Vulnerability index

Browse CVEs

10,000+ matching
Filters
Severity

Filters apply as you choose them.

HIGH 8.8 CVE-2026-9771 The flash_copy() system call is verified by z_vrfy_flash_copy() in drivers/flash/flash_util.c. On builds with CONFIG_USERSPACE enabled, this handler … Patch available Fix from $4,9002026-08-17 HIGH 8.8 CVE-2026-68518 Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.6, _sanitize_mustache_dict() in glances/actions.py sanitizes individual… Patch available Fix from $4,9002026-08-17 MEDIUM 6.5 CVE-2026-68517 Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.6, the cors_origins guard in glances/outputs/glances_restful_api.py use… Patch available Fix from $4,0002026-08-17 HIGH 8.9 CVE-2026-61666 websocket-driver is a WebSocket protocol handler with pluggable I/O. Prior to 0.8.2, WebSocket::Driver.server() passes a malformed Host header to URI… Patch available Fix from $4,9002026-08-17 HIGH 7.1 CVE-2026-40145 A vulnerability exists in the interaction between a Endpoint Privilege Management (Windows Deployment) support utility and the agent's tamper protect… No fix yet Fix from $4,9002026-08-17 MEDIUM 5.0 CVE-2026-12519 The WNC-M14A2A LTE-M modem driver mishandles unsolicited %NOTIFYEV: events in on_cmd_socknotifyev() (drivers/modem/vendor_standalone/wncm14a2a.c). Th… Patch available Fix from $4,0002026-08-17 HIGH 8.4 CVE-2026-75060 In JetBrains PyCharm before 2026.2.1 code execution was possible via unauthenticated Jupyter MCP tools No fix yet Fix from $4,9002026-08-17 MEDIUM 5.5 CVE-2026-75058 In JetBrains IntelliJ IDEA before 2026.2.1 xXE was possible in the Eclipse settings importers No fix yet Fix from $4,0002026-08-17 MEDIUM 6.2 CVE-2026-75057 In JetBrains IntelliJ IDEA before 2026.1.5 git credentials were written in plaintext to the IDE log No fix yet Fix from $4,0002026-08-17 HIGH 7.8 CVE-2026-75056 In JetBrains IntelliJ IDEA before 2026.2.1 rCE via Markdown export tool was possible No fix yet Fix from $4,9002026-08-17 MEDIUM 5.5 CVE-2026-75055 In JetBrains IntelliJ IDEA before 2026.2.1 hadoop ResourceManager could read local files via XXE No fix yet Fix from $4,0002026-08-17 MEDIUM 6.3 CVE-2026-75054 In JetBrains IntelliJ IDEA before 2026.2.1 sSRF was possible via the OpenAPI preview proxy in untrusted projects No fix yet Fix from $4,0002026-08-17 MEDIUM 5.4 CVE-2026-75053 In JetBrains IntelliJ IDEA before 2026.2.1 sSRF was possible via the DevKit debug listener endpoint No fix yet Fix from $4,0002026-08-17 HIGH 8.1 CVE-2026-75051 In JetBrains YouTrack before 2026.2.17917 unauthorised project transfer between organisations was possible No fix yet Fix from $4,9002026-08-17 HIGH 7.1 CVE-2026-75050 In JetBrains YouTrack before 2026.1.13901, 2026.2.17950 doS attack was possible via crafted type parameters No fix yet Fix from $4,9002026-08-17 MEDIUM 6.5 CVE-2026-75049 In JetBrains YouTrack before 2026.1.13903, 2026.2.17950 an authenticated user could read restricted articles from other projects via the draft creat… No fix yet Fix from $4,0002026-08-17 HIGH 8.2 CVE-2026-75048 In JetBrains YouTrack before 2026.2.18068 stored XSS via the fenced code-block language label was possible No fix yet Fix from $4,9002026-08-17 MEDIUM 6.5 CVE-2026-75047 In JetBrains YouTrack before 2026.2.18177 doS attack was possible via a decompression bomb in the import endpoint No fix yet Fix from $4,0002026-08-17 CRITICAL 9.1 CVE-2026-75045 In JetBrains YouTrack before 2025.3.156085, 2026.1.13913, 2026.2.18112 an unauthenticated attacker could download database backups via shared draft… No fix yet Fix from $5,7502026-08-17 HIGH 8.1 CVE-2026-75044 In JetBrains YouTrack before 2025.3.156085, 2026.1.13914, 2026.2.18095 missing authorisation allowed an authenticated user to delete arbitrary enti… No fix yet Fix from $4,9002026-08-17 MEDIUM 6.3 CVE-2026-74858 A vulnerability has been found in jae-jae fetcher-mcp up to 0.3.9. Impacted is the function fetch_url/fetch_urls of the file /latest/meta-data/iam/se… No fix yet Fix from $4,0002026-08-17 HIGH 7.5 CVE-2026-73646 PostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rules into an Abstract Syntax Tree. Prior to 8.5.18,… Patch available Fix from $4,9002026-08-17 CRITICAL 9.1 CVE-2026-71479 New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to 1.0.0-rc.18, user-controlled image … Patch available Fix from $5,7502026-08-17 MEDIUM 5.9 CVE-2026-68762 In JetBrains Ktor before 3.4.1 potential DoS attack via WebSocket decompression was possible No fix yet Fix from $4,0002026-08-17 HIGH 7.5 CVE-2026-64868 New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to 1.0.0-rc.11, POST /api/stripe/webho… Patch available Fix from $4,9002026-08-17 MEDIUM 5.1 CVE-2026-64866 New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. From 0.9.1.3 until 1.0.0-rc.7, AdminResetPas… Patch available Fix from $4,0002026-08-17 MEDIUM 6.0 CVE-2026-64865 New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to 1.0.0-rc.16, repeated PUT /api/user… Patch available Fix from $4,0002026-08-17 CRITICAL 9.1 CVE-2026-64859 New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to 1.0.0-rc.7, the admin user list and… Patch available Fix from $5,7502026-08-17 CRITICAL 9.3 CVE-2026-55674 Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, an unauthenticated attacker could send a single… No fix yet Fix from $5,7502026-08-17 MEDIUM 5.3 CVE-2026-53960 Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, hidden or otherwise unviewable first-post conte… No fix yet Fix from $4,0002026-08-17