Top technology
Linux 13140
Google 12530
Microsoft 12379
Oracle 6737
Apple 6692
Adobe 6387
Ibm 6330
Cisco 5757
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.8
CVE-2026-50770
An issue in Squirro Cognitive Search before v.3.14.2 allows a remote attacker to escalate privileges via a crafted request.
No fix yet
CRITICAL 9.8
CVE-2026-50769
The CRM+ application before and including version 2025.6 from Brainformatik is vulnerable to SQL Injection (time-based) vulnerability. The check conf…
No fix yet
CRITICAL 9.8
CVE-2026-50768
File Upload vulnerability in T-Systems International GmbH ImageMaster Version: 9.14.2.8.1 allows a remote attacker to execute arbitrary code via the …
No fix yet
MEDIUM 5.8
CVE-2026-48053
Kolibri is an offline-first education platform. Prior to version 0.19.4, several Kolibri API endpoints accept an unvalidated `baseurl` parameter and …
No fix yet
HIGH 8.1
CVE-2026-33437
Stirling-PDF is a locally hosted web application that facilitates various operations on PDF files. Prior to 2.0.0, the Get Info workflow in app/core/…
No fix yet
HIGH 7.1
CVE-2026-40145
A vulnerability exists in the interaction between a Endpoint Privilege Management (Windows Deployment) support utility and the agent's tamper protect…
No fix yet
HIGH 8.4
CVE-2026-75060
In JetBrains PyCharm before 2026.2.1 code execution was possible via unauthenticated Jupyter MCP tools
No fix yet
MEDIUM 5.5
CVE-2026-75058
In JetBrains IntelliJ IDEA before 2026.2.1 xXE was possible in the Eclipse settings importers
No fix yet
MEDIUM 6.2
CVE-2026-75057
In JetBrains IntelliJ IDEA before 2026.1.5 git credentials were written in plaintext to the IDE log
No fix yet
HIGH 7.8
CVE-2026-75056
In JetBrains IntelliJ IDEA before 2026.2.1 rCE via Markdown export tool was possible
No fix yet
MEDIUM 5.5
CVE-2026-75055
In JetBrains IntelliJ IDEA before 2026.2.1 hadoop ResourceManager could read local files via XXE
No fix yet
MEDIUM 6.3
CVE-2026-75054
In JetBrains IntelliJ IDEA before 2026.2.1 sSRF was possible via the OpenAPI preview proxy in untrusted projects
No fix yet
MEDIUM 5.4
CVE-2026-75053
In JetBrains IntelliJ IDEA before 2026.2.1 sSRF was possible via the DevKit debug listener endpoint
No fix yet
HIGH 8.1
CVE-2026-75051
In JetBrains YouTrack before 2026.2.17917 unauthorised project transfer between organisations was possible
No fix yet
HIGH 7.1
CVE-2026-75050
In JetBrains YouTrack before 2026.1.13901,
2026.2.17950 doS attack was possible via crafted type parameters
No fix yet
MEDIUM 6.5
CVE-2026-75049
In JetBrains YouTrack before 2026.1.13903,
2026.2.17950 an authenticated user could read restricted articles from other projects via the draft creat…
No fix yet
HIGH 8.2
CVE-2026-75048
In JetBrains YouTrack before 2026.2.18068 stored XSS via the fenced code-block language label was possible
No fix yet
MEDIUM 6.5
CVE-2026-75047
In JetBrains YouTrack before 2026.2.18177 doS attack was possible via a decompression bomb in the import endpoint
No fix yet
CRITICAL 9.1
CVE-2026-75045
In JetBrains YouTrack before 2025.3.156085,
2026.1.13913,
2026.2.18112 an unauthenticated attacker could download database backups via shared draft…
No fix yet
HIGH 8.1
CVE-2026-75044
In JetBrains YouTrack before 2025.3.156085,
2026.1.13914,
2026.2.18095 missing authorisation allowed an authenticated user to delete arbitrary enti…
No fix yet
MEDIUM 6.3
CVE-2026-74858
A vulnerability has been found in jae-jae fetcher-mcp up to 0.3.9. Impacted is the function fetch_url/fetch_urls of the file /latest/meta-data/iam/se…
No fix yet
MEDIUM 5.9
CVE-2026-68762
In JetBrains Ktor before 3.4.1 potential DoS attack via WebSocket decompression was possible
No fix yet
CRITICAL 9.3
CVE-2026-55674
Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, an unauthenticated attacker could send a single…
No fix yet
MEDIUM 5.3
CVE-2026-53960
Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, hidden or otherwise unviewable first-post conte…
No fix yet
HIGH 7.3
CVE-2026-40144
A memory-corruption vulnerability exists in a kernel-mode component of BeyondTrust Endpoint Privilege Management (Windows deployments) prior to versi…
No fix yet
HIGH 7.4
CVE-2025-27772
UpTrain is an open-source platform to evaluate and improve generative AI applications. In version 0.7.1 and prior, the `/new_run` endpoint is vulnera…
No fix yet
HIGH 7.4
CVE-2025-27771
UpTrain is an open-source platform to evaluate and improve generative AI applications. In version 0.7.1 and prior, the `/add_prompts` endpoint is vul…
No fix yet
HIGH 7.4
CVE-2025-27770
UpTrain is an open-source platform to evaluate and improve generative AI applications. In version 0.7.1 and prior, the `/create_project` endpoint is …
No fix yet
HIGH 7.7
CVE-2025-27621
UpTrain is an open-source platform to evaluate and improve generative AI applications. In version 0.7.1 and prior, the UpTrain backend creates a new …
No fix yet
HIGH 7.7
CVE-2026-71567
In openshift-metal3/fakefish there is a repeated pattern in some of the scripts where shell variables
are injected without quoting them either into …
No fix yet