Export limit exceeded: 387297 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (387297 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-79642 | 2026-09-07 | 5.6 Medium | ||
| Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access. | ||||
| CVE-2026-80127 | 2026-09-07 | 7.2 High | ||
| Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to elevation of privileges. | ||||
| CVE-2026-80058 | 2026-09-07 | 5.5 Medium | ||
| Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Cleartext Storage of Sensitive Information vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to information exposure. | ||||
| CVE-2026-79975 | 2026-09-07 | 5.5 Medium | ||
| Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Certificate Validation vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to server-side request forgery. | ||||
| CVE-2026-80126 | 2026-09-07 | 6.5 Medium | ||
| Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Locking vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to filesystem access for attacker. | ||||
| CVE-2026-86478 | 1 Jetbrains | 1 Youtrack | 2026-09-07 | 9.8 Critical |
| In JetBrains YouTrack before 2025.3.161254, 2026.1.14042 improper authentication in YouTrack Helpdesk allowed unauthenticated account takeover via a self-asserted email address | ||||
| CVE-2026-86479 | 1 Jetbrains | 1 Youtrack | 2026-09-07 | 8 High |
| In JetBrains YouTrack before 2026.2.18788, 2026.1.14055, 2025.3.161254 missing authorisation allowed access to restricted REST API resources via IDOR | ||||
| CVE-2026-86480 | 1 Jetbrains | 1 Hub | 2026-09-07 | 9.8 Critical |
| In JetBrains Hub before 2026.2.52442 an unauthenticated attacker could register a trusted service and gain superuser privileges | ||||
| CVE-2026-86482 | 1 Jetbrains | 1 Youtrack | 2026-09-07 | 8.8 High |
| In JetBrains YouTrack before 2026.2.18634 unchecked group membership changes allowed privilege escalation | ||||
| CVE-2026-86484 | 1 Jetbrains | 1 Youtrack | 2026-09-07 | 4.6 Medium |
| In JetBrains YouTrack before 2026.2.18634 angularJS template injection in assignee names led to stored XSS | ||||
| CVE-2026-86500 | 1 Jetbrains | 1 Youtrack | 2026-09-07 | 5.5 Medium |
| In JetBrains YouTrack before 2026.1.14047 a missing escalation check let a user with project update permissions grant themselves Project Admin | ||||
| CVE-2026-86502 | 1 Jetbrains | 1 Intellij Idea | 2026-09-07 | 8.4 High |
| In JetBrains IntelliJ IDEA before 2026.2.2 missing TLS and authentication on the IJent gRPC server allowed local code execution on Remote Development hosts | ||||
| CVE-2026-86503 | 1 Jetbrains | 1 Intellij Idea | 2026-09-07 | 3.3 Low |
| In JetBrains IntelliJ IDEA before 2026.2.2 opening an untrusted project could trigger SSRF via Kubernetes spec-source URL fetching | ||||
| CVE-2026-86504 | 1 Jetbrains | 1 Intellij Idea | 2026-09-07 | 7.8 High |
| In JetBrains IntelliJ IDEA before 2026.2.2 missing project-trust confirmation before building a Dev Container allowed host-level code execution | ||||
| CVE-2026-86505 | 1 Jetbrains | 1 Intellij Idea | 2026-09-07 | 3.3 Low |
| In JetBrains IntelliJ IDEA before 2026.2.2 missing project-trust check leaked project metadata to JetBrains Marketplace | ||||
| CVE-2026-86506 | 1 Jetbrains | 1 Goland | 2026-09-07 | 5.9 Medium |
| In JetBrains GoLand before 2026.2.2.1 missing authentication on the GoLand profiler's injected pprof server exposed profiling data | ||||
| CVE-2026-86496 | 1 Jetbrains | 1 Youtrack | 2026-09-07 | 4.3 Medium |
| In JetBrains YouTrack before 2026.2.18769 missing access control on Helpdesk authorized reporters exposed reporter email addresses | ||||
| CVE-2026-86497 | 1 Jetbrains | 1 Youtrack | 2026-09-07 | 6.8 Medium |
| In JetBrains YouTrack before 2026.2.18769 changing a mailbox host without re-authentication allowed a project administrator to exfiltrate stored mailbox credentials | ||||
| CVE-2026-86485 | 1 Jetbrains | 1 Youtrack | 2026-09-07 | 3.5 Low |
| In JetBrains YouTrack before 2026.2.18634 iP spoofing via HTTP headers allowed forged Bitbucket webhooks | ||||
| CVE-2026-86487 | 1 Jetbrains | 1 Youtrack | 2026-09-07 | 3.1 Low |
| In JetBrains YouTrack before 2026.2.18634 a crafted WebSocket message allowed read-only whiteboard users to modify canvas content | ||||