Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.5 HIGH
CVE-2026-49370 — JetBrains YouTrack Information Disclosure Vulnerability

In JetBrains YouTrack before 2026.1.13162 information disclosure was possible on fetchApp requests

youtrack | Remote | Information Disclosure
May 29, 2026 Jun 01, 2026
May 29, 2026
Jun 01, 2026
4.3 MEDIUM
CVE-2026-49369 — JetBrains YouTrack Information Disclosure Vulnerability

In JetBrains YouTrack before 2026.1.13162 information disclosure was possible on Users and Groups pages

youtrack | Remote | Information Disclosure
May 29, 2026 Jun 01, 2026
May 29, 2026
Jun 01, 2026
8.7 HIGH
CVE-2026-49368 — "JetBrains YouTrack Stored XSS Vulnerability in Project Notification Templates"

In JetBrains YouTrack before 2026.1.13162 stored XSS in project notification templates was possible

youtrack | Remote | Cross-Site Scripting
May 29, 2026 Jun 01, 2026
May 29, 2026
Jun 01, 2026
8.8 HIGH
CVE-2026-49367 — JetBrains IntelliJ IDEA Command Execution Vulnerability

In JetBrains IntelliJ IDEA before 2026.1.1 command execution was possible via the guest user account

intellij_idea | Remote | Authentication
May 29, 2026 Jun 01, 2026
May 29, 2026
Jun 01, 2026
7.8 HIGH
CVE-2026-49366 — JetBrains IntelliJ IDEA Command Injection Vulnerability

In JetBrains IntelliJ IDEA before 2026.1.1 command injection was possible via filename completion

intellij_idea | Injection
May 29, 2026 Jun 01, 2026
May 29, 2026
Jun 01, 2026
6.5 MEDIUM
CVE-2026-47745 — Shopper: Missing per-action authorization on PaymentMethods, Currencies and Carriers admi…

Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, the admin tables for PaymentMethods, Currencies and Carriers exposed inline toggles and per-record actions (enable, disable, edit, delete…

Remote | Authorization
May 29, 2026 May 29, 2026
May 29, 2026
May 29, 2026
9.9 CRITICAL
CVE-2026-47744 — Shopper: Authorization bypass and RBAC privilege escalation in team settings

Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, two distinct authorization defects in the team settings allowed any authenticated panel user to take over the RBAC system. Settings/Team/…

Remote | Authorization
May 29, 2026 May 29, 2026
May 29, 2026
May 29, 2026
6.5 MEDIUM
CVE-2026-47742 — Shopper: Missing authorization on Product admin Livewire sub-form components

Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, Sub-form Livewire components used in the product editor (Edit, Inventory, Seo, Shipping, Files) had no authorization on their store() met…

Remote | Authorization
May 29, 2026 May 29, 2026
May 29, 2026
May 29, 2026
5.9 MEDIUM
CVE-2026-47741 — Shopper: Race condition on Discount.usage_limit allows silent over-redemption

Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, CreateOrderFromCartAction::execute previously created the Order row before checking and incrementing the discount's total_use counter. Un…

Remote | Race Condition
May 29, 2026 May 29, 2026
May 29, 2026
May 29, 2026
8.1 HIGH
CVE-2026-47740 — Shopper: Authorization bypass in multiple Livewire admin components

Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, Multiple Filament actions on the admin Order detail and Order shipments table were callable by an authenticated low-privilege user withou…

Remote | Authorization
May 29, 2026 May 29, 2026
May 29, 2026
May 29, 2026
8.5 HIGH
CVE-2026-46372 — SillyTavern: SSRF in SearXNG Search Proxy via Unvalidated baseUrl

SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models. Prior to 1.18.0,…

sillytavern | Remote | Server-Side Request Forgery
May 29, 2026 May 29, 2026
May 29, 2026
May 29, 2026
5.3 MEDIUM
CVE-2026-46344 — liboqs: Heap-buffer-overflow in XMSS verification path via OID-controlled parameter misma…

liboqs is a C-language cryptographic library that provides implementations of post-quantum cryptography algorithms. Prior to 0.16.0, an out-of-bounds read has been identified in the XMSS and XMSS^MT …

liboqs | Remote | Memory Corruption
May 29, 2026 Jun 04, 2026
May 29, 2026
Jun 04, 2026
6.9 MEDIUM
CVE-2026-44652 — SillyTavern: SSRF vulnerability in the CORS proxy middleware

SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models. Prior to 1.18.0,…

sillytavern | Remote | Server-Side Request Forgery
May 29, 2026 May 29, 2026
May 29, 2026
May 29, 2026
6.9 MEDIUM
CVE-2026-44651 — SillyTavern: Reflected XSS vulnerability in the CORS proxy middleware

SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models. Prior to 1.18.0,…

sillytavern | Remote | Server-Side Request Forgery
May 29, 2026 May 29, 2026
May 29, 2026
May 29, 2026
9.1 CRITICAL
CVE-2026-44650 — SillyTavern: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal…

SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models. Prior to 1.18.0,…

sillytavern | Remote | Misconfiguration
May 29, 2026 May 29, 2026
May 29, 2026
May 29, 2026
9.8 CRITICAL
CVE-2026-44649 — SillyTavern: Authentication Bypass via SSO Header Injection

SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models. Prior to 1.18.0,…

sillytavern | Remote | Authentication
May 29, 2026 Jun 02, 2026
May 29, 2026
Jun 02, 2026
7.5 HIGH
CVE-2026-44648 — SillyTavern: Existing sessions are not invalidated after password change, allowing sessio…

SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models. Prior to 1.18.0,…

sillytavern | Remote | Authentication
May 29, 2026 May 29, 2026
May 29, 2026
May 29, 2026
5.9 MEDIUM
CVE-2026-44611 — MacGregor Voyage Data Recorder (VDR) G4e Use of Password Hash With Insufficient Computati…

Danelec MacGregor Voyage Data Recorder passwords are stored with a hashing method which limits password length and is susceptible to brute force attacks.

May 29, 2026 Jun 04, 2026
May 29, 2026
Jun 04, 2026
5.3 MEDIUM
CVE-2026-44518 — liboqs: XMSS Buffer Overread Bug

liboqs is a C-language cryptographic library that provides implementations of post-quantum cryptography algorithms. Prior to 0.16.0, an out-of-bounds read has been identified in the XMSS and XMSS^MT …

liboqs | Remote | Memory Corruption
May 29, 2026 Jun 04, 2026
May 29, 2026
Jun 04, 2026
5.9 MEDIUM
CVE-2026-42951 — MacGregor Voyage Data Recorder (VDR) G4e Insufficiently Protected Credentials

An authenticated user can download a backup of the Danelec MacGregor Voyage Data Recorder device which includes account data and password hashes.

May 29, 2026 Jun 04, 2026
May 29, 2026
Jun 04, 2026
Showing 20 of 7261 Results