CVE Database
Search and filter vulnerabilities by ID, vendor, product, severity, or description.
Search and filter vulnerabilities by ID, vendor, product, severity, or description.
| CVE ID | Severity | Score | Description | Published | |
|---|---|---|---|---|---|
| CVE-2026-86498 | HIGH | 7.7 | In JetBrains YouTrack before 2025.3.160480, 2026.1.14047 pUT requests on link sub-resources allowed modification linked entities without update permission | Sep 7, 2026 | |
| CVE-2026-86497 | MEDIUM | 6.8 | In JetBrains YouTrack before 2026.2.18769 changing a mailbox host without re-authentication allowed a project administrator to exfiltrate stored mailbox credentials | Sep 7, 2026 | |
| CVE-2026-86496 | MEDIUM | 4.3 | In JetBrains YouTrack before 2026.2.18769 missing access control on Helpdesk authorized reporters exposed reporter email addresses | Sep 7, 2026 | |
| CVE-2026-86495 | MEDIUM | 6.5 | In JetBrains YouTrack before 2026.2.18687 missing permission checks allowed creating knowledge base articles in inaccessible projects | Sep 7, 2026 | |
| CVE-2026-86494 | HIGH | 7.7 | In JetBrains YouTrack before 2026.2.18634 cloning a whiteboard allowed unauthorized changes to links on inaccessible issues | Sep 7, 2026 | |
| CVE-2026-86493 | MEDIUM | 6.5 | In JetBrains YouTrack before 2026.2.18634 improper permission checks allowed read-only users to create and modify whiteboard cards | Sep 7, 2026 | |
| CVE-2026-86492 | HIGH | 8.5 | In JetBrains YouTrack before 2026.2.18634 a shared token cache allowed cross-tenant theft of GitHub App installation tokens | Sep 7, 2026 | |
| CVE-2026-86491 | LOW | 3.5 | In JetBrains YouTrack before 2026.2.18634 stored XSS was possible via project and organization icon uploads | Sep 7, 2026 | |
| CVE-2026-86490 | MEDIUM | 6.5 | In JetBrains YouTrack before 2026.2.18634 improper permission checks allowed overwriting of bundled apps via the app import endpoint | Sep 7, 2026 | |
| CVE-2026-86489 | MEDIUM | 6.5 | In JetBrains YouTrack before 2026.2.18634 an IDOR in the user profile API disclosed private issues and starred folders across organizations | Sep 7, 2026 | |
| CVE-2026-86488 | MEDIUM | 6.5 | In JetBrains YouTrack before 2026.2.18634 iDOR via the watchRules and issueListConfig endpoints exposed private saved searches | Sep 7, 2026 | |
| CVE-2026-86487 | LOW | 3.1 | In JetBrains YouTrack before 2026.2.18634 a crafted WebSocket message allowed read-only whiteboard users to modify canvas content | Sep 7, 2026 | |
| CVE-2026-86486 | LOW | 3.7 | In JetBrains YouTrack before 2026.2.18634 the generic VCS webhook handler failed open when its secret was blank | Sep 7, 2026 | |
| CVE-2026-86485 | LOW | 3.3 | In JetBrains YouTrack before 2026.2.18634 iP spoofing via HTTP headers allowed forged Bitbucket webhooks | Sep 7, 2026 | |
| CVE-2026-86484 | MEDIUM | 4.6 | In JetBrains YouTrack before 2026.2.18634 angularJS template injection in assignee names led to stored XSS | Sep 7, 2026 | |
| CVE-2026-86483 | MEDIUM | 5.4 | In JetBrains YouTrack before 2026.2.18634 stored XSS via a custom field on Agile board cards was possible | Sep 7, 2026 | |
| CVE-2026-86482 | HIGH | 8.8 | In JetBrains YouTrack before 2026.2.18634 unchecked group membership changes allowed privilege escalation | Sep 7, 2026 | |
| CVE-2026-86481 | MEDIUM | 4.3 | In JetBrains YouTrack before 2026.2.18634 signed URL reuse allowed disclosure of restricted project icons | Sep 7, 2026 | |
| CVE-2026-86480 | CRITICAL | 9.8 | In JetBrains Hub before 2026.2.52442 an unauthenticated attacker could register a trusted service and gain superuser privileges | Sep 7, 2026 | |
| CVE-2026-86479 | HIGH | 8.1 | In JetBrains YouTrack before 2026.2.18788, 2026.1.14055, 2025.3.161254 missing authorisation allowed access to restricted REST API resources via IDOR | Sep 7, 2026 | |
| CVE-2026-86478 | CRITICAL | 9.8 | In JetBrains YouTrack before 2025.3.161254, 2026.1.14042 improper authentication in YouTrack Helpdesk allowed unauthenticated account takeover via a self-asserted email address | Sep 7, 2026 | |
| CVE-2026-80176 | MEDIUM | 4.7 | Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Plaintext Storage of a Password vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to information disclosure. | Sep 7, 2026 | |
| CVE-2026-80167 | MEDIUM | 5.5 | Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Use of Hard-coded Cryptographic Key vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to information disclosure. | Sep 7, 2026 | |
| CVE-2026-80166 | HIGH | 7.8 | Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Privilege Management vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability, leading to elevation of privileges. | Sep 7, 2026 | |
| CVE-2026-80126 | MEDIUM | 6.5 | Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Locking vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to filesystem access for attacker. | Sep 7, 2026 |