Export limit exceeded: 388881 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 388881 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (388881 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-86493 | 1 Jetbrains | 1 Youtrack | 2026-09-08 | 6.5 Medium |
| In JetBrains YouTrack before 2026.2.18634 improper permission checks allowed read-only users to create and modify whiteboard cards | ||||
| CVE-2026-86492 | 1 Jetbrains | 1 Youtrack | 2026-09-08 | 8.5 High |
| In JetBrains YouTrack before 2026.2.18634 a shared token cache allowed cross-tenant theft of GitHub App installation tokens | ||||
| CVE-2026-86491 | 1 Jetbrains | 1 Youtrack | 2026-09-08 | 3.5 Low |
| In JetBrains YouTrack before 2026.2.18634 stored XSS was possible via project and organization icon uploads | ||||
| CVE-2026-86490 | 1 Jetbrains | 1 Youtrack | 2026-09-08 | 6.5 Medium |
| In JetBrains YouTrack before 2026.2.18634 improper permission checks allowed overwriting of bundled apps via the app import endpoint | ||||
| CVE-2026-86489 | 1 Jetbrains | 1 Youtrack | 2026-09-08 | 6.5 Medium |
| In JetBrains YouTrack before 2026.2.18634 an IDOR in the user profile API disclosed private issues and starred folders across organizations | ||||
| CVE-2026-86488 | 1 Jetbrains | 1 Youtrack | 2026-09-08 | 6.5 Medium |
| In JetBrains YouTrack before 2026.2.18634 iDOR via the watchRules and issueListConfig endpoints exposed private saved searches | ||||
| CVE-2026-86487 | 1 Jetbrains | 1 Youtrack | 2026-09-08 | 3.1 Low |
| In JetBrains YouTrack before 2026.2.18634 a crafted WebSocket message allowed read-only whiteboard users to modify canvas content | ||||
| CVE-2026-86486 | 1 Jetbrains | 1 Youtrack | 2026-09-08 | 3.7 Low |
| In JetBrains YouTrack before 2026.2.18634 the generic VCS webhook handler failed open when its secret was blank | ||||
| CVE-2026-86485 | 1 Jetbrains | 1 Youtrack | 2026-09-08 | 3.5 Low |
| In JetBrains YouTrack before 2026.2.18634 iP spoofing via HTTP headers allowed forged Bitbucket webhooks | ||||
| CVE-2026-86484 | 1 Jetbrains | 1 Youtrack | 2026-09-08 | 4.6 Medium |
| In JetBrains YouTrack before 2026.2.18634 angularJS template injection in assignee names led to stored XSS | ||||
| CVE-2026-86483 | 1 Jetbrains | 1 Youtrack | 2026-09-08 | 5.4 Medium |
| In JetBrains YouTrack before 2026.2.18634 stored XSS via a custom field on Agile board cards was possible | ||||
| CVE-2026-86482 | 1 Jetbrains | 1 Youtrack | 2026-09-08 | 8.8 High |
| In JetBrains YouTrack before 2026.2.18634 unchecked group membership changes allowed privilege escalation | ||||
| CVE-2026-86481 | 1 Jetbrains | 1 Youtrack | 2026-09-08 | 4.3 Medium |
| In JetBrains YouTrack before 2026.2.18634 signed URL reuse allowed disclosure of restricted project icons | ||||
| CVE-2026-86480 | 1 Jetbrains | 1 Hub | 2026-09-08 | 9.8 Critical |
| In JetBrains Hub before 2026.2.52442 an unauthenticated attacker could register a trusted service and gain superuser privileges | ||||
| CVE-2026-86479 | 1 Jetbrains | 1 Youtrack | 2026-09-08 | 8 High |
| In JetBrains YouTrack before 2026.2.18788, 2026.1.14055, 2025.3.161254 missing authorisation allowed access to restricted REST API resources via IDOR | ||||
| CVE-2026-86478 | 1 Jetbrains | 1 Youtrack | 2026-09-08 | 9.8 Critical |
| In JetBrains YouTrack before 2025.3.161254, 2026.1.14042 improper authentication in YouTrack Helpdesk allowed unauthenticated account takeover via a self-asserted email address | ||||
| CVE-2026-86206 | 1 N-able | 1 N-central | 2026-09-08 | N/A |
| A vulnerability in the N-central internal API access control filter allows unauthorised access to internal APIs. This is fixed in N-central 2026.3 HF3 and 2026.4 | ||||
| CVE-2026-84820 | 2 Unlimited-elements, Wordpress | 2 Unlimited Elements For Elementor (free Widgets, Addons, Templates), Wordpress | 2026-09-08 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 2.0.17 versions. | ||||
| CVE-2026-84818 | 2 100plugins, Wordpress | 2 Open User Map, Wordpress | 2026-09-08 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Open User Map <= 1.4.50 versions. | ||||
| CVE-2026-84817 | 2 Crocoblock, Wordpress | 2 Jetformbuilder, Wordpress | 2026-09-08 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in JetFormBuilder <= 3.6.5.1 versions. | ||||