Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-60106 |
|
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
|
| CVE-2026-50776 |
|
Path Traversal in path-traversal (CVE-2026-50776)
path traversal in path-traversal (CVE-2026-50776). Confidential information can be exposed externally.
|
| CVE-2026-50775 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-50775)
SSRF in ssrf (CVE-2026-50775). Successful exploitation can lead to full system takeover.
|
| CVE-2026-50774 |
|
Privilege Escalation in CVE-2026-50774 (CVE-2026-50774)
vulnerability in CVE-2026-50774 (CVE-2026-50774). Successful exploitation can lead to full system takeover.
|
| CVE-2026-50773 |
|
Vulnerability in CVE-2026-50773 (CVE-2026-50773)
vulnerability in CVE-2026-50773 (CVE-2026-50773). Successful exploitation can lead to full system takeover.
|
| CVE-2026-45698 |
|
Vulnerability in CVE-2026-45698 (CVE-2026-45698)
vulnerability in CVE-2026-45698 (CVE-2026-45698). Successful exploitation can lead to full system takeover.
|
| CVE-2026-17639 |
|
Vulnerability in dos (CVE-2026-17639)
vulnerability in dos (CVE-2026-17639). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-12553 |
|
Out-of-Bounds Write in CVE-2026-12553 (CVE-2026-12553)
out-of-bounds write in CVE-2026-12553 (CVE-2026-12553). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-74254 |
|
SQL Injection in sqli (CVE-2026-74254)
SQL injection in sqli (CVE-2026-74254). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-74253 |
|
Code Injection in CVE-2026-74253 (CVE-2026-74253)
code injection in CVE-2026-74253 (CVE-2026-74253). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-73522 |
|
Vulnerability in dos (CVE-2026-73522)
vulnerability in dos (CVE-2026-73522). Data can be tampered with by attackers.
|
| CVE-2026-50771 |
|
Cross-Site Scripting (XSS) in CVE-2026-50771 (CVE-2026-50771)
cross-site scripting in CVE-2026-50771 (CVE-2026-50771). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-71979 |
|
Vulnerability in cpp (CVE-2026-71979)
vulnerability in cpp (CVE-2026-71979). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-50770 |
|
Privilege Escalation in CVE-2026-50770 (CVE-2026-50770)
vulnerability in CVE-2026-50770 (CVE-2026-50770). Successful exploitation can lead to full system takeover.
|
| CVE-2026-71980 |
|
Out-of-Bounds Read in c (CVE-2026-71980)
vulnerability in c (CVE-2026-71980). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-73523 |
|
Vulnerability in c (CVE-2026-73523)
vulnerability in c (CVE-2026-73523). Confidential information can be exposed externally.
|
| CVE-2026-50769 |
|
SQL Injection in sqli (CVE-2026-50769)
SQL injection in sqli (CVE-2026-50769). Successful exploitation can lead to full system takeover.
|
| CVE-2026-51346 |
|
SQL Injection in sqli (CVE-2026-51346)
SQL injection in sqli (CVE-2026-51346). Confidential information can be exposed externally.
|
| CVE-2026-50772 |
|
Code Injection in CVE-2026-50772 (CVE-2026-50772)
code injection in CVE-2026-50772 (CVE-2026-50772). Successful exploitation can lead to full system takeover.
|
| CVE-2026-75054 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-75054)
SSRF in ssrf (CVE-2026-75054). Confidential information can be exposed externally.
|
| CVE-2026-40145 |
|
Vulnerability in CVE-2026-40145 (CVE-2026-40145)
vulnerability in CVE-2026-40145 (CVE-2026-40145). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-75056 |
|
In JetBrains IntelliJ IDEA before 2026.2.1 rCE via Markdown export tool was possible
In JetBrains IntelliJ IDEA before 2026.2.1 rCE via Markdown export tool was possible
|
| CVE-2026-50768 |
|
Unrestricted File Upload in CVE-2026-50768 (CVE-2026-50768)
vulnerability in CVE-2026-50768 (CVE-2026-50768). Successful exploitation can lead to full system takeover.
|
| CVE-2026-75059 |
|
In JetBrains PyCharm before 2026.2.1 code execution via Quick Documentation was possible
In JetBrains PyCharm before 2026.2.1 code execution via Quick Documentation was possible
|
| CVE-2026-75057 |
|
In JetBrains IntelliJ IDEA before 2026.1.5 git credentials were written in plaintext to the IDE log
In JetBrains IntelliJ IDEA before 2026.1.5 git credentials were written in plaintext to the IDE log
|
| CVE-2026-75060 |
|
Vulnerability in CVE-2026-75060 (CVE-2026-75060)
vulnerability in CVE-2026-75060 (CVE-2026-75060). Successful exploitation can lead to full system takeover.
|
| CVE-2026-75055 |
|
In JetBrains IntelliJ IDEA before 2026.2.1 hadoop ResourceManager could read local files via XXE
In JetBrains IntelliJ IDEA before 2026.2.1 hadoop ResourceManager could read local files via XXE
|
| CVE-2026-75053 |
|
In JetBrains IntelliJ IDEA before 2026.2.1 sSRF was possible via the DevKit debug listener endpoint
In JetBrains IntelliJ IDEA before 2026.2.1 sSRF was possible via the DevKit debug listener endpoint
|
| CVE-2026-75058 |
|
In JetBrains IntelliJ IDEA before 2026.2.1 xXE was possible in the Eclipse settings importers
In JetBrains IntelliJ IDEA before 2026.2.1 xXE was possible in the Eclipse settings importers
|
| CVE-2026-75050 |
|
Vulnerability in dos (CVE-2026-75050)
vulnerability in dos (CVE-2026-75050). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-75051 |
|
Vulnerability in CVE-2026-75051 (CVE-2026-75051)
vulnerability in CVE-2026-75051 (CVE-2026-75051). Confidential information can be exposed externally.
|
| CVE-2026-75052 |
|
Command Injection in CVE-2026-75052 (CVE-2026-75052)
command injection in CVE-2026-75052 (CVE-2026-75052). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-75049 |
|
Vulnerability in CVE-2026-75049 (CVE-2026-75049)
vulnerability in CVE-2026-75049 (CVE-2026-75049). Confidential information can be exposed externally.
|
| CVE-2026-75045 |
|
Vulnerability in CVE-2026-75045 (CVE-2026-75045)
vulnerability in CVE-2026-75045 (CVE-2026-75045). Confidential information can be exposed externally.
|
| CVE-2026-75048 |
|
Cross-Site Scripting (XSS) in CVE-2026-75048 (CVE-2026-75048)
cross-site scripting in CVE-2026-75048 (CVE-2026-75048). Confidential information can be exposed externally.
|
| CVE-2026-75047 |
|
Vulnerability in dos (CVE-2026-75047)
vulnerability in dos (CVE-2026-75047). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-75046 |
|
Vulnerability in CVE-2026-75046 (CVE-2026-75046)
vulnerability in CVE-2026-75046 (CVE-2026-75046). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-75044 |
|
Vulnerability in CVE-2026-75044 (CVE-2026-75044)
vulnerability in CVE-2026-75044 (CVE-2026-75044). Data can be tampered with by attackers.
|
| CVE-2026-74858 |
|
SSRF (Server-Side Request Forgery) in CVE-2026-74858 (CVE-2026-74858)
SSRF in CVE-2026-74858 (CVE-2026-74858). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-40144 |
|
Out-of-Bounds Read in CVE-2026-40144 (CVE-2026-40144)
vulnerability in CVE-2026-40144 (CVE-2026-40144). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-68762 |
|
In JetBrains Ktor before 3.4.1 potential DoS attack via WebSocket decompression was possible
In JetBrains Ktor before 3.4.1 potential DoS attack via WebSocket decompression was possible
|
| CVE-2026-59903 |
|
Vulnerability in io.netty:netty-codec-http (CVE-2026-59903)
vulnerability in io.netty:netty-codec-http (CVE-2026-59903). Confidential information can be exposed externally. Exploitable via ``CorsHandler``. Mitigation: upgrade to `4.1.137.Final` or later.
|
| CVE-2026-33437 |
|
Cross-Site Scripting (XSS) in CVE-2026-33437 (CVE-2026-33437)
cross-site scripting in CVE-2026-33437 (CVE-2026-33437). Confidential information can be exposed externally.
|
| CVE-2026-59902 |
|
Vulnerability in io.netty:netty-transport-sctp (CVE-2026-59902)
vulnerability in io.netty:netty-transport-sctp (CVE-2026-59902). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `4.1.137.Final` or later.
|
| GHSA-fhgh-wq4q-r37x |
|
OS Command Injection in gitlab.com/uniget-org/cli (GHSA-fhgh-wq4q-r37x)
OS command injection in gitlab.com/uniget-org/cli (GHSA-fhgh-wq4q-r37x). Risk of unauthorized operations or information disclosure. Exploitable via ``LoadMetadata``. Mitigation: upgrade to `0.27.1` or later.
|
| CVE-2026-59893 |
|
Vulnerability in sqlparse (CVE-2026-59893)
vulnerability in sqlparse (CVE-2026-59893). Risk of unauthorized operations or information disclosure. Exploitable via ``SQL_REGEX``. Mitigation: upgrade to `0.6.0` or later.
|
| CVE-2026-54284 |
|
Vulnerability in sqlparse (CVE-2026-54284)
vulnerability in sqlparse (CVE-2026-54284). Risk of unauthorized operations or information disclosure. Exploitable via ``sqlparse``. Mitigation: upgrade to `0.6.0` or later.
|
| CVE-2026-55090 |
|
Cross-Site Scripting (XSS) in ep_etherpad-lite (CVE-2026-55090)
cross-site scripting in ep_etherpad-lite (CVE-2026-55090). Risk of unauthorized operations or information disclosure. Exploitable via ``getHTMLFromAtext``. Mitigation: upgrade to `3.3.0` or later.
|
| GHSA-92hr-gmr6-h8cp |
|
Path Traversal in ep_etherpad-lite (GHSA-92hr-gmr6-h8cp)
path traversal in ep_etherpad-lite (GHSA-92hr-gmr6-h8cp). Risk of unauthorized operations or information disclosure. Exploitable via ``crypto.getRandomValues``. Mitigation: upgrade to `3.3.0` or later.
|
| CVE-2026-55062 |
|
Path Traversal in gitlab.com/uniget-org/cli (CVE-2026-55062)
path traversal in gitlab.com/uniget-org/cli (CVE-2026-55062). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.27.6` or later.
|