Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-63667 |
|
Path Traversal in CVE-2026-63667 (CVE-2026-63667)
path traversal in CVE-2026-63667 (CVE-2026-63667). Confidential information can be exposed externally.
|
| CVE-2026-63669 |
|
Vulnerability in CVE-2026-63669 (CVE-2026-63669)
vulnerability in CVE-2026-63669 (CVE-2026-63669). Data can be tampered with by attackers.
|
| CVE-2026-57485 |
|
Information Disclosure in CVE-2026-57485 (CVE-2026-57485)
vulnerability in CVE-2026-57485 (CVE-2026-57485). Confidential information can be exposed externally.
|
| CVE-2026-54758 |
|
Vulnerability in cpp (CVE-2026-54758)
vulnerability in cpp (CVE-2026-54758). Successful exploitation can lead to full system takeover.
|
| CVE-2026-19478 |
|
Code Injection in CVE-2026-19478 (CVE-2026-19478)
code injection in CVE-2026-19478 (CVE-2026-19478). Data can be tampered with by attackers.
|
| CVE-2026-19650 |
|
Cross-Site Request Forgery (CSRF) in CVE-2026-19650 (CVE-2026-19650)
vulnerability in CVE-2026-19650 (CVE-2026-19650). Data can be tampered with by attackers.
|
| CVE-2026-75011 |
|
Vulnerability in CVE-2026-75011 (CVE-2026-75011)
vulnerability in CVE-2026-75011 (CVE-2026-75011). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-74238 |
|
Out-of-Bounds Read in CVE-2026-74238 (CVE-2026-74238)
vulnerability in CVE-2026-74238 (CVE-2026-74238). Data can be tampered with by attackers.
|
| CVE-2026-66792 |
|
Authorization Flaw in CVE-2026-66792 (CVE-2026-66792)
vulnerability in CVE-2026-66792 (CVE-2026-66792). Successful exploitation can lead to full system takeover.
|
| CVE-2026-50776 |
|
Path Traversal in path-traversal (CVE-2026-50776)
path traversal in path-traversal (CVE-2026-50776). Confidential information can be exposed externally.
|
| CVE-2026-50775 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-50775)
SSRF in ssrf (CVE-2026-50775). Successful exploitation can lead to full system takeover.
|
| CVE-2026-50773 |
|
Vulnerability in CVE-2026-50773 (CVE-2026-50773)
vulnerability in CVE-2026-50773 (CVE-2026-50773). Successful exploitation can lead to full system takeover.
|
| CVE-2026-50774 |
|
Privilege Escalation in CVE-2026-50774 (CVE-2026-50774)
vulnerability in CVE-2026-50774 (CVE-2026-50774). Successful exploitation can lead to full system takeover.
|
| CVE-2026-45698 |
|
Vulnerability in CVE-2026-45698 (CVE-2026-45698)
vulnerability in CVE-2026-45698 (CVE-2026-45698). Successful exploitation can lead to full system takeover.
|
| CVE-2026-17639 |
|
Vulnerability in dos (CVE-2026-17639)
vulnerability in dos (CVE-2026-17639). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-12553 |
|
Out-of-Bounds Write in CVE-2026-12553 (CVE-2026-12553)
out-of-bounds write in CVE-2026-12553 (CVE-2026-12553). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-74253 |
|
Code Injection in CVE-2026-74253 (CVE-2026-74253)
code injection in CVE-2026-74253 (CVE-2026-74253). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-74254 |
|
SQL Injection in sqli (CVE-2026-74254)
SQL injection in sqli (CVE-2026-74254). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-50771 |
|
Cross-Site Scripting (XSS) in CVE-2026-50771 (CVE-2026-50771)
cross-site scripting in CVE-2026-50771 (CVE-2026-50771). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-51346 |
|
SQL Injection in sqli (CVE-2026-51346)
SQL injection in sqli (CVE-2026-51346). Confidential information can be exposed externally.
|
| CVE-2026-50769 |
|
SQL Injection in sqli (CVE-2026-50769)
SQL injection in sqli (CVE-2026-50769). Successful exploitation can lead to full system takeover.
|
| CVE-2026-73523 |
|
Vulnerability in c (CVE-2026-73523)
vulnerability in c (CVE-2026-73523). Confidential information can be exposed externally.
|
| CVE-2026-50770 |
|
Privilege Escalation in CVE-2026-50770 (CVE-2026-50770)
vulnerability in CVE-2026-50770 (CVE-2026-50770). Successful exploitation can lead to full system takeover.
|
| CVE-2026-71979 |
|
Vulnerability in cpp (CVE-2026-71979)
vulnerability in cpp (CVE-2026-71979). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-73522 |
|
Vulnerability in dos (CVE-2026-73522)
vulnerability in dos (CVE-2026-73522). Data can be tampered with by attackers.
|
| CVE-2026-71980 |
|
Out-of-Bounds Read in c (CVE-2026-71980)
vulnerability in c (CVE-2026-71980). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-50772 |
|
Code Injection in CVE-2026-50772 (CVE-2026-50772)
code injection in CVE-2026-50772 (CVE-2026-50772). Successful exploitation can lead to full system takeover.
|
| CVE-2026-75056 |
|
In JetBrains IntelliJ IDEA before 2026.2.1 rCE via Markdown export tool was possible
In JetBrains IntelliJ IDEA before 2026.2.1 rCE via Markdown export tool was possible
|
| CVE-2026-75059 |
|
In JetBrains PyCharm before 2026.2.1 code execution via Quick Documentation was possible
In JetBrains PyCharm before 2026.2.1 code execution via Quick Documentation was possible
|
| CVE-2026-75055 |
|
In JetBrains IntelliJ IDEA before 2026.2.1 hadoop ResourceManager could read local files via XXE
In JetBrains IntelliJ IDEA before 2026.2.1 hadoop ResourceManager could read local files via XXE
|
| CVE-2026-75058 |
|
In JetBrains IntelliJ IDEA before 2026.2.1 xXE was possible in the Eclipse settings importers
In JetBrains IntelliJ IDEA before 2026.2.1 xXE was possible in the Eclipse settings importers
|
| CVE-2026-75057 |
|
In JetBrains IntelliJ IDEA before 2026.1.5 git credentials were written in plaintext to the IDE log
In JetBrains IntelliJ IDEA before 2026.1.5 git credentials were written in plaintext to the IDE log
|
| CVE-2026-40145 |
|
Vulnerability in CVE-2026-40145 (CVE-2026-40145)
vulnerability in CVE-2026-40145 (CVE-2026-40145). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-75054 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-75054)
SSRF in ssrf (CVE-2026-75054). Confidential information can be exposed externally.
|
| CVE-2026-75053 |
|
In JetBrains IntelliJ IDEA before 2026.2.1 sSRF was possible via the DevKit debug listener endpoint
In JetBrains IntelliJ IDEA before 2026.2.1 sSRF was possible via the DevKit debug listener endpoint
|
| CVE-2026-75060 |
|
Vulnerability in CVE-2026-75060 (CVE-2026-75060)
vulnerability in CVE-2026-75060 (CVE-2026-75060). Successful exploitation can lead to full system takeover.
|
| CVE-2026-50768 |
|
Unrestricted File Upload in CVE-2026-50768 (CVE-2026-50768)
vulnerability in CVE-2026-50768 (CVE-2026-50768). Successful exploitation can lead to full system takeover.
|
| CVE-2026-75052 |
|
Command Injection in CVE-2026-75052 (CVE-2026-75052)
command injection in CVE-2026-75052 (CVE-2026-75052). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-75049 |
|
Vulnerability in CVE-2026-75049 (CVE-2026-75049)
vulnerability in CVE-2026-75049 (CVE-2026-75049). Confidential information can be exposed externally.
|
| CVE-2026-75051 |
|
Vulnerability in CVE-2026-75051 (CVE-2026-75051)
vulnerability in CVE-2026-75051 (CVE-2026-75051). Confidential information can be exposed externally.
|
| CVE-2026-75050 |
|
Vulnerability in dos (CVE-2026-75050)
vulnerability in dos (CVE-2026-75050). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-74858 |
|
SSRF (Server-Side Request Forgery) in CVE-2026-74858 (CVE-2026-74858)
SSRF in CVE-2026-74858 (CVE-2026-74858). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-75044 |
|
Vulnerability in CVE-2026-75044 (CVE-2026-75044)
vulnerability in CVE-2026-75044 (CVE-2026-75044). Data can be tampered with by attackers.
|
| CVE-2026-75046 |
|
Vulnerability in CVE-2026-75046 (CVE-2026-75046)
vulnerability in CVE-2026-75046 (CVE-2026-75046). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-75045 |
|
Vulnerability in CVE-2026-75045 (CVE-2026-75045)
vulnerability in CVE-2026-75045 (CVE-2026-75045). Confidential information can be exposed externally.
|
| CVE-2026-75048 |
|
Cross-Site Scripting (XSS) in CVE-2026-75048 (CVE-2026-75048)
cross-site scripting in CVE-2026-75048 (CVE-2026-75048). Confidential information can be exposed externally.
|
| CVE-2026-40144 |
|
Out-of-Bounds Read in CVE-2026-40144 (CVE-2026-40144)
vulnerability in CVE-2026-40144 (CVE-2026-40144). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-68762 |
|
In JetBrains Ktor before 3.4.1 potential DoS attack via WebSocket decompression was possible
In JetBrains Ktor before 3.4.1 potential DoS attack via WebSocket decompression was possible
|
| CVE-2026-59903 |
|
Vulnerability in io.netty:netty-codec-http (CVE-2026-59903)
vulnerability in io.netty:netty-codec-http (CVE-2026-59903). Confidential information can be exposed externally. Exploitable via ``CorsHandler``. Mitigation: upgrade to `4.1.137.Final` or later.
|
| CVE-2026-33437 |
|
Cross-Site Scripting (XSS) in CVE-2026-33437 (CVE-2026-33437)
cross-site scripting in CVE-2026-33437 (CVE-2026-33437). Confidential information can be exposed externally.
|