CVE Database
Search and filter vulnerabilities by ID, vendor, product, severity, or description.
Search and filter vulnerabilities by ID, vendor, product, severity, or description.
| CVE ID | Severity | Score | Description | Published | |
|---|---|---|---|---|---|
| CVE-2026-86501 | LOW | 2.8 | In JetBrains IntelliJ IDEA before 2026.2.2 terminal command input could be written to idea.log | Sep 7, 2026 | |
| CVE-2026-86500 | MEDIUM | 5.5 | In JetBrains YouTrack before 2026.1.14047 a missing escalation check let a user with project update permissions grant themselves Project Admin | Sep 7, 2026 | |
| CVE-2026-86499 | MEDIUM | 4.3 | In JetBrains YouTrack before 2026.1.14047 predefined search fields leaked all group names to any user, regardless of visibility permission | Sep 7, 2026 | |
| CVE-2026-86498 | HIGH | 7.7 | In JetBrains YouTrack before 2025.3.160480, 2026.1.14047 pUT requests on link sub-resources allowed modification linked entities without update permission | Sep 7, 2026 | |
| CVE-2026-86497 | MEDIUM | 6.8 | In JetBrains YouTrack before 2026.2.18769 changing a mailbox host without re-authentication allowed a project administrator to exfiltrate stored mailbox credentials | Sep 7, 2026 | |
| CVE-2026-86496 | MEDIUM | 4.3 | In JetBrains YouTrack before 2026.2.18769 missing access control on Helpdesk authorized reporters exposed reporter email addresses | Sep 7, 2026 | |
| CVE-2026-86495 | MEDIUM | 6.5 | In JetBrains YouTrack before 2026.2.18687 missing permission checks allowed creating knowledge base articles in inaccessible projects | Sep 7, 2026 | |
| CVE-2026-86494 | HIGH | 7.7 | In JetBrains YouTrack before 2026.2.18634 cloning a whiteboard allowed unauthorized changes to links on inaccessible issues | Sep 7, 2026 | |
| CVE-2026-86493 | MEDIUM | 6.5 | In JetBrains YouTrack before 2026.2.18634 improper permission checks allowed read-only users to create and modify whiteboard cards | Sep 7, 2026 | |
| CVE-2026-86492 | HIGH | 8.5 | In JetBrains YouTrack before 2026.2.18634 a shared token cache allowed cross-tenant theft of GitHub App installation tokens | Sep 7, 2026 | |
| CVE-2026-86491 | LOW | 3.5 | In JetBrains YouTrack before 2026.2.18634 stored XSS was possible via project and organization icon uploads | Sep 7, 2026 | |
| CVE-2026-86490 | MEDIUM | 6.5 | In JetBrains YouTrack before 2026.2.18634 improper permission checks allowed overwriting of bundled apps via the app import endpoint | Sep 7, 2026 | |
| CVE-2026-86489 | MEDIUM | 6.5 | In JetBrains YouTrack before 2026.2.18634 an IDOR in the user profile API disclosed private issues and starred folders across organizations | Sep 7, 2026 | |
| CVE-2026-86488 | MEDIUM | 6.5 | In JetBrains YouTrack before 2026.2.18634 iDOR via the watchRules and issueListConfig endpoints exposed private saved searches | Sep 7, 2026 | |
| CVE-2026-86487 | LOW | 3.1 | In JetBrains YouTrack before 2026.2.18634 a crafted WebSocket message allowed read-only whiteboard users to modify canvas content | Sep 7, 2026 | |
| CVE-2026-86486 | LOW | 3.7 | In JetBrains YouTrack before 2026.2.18634 the generic VCS webhook handler failed open when its secret was blank | Sep 7, 2026 | |
| CVE-2026-86485 | LOW | 3.3 | In JetBrains YouTrack before 2026.2.18634 iP spoofing via HTTP headers allowed forged Bitbucket webhooks | Sep 7, 2026 | |
| CVE-2026-86484 | MEDIUM | 4.6 | In JetBrains YouTrack before 2026.2.18634 angularJS template injection in assignee names led to stored XSS | Sep 7, 2026 | |
| CVE-2026-86483 | MEDIUM | 5.4 | In JetBrains YouTrack before 2026.2.18634 stored XSS via a custom field on Agile board cards was possible | Sep 7, 2026 | |
| CVE-2026-86482 | HIGH | 8.8 | In JetBrains YouTrack before 2026.2.18634 unchecked group membership changes allowed privilege escalation | Sep 7, 2026 | |
| CVE-2026-86481 | MEDIUM | 4.3 | In JetBrains YouTrack before 2026.2.18634 signed URL reuse allowed disclosure of restricted project icons | Sep 7, 2026 | |
| CVE-2026-86480 | CRITICAL | 9.8 | In JetBrains Hub before 2026.2.52442 an unauthenticated attacker could register a trusted service and gain superuser privileges | Sep 7, 2026 | |
| CVE-2026-86479 | HIGH | 8.1 | In JetBrains YouTrack before 2026.2.18788, 2026.1.14055, 2025.3.161254 missing authorisation allowed access to restricted REST API resources via IDOR | Sep 7, 2026 | |
| CVE-2026-86478 | CRITICAL | 9.8 | In JetBrains YouTrack before 2025.3.161254, 2026.1.14042 improper authentication in YouTrack Helpdesk allowed unauthenticated account takeover via a self-asserted email address | Sep 7, 2026 | |
| CVE-2026-80176 | MEDIUM | 4.7 | Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Plaintext Storage of a Password vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to information disclosure. | Sep 7, 2026 |