Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
4.3 MEDIUM
CVE-2026-12630 — 6LoWPAN IPHC uncompression out-of-bounds read on reserved destination addressing mode

Zephyr's 6LoWPAN IP Header Compression (IPHC) uncompression code contains an out-of-bounds read in get_ihpc_inlined_size() (subsys/net/ip/6lo.c). The destination inline size is looked up in da_inline…

zephyr zephyr | Memory Corruption
Aug 17, 2026 Aug 26, 2026
Aug 17, 2026
Aug 26, 2026
4.6 MEDIUM
CVE-2026-12629 — PL011 UART error interrupts never cleared, enabling an external-peer interrupt-storm deni…

The ARM PL011 UART driver in drivers/serial/uart_pl011.c fails to acknowledge receive error interrupts. On the PL011, the framing, parity, break, and overrun error interrupts (PL011_IMSC_ERROR_MASK) …

zephyr zephyr | Denial of Service
Aug 17, 2026 Aug 26, 2026
Aug 17, 2026
Aug 26, 2026
5.0 MEDIUM
CVE-2026-12519 — Out-of-bounds stack read and write in Zephyr WNC-M14A2A modem socket-notify parsing

The WNC-M14A2A LTE-M modem driver mishandles unsolicited %NOTIFYEV: events in on_cmd_socknotifyev() (drivers/modem/vendor_standalone/wncm14a2a.c). The response line is linearized into a fixed 40-byte…

zephyr zephyr | Memory Corruption
Aug 17, 2026 Aug 26, 2026
Aug 17, 2026
Aug 26, 2026
8.4 HIGH
CVE-2026-75060 — JetBrains PyCharm Remote Code Execution Vulnerability

In JetBrains PyCharm before 2026.2.1 code execution was possible via unauthenticated Jupyter MCP tools

pycharm | Authentication
Aug 17, 2026 Sep 10, 2026
Aug 17, 2026
Sep 10, 2026
4.4 MEDIUM
CVE-2026-75059 — JetBrains PyCharm Remote Code Execution

In JetBrains PyCharm before 2026.2.1 code execution via Quick Documentation was possible

pycharm | Injection
Aug 17, 2026 Sep 10, 2026
Aug 17, 2026
Sep 10, 2026
5.5 MEDIUM
CVE-2026-75058 — JetBrains IntelliJ IDEA XML External Entity Injection

In JetBrains IntelliJ IDEA before 2026.2.1 xXE was possible in the Eclipse settings importers

intellij_idea | XML External Entity
Aug 17, 2026 Sep 11, 2026
Aug 17, 2026
Sep 11, 2026
6.2 MEDIUM
CVE-2026-75057 — JetBrains IntelliJ IDEA Git Credential Information Disclosure

In JetBrains IntelliJ IDEA before 2026.1.5 git credentials were written in plaintext to the IDE log

intellij_idea | Information Disclosure
Aug 17, 2026 Sep 11, 2026
Aug 17, 2026
Sep 11, 2026
7.8 HIGH
CVE-2026-75056 — JetBrains IntelliJ IDEA Remote Code Execution Vulnerability

In JetBrains IntelliJ IDEA before 2026.2.1 rCE via Markdown export tool was possible

intellij_idea | Information Disclosure
Aug 17, 2026 Sep 11, 2026
Aug 17, 2026
Sep 11, 2026
5.5 MEDIUM
CVE-2026-75055 — JetBrains IntelliJ IDEA XML External Entity Injection Vulnerability

In JetBrains IntelliJ IDEA before 2026.2.1 hadoop ResourceManager could read local files via XXE

intellij_idea | XML External Entity
Aug 17, 2026 Sep 11, 2026
Aug 17, 2026
Sep 11, 2026
6.3 MEDIUM
CVE-2026-75054 — JetBrains IntelliJ IDEA Server-Side Request Forgery

In JetBrains IntelliJ IDEA before 2026.2.1 sSRF was possible via the OpenAPI preview proxy in untrusted projects

intellij_idea | Server-Side Request Forgery
Aug 17, 2026 Sep 11, 2026
Aug 17, 2026
Sep 11, 2026
5.4 MEDIUM
CVE-2026-75053 — JetBrains IntelliJ IDEA Server-Side Request Forgery

In JetBrains IntelliJ IDEA before 2026.2.1 sSRF was possible via the DevKit debug listener endpoint

intellij_idea | Remote | Server-Side Request Forgery
Aug 17, 2026 Sep 11, 2026
Aug 17, 2026
Sep 11, 2026
4.4 MEDIUM
CVE-2026-75052 — JetBrains IntelliJ IDEA Arbitrary Command Execution

In JetBrains IntelliJ IDEA before 2026.2.1 command execution via crafted Markdown preview content was possible in trusted projects

intellij_idea | Misconfiguration
Aug 17, 2026 Sep 01, 2026
Aug 17, 2026
Sep 01, 2026
8.1 HIGH
CVE-2026-75051 — JetBrains YouTrack Unauthorized Project Transfer Vulnerability

In JetBrains YouTrack before 2026.2.17917 unauthorised project transfer between organisations was possible

youtrack | Remote | Authorization
Aug 17, 2026 Sep 15, 2026
Aug 17, 2026
Sep 15, 2026
7.1 HIGH
CVE-2026-75050 — JetBrains YouTrack Denial of Service Vulnerability

In JetBrains YouTrack before 2026.1.13901, 2026.2.17950 doS attack was possible via crafted type parameters

youtrack | Remote | Denial of Service
Aug 17, 2026 Sep 15, 2026
Aug 17, 2026
Sep 15, 2026
6.5 MEDIUM
CVE-2026-75049 — JetBrains YouTrack Unauthorized Information Disclosure

In JetBrains YouTrack before 2026.1.13903, 2026.2.17950 an authenticated user could read restricted articles from other projects via the draft creation endpoint

youtrack | Remote | Authorization
Aug 17, 2026 Sep 15, 2026
Aug 17, 2026
Sep 15, 2026
8.2 HIGH
CVE-2026-75048 — JetBrains YouTrack Stored Cross-Site Scripting Vulnerability

In JetBrains YouTrack before 2026.2.18068 stored XSS via the fenced code-block language label was possible

youtrack | Remote | Cross-Site Scripting
Aug 17, 2026 Sep 15, 2026
Aug 17, 2026
Sep 15, 2026
6.5 MEDIUM
CVE-2026-75047 — JetBrains YouTrack Denial of Service Vulnerability

In JetBrains YouTrack before 2026.2.18177 doS attack was possible via a decompression bomb in the import endpoint

youtrack | Remote | Denial of Service
Aug 17, 2026 Sep 15, 2026
Aug 17, 2026
Sep 15, 2026
4.3 MEDIUM
CVE-2026-75046 — JetBrains YouTrack Account Enumeration Vulnerability

In JetBrains YouTrack before 2026.2.18112 an authenticated user could enumerate accounts via the users search endpoint

youtrack | Remote | Authorization
Aug 17, 2026 Sep 15, 2026
Aug 17, 2026
Sep 15, 2026
9.1 CRITICAL
CVE-2026-75045 — JetBrains YouTrack Unauthenticated Backup Disclosure Vulnerability

In JetBrains YouTrack before 2025.3.156085, 2026.1.13913, 2026.2.18112 an unauthenticated attacker could download database backups via shared draft signature

youtrack | Remote | Information Disclosure
Aug 17, 2026 Sep 15, 2026
Aug 17, 2026
Sep 15, 2026
8.1 HIGH
CVE-2026-75044 — JetBrains YouTrack Improper Authorization Vulnerability

In JetBrains YouTrack before 2025.3.156085, 2026.1.13914, 2026.2.18095 missing authorisation allowed an authenticated user to delete arbitrary entities via the mailbox endpoint

youtrack | Remote | Authorization
Aug 17, 2026 Sep 15, 2026
Aug 17, 2026
Sep 15, 2026
Showing 20 of 14717 Results