CVE Feed

    Dashboard / CVE

    7.6
    High

    CVE-2026-79639

    Last Modified: 8 Sept 2026

    Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access.

    Published: 7 Sept 2026
    5.9
    Medium

    CVE-2026-86506

    Last Modified: 8 Sept 2026

    In JetBrains GoLand before 2026.2.2.1 missing authentication on the GoLand profiler's injected pprof server exposed profiling data

    Published: 7 Sept 2026
    3.3
    Low

    CVE-2026-86505

    Last Modified: 8 Sept 2026

    In JetBrains IntelliJ IDEA before 2026.2.2 missing project-trust check leaked project metadata to JetBrains Marketplace

    Published: 7 Sept 2026
    7.8
    High

    CVE-2026-86504

    Last Modified: 8 Sept 2026

    In JetBrains IntelliJ IDEA before 2026.2.2 missing project-trust confirmation before building a Dev Container allowed host-level code execution

    Published: 7 Sept 2026
    3.3
    Low

    CVE-2026-86503

    Last Modified: 8 Sept 2026

    In JetBrains IntelliJ IDEA before 2026.2.2 opening an untrusted project could trigger SSRF via Kubernetes spec-source URL fetching

    Published: 7 Sept 2026
    8.4
    High

    CVE-2026-86502

    Last Modified: 8 Sept 2026

    In JetBrains IntelliJ IDEA before 2026.2.2 missing TLS and authentication on the IJent gRPC server allowed local code execution on Remote Development hosts

    Published: 7 Sept 2026
    2.8
    Low

    CVE-2026-86501

    Last Modified: 8 Sept 2026

    In JetBrains IntelliJ IDEA before 2026.2.2 terminal command input could be written to idea.log

    Published: 7 Sept 2026
    5.5
    Medium

    CVE-2026-86500

    Last Modified: 8 Sept 2026

    In JetBrains YouTrack before 2026.1.14047 a missing escalation check let a user with project update permissions grant themselves Project Admin

    Published: 7 Sept 2026
    4.3
    Medium

    CVE-2026-86499

    Last Modified: 8 Sept 2026

    In JetBrains YouTrack before 2026.1.14047 predefined search fields leaked all group names to any user, regardless of visibility permission

    Published: 7 Sept 2026
    7.7
    High

    CVE-2026-86498

    Last Modified: 8 Sept 2026

    In JetBrains YouTrack before 2025.3.160480, 2026.1.14047 pUT requests on link sub-resources allowed modification linked entities without update permission

    Published: 7 Sept 2026
    6.8
    Medium

    CVE-2026-86497

    Last Modified: 8 Sept 2026

    In JetBrains YouTrack before 2026.2.18769 changing a mailbox host without re-authentication allowed a project administrator to exfiltrate stored mailbox credentials

    Published: 7 Sept 2026
    4.3
    Medium

    CVE-2026-86496

    Last Modified: 8 Sept 2026

    In JetBrains YouTrack before 2026.2.18769 missing access control on Helpdesk authorized reporters exposed reporter email addresses

    Published: 7 Sept 2026
    6.5
    Medium

    CVE-2026-86495

    Last Modified: 8 Sept 2026

    In JetBrains YouTrack before 2026.2.18687 missing permission checks allowed creating knowledge base articles in inaccessible projects

    Published: 7 Sept 2026
    7.7
    High

    CVE-2026-86494

    Last Modified: 8 Sept 2026

    In JetBrains YouTrack before 2026.2.18634 cloning a whiteboard allowed unauthorized changes to links on inaccessible issues

    Published: 7 Sept 2026
    6.5
    Medium

    CVE-2026-86493

    Last Modified: 8 Sept 2026

    In JetBrains YouTrack before 2026.2.18634 improper permission checks allowed read-only users to create and modify whiteboard cards

    Published: 7 Sept 2026
    8.5
    High

    CVE-2026-86492

    Last Modified: 8 Sept 2026

    In JetBrains YouTrack before 2026.2.18634 a shared token cache allowed cross-tenant theft of GitHub App installation tokens

    Published: 7 Sept 2026
    3.5
    Low

    CVE-2026-86491

    Last Modified: 8 Sept 2026

    In JetBrains YouTrack before 2026.2.18634 stored XSS was possible via project and organization icon uploads

    Published: 7 Sept 2026
    6.5
    Medium

    CVE-2026-86490

    Last Modified: 8 Sept 2026

    In JetBrains YouTrack before 2026.2.18634 improper permission checks allowed overwriting of bundled apps via the app import endpoint

    Published: 7 Sept 2026
    6.5
    Medium

    CVE-2026-86489

    Last Modified: 8 Sept 2026

    In JetBrains YouTrack before 2026.2.18634 an IDOR in the user profile API disclosed private issues and starred folders across organizations

    Published: 7 Sept 2026
    6.5
    Medium

    CVE-2026-86488

    Last Modified: 8 Sept 2026

    In JetBrains YouTrack before 2026.2.18634 iDOR via the watchRules and issueListConfig endpoints exposed private saved searches

    Published: 7 Sept 2026
    3.1
    Low

    CVE-2026-86487

    Last Modified: 8 Sept 2026

    In JetBrains YouTrack before 2026.2.18634 a crafted WebSocket message allowed read-only whiteboard users to modify canvas content

    Published: 7 Sept 2026
    3.7
    Low

    CVE-2026-86486

    Last Modified: 8 Sept 2026

    In JetBrains YouTrack before 2026.2.18634 the generic VCS webhook handler failed open when its secret was blank

    Published: 7 Sept 2026
    3.3
    Low

    CVE-2026-86485

    Last Modified: 8 Sept 2026

    In JetBrains YouTrack before 2026.2.18634 iP spoofing via HTTP headers allowed forged Bitbucket webhooks

    Published: 7 Sept 2026
    4.6
    Medium

    CVE-2026-86484

    Last Modified: 8 Sept 2026

    In JetBrains YouTrack before 2026.2.18634 angularJS template injection in assignee names led to stored XSS

    Published: 7 Sept 2026
    5.4
    Medium

    CVE-2026-86483

    Last Modified: 8 Sept 2026

    In JetBrains YouTrack before 2026.2.18634 stored XSS via a custom field on Agile board cards was possible

    Published: 7 Sept 2026
    8.8
    High

    CVE-2026-86482

    Last Modified: 8 Sept 2026

    In JetBrains YouTrack before 2026.2.18634 unchecked group membership changes allowed privilege escalation

    Published: 7 Sept 2026
    4.3
    Medium

    CVE-2026-86481

    Last Modified: 8 Sept 2026

    In JetBrains YouTrack before 2026.2.18634 signed URL reuse allowed disclosure of restricted project icons

    Published: 7 Sept 2026
    9.8
    Critical

    CVE-2026-86480

    Last Modified: 8 Sept 2026

    In JetBrains Hub before 2026.2.52442 an unauthenticated attacker could register a trusted service and gain superuser privileges

    Published: 7 Sept 2026
    8.1
    High

    CVE-2026-86479

    Last Modified: 8 Sept 2026

    In JetBrains YouTrack before 2026.2.18788, 2026.1.14055, 2025.3.161254 missing authorisation allowed access to restricted REST API resources via IDOR

    Published: 7 Sept 2026
    9.8
    Critical

    CVE-2026-86478

    Last Modified: 8 Sept 2026

    In JetBrains YouTrack before 2025.3.161254, 2026.1.14042 improper authentication in YouTrack Helpdesk allowed unauthenticated account takeover via a self-asserted email address

    Published: 7 Sept 2026
    5.9
    Medium

    CVE-2026-80125

    Last Modified: 9 Sept 2026

    Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access.

    Published: 7 Sept 2026
    5.5
    Medium

    CVE-2026-80167

    Last Modified: 8 Sept 2026

    Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Use of Hard-coded Cryptographic Key vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to information disclosure.

    Published: 7 Sept 2026
    6.5
    Medium

    CVE-2026-80126

    Last Modified: 8 Sept 2026

    Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Locking vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to filesystem access for attacker.

    Published: 7 Sept 2026
    5.5
    Medium

    CVE-2026-79975

    Last Modified: 8 Sept 2026

    Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Certificate Validation vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to server-side request forgery.

    Published: 7 Sept 2026
    5.5
    Medium

    CVE-2026-80058

    Last Modified: 9 Sept 2026

    Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Cleartext Storage of Sensitive Information vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to information exposure.

    Published: 7 Sept 2026
    7.2
    High

    CVE-2026-80127

    Last Modified: 8 Sept 2026

    Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to elevation of privileges.

    Published: 7 Sept 2026
    5.6
    Medium

    CVE-2026-79642

    Last Modified: 9 Sept 2026

    Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access.

    Published: 7 Sept 2026
    4.8
    Medium

    CVE-2026-79943

    Last Modified: 8 Sept 2026

    Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Validation of Certificate with Host Mismatch vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to protection mechanism bypass.

    Published: 7 Sept 2026
    7.3
    High

    CVE-2026-79691

    Last Modified: 8 Sept 2026

    Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to protection mechanism bypass.

    Published: 7 Sept 2026
    Unknown

    CVE-2026-86477

    Last Modified: 8 Sept 2026

    ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this candidate have been removed to prevent accidental usage.

    Published: 7 Sept 2026
    7.3
    High

    CVE-2026-79643

    Last Modified: 8 Sept 2026

    Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Use of Incorrect Operator vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access.

    Published: 7 Sept 2026
    5.5
    Medium

    CVE-2026-80054

    Last Modified: 8 Sept 2026

    Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Incorrect Permission Assignment for Critical Resource vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to unauthorized access.

    Published: 7 Sept 2026
    5.5
    Medium

    CVE-2026-86321

    Last Modified: 8 Sept 2026

    A vulnerability was found in java-json-tools jackson-coreutils 2.0. Affected by this issue is the function JsonLoader.fromURL of the file src/main/java/com/github/fge/jackson/JsonLoader.java of the component URL Validation. The manipulation results in server-side request forgery. It is possible to launch the attack remotely. The exploit has been made public and could be used. The project was informed of the problem early through an issue report but has not responded yet.

    Published: 7 Sept 2026
    5.3
    Medium

    CVE-2026-86469

    Last Modified: 8 Sept 2026

    A flaw was found in GLib2. When g_file_replace() is used with G_FILE_CREATE_REPLACE_DESTINATION and creating the .goutputstream-XXXXXX temporary file fails, the library unlinks the destination and recreates it without exclusive creation or symlink protection. A local attacker who can write to the destination directory can win that race and redirect the write to another file.

    Published: 7 Sept 2026
    5.5
    Medium

    CVE-2026-86319

    Last Modified: 9 Sept 2026

    A vulnerability has been found in java-json-tools json-patch up to 1.13. Affected by this vulnerability is the function JsonPatch.apply of the file src/main/java/com/github/fge/jsonpatch/JsonPatch.java of the component Patch Operation Handler. The manipulation leads to resource consumption. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The project was informed of the problem early through an issue report but has not responded yet.

    Published: 7 Sept 2026
    5.5
    Medium

    CVE-2026-86318

    Last Modified: 8 Sept 2026

    A flaw has been found in java-json-tools json-patch up to 1.13. Affected is the function JsonMergePatch.fromJson of the file JsonMergePatchDeserializer.java. Executing a manipulation can lead to stack-based buffer overflow. The attack may be performed from remote. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet.

    Published: 7 Sept 2026
    6.5
    Medium

    CVE-2026-78488

    Last Modified: 11 Sept 2026

    Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to command execution.

    Published: 7 Sept 2026
    9.8
    Critical

    CVE-2026-7861

    Last Modified: 9 Sept 2026

    Deserialization of untrusted data vulnerability in Next4Biz Information Technologies Inc. CSM (Customer Service Management) allows Code Injection. This issue affects CSM (Customer Service Management): before 8.0.3.

    Published: 7 Sept 2026
    5.5
    Medium

    CVE-2026-80056

    Last Modified: 11 Sept 2026

    Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Insertion of Sensitive Information into Log File vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to information exposure.

    Published: 7 Sept 2026
    7.5
    High

    CVE-2026-6377

    Last Modified: 8 Sept 2026

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Next4Biz Information Technologies Inc. CSM (Customer Service Management) allows Path Traversal. This issue affects CSM (Customer Service Management): from 6.8.9 before 8.0.3.

    Published: 7 Sept 2026
    Items Per Page