Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.1 MEDIUM
CVE-2026-49375 — JetBrains TeamCity Reflected Cross-Site Scripting Vulnerability

In JetBrains TeamCity before 2026.1, 2025.11.5 reflected XSS was possible on the repository download page

Remote | Cross-Site Scripting
May 29, 2026 May 29, 2026
May 29, 2026
May 29, 2026
7.6 HIGH
CVE-2026-49374 — JetBrains TeamCity Path Traversal Vulnerability

In JetBrains TeamCity before 2026.1 improper permission checks exposed build configuration parameters

Remote | Authorization
May 29, 2026 May 29, 2026
May 29, 2026
May 29, 2026
7.1 HIGH
CVE-2026-49373 — JetBrains TeamCity Perforce Remote Code Execution Vulnerability

In JetBrains TeamCity before 2026.1 remote code execution was possible via Perforce connection settings

Remote | Injection
May 29, 2026 May 29, 2026
May 29, 2026
May 29, 2026
7.5 HIGH
CVE-2026-49372 — JetBrains TeamCity SSRF Vulnerability

In JetBrains TeamCity before 2026.1, 2025.11.5 unauthenticated SSRF via build status was possible

Remote | Server-Side Request Forgery
May 29, 2026 May 29, 2026
May 29, 2026
May 29, 2026
7.1 HIGH
CVE-2026-49371 — JetBrains TeamCity Reflected Cross-Site Scripting Vulnerability

In JetBrains TeamCity before 2026.1.1 reflected XSS in the keyword filter was possible

Remote | Cross-Site Scripting
May 29, 2026 May 29, 2026
May 29, 2026
May 29, 2026
3.4 LOW
CVE-2026-49370 — JetBrains YouTrack Information Disclosure Vulnerability

In JetBrains YouTrack before 2026.1.13162 information disclosure was possible on fetchApp requests

Remote | Information Disclosure
May 29, 2026 May 29, 2026
May 29, 2026
May 29, 2026
4.3 MEDIUM
CVE-2026-49369 — JetBrains YouTrack Information Disclosure Vulnerability

In JetBrains YouTrack before 2026.1.13162 information disclosure was possible on Users and Groups pages

Remote | Information Disclosure
May 29, 2026 May 29, 2026
May 29, 2026
May 29, 2026
8.7 HIGH
CVE-2026-49368 — "JetBrains YouTrack Stored XSS Vulnerability in Project Notification Templates"

In JetBrains YouTrack before 2026.1.13162 stored XSS in project notification templates was possible

Remote | Cross-Site Scripting
May 29, 2026 May 29, 2026
May 29, 2026
May 29, 2026
8.0 HIGH
CVE-2026-49367 — JetBrains IntelliJ IDEA Command Execution Vulnerability

In JetBrains IntelliJ IDEA before 2026.1.1 command execution was possible via the guest user account

Remote | Authentication
May 29, 2026 May 29, 2026
May 29, 2026
May 29, 2026
7.8 HIGH
CVE-2026-49366 — JetBrains IntelliJ IDEA Command Injection Vulnerability

In JetBrains IntelliJ IDEA before 2026.1.1 command injection was possible via filename completion

| Injection
May 29, 2026 May 29, 2026
May 29, 2026
May 29, 2026
6.5 MEDIUM
CVE-2026-47745 — Shopper: Missing per-action authorization on PaymentMethods, Currencies and Carriers admi…

Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, the admin tables for PaymentMethods, Currencies and Carriers exposed inline toggles and per-record actions (enable, disable, edit, delete…

Remote | Authorization
May 29, 2026 May 29, 2026
May 29, 2026
May 29, 2026
9.9 CRITICAL
CVE-2026-47744 — Shopper: Authorization bypass and RBAC privilege escalation in team settings

Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, two distinct authorization defects in the team settings allowed any authenticated panel user to take over the RBAC system. Settings/Team/…

Remote | Authorization
May 29, 2026 May 29, 2026
May 29, 2026
May 29, 2026
6.5 MEDIUM
CVE-2026-47742 — Shopper: Missing authorization on Product admin Livewire sub-form components

Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, Sub-form Livewire components used in the product editor (Edit, Inventory, Seo, Shipping, Files) had no authorization on their store() met…

Remote | Authorization
May 29, 2026 May 29, 2026
May 29, 2026
May 29, 2026
5.9 MEDIUM
CVE-2026-47741 — Shopper: Race condition on Discount.usage_limit allows silent over-redemption

Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, CreateOrderFromCartAction::execute previously created the Order row before checking and incrementing the discount's total_use counter. Un…

Remote | Race Condition
May 29, 2026 May 29, 2026
May 29, 2026
May 29, 2026
8.1 HIGH
CVE-2026-47740 — Shopper: Authorization bypass in multiple Livewire admin components

Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, Multiple Filament actions on the admin Order detail and Order shipments table were callable by an authenticated low-privilege user withou…

Remote | Authorization
May 29, 2026 May 29, 2026
May 29, 2026
May 29, 2026
8.5 HIGH
CVE-2026-46372 — SillyTavern: SSRF in SearXNG Search Proxy via Unvalidated baseUrl

SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models. Prior to 1.18.0,…

Remote | Server-Side Request Forgery
May 29, 2026 May 29, 2026
May 29, 2026
May 29, 2026
5.3 MEDIUM
CVE-2026-46344 — liboqs: Heap-buffer-overflow in XMSS verification path via OID-controlled parameter misma…

liboqs is a C-language cryptographic library that provides implementations of post-quantum cryptography algorithms. Prior to 0.16.0, an out-of-bounds read has been identified in the XMSS and XMSS^MT …

Remote | Memory Corruption
May 29, 2026 May 29, 2026
May 29, 2026
May 29, 2026
6.9 MEDIUM
CVE-2026-44652 — SillyTavern: SSRF vulnerability in the CORS proxy middleware

SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models. Prior to 1.18.0,…

Remote | Server-Side Request Forgery
May 29, 2026 May 29, 2026
May 29, 2026
May 29, 2026
6.9 MEDIUM
CVE-2026-44651 — SillyTavern: Reflected XSS vulnerability in the CORS proxy middleware

SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models. Prior to 1.18.0,…

Remote | Server-Side Request Forgery
May 29, 2026 May 29, 2026
May 29, 2026
May 29, 2026
9.1 CRITICAL
CVE-2026-44650 — SillyTavern: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal…

SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models. Prior to 1.18.0,…

Remote | Misconfiguration
May 29, 2026 May 29, 2026
May 29, 2026
May 29, 2026
Showing 20 of 7023 Results