CVE search
401,036 resultsCVE-2026-103494MEDIUMIn JetBrains YouTrack before 2026.2.19422 privilege escalation was possible via user group membership changesEPSS 0.2%CVE-2026-103493HIGHIn JetBrains YouTrack before 2026.2.19422 stored XSS via Mermaid and LaTeX content was possibleEPSS 0.2%CVE-2026-103492MEDIUMIn JetBrains YouTrack before 2026.2.19422 doS attack was possible via crafted PSD attachmentsEPSS 0.7%CVE-2026-103491MEDIUMIn JetBrains YouTrack before 2026.2.19422 iDOR in the issue activities API allowed reading restricted issuesEPSS 0.2%CVE-2026-103490HIGHIn JetBrains YouTrack before 2026.2.19422 privilege escalation was possible via user group linksEPSS 0.4%CVE-2026-103489LOWIn JetBrains YouTrack before 2026.2.19422 hTML injection in VCS command failure notifications was possibleEPSS 0.1%CVE-2026-103488HIGHIn JetBrains YouTrack before 2026.2.19422 missing authorisation allowed authenticated users to add themselves to project teams and access reEPSS 0.3%CVE-2026-103664MEDIUMMISP Reflected Cross-Site Scripting via Unsanitized Analyst Data Seed ParameterEPSS 0.3%CVE-2026-103662MEDIUMMISP Reflected XSS in Taxonomy Tag Confirmation FormsEPSS 0.3%CVE-2026-103431HIGHCollectl: collectl: colmux does not sanitize ansi/vt100 terminal escape sequences in data received from remote collectl instancesEPSS 0.2%CVE-2026-103659HIGHMISP: Object Distribution ACL Bypass via Event Flattening Exposes Organisation-Only AttributesEPSS 0.2%CVE-2026-97661HIGHBusiness Essentials for Contact Form 7 <= 1.2.1 - Unauthenticated Stored Cross-Site Scripting via 'gateway' Form FieldEPSS 0.2%CVE-2026-89424MEDIUMDuplicate Post <= 1.5.6 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'noti_token' ParameterEPSS 0.2%CVE-2026-89427MEDIUMAd Inserter <= 2.8.18 - Reflected Cross-Site Scripting via 's' Search ParameterEPSS 0.3%CVE-2026-96813HIGHForm Maker by 10Web <= 1.15.47 - Unauthenticated Stored Cross-Site Scripting via Mark on Map Longitude/Latitude FieldsEPSS 0.3%CVE-2026-100184MEDIUMCalculated Fields Form <= 5.5.1.3 - Reflected DOM-Based Cross-Site Scripting via 'x' URL Query Parameter via Text Area Predefined ValueEPSS 0.2%CVE-2026-96268MEDIUMAwesome Support <= 6.4.0 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'gdpr-data' Parameter via wpas_gdpr_user_opt_out AJAX ActionEPSS 0.2%CVE-2026-95687HIGHWPC Shop as a Customer for WooCommerce <= 2.0.0 - Authenticated (Subscriber+) Privilege Escalation via Missing Role Check on Target User to wpcsa_login AJAX EndpointEPSS 0.5%CVE-2026-101925MEDIUMbbp style pack <= 6.4.8 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Author Display NameEPSS 0.2%CVE-2026-96573HIGHAppointment Hour Booking <= 1.5.97 - Unauthenticated Stored DOM-Based Cross-Site Scripting via Booking Form Single-Line Field via Schedule Calendar List RendererEPSS 0.3%