Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.5 MEDIUM
CVE-2026-86489 — JetBrains YouTrack Insecure Direct Object Reference Vulnerability

In JetBrains YouTrack before 2026.2.18634 an IDOR in the user profile API disclosed private issues and starred folders across organizations

youtrack | Remote | Authorization
Sep 07, 2026 Sep 07, 2026
Sep 07, 2026
Sep 07, 2026
6.5 MEDIUM
CVE-2026-86488 — JetBrains YouTrack Insecure Direct Object Reference Vulnerability

In JetBrains YouTrack before 2026.2.18634 iDOR via the watchRules and issueListConfig endpoints exposed private saved searches

youtrack | Remote | Authorization
Sep 07, 2026 Sep 07, 2026
Sep 07, 2026
Sep 07, 2026
3.1 LOW
CVE-2026-86487 — JetBrains YouTrack Improper Authorization Vulnerability

In JetBrains YouTrack before 2026.2.18634 a crafted WebSocket message allowed read-only whiteboard users to modify canvas content

youtrack | Remote | Authorization
Sep 07, 2026 Sep 07, 2026
Sep 07, 2026
Sep 07, 2026
3.7 LOW
CVE-2026-86486 — JetBrains YouTrack VCS Webhook Authentication Bypass

In JetBrains YouTrack before 2026.2.18634 the generic VCS webhook handler failed open when its secret was blank

youtrack | Remote | Misconfiguration
Sep 07, 2026 Sep 07, 2026
Sep 07, 2026
Sep 07, 2026
3.5 LOW
CVE-2026-86485 — JetBrains YouTrack IP Spoofing Vulnerability

In JetBrains YouTrack before 2026.2.18634 iP spoofing via HTTP headers allowed forged Bitbucket webhooks

youtrack | Misconfiguration
Sep 07, 2026 Sep 07, 2026
Sep 07, 2026
Sep 07, 2026
4.6 MEDIUM
CVE-2026-86484 — JetBrains YouTrack AngularJS Template Injection Stored Cross-Site Scripting

In JetBrains YouTrack before 2026.2.18634 angularJS template injection in assignee names led to stored XSS

youtrack | Remote | Cross-Site Scripting
Sep 07, 2026 Sep 07, 2026
Sep 07, 2026
Sep 07, 2026
5.4 MEDIUM
CVE-2026-86483 — JetBrains YouTrack Stored Cross-Site Scripting

In JetBrains YouTrack before 2026.2.18634 stored XSS via a custom field on Agile board cards was possible

youtrack | Remote | Cross-Site Scripting
Sep 07, 2026 Sep 07, 2026
Sep 07, 2026
Sep 07, 2026
8.8 HIGH
CVE-2026-86482 — JetBrains YouTrack Privilege Escalation via Group Membership Modification

In JetBrains YouTrack before 2026.2.18634 unchecked group membership changes allowed privilege escalation

youtrack | Remote | Authorization
Sep 07, 2026 Sep 07, 2026
Sep 07, 2026
Sep 07, 2026
4.3 MEDIUM
CVE-2026-86481 — JetBrains YouTrack URL Reuse Information Disclosure

In JetBrains YouTrack before 2026.2.18634 signed URL reuse allowed disclosure of restricted project icons

youtrack | Remote | Information Disclosure
Sep 07, 2026 Sep 07, 2026
Sep 07, 2026
Sep 07, 2026
9.8 CRITICAL
CVE-2026-86480 — JetBrains Hub Improper Authorization Vulnerability

In JetBrains Hub before 2026.2.52442 an unauthenticated attacker could register a trusted service and gain superuser privileges

hub | Remote | Authentication
Sep 07, 2026 Sep 07, 2026
Sep 07, 2026
Sep 07, 2026
8.0 HIGH
CVE-2026-86479 — JetBrains YouTrack Insecure Direct Object Reference Vulnerability

In JetBrains YouTrack before 2026.2.18788, 2026.1.14055, 2025.3.161254 missing authorisation allowed access to restricted REST API resources via IDOR

youtrack | Remote | Authorization
Sep 07, 2026 Sep 07, 2026
Sep 07, 2026
Sep 07, 2026
9.8 CRITICAL
CVE-2026-86478 — JetBrains YouTrack Improper Authentication Vulnerability

In JetBrains YouTrack before 2025.3.161254, 2026.1.14042 improper authentication in YouTrack Helpdesk allowed unauthenticated account takeover via a self-asserted email address

youtrack | Remote | Authentication
Sep 07, 2026 Sep 07, 2026
Sep 07, 2026
Sep 07, 2026
5.9 MEDIUM
CVE-2026-80125 — Dell Secure Connect Gateway Improper Certificate Validation Vulnerability

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker w…

Remote | Authentication
Sep 07, 2026 Sep 07, 2026
Sep 07, 2026
Sep 07, 2026
5.3 MEDIUM
CVE-2026-86469 — Glib2: toctou symlink race in `g_file_create_replace_destination` fallback path

A flaw was found in GLib2. When g_file_replace() is used with G_FILE_CREATE_REPLACE_DESTINATION and creating the .goutputstream-XXXXXX temporary file fails, the library unlinks the destination and re…

Sep 07, 2026 Sep 07, 2026
Sep 07, 2026
Sep 07, 2026
5.5 MEDIUM
CVE-2026-86321 — java-json-tools jackson-coreutils URL Validation JsonLoader.java JsonLoader.fromURL serve…

A vulnerability was found in java-json-tools jackson-coreutils 2.0. Affected by this issue is the function JsonLoader.fromURL of the file src/main/java/com/github/fge/jackson/JsonLoader.java of the c…

Remote | Server-Side Request Forgery
Sep 07, 2026 Sep 07, 2026
Sep 07, 2026
Sep 07, 2026
7.2 HIGH
CVE-2026-80127 — Dell Secure Connect Gateway OS Command Injection Vulnerability

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Comma…

Remote | Injection
Sep 07, 2026 Sep 07, 2026
Sep 07, 2026
Sep 07, 2026
5.5 MEDIUM
CVE-2026-80054 — Dell SCG Incorrect Permission Assignment Vulnerability

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Incorrect Permission Assignment for Critical Resource vulnerability. A low p…

| Authorization
Sep 07, 2026 Sep 07, 2026
Sep 07, 2026
Sep 07, 2026
4.8 MEDIUM
CVE-2026-79943 — Dell Secure Connect Gateway Improper Certificate Validation Vulnerability

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Validation of Certificate with Host Mismatch vulnerability. An unau…

Remote | Authentication
Sep 07, 2026 Sep 07, 2026
Sep 07, 2026
Sep 07, 2026
7.3 HIGH
CVE-2026-79691 — Dell Secure Connect Gateway Improper Certificate Validation Vulnerability

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker w…

Remote | Misconfiguration
Sep 07, 2026 Sep 07, 2026
Sep 07, 2026
Sep 07, 2026
5.5 MEDIUM
CVE-2026-80167 — Dell SCG Use of Hard-coded Cryptographic Key Vulnerability

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Use of Hard-coded Cryptographic Key vulnerability. A low privileged attacker…

| Cryptography
Sep 07, 2026 Sep 07, 2026
Sep 07, 2026
Sep 07, 2026
Showing 20 of 12492 Results