Export limit exceeded: 400056 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (400056 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-100268 | 2026-09-30 | 7.7 High | ||
| In JetBrains YouTrack before 2026.2.19197 project administrators could read comments from other projects via notification templates | ||||
| CVE-2026-100267 | 2026-09-30 | 5.9 Medium | ||
| In JetBrains YouTrack before 2026.2.19197 reDoS attack was possible via mailbox regex mail-rule filters | ||||
| CVE-2026-100266 | 2026-09-30 | 7.7 High | ||
| In JetBrains Hub before 2026.2.52366 missing authorisation allowed authenticated users to send arbitrary emails from the server's trusted address | ||||
| CVE-2026-100265 | 2026-09-30 | 4.8 Medium | ||
| In JetBrains Rider before 2026.2.1 aI Assistant could auto-update third-party skills without user confirmation | ||||
| CVE-2026-100264 | 2026-09-30 | 2.7 Low | ||
| In JetBrains YouTrack before 2026.2.18991 stored SMTP server credentials could be disclosed by changing the server host | ||||
| CVE-2026-100263 | 2026-09-30 | 4.7 Medium | ||
| In JetBrains YouTrack before 2026.2.18991 stored HTML injection via the User-Agent header was possible | ||||
| CVE-2026-100262 | 2026-09-30 | 7.6 High | ||
| In JetBrains YouTrack before 2026.2.18991 missing authorisation allowed users with read-only project access to overwrite project notification templates | ||||
| CVE-2026-100261 | 2026-09-30 | 5.4 Medium | ||
| In JetBrains YouTrack before 2026.2.18991 changing article visibility settings was possible without update permission | ||||
| CVE-2026-100260 | 2026-09-30 | 5.3 Medium | ||
| In JetBrains YouTrack before 2026.2.18991 mailbox integration allowed authentication after a password reset | ||||
| CVE-2026-100259 | 2026-09-30 | 4.3 Medium | ||
| In JetBrains YouTrack before 2026.2.18991 improper access control on Gantt chart allowed edits by users with view-only access | ||||
| CVE-2026-100258 | 2026-09-30 | 4.3 Medium | ||
| In JetBrains YouTrack before 2026.2.18991 missing authorisation allowed read-only users to read project settings | ||||
| CVE-2026-100257 | 2026-09-30 | 4.3 Medium | ||
| In JetBrains YouTrack before 2026.2.18991 sSRF via stored XHTML injection was possible during PDF export | ||||
| CVE-2026-100256 | 2026-09-30 | 7.8 High | ||
| In JetBrains IntelliJ IDEA before 2026.2.3 rCE via Structural Search script constraints was possible in untrusted projects | ||||
| CVE-2026-100255 | 2026-09-30 | 8.1 High | ||
| In JetBrains TeamCity before 2026.2, 2026.1.4, 2025.11.8 administrator account takeover was possible via password reset | ||||
| CVE-2026-100254 | 2026-09-30 | 8.8 High | ||
| In JetBrains TeamCity before 2026.2, 2026.1.4, 2025.11.8 authenticated users could execute commands on Windows servers via CRLF injection in Pipeline Git connection settings | ||||
| CVE-2026-100253 | 2026-09-30 | 8.8 High | ||
| In JetBrains TeamCity before 2026.2, 2026.1.4, 2025.11.8 sandbox escape leading to code execution was possible via the versioned settings Kotlin DSL | ||||
| CVE-2026-100642 | 2 B3log, Siyuan | 2 Siyuan, Siyuan | 2026-09-30 | 7.6 High |
| SiYuan versions from v2.1.0 before v3.8.4 contain a cross-site request forgery vulnerability in the CheckAuth lock-screen pass-through branch that grants administrator access to loopback requests without validating Origin headers. Attackers can craft malicious web pages that force victims to terminate the kernel process, read workspace configuration and proxy settings, and trigger administrative actions via zero-credential cross-origin requests from the victim's browser. | ||||
| CVE-2026-102584 | 1 Moodle | 1 Moodle | 2026-09-30 | 4.3 Medium |
| A flaw was found in Moodle. Due to a missing capability check, a low-privileged authenticated user can trigger the recalculation of grade penalties without holding the required permissions. This issue allows unauthorized users to modify grade penalty records, potentially altering student assessment scores. | ||||
| CVE-2026-103229 | 1 Adithyayelloju | 1 Restaurant-management-system | 2026-09-30 | 7.3 High |
| A vulnerability was found in AdithyaYelloju Restaurant-Management-System up to 7f0e7e84255e8fcfd488e83f8f91451bbbff6b9c. This issue affects the function mysqli_query of the file admin/delete1.php of the component Unauthenticated Action Script. Performing a manipulation of the argument ID results in sql injection. The attack can be initiated remotely. The exploit has been made public and could be used. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available. The project was informed of the problem early through an issue report but has not responded yet. | ||||
| CVE-2026-102427 | 2026-09-30 | N/A | ||
| Joomla Extension - ordasoft.com - Unauthenticated Remote Code Execution in OrdaSoft Joomla CCK < 8.3.16 - site/uploader.php is reached through the component’s normal frontend routing (task=getContent), a task with no authentication or ACL check anywhere in the dispatch chain. The handler validates the uploaded file’s content with a real magic-byte MIME check, but the extension allow-list that would otherwise restrict the saved file’s extension was present in the source and commented out. The saved file’s extension was taken directly from the attacker-supplied filename with no validation, and the file was written to a path directly under the Joomla web root that is executed by the PHP handler. An image/PHP polyglot, a file whose header bytes satisfy the MIME check with PHP source appended after, passed the content check while carrying a .php extension of the attacker’s choosing. | ||||