CVE search

401,151 results
CVE-2026-100278MEDIUMIn JetBrains YouTrack before 2026.2.19197 users with restricted permission could edit and hide other users' commentsEPSS 0.2%CVE-2026-100277HIGHIn JetBrains YouTrack before 2026.2.19197 account takeover was possible by replaying a notification signatureEPSS 0.3%CVE-2026-100276MEDIUMIn JetBrains YouTrack before 2026.2.19197 guest users could remove a workflow action's visibility restriction and run the actionEPSS 0.2%CVE-2026-100275MEDIUMIn JetBrains YouTrack before 2026.2.19197 stored XSS in the workflow error notification toast was possibleEPSS 0.2%CVE-2026-100274MEDIUMIn JetBrains YouTrack before 2026.2.19197 project Admin could trigger DoS via a notification templateEPSS 0.8%CVE-2026-100273HIGHIn JetBrains YouTrack before 2026.2.19197 authorisation bypass in the scripts debugger allowed arbitrary code executionEPSS 0.3%CVE-2026-100272MEDIUMIn JetBrains YouTrack before 2026.2.19197 missing authorisation in the notification template preview allowed Project Administrators to read EPSS 0.3%CVE-2026-100271LOWIn JetBrains YouTrack before 2026.2.19197 missing authorisation on several endpoints allowed authenticated users to access information from EPSS 0.2%CVE-2026-100270LOWIn JetBrains YouTrack before 2026.2.19197 low-level Admin Read permission users could disclose integration credentials via import configuratEPSS 0.2%CVE-2026-100269MEDIUMIn JetBrains YouTrack before 2026.2.19197 helpdesk project's Authorized Reporters list could be bypassedEPSS 0.2%CVE-2026-100268HIGHIn JetBrains YouTrack before 2026.2.19197 project administrators could read comments from other projects via notification templatesEPSS 0.2%CVE-2026-100267MEDIUMIn JetBrains YouTrack before 2026.2.19197 reDoS attack was possible via mailbox regex mail-rule filtersEPSS 0.3%CVE-2026-100266HIGHIn JetBrains Hub before 2026.2.52366 missing authorisation allowed authenticated users to send arbitrary emails from the server's trusted adEPSS 0.2%CVE-2026-100265MEDIUMIn JetBrains Rider before 2026.2.1 aI Assistant could auto-update third-party skills without user confirmationEPSS 0.1%CVE-2026-100264LOWIn JetBrains YouTrack before 2026.2.18991 stored SMTP server credentials could be disclosed by changing the server hostEPSS 0.2%CVE-2026-100263MEDIUMIn JetBrains YouTrack before 2026.2.18991 stored HTML injection via the User-Agent header was possibleEPSS 0.2%CVE-2026-100262HIGHIn JetBrains YouTrack before 2026.2.18991 missing authorisation allowed users with read-only project access to overwrite project notificatioEPSS 0.2%CVE-2026-100261MEDIUMIn JetBrains YouTrack before 2026.2.18991 changing article visibility settings was possible without update permissionEPSS 0.2%CVE-2026-100260MEDIUMIn JetBrains YouTrack before 2026.2.18991 mailbox integration allowed authentication after a password resetEPSS 0.3%CVE-2026-100259MEDIUMIn JetBrains YouTrack before 2026.2.18991 improper access control on Gantt chart allowed edits by users with view-only accessEPSS 0.2%