CVE search
401,451 resultsCVE-2026-100258MEDIUMIn JetBrains YouTrack before 2026.2.18991 missing authorisation allowed read-only users to read project settingsEPSS 0.7%CVE-2026-100257MEDIUMIn JetBrains YouTrack before 2026.2.18991 sSRF via stored XHTML injection was possible during PDF exportEPSS 0.2%CVE-2026-100256HIGHIn JetBrains IntelliJ IDEA before 2026.2.3 rCE via Structural Search script constraints was possible in untrusted projectsEPSS 0.1%CVE-2026-100255HIGHIn JetBrains TeamCity before 2026.2,
2026.1.4,
2025.11.8 administrator account takeover was possible via password resetEPSS 0.4%CVE-2026-100254HIGHIn JetBrains TeamCity before 2026.2,
2026.1.4,
2025.11.8 authenticated users could execute commands on Windows servers via CRLF injection EPSS 0.5%CVE-2026-100253HIGHIn JetBrains TeamCity before 2026.2,
2026.1.4,
2025.11.8 sandbox escape leading to code execution was possible via the versioned settings EPSS 0.4%CVE-2026-103229MEDIUMAdithyaYelloju Restaurant-Management-System Unauthenticated Action Script delete1.php mysqli_query sql injectionEPSS 0.4%CVE-2026-102427CRITICALJoomla Extension - ordasoft.com - Unauthenticated Remote Code Execution in OrdaSoft Joomla CCK < 8.3.16EPSS 0.8%CVE-2026-94545MEDIUMSatori-generated SVG has improper escapingEPSS 0.8%CVE-2026-103398HIGHOpenSave through 2.4.0 Arbitrary File Read and Write via Peer-Controlled Save PathEPSS 0.3%CVE-2026-103397MEDIUMOpenSave before 2.4.0-beta.1 Authentication Bypass via Spoofed Relay SenderEPSS 0.2%CVE-2026-103396MEDIUMbbs-go through 4.4.6 Incorrect Authorization via /api/admin/user/synccountEPSS 0.3%CVE-2026-103395CRITICALLightLLM through 1.2.0 Unauthenticated Remote Code Execution via Visual-Only RPyC ServiceEPSS 0.6%CVE-2026-103270HIGHLightLLM through 1.2.0 Missing Authentication on RL Control RoutesEPSS 0.5%CVE-2026-103243MEDIUMLightLLM through 1.2.0 Server-Side Request Forgery via multimodal endpointsEPSS 0.2%CVE-2026-76570CRITICALJoomla Extension - joomcode.com - Unauthenticated SQL injection in read and write queries in JCTables < 1.21.1EPSS 0.5%CVE-2026-102984HIGHAstro: Malformed port in the Host header can crash the Node adapterEPSS 0.4%CVE-2026-102983MEDIUMAstro: Netlify Image CDN allowlist bypass enables SSRFEPSS 0.3%CVE-2026-102717HIGHMQTT WebSocket setter ABI mismatch may disclose memory or cause a crashEPSS 0.3%CVE-2026-47097HIGHAJA HELO Plus < 2.1.7 Hardcoded AES Passphrase for Diagnostics Export BundleEPSS 0.4%