Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.3 MEDIUM
CVE-2026-103222 — Blosc C-Blosc2 blosclz Decompression blosclz.c blosclz_decompress integer overflow

A vulnerability was determined in Blosc C-Blosc2 up to 3.3.2. This impacts the function blosclz_decompress of the file blosc/blosclz.c of the component blosclz Decompression. Executing a manipulation…

c-blosc2 | Remote | Memory Corruption
Sep 30, 2026 Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
8.2 HIGH
CVE-2026-102984 — Astro: Malformed port in the Host header can crash the Node adapter

Astro is a web framework for content-driven websites. Prior to 11.1.3, the @astrojs/node adapter builds a request URL from the Host header, and a malformed port can make that URL invalid. The recover…

Remote | Misconfiguration
Sep 30, 2026 Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
6.3 MEDIUM
CVE-2026-102983 — Astro: Netlify Image CDN allowlist bypass enables SSRF

Astro is a web framework for content-driven websites. From 5.2.0 until 8.2.4, the @astrojs/netlify adapter generates regular expressions for Netlify Image CDN remote-image allowlists without anchorin…

Remote | Misconfiguration
Sep 30, 2026 Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
0.0 NA
CVE-2026-102717 — MQTT WebSocket setter ABI mismatch may disclose memory or cause a crash

MQTT WebSocket setter ABI mismatch may disclose memory or cause a crash

| Memory Corruption
Sep 30, 2026 Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
7.3 HIGH
CVE-2026-101295 — Oc-mirror: oc-mirror: path traversal / arbitrary file write in operator catalog image ext…

Path traversal / arbitrary file write in oc-mirror's operator catalog image extraction. When mirroring operator catalogs using either the legacy v1 path (--v1) or the OCI feature path (--use-oci-feat…

openshift_container_platform | Path Traversal
Sep 30, 2026 Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
0.0 NA
CVE-2026-80490 — Algorithm::AhoCorasick::XS versions through 0.04 for Perl read the haystack string length…

Algorithm::AhoCorasick::XS versions through 0.04 for Perl read the haystack string length before the scalar is stringified. The matches, first_match and match_details methods use the T_STD_STRING ty…

| Memory Corruption
Sep 30, 2026 Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
3.1 LOW
CVE-2026-100280 — JetBrains YouTrack Improper Access Control Vulnerability

In JetBrains YouTrack before 2026.2.19197 creating a project from an unreadable custom template was possible

youtrack | Remote | Misconfiguration
Sep 30, 2026 Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
6.5 MEDIUM
CVE-2026-100279 — JetBrains YouTrack Credential Exposure via Integration URL Modification

In JetBrains YouTrack before 2026.2.19197 changing an integration URL exposed its stored credentials

youtrack | Remote | Information Disclosure
Sep 30, 2026 Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
4.9 MEDIUM
CVE-2026-100278 — JetBrains YouTrack Improper Authorization Vulnerability

In JetBrains YouTrack before 2026.2.19197 users with restricted permission could edit and hide other users' comments

youtrack | Remote | Authorization
Sep 30, 2026 Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
8.9 HIGH
CVE-2026-100277 — JetBrains YouTrack Notification Signature Replay Account Takeover

In JetBrains YouTrack before 2026.2.19197 account takeover was possible by replaying a notification signature

youtrack | Remote | Authentication
Sep 30, 2026 Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
5.9 MEDIUM
CVE-2026-100276 — JetBrains YouTrack Improper Authorization Vulnerability

In JetBrains YouTrack before 2026.2.19197 guest users could remove a workflow action's visibility restriction and run the action

youtrack | Remote | Authorization
Sep 30, 2026 Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
6.9 MEDIUM
CVE-2026-100275 — JetBrains YouTrack Stored Cross-Site Scripting

In JetBrains YouTrack before 2026.2.19197 stored XSS in the workflow error notification toast was possible

youtrack | Remote | Cross-Site Scripting
Sep 30, 2026 Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
6.5 MEDIUM
CVE-2026-100274 — JetBrains YouTrack Denial of Service Vulnerability

In JetBrains YouTrack before 2026.2.19197 project Admin could trigger DoS via a notification template

youtrack | Remote | Denial of Service
Sep 30, 2026 Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
8.2 HIGH
CVE-2026-100273 — JetBrains YouTrack Authorization Bypass and Arbitrary Code Execution

In JetBrains YouTrack before 2026.2.19197 authorisation bypass in the scripts debugger allowed arbitrary code execution

youtrack | Remote | Authorization
Sep 30, 2026 Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
4.9 MEDIUM
CVE-2026-100272 — JetBrains YouTrack Missing Authorization Vulnerability

In JetBrains YouTrack before 2026.2.19197 missing authorisation in the notification template preview allowed Project Administrators to read restricted issues

youtrack | Remote | Authorization
Sep 30, 2026 Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
2.7 LOW
CVE-2026-100271 — JetBrains YouTrack Broken Access Control Vulnerability

In JetBrains YouTrack before 2026.2.19197 missing authorisation on several endpoints allowed authenticated users to access information from other projects

youtrack | Remote | Authorization
Sep 30, 2026 Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
3.3 LOW
CVE-2026-100270 — JetBrains YouTrack Integration Credential Information Disclosure

In JetBrains YouTrack before 2026.2.19197 low-level Admin Read permission users could disclose integration credentials via import configurations

youtrack | Remote | Information Disclosure
Sep 30, 2026 Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
4.3 MEDIUM
CVE-2026-100269 — JetBrains YouTrack Authorized Reporters Bypass Vulnerability

In JetBrains YouTrack before 2026.2.19197 helpdesk project's Authorized Reporters list could be bypassed

youtrack | Remote | Authorization
Sep 30, 2026 Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
7.7 HIGH
CVE-2026-100268 — JetBrains YouTrack Unauthorized Information Disclosure

In JetBrains YouTrack before 2026.2.19197 project administrators could read comments from other projects via notification templates

youtrack | Remote | Authorization
Sep 30, 2026 Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
5.9 MEDIUM
CVE-2026-100267 — JetBrains YouTrack Regular Expression Denial of Service

In JetBrains YouTrack before 2026.2.19197 reDoS attack was possible via mailbox regex mail-rule filters

youtrack | Remote | Denial of Service
Sep 30, 2026 Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
Showing 20 of 14938 Results