CVE search
401,481 resultsCVE-2026-100268HIGHIn JetBrains YouTrack before 2026.2.19197 project administrators could read comments from other projects via notification templatesEPSS 0.2%CVE-2026-100267MEDIUMIn JetBrains YouTrack before 2026.2.19197 reDoS attack was possible via mailbox regex mail-rule filtersEPSS 0.3%CVE-2026-100266HIGHIn JetBrains Hub before 2026.2.52366 missing authorisation allowed authenticated users to send arbitrary emails from the server's trusted adEPSS 0.2%CVE-2026-100265MEDIUMIn JetBrains Rider before 2026.2.1 aI Assistant could auto-update third-party skills without user confirmationEPSS 0.1%CVE-2026-100264LOWIn JetBrains YouTrack before 2026.2.18991 stored SMTP server credentials could be disclosed by changing the server hostEPSS 0.2%CVE-2026-100263MEDIUMIn JetBrains YouTrack before 2026.2.18991 stored HTML injection via the User-Agent header was possibleEPSS 0.2%CVE-2026-100262HIGHIn JetBrains YouTrack before 2026.2.18991 missing authorisation allowed users with read-only project access to overwrite project notificatioEPSS 0.2%CVE-2026-100261MEDIUMIn JetBrains YouTrack before 2026.2.18991 changing article visibility settings was possible without update permissionEPSS 0.2%CVE-2026-100260MEDIUMIn JetBrains YouTrack before 2026.2.18991 mailbox integration allowed authentication after a password resetEPSS 0.3%CVE-2026-100259MEDIUMIn JetBrains YouTrack before 2026.2.18991 improper access control on Gantt chart allowed edits by users with view-only accessEPSS 0.2%CVE-2026-100258MEDIUMIn JetBrains YouTrack before 2026.2.18991 missing authorisation allowed read-only users to read project settingsEPSS 0.7%CVE-2026-100257MEDIUMIn JetBrains YouTrack before 2026.2.18991 sSRF via stored XHTML injection was possible during PDF exportEPSS 0.2%CVE-2026-100256HIGHIn JetBrains IntelliJ IDEA before 2026.2.3 rCE via Structural Search script constraints was possible in untrusted projectsEPSS 0.1%CVE-2026-100255HIGHIn JetBrains TeamCity before 2026.2,
2026.1.4,
2025.11.8 administrator account takeover was possible via password resetEPSS 0.4%CVE-2026-100254HIGHIn JetBrains TeamCity before 2026.2,
2026.1.4,
2025.11.8 authenticated users could execute commands on Windows servers via CRLF injection EPSS 0.5%CVE-2026-100253HIGHIn JetBrains TeamCity before 2026.2,
2026.1.4,
2025.11.8 sandbox escape leading to code execution was possible via the versioned settings EPSS 0.4%CVE-2026-103229MEDIUMAdithyaYelloju Restaurant-Management-System Unauthenticated Action Script delete1.php mysqli_query sql injectionEPSS 0.4%CVE-2026-102427CRITICALJoomla Extension - ordasoft.com - Unauthenticated Remote Code Execution in OrdaSoft Joomla CCK < 8.3.16EPSS 0.8%CVE-2026-94545MEDIUMSatori-generated SVG has improper escapingEPSS 0.8%CVE-2026-103398HIGHOpenSave through 2.4.0 Arbitrary File Read and Write via Peer-Controlled Save PathEPSS 0.3%