Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
45502
Total
3651
Critical
13471
High
13397
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-12629 | MEDIUM | 4.6 | The ARM PL011 UART driver in drivers/serial/uart_pl011.c fails to acknowledge receive error interrupts. On the PL011, the framing, parity, break, and overrun error interrupts (PL011_IMSC_ERROR_MASK) … | Aug 17, 2026 |
| CVE-2026-12519 | MEDIUM | 5.0 | The WNC-M14A2A LTE-M modem driver mishandles unsolicited %NOTIFYEV: events in on_cmd_socknotifyev() (drivers/modem/vendor_standalone/wncm14a2a.c). The response line is linearized into a fixed 40-byte stack buffer via net_buf_linearize(), … | Aug 17, 2026 |
| CVE-2026-75060 | HIGH | 8.4 | In JetBrains PyCharm before 2026.2.1 code execution was possible via unauthenticated Jupyter MCP tools | Aug 17, 2026 |
| CVE-2026-75059 | MEDIUM | 4.4 | In JetBrains PyCharm before 2026.2.1 code execution via Quick Documentation was possible | Aug 17, 2026 |
| CVE-2026-75058 | MEDIUM | 5.5 | In JetBrains IntelliJ IDEA before 2026.2.1 xXE was possible in the Eclipse settings importers | Aug 17, 2026 |
| CVE-2026-75057 | MEDIUM | 6.2 | In JetBrains IntelliJ IDEA before 2026.1.5 git credentials were written in plaintext to the IDE log | Aug 17, 2026 |
| CVE-2026-75056 | HIGH | 7.8 | In JetBrains IntelliJ IDEA before 2026.2.1 rCE via Markdown export tool was possible | Aug 17, 2026 |
| CVE-2026-75055 | MEDIUM | 5.5 | In JetBrains IntelliJ IDEA before 2026.2.1 hadoop ResourceManager could read local files via XXE | Aug 17, 2026 |
| CVE-2026-75054 | MEDIUM | 6.3 | In JetBrains IntelliJ IDEA before 2026.2.1 sSRF was possible via the OpenAPI preview proxy in untrusted projects | Aug 17, 2026 |
| CVE-2026-75053 | MEDIUM | 5.4 | In JetBrains IntelliJ IDEA before 2026.2.1 sSRF was possible via the DevKit debug listener endpoint | Aug 17, 2026 |
| CVE-2026-75052 | LOW | 3.6 | In JetBrains IntelliJ IDEA before 2026.2.1 command execution via crafted Markdown preview content was possible in trusted projects | Aug 17, 2026 |
| CVE-2026-75051 | HIGH | 8.1 | In JetBrains YouTrack before 2026.2.17917 unauthorised project transfer between organisations was possible | Aug 17, 2026 |
| CVE-2026-75050 | HIGH | 7.1 | In JetBrains YouTrack before 2026.1.13901, 2026.2.17950 doS attack was possible via crafted type parameters | Aug 17, 2026 |
| CVE-2026-75049 | MEDIUM | 6.5 | In JetBrains YouTrack before 2026.1.13903, 2026.2.17950 an authenticated user could read restricted articles from other projects via the draft creation endpoint | Aug 17, 2026 |
| CVE-2026-75048 | HIGH | 8.2 | In JetBrains YouTrack before 2026.2.18068 stored XSS via the fenced code-block language label was possible | Aug 17, 2026 |
| CVE-2026-75047 | MEDIUM | 6.5 | In JetBrains YouTrack before 2026.2.18177 doS attack was possible via a decompression bomb in the import endpoint | Aug 17, 2026 |
| CVE-2026-75046 | MEDIUM | 4.3 | In JetBrains YouTrack before 2026.2.18112 an authenticated user could enumerate accounts via the users search endpoint | Aug 17, 2026 |
| CVE-2026-75045 | CRITICAL | 9.1 | In JetBrains YouTrack before 2025.3.156085, 2026.1.13913, 2026.2.18112 an unauthenticated attacker could download database backups via shared draft signature | Aug 17, 2026 |
| CVE-2026-75044 | HIGH | 8.1 | In JetBrains YouTrack before 2025.3.156085, 2026.1.13914, 2026.2.18095 missing authorisation allowed an authenticated user to delete arbitrary entities via the mailbox endpoint | Aug 17, 2026 |
| CVE-2026-74858 | MEDIUM | 6.3 | A vulnerability has been found in jae-jae fetcher-mcp up to 0.3.9. Impacted is the function fetch_url/fetch_urls of the file /latest/meta-data/iam/security-credentials/ of the component URL Validation. … | Aug 17, 2026 |
| CVE-2026-73646 | HIGH | 7.5 | PostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rules into an Abstract Syntax Tree. Prior … | Aug 17, 2026 |
| CVE-2026-71479 | CRITICAL | 9.1 | New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to 1.0.0-rc.18, user-controlled image n, video seconds and … | Aug 17, 2026 |
| CVE-2026-68762 | MEDIUM | 5.9 | In JetBrains Ktor before 3.4.1 potential DoS attack via WebSocket decompression was possible | Aug 17, 2026 |
| CVE-2026-64868 | HIGH | 7.5 | New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to 1.0.0-rc.11, POST /api/stripe/webhook, POST /api/creem/webhook, and POST … | Aug 17, 2026 |
| CVE-2026-64866 | UNKNOWN | — | New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. From 0.9.1.3 until 1.0.0-rc.7, AdminResetPasskey in controller/passkey.go lacks the … | Aug 17, 2026 |