Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-49384 |
|
In JetBrains PyCharm before 2025.3.4 stored XSS in Jupyter notebook Markdown cells was possible
In JetBrains PyCharm before 2025.3.4 stored XSS in Jupyter notebook Markdown cells was possible
|
| CVE-2026-49385 |
|
Vulnerability in jetbrains (CVE-2026-49385)
vulnerability in jetbrains (CVE-2026-49385). Data can be tampered with by attackers.
|
| CVE-2026-49386 |
|
Vulnerability in jetbrains (CVE-2026-49386)
vulnerability in jetbrains (CVE-2026-49386). Confidential information can be exposed externally.
|
| CVE-2026-49372 |
|
In JetBrains TeamCity before 2026.1,
2025.11.5 unauthenticated SSRF via build status was possible
In JetBrains TeamCity before 2026.1,
2025.11.5 unauthenticated SSRF via build status was possible
|
| CVE-2026-49373 |
|
Vulnerability in jetbrains (CVE-2026-49373)
vulnerability in jetbrains (CVE-2026-49373). Confidential information can be exposed externally.
|
| CVE-2026-49374 |
|
Vulnerability in jetbrains (CVE-2026-49374)
vulnerability in jetbrains (CVE-2026-49374). Confidential information can be exposed externally.
|
| CVE-2026-49375 |
|
Cross-Site Scripting (XSS) in jetbrains (CVE-2026-49375)
cross-site scripting in jetbrains (CVE-2026-49375). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-49376 |
|
In JetBrains TeamCity before 2026.1 insufficient username validation in the SAML plugin
In JetBrains TeamCity before 2026.1 insufficient username validation in the SAML plugin
|
| CVE-2026-49377 |
|
In JetBrains TeamCity before 2025.11.2 exposure of sensitive data via default agent parameters
In JetBrains TeamCity before 2025.11.2 exposure of sensitive data via default agent parameters
|
| CVE-2026-49378 |
|
Vulnerability in jetbrains (CVE-2026-49378)
vulnerability in jetbrains (CVE-2026-49378). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-49379 |
|
In JetBrains TeamCity before 2026.1 credentials could be exposed in thread names
In JetBrains TeamCity before 2026.1 credentials could be exposed in thread names
|
| CVE-2026-49380 |
|
In JetBrains TeamCity before 2026.1 open redirect in the SAML plugin was possible
In JetBrains TeamCity before 2026.1 open redirect in the SAML plugin was possible
|
| CVE-2026-49366 |
|
In JetBrains IntelliJ IDEA before 2026.1.1 command injection was possible via filename completion
In JetBrains IntelliJ IDEA before 2026.1.1 command injection was possible via filename completion
|
| CVE-2026-49367 |
|
In JetBrains IntelliJ IDEA before 2026.1.1 command execution was possible via the guest user account
In JetBrains IntelliJ IDEA before 2026.1.1 command execution was possible via the guest user account
|
| CVE-2026-49368 |
|
In JetBrains YouTrack before 2026.1.13162 stored XSS in project notification templates was possible
In JetBrains YouTrack before 2026.1.13162 stored XSS in project notification templates was possible
|
| CVE-2026-49369 |
|
Authorization Flaw in jetbrains (CVE-2026-49369)
vulnerability in jetbrains (CVE-2026-49369). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-49370 |
|
In JetBrains YouTrack before 2026.1.13162 information disclosure was possible on fetchApp requests
In JetBrains YouTrack before 2026.1.13162 information disclosure was possible on fetchApp requests
|
| CVE-2026-49371 |
|
In JetBrains TeamCity before 2026.1.1 reflected XSS in the keyword filter was possible
In JetBrains TeamCity before 2026.1.1 reflected XSS in the keyword filter was possible
|
| CVE-2026-35630 |
|
Vulnerability in openclaw (CVE-2026-35630)
vulnerability in openclaw (CVE-2026-35630). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `2026.5.18` or later.
|
| CVE-2026-35673 |
|
Authorization Flaw in ssrf (CVE-2026-35673)
vulnerability in ssrf (CVE-2026-35673). Confidential information can be exposed externally.
|
| CVE-2026-35674 |
|
Authorization Flaw in openclaw (CVE-2026-35674)
vulnerability in openclaw (CVE-2026-35674). Successful exploitation can lead to full system takeover.
|
| CVE-2026-36324 |
|
Cross-Site Scripting (XSS) in CVE-2026-36324 (CVE-2026-36324)
cross-site scripting in CVE-2026-36324 (CVE-2026-36324). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-39276 |
|
Path Traversal in path-traversal (CVE-2026-39276)
path traversal in path-traversal (CVE-2026-39276). Successful exploitation can lead to full system takeover.
|
| CVE-2026-32905 |
|
Vulnerability in openclaw (CVE-2026-32905)
vulnerability in openclaw (CVE-2026-32905). Confidential information can be exposed externally.
|
| CVE-2026-32906 |
|
Authorization Flaw in privilege-escalation (CVE-2026-32906)
vulnerability in privilege-escalation (CVE-2026-32906). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-34507 |
|
Authorization Flaw in openclaw (CVE-2026-34507)
vulnerability in openclaw (CVE-2026-34507). Risk of unauthorized operations or information disclosure.
|
| CVE-2018-25403 |
|
SQL Injection in sqli (CVE-2018-25403)
SQL injection in sqli (CVE-2018-25403). Confidential information can be exposed externally.
|
| CVE-2018-25404 |
|
SQL Injection in sqli (CVE-2018-25404)
SQL injection in sqli (CVE-2018-25404). Confidential information can be exposed externally.
|
| CVE-2018-25397 |
|
Cross-Site Request Forgery (CSRF) in CVE-2018-25397 (CVE-2018-25397)
vulnerability in CVE-2018-25397 (CVE-2018-25397). Risk of unauthorized operations or information disclosure.
|
| CVE-2018-25398 |
|
SQL Injection in sqli (CVE-2018-25398)
SQL injection in sqli (CVE-2018-25398). Confidential information can be exposed externally.
|
| CVE-2018-25399 |
|
SQL Injection in sqli (CVE-2018-25399)
SQL injection in sqli (CVE-2018-25399). Confidential information can be exposed externally.
|
| CVE-2018-25400 |
|
SQL Injection in sqli (CVE-2018-25400)
SQL injection in sqli (CVE-2018-25400). Confidential information can be exposed externally.
|
| CVE-2018-25401 |
|
SQL Injection in sqli (CVE-2018-25401)
SQL injection in sqli (CVE-2018-25401). Confidential information can be exposed externally.
|
| CVE-2018-25402 |
|
SQL Injection in sqli (CVE-2018-25402)
SQL injection in sqli (CVE-2018-25402). Confidential information can be exposed externally.
|
| CVE-2018-25389 |
|
SQL Injection in sqli (CVE-2018-25389)
SQL injection in sqli (CVE-2018-25389). Confidential information can be exposed externally.
|
| CVE-2018-25390 |
|
SQL Injection in sqli (CVE-2018-25390)
SQL injection in sqli (CVE-2018-25390). Confidential information can be exposed externally.
|
| CVE-2018-25391 |
|
Vulnerability in CVE-2018-25391 (CVE-2018-25391)
vulnerability in CVE-2018-25391 (CVE-2018-25391). Data can be tampered with by attackers.
|
| CVE-2018-25392 |
|
SQL Injection in sqli (CVE-2018-25392)
SQL injection in sqli (CVE-2018-25392). Confidential information can be exposed externally.
|
| CVE-2018-25393 |
|
Path Traversal in path-traversal (CVE-2018-25393)
path traversal in path-traversal (CVE-2018-25393). Confidential information can be exposed externally.
|
| CVE-2018-25394 |
|
SQL Injection in sqli (CVE-2018-25394)
SQL injection in sqli (CVE-2018-25394). Confidential information can be exposed externally.
|
| CVE-2018-25395 |
|
SQL Injection in sqli (CVE-2018-25395)
SQL injection in sqli (CVE-2018-25395). Confidential information can be exposed externally.
|
| CVE-2018-25382 |
|
SQL Injection in sqli (CVE-2018-25382)
SQL injection in sqli (CVE-2018-25382). Confidential information can be exposed externally.
|
| CVE-2018-25384 |
|
Cross-Site Scripting (XSS) in CVE-2018-25384 (CVE-2018-25384)
cross-site scripting in CVE-2018-25384 (CVE-2018-25384). Risk of unauthorized operations or information disclosure.
|
| CVE-2018-25385 |
|
SQL Injection in sqli (CVE-2018-25385)
SQL injection in sqli (CVE-2018-25385). Confidential information can be exposed externally.
|
| CVE-2018-25386 |
|
SQL Injection in sqli (CVE-2018-25386)
SQL injection in sqli (CVE-2018-25386). Confidential information can be exposed externally.
|
| CVE-2018-25387 |
|
Cross-Site Request Forgery (CSRF) in CVE-2018-25387 (CVE-2018-25387)
vulnerability in CVE-2018-25387 (CVE-2018-25387). Risk of unauthorized operations or information disclosure.
|
| CVE-2018-25388 |
|
Unrestricted File Upload in CVE-2018-25388 (CVE-2018-25388)
vulnerability in CVE-2018-25388 (CVE-2018-25388). Successful exploitation can lead to full system takeover.
|
| CVE-2026-44495 |
|
Code Injection in axios (CVE-2026-44495)
code injection in axios (CVE-2026-44495). Confidential information can be exposed externally. Exploitable via ``Object.prototype.transformResponse``. Mitigation: upgrade to `1.15.0` or later.
|
| CVE-2026-44494 |
|
Vulnerability in axios (CVE-2026-44494)
vulnerability in axios (CVE-2026-44494). Confidential information can be exposed externally. Exploitable via `Authorization header`. Mitigation: upgrade to `1.15.0` or later.
|
| CVE-2026-44492 |
|
SSRF (Server-Side Request Forgery) in axios (CVE-2026-44492)
SSRF in axios (CVE-2026-44492). Confidential information can be exposed externally. Mitigation: upgrade to `1.16.0` or later.
|