patched 7.8 2026-09-07 knowns versions before 0.30.0 fail to validate the settings.lsp.languages binary field in project configuration files, allowing attackers to execute arbitrary binaries by c…
CVE-2026-86539 HIGH 7.2 2026-09-07 knowns through 0.33.0 contains a server-side request forgery vulnerability in the POST /api/embedding-models/test endpoint that issues outbound requests to caller-supplied …
CVE-2026-86538 HIGH Patched 7.5 2026-09-07 knowns versions before 0.30.0 contain a path traversal vulnerability in the POST /api/templates/preview endpoint that allows unauthenticated attackers to read arbitrary fil…
CVE-2026-86504 HIGH Patched 7.8 2026-09-07 In JetBrains IntelliJ IDEA before 2026.2.2 missing project-trust confirmation before building a Dev Container allowed host-level code execution
CVE-2026-86502 HIGH Patched 8.4 2026-09-07 In JetBrains IntelliJ IDEA before 2026.2.2 missing TLS and authentication on the IJent gRPC server allowed local code execution on Remote Development hosts
CVE-2026-86498 HIGH Patched 7.7 2026-09-07 In JetBrains YouTrack before 2025.3.160480, 2026.1.14047 pUT requests on link sub-resources allowed modification linked entities without update permission
CVE-2026-86494 HIGH Patched 7.7 2026-09-07 In JetBrains YouTrack before 2026.2.18634 cloning a whiteboard allowed unauthorized changes to links on inaccessible issues
CVE-2026-86492 HIGH Patched 8.5 2026-09-07 In JetBrains YouTrack before 2026.2.18634 a shared token cache allowed cross-tenant theft of GitHub App installation tokens
CVE-2026-86482 HIGH Patched 8.8 2026-09-07 In JetBrains YouTrack before 2026.2.18634 unchecked group membership changes allowed privilege escalation
CVE-2026-86479 HIGH Patched 8.1 2026-09-07 In JetBrains YouTrack before 2026.2.18788, 2026.1.14055, 2025.3.161254 missing authorisation allowed access to restricted REST API resources via IDOR
CVE-2026-86439 HIGH Patched 8.8 2026-09-07 knowns versions before 0.30.0 fail to validate filesystem paths in MCP tool arguments, allowing attackers to read, create, overwrite and delete files outside the project di…
CVE-2026-86438 HIGH Patched 7.2 2026-09-07 Lara Dashboard before 1.3.2 fails to authorize the MarketplaceModuleBrowser installModule Livewire action, allowing non-Superadmin administrators to install modules. Attack…
CVE-2026-86437 HIGH Patched 7.2 2026-09-07 Lara Dashboard before 1.3.2 authorizes the POST /admin/settings/core-upgrades/upload endpoint with only the settings.edit permission, allowing non-Superadmin administrators…
CVE-2026-86435 HIGH Patched 7.5 2026-09-07 commonmark versions from 1.5.0 before 2.8.4 contain a denial of service vulnerability in the Footnote extension that fails to deduplicate footnote definitions. Attackers ca…
CVE-2026-86434 HIGH Patched 7.5 2026-09-07 league/commonmark versions >= 2.0.0 and < 2.8.4 (patched in 2.9.0) contain a denial of service vulnerability in UniqueSlugNormalizer::normalize(), which restarts its numeri&hellip;
CVE-2026-86433 HIGH Patched 7.5 2026-09-07 commonmark versions from 1.5.0 before 2.8.4 contain a denial of service vulnerability in the Attributes extension where AttributesListener::findTargetAndDirection() perform&hellip;
CVE-2026-86431 HIGH Patched 7.2 2026-09-07 league/commonmark (thephpleague/commonmark) versions >= 2.7.0 and < 2.9.1 contain a cross-site scripting vulnerability in the AttributesExtension. Prefixing an attribute na&hellip;
CVE-2026-86430 HIGH Patched 7.5 2026-09-07 league/commonmark versions before 2.9.1 contain multiple denial of service vulnerabilities in fenced code block detection, reference link label lookup, and emphasis delimit&hellip;
CVE-2026-86429 HIGH Patched 7.5 2026-09-07 The league/commonmark (thephpleague/commonmark) library in versions >= 1.5.0 and < 2.9.1 contains quadratic parsing complexity in its SmartPunctExtension and AttributesExte&hellip;