Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.1 HIGH
CVE-2026-49371 — JetBrains TeamCity Reflected Cross-Site Scripting Vulnerability

In JetBrains TeamCity before 2026.1.1 reflected XSS in the keyword filter was possible

teamcity | Remote | Cross-Site Scripting
May 29, 2026 May 29, 2026
May 29, 2026
May 29, 2026
3.4 LOW
CVE-2026-49370 — JetBrains YouTrack Information Disclosure Vulnerability

In JetBrains YouTrack before 2026.1.13162 information disclosure was possible on fetchApp requests

youtrack | Remote | Information Disclosure
May 29, 2026 May 29, 2026
May 29, 2026
May 29, 2026
4.3 MEDIUM
CVE-2026-49369 — JetBrains YouTrack Information Disclosure Vulnerability

In JetBrains YouTrack before 2026.1.13162 information disclosure was possible on Users and Groups pages

youtrack | Remote | Information Disclosure
May 29, 2026 May 29, 2026
May 29, 2026
May 29, 2026
8.7 HIGH
CVE-2026-49368 — "JetBrains YouTrack Stored XSS Vulnerability in Project Notification Templates"

In JetBrains YouTrack before 2026.1.13162 stored XSS in project notification templates was possible

youtrack | Remote | Cross-Site Scripting
May 29, 2026 May 29, 2026
May 29, 2026
May 29, 2026
8.0 HIGH
CVE-2026-49367 — JetBrains IntelliJ IDEA Command Execution Vulnerability

In JetBrains IntelliJ IDEA before 2026.1.1 command execution was possible via the guest user account

intellij_idea | Remote | Authentication
May 29, 2026 May 29, 2026
May 29, 2026
May 29, 2026
7.8 HIGH
CVE-2026-49366 — JetBrains IntelliJ IDEA Command Injection Vulnerability

In JetBrains IntelliJ IDEA before 2026.1.1 command injection was possible via filename completion

intellij_idea | Injection
May 29, 2026 May 29, 2026
May 29, 2026
May 29, 2026
6.5 MEDIUM
CVE-2026-47745 — Shopper: Missing per-action authorization on PaymentMethods, Currencies and Carriers admi…

Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, the admin tables for PaymentMethods, Currencies and Carriers exposed inline toggles and per-record actions (enable, disable, edit, delete…

Remote | Authorization
May 29, 2026 May 29, 2026
May 29, 2026
May 29, 2026
9.9 CRITICAL
CVE-2026-47744 — Shopper: Authorization bypass and RBAC privilege escalation in team settings

Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, two distinct authorization defects in the team settings allowed any authenticated panel user to take over the RBAC system. Settings/Team/…

Remote | Authorization
May 29, 2026 May 29, 2026
May 29, 2026
May 29, 2026
6.5 MEDIUM
CVE-2026-47742 — Shopper: Missing authorization on Product admin Livewire sub-form components

Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, Sub-form Livewire components used in the product editor (Edit, Inventory, Seo, Shipping, Files) had no authorization on their store() met…

Remote | Authorization
May 29, 2026 May 29, 2026
May 29, 2026
May 29, 2026
5.9 MEDIUM
CVE-2026-47741 — Shopper: Race condition on Discount.usage_limit allows silent over-redemption

Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, CreateOrderFromCartAction::execute previously created the Order row before checking and incrementing the discount's total_use counter. Un…

Remote | Race Condition
May 29, 2026 May 29, 2026
May 29, 2026
May 29, 2026
8.1 HIGH
CVE-2026-47740 — Shopper: Authorization bypass in multiple Livewire admin components

Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, Multiple Filament actions on the admin Order detail and Order shipments table were callable by an authenticated low-privilege user withou…

Remote | Authorization
May 29, 2026 May 29, 2026
May 29, 2026
May 29, 2026
8.5 HIGH
CVE-2026-46372 — SillyTavern: SSRF in SearXNG Search Proxy via Unvalidated baseUrl

SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models. Prior to 1.18.0,…

sillytavern | Remote | Server-Side Request Forgery
May 29, 2026 May 29, 2026
May 29, 2026
May 29, 2026
5.3 MEDIUM
CVE-2026-46344 — liboqs: Heap-buffer-overflow in XMSS verification path via OID-controlled parameter misma…

liboqs is a C-language cryptographic library that provides implementations of post-quantum cryptography algorithms. Prior to 0.16.0, an out-of-bounds read has been identified in the XMSS and XMSS^MT …

liboqs | Remote | Memory Corruption
May 29, 2026 May 29, 2026
May 29, 2026
May 29, 2026
6.9 MEDIUM
CVE-2026-44652 — SillyTavern: SSRF vulnerability in the CORS proxy middleware

SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models. Prior to 1.18.0,…

sillytavern | Remote | Server-Side Request Forgery
May 29, 2026 May 29, 2026
May 29, 2026
May 29, 2026
6.9 MEDIUM
CVE-2026-44651 — SillyTavern: Reflected XSS vulnerability in the CORS proxy middleware

SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models. Prior to 1.18.0,…

sillytavern | Remote | Server-Side Request Forgery
May 29, 2026 May 29, 2026
May 29, 2026
May 29, 2026
9.1 CRITICAL
CVE-2026-44650 — SillyTavern: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal…

SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models. Prior to 1.18.0,…

sillytavern | Remote | Misconfiguration
May 29, 2026 May 29, 2026
May 29, 2026
May 29, 2026
9.8 CRITICAL
CVE-2026-44649 — SillyTavern: Authentication Bypass via SSO Header Injection

SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models. Prior to 1.18.0,…

sillytavern | Remote | Authentication
May 29, 2026 May 29, 2026
May 29, 2026
May 29, 2026
7.5 HIGH
CVE-2026-44648 — SillyTavern: Existing sessions are not invalidated after password change, allowing sessio…

SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models. Prior to 1.18.0,…

sillytavern | Remote | Authentication
May 29, 2026 May 29, 2026
May 29, 2026
May 29, 2026
5.9 MEDIUM
CVE-2026-44611 — MacGregor Voyage Data Recorder (VDR) G4e Use of Password Hash With Insufficient Computati…

Danelec MacGregor Voyage Data Recorder passwords are stored with a hashing method which limits password length and is susceptible to brute force attacks.

| Authentication
May 29, 2026 May 29, 2026
May 29, 2026
May 29, 2026
5.3 MEDIUM
CVE-2026-44518 — liboqs: XMSS Buffer Overread Bug

liboqs is a C-language cryptographic library that provides implementations of post-quantum cryptography algorithms. Prior to 0.16.0, an out-of-bounds read has been identified in the XMSS and XMSS^MT …

liboqs | Remote | Memory Corruption
May 29, 2026 May 29, 2026
May 29, 2026
May 29, 2026
Showing 20 of 6956 Results