Export limit exceeded: 404328 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (695 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-108474 | 1 Jetbrains | 1 Exposed | 2026-10-11 | 9.8 Critical |
| In JetBrains Exposed before 1.5.1 sQL injection was possible via unescaped string arguments of several SQL functions | ||||
| CVE-2026-106218 | 1 Jetbrains | 1 Teamcity | 2026-10-08 | 8.8 High |
| In JetBrains TeamCity before 2026.1.3 2025.11.7 kotlin DSL sandbox escape leading to RCE on the server was possible | ||||
| CVE-2026-106219 | 1 Jetbrains | 1 Teamcity | 2026-10-08 | 6.5 Medium |
| In JetBrains TeamCity before 2026.2.1 missing validation of Git submodule URLs allowed reading local repositories on the server | ||||
| CVE-2026-100254 | 1 Jetbrains | 1 Teamcity | 2026-10-06 | 8.8 High |
| In JetBrains TeamCity before 2026.2, 2026.1.4, 2025.11.8 authenticated users could execute commands on Windows servers via CRLF injection in Pipeline Git connection settings | ||||
| CVE-2026-100253 | 1 Jetbrains | 1 Teamcity | 2026-10-06 | 8.8 High |
| In JetBrains TeamCity before 2026.2, 2026.1.4, 2025.11.8 sandbox escape leading to code execution was possible via the versioned settings Kotlin DSL | ||||
| CVE-2026-103488 | 1 Jetbrains | 1 Youtrack | 2026-10-05 | 7.1 High |
| In JetBrains YouTrack before 2026.2.19422 missing authorisation allowed authenticated users to add themselves to project teams and access restricted issues | ||||
| CVE-2026-103489 | 1 Jetbrains | 1 Youtrack | 2026-10-05 | 2 Low |
| In JetBrains YouTrack before 2026.2.19422 hTML injection in VCS command failure notifications was possible | ||||
| CVE-2026-103490 | 1 Jetbrains | 1 Youtrack | 2026-10-05 | 7.2 High |
| In JetBrains YouTrack before 2026.2.19422 privilege escalation was possible via user group links | ||||
| CVE-2026-100255 | 1 Jetbrains | 1 Teamcity | 2026-10-02 | 8.1 High |
| In JetBrains TeamCity before 2026.2, 2026.1.4, 2025.11.8 administrator account takeover was possible via password reset | ||||
| CVE-2026-100256 | 1 Jetbrains | 1 Intellij Idea | 2026-10-02 | 7.8 High |
| In JetBrains IntelliJ IDEA before 2026.2.3 rCE via Structural Search script constraints was possible in untrusted projects | ||||
| CVE-2026-100257 | 1 Jetbrains | 1 Youtrack | 2026-10-02 | 4.3 Medium |
| In JetBrains YouTrack before 2026.2.18991 sSRF via stored XHTML injection was possible during PDF export | ||||
| CVE-2026-100258 | 1 Jetbrains | 1 Youtrack | 2026-10-02 | 4.3 Medium |
| In JetBrains YouTrack before 2026.2.18991 missing authorisation allowed read-only users to read project settings | ||||
| CVE-2026-100259 | 1 Jetbrains | 1 Youtrack | 2026-10-02 | 4.3 Medium |
| In JetBrains YouTrack before 2026.2.18991 improper access control on Gantt chart allowed edits by users with view-only access | ||||
| CVE-2026-100260 | 1 Jetbrains | 1 Youtrack | 2026-10-02 | 5.3 Medium |
| In JetBrains YouTrack before 2026.2.18991 mailbox integration allowed authentication after a password reset | ||||
| CVE-2026-100261 | 1 Jetbrains | 1 Youtrack | 2026-10-02 | 5.4 Medium |
| In JetBrains YouTrack before 2026.2.18991 changing article visibility settings was possible without update permission | ||||
| CVE-2026-100262 | 1 Jetbrains | 1 Youtrack | 2026-10-02 | 7.6 High |
| In JetBrains YouTrack before 2026.2.18991 missing authorisation allowed users with read-only project access to overwrite project notification templates | ||||
| CVE-2026-100263 | 1 Jetbrains | 1 Youtrack | 2026-10-02 | 4.7 Medium |
| In JetBrains YouTrack before 2026.2.18991 stored HTML injection via the User-Agent header was possible | ||||
| CVE-2026-100264 | 1 Jetbrains | 1 Youtrack | 2026-10-02 | 2.7 Low |
| In JetBrains YouTrack before 2026.2.18991 stored SMTP server credentials could be disclosed by changing the server host | ||||
| CVE-2026-100265 | 1 Jetbrains | 1 Rider | 2026-10-02 | 4.8 Medium |
| In JetBrains Rider before 2026.2.1 aI Assistant could auto-update third-party skills without user confirmation | ||||
| CVE-2026-100266 | 1 Jetbrains | 1 Hub | 2026-10-02 | 7.7 High |
| In JetBrains Hub before 2026.2.52366 missing authorisation allowed authenticated users to send arbitrary emails from the server's trusted address | ||||