Export limit exceeded: 388850 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 388850 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (388850 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-86490 | 1 Jetbrains | 1 Youtrack | 2026-09-08 | 6.5 Medium |
| In JetBrains YouTrack before 2026.2.18634 improper permission checks allowed overwriting of bundled apps via the app import endpoint | ||||
| CVE-2026-86489 | 1 Jetbrains | 1 Youtrack | 2026-09-08 | 6.5 Medium |
| In JetBrains YouTrack before 2026.2.18634 an IDOR in the user profile API disclosed private issues and starred folders across organizations | ||||
| CVE-2026-86488 | 1 Jetbrains | 1 Youtrack | 2026-09-08 | 6.5 Medium |
| In JetBrains YouTrack before 2026.2.18634 iDOR via the watchRules and issueListConfig endpoints exposed private saved searches | ||||
| CVE-2026-86487 | 1 Jetbrains | 1 Youtrack | 2026-09-08 | 3.1 Low |
| In JetBrains YouTrack before 2026.2.18634 a crafted WebSocket message allowed read-only whiteboard users to modify canvas content | ||||
| CVE-2026-86486 | 1 Jetbrains | 1 Youtrack | 2026-09-08 | 3.7 Low |
| In JetBrains YouTrack before 2026.2.18634 the generic VCS webhook handler failed open when its secret was blank | ||||
| CVE-2026-86485 | 1 Jetbrains | 1 Youtrack | 2026-09-08 | 3.5 Low |
| In JetBrains YouTrack before 2026.2.18634 iP spoofing via HTTP headers allowed forged Bitbucket webhooks | ||||
| CVE-2026-86484 | 1 Jetbrains | 1 Youtrack | 2026-09-08 | 4.6 Medium |
| In JetBrains YouTrack before 2026.2.18634 angularJS template injection in assignee names led to stored XSS | ||||
| CVE-2026-86483 | 1 Jetbrains | 1 Youtrack | 2026-09-08 | 5.4 Medium |
| In JetBrains YouTrack before 2026.2.18634 stored XSS via a custom field on Agile board cards was possible | ||||
| CVE-2026-86482 | 1 Jetbrains | 1 Youtrack | 2026-09-08 | 8.8 High |
| In JetBrains YouTrack before 2026.2.18634 unchecked group membership changes allowed privilege escalation | ||||
| CVE-2026-86481 | 1 Jetbrains | 1 Youtrack | 2026-09-08 | 4.3 Medium |
| In JetBrains YouTrack before 2026.2.18634 signed URL reuse allowed disclosure of restricted project icons | ||||
| CVE-2026-86480 | 1 Jetbrains | 1 Hub | 2026-09-08 | 9.8 Critical |
| In JetBrains Hub before 2026.2.52442 an unauthenticated attacker could register a trusted service and gain superuser privileges | ||||
| CVE-2026-86479 | 1 Jetbrains | 1 Youtrack | 2026-09-08 | 8 High |
| In JetBrains YouTrack before 2026.2.18788, 2026.1.14055, 2025.3.161254 missing authorisation allowed access to restricted REST API resources via IDOR | ||||
| CVE-2026-86478 | 1 Jetbrains | 1 Youtrack | 2026-09-08 | 9.8 Critical |
| In JetBrains YouTrack before 2025.3.161254, 2026.1.14042 improper authentication in YouTrack Helpdesk allowed unauthenticated account takeover via a self-asserted email address | ||||
| CVE-2026-86206 | 1 N-able | 1 N-central | 2026-09-08 | N/A |
| A vulnerability in the N-central internal API access control filter allows unauthorised access to internal APIs. This is fixed in N-central 2026.3 HF3 and 2026.4 | ||||
| CVE-2026-84820 | 2 Unlimited-elements, Wordpress | 2 Unlimited Elements For Elementor (free Widgets, Addons, Templates), Wordpress | 2026-09-08 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 2.0.17 versions. | ||||
| CVE-2026-84818 | 2 100plugins, Wordpress | 2 Open User Map, Wordpress | 2026-09-08 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Open User Map <= 1.4.50 versions. | ||||
| CVE-2026-84817 | 2 Crocoblock, Wordpress | 2 Jetformbuilder, Wordpress | 2026-09-08 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in JetFormBuilder <= 3.6.5.1 versions. | ||||
| CVE-2026-83534 | 1 Dalibo | 1 Postgresql Anonymizer | 2026-09-08 | 6.4 Medium |
| PostgreSQL Anonymizer contains a vulnerability in the anon.anonymize_database_parallel() function that allows the owner of a table to run arbitrary code with superuser privilege. The issue is fixed in PostgreSQL Anonymizer 3.2.0 and later versions | ||||
| CVE-2026-81806 | 2 John Darrel, Wordpress | 2 Hide My Wp Ghost, Wordpress | 2026-09-08 | 7.2 High |
| Server-Side Request Forgery (SSRF) vulnerability in John Darrel Hide My WP Ghost allows Server Side Request Forgery. This issue affects Hide My WP Ghost: from n/a through 7.0.09. | ||||
| CVE-2026-81798 | 2 Easy-appointments, Wordpress | 2 Easy Appointments, Wordpress | 2026-09-08 | 7.1 High |
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Easy Appointments allows DOM-Based XSS. This issue affects Easy Appointments: from n/a through 4.0.2.1. | ||||