Search
674 CVEs · High severity
CVEs (674, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 1–25 of 674 (capped at 500)
| CVE ID ↓ | Severity | Patch | CVSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-9331 | HIGH | 7.1 | 2026-09-08 | The EDD Product Catalog Feed by PixelYourSite plugin for WordPress is vulnerable to unauthorized modification of data that can lead to a denial of service due to a missing … | |
| CVE-2026-9317 | HIGH | Patched | 8.1 | 2026-09-04 | Nango before 0.71.6 contains a missing authentication vulnerability in the runner tRPC server that allows unauthenticated attackers to execute arbitrary JavaScript code by … |
| CVE-2026-8862 | HIGH | 7.5 | 2026-09-03 | IBM Netezza Software 11.3.0.3 through Interim Fix 002 has credentials that are hardcoded in the application source code, allowing unauthorized access to the container regis… | |
| CVE-2026-8712 | HIGH | Patched | 8.3 | 2026-09-01 | Wyoming before 1.10.2 contains a server-side request forgery vulnerability that allows unauthenticated attackers with network access to force outbound connections to arbitr… |
| CVE-2026-86544 | HIGH | Patched | 8.1 | 2026-09-07 | knowns versions before 0.30.0 contain an authorization bypass vulnerability where mutating code actions are incorrectly classified as read-only operations. Attackers with r… |
| CVE-2026-86541 | HIGH | Patched | 8.3 | 2026-09-07 | knowns versions before 0.30.0 contain a path traversal vulnerability in the handleCodeReplace() function that allows attackers to overwrite arbitrary files outside the proj… |
| CVE-2026-86540 | HIGH | Patched | 7.8 | 2026-09-07 | knowns versions before 0.30.0 fail to validate the settings.lsp.languages binary field in project configuration files, allowing attackers to execute arbitrary binaries by c… |
| CVE-2026-86539 | HIGH | 7.2 | 2026-09-07 | knowns through 0.33.0 contains a server-side request forgery vulnerability in the POST /api/embedding-models/test endpoint that issues outbound requests to caller-supplied … | |
| CVE-2026-86538 | HIGH | Patched | 7.5 | 2026-09-07 | knowns versions before 0.30.0 contain a path traversal vulnerability in the POST /api/templates/preview endpoint that allows unauthenticated attackers to read arbitrary fil… |
| CVE-2026-86504 | HIGH | Patched | 7.8 | 2026-09-07 | In JetBrains IntelliJ IDEA before 2026.2.2 missing project-trust confirmation before building a Dev Container allowed host-level code execution |
| CVE-2026-86502 | HIGH | Patched | 8.4 | 2026-09-07 | In JetBrains IntelliJ IDEA before 2026.2.2 missing TLS and authentication on the IJent gRPC server allowed local code execution on Remote Development hosts |
| CVE-2026-86498 | HIGH | Patched | 7.7 | 2026-09-07 | In JetBrains YouTrack before 2025.3.160480, 2026.1.14047 pUT requests on link sub-resources allowed modification linked entities without update permission |
| CVE-2026-86494 | HIGH | Patched | 7.7 | 2026-09-07 | In JetBrains YouTrack before 2026.2.18634 cloning a whiteboard allowed unauthorized changes to links on inaccessible issues |
| CVE-2026-86492 | HIGH | Patched | 8.5 | 2026-09-07 | In JetBrains YouTrack before 2026.2.18634 a shared token cache allowed cross-tenant theft of GitHub App installation tokens |
| CVE-2026-86482 | HIGH | Patched | 8.8 | 2026-09-07 | In JetBrains YouTrack before 2026.2.18634 unchecked group membership changes allowed privilege escalation |
| CVE-2026-86479 | HIGH | Patched | 8.1 | 2026-09-07 | In JetBrains YouTrack before 2026.2.18788, 2026.1.14055, 2025.3.161254 missing authorisation allowed access to restricted REST API resources via IDOR |
| CVE-2026-86439 | HIGH | Patched | 8.8 | 2026-09-07 | knowns versions before 0.30.0 fail to validate filesystem paths in MCP tool arguments, allowing attackers to read, create, overwrite and delete files outside the project di… |
| CVE-2026-86438 | HIGH | Patched | 7.2 | 2026-09-07 | Lara Dashboard before 1.3.2 fails to authorize the MarketplaceModuleBrowser installModule Livewire action, allowing non-Superadmin administrators to install modules. Attack… |
| CVE-2026-86437 | HIGH | Patched | 7.2 | 2026-09-07 | Lara Dashboard before 1.3.2 authorizes the POST /admin/settings/core-upgrades/upload endpoint with only the settings.edit permission, allowing non-Superadmin administrators… |
| CVE-2026-86435 | HIGH | Patched | 7.5 | 2026-09-07 | commonmark versions from 1.5.0 before 2.8.4 contain a denial of service vulnerability in the Footnote extension that fails to deduplicate footnote definitions. Attackers ca… |
| CVE-2026-86434 | HIGH | Patched | 7.5 | 2026-09-07 | league/commonmark versions >= 2.0.0 and < 2.8.4 (patched in 2.9.0) contain a denial of service vulnerability in UniqueSlugNormalizer::normalize(), which restarts its numeri… |
| CVE-2026-86433 | HIGH | Patched | 7.5 | 2026-09-07 | commonmark versions from 1.5.0 before 2.8.4 contain a denial of service vulnerability in the Attributes extension where AttributesListener::findTargetAndDirection() perform… |
| CVE-2026-86431 | HIGH | Patched | 7.2 | 2026-09-07 | league/commonmark (thephpleague/commonmark) versions >= 2.7.0 and < 2.9.1 contain a cross-site scripting vulnerability in the AttributesExtension. Prefixing an attribute na… |
| CVE-2026-86430 | HIGH | Patched | 7.5 | 2026-09-07 | league/commonmark versions before 2.9.1 contain multiple denial of service vulnerabilities in fenced code block detection, reference link label lookup, and emphasis delimit… |
| CVE-2026-86429 | HIGH | Patched | 7.5 | 2026-09-07 | The league/commonmark (thephpleague/commonmark) library in versions >= 1.5.0 and < 2.9.1 contains quadratic parsing complexity in its SmartPunctExtension and AttributesExte… |