Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

45656
Total
3653
Critical
13500
High
13451
Medium
CVE ID Severity Score Description Published
CVE-2026-68517 MEDIUM 6.5 Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.6, the cors_origins guard in glances/outputs/glances_restful_api.py uses exact list equality instead of wildcard membership, allowing … Aug 17, 2026
CVE-2026-61666 UNKNOWN websocket-driver is a WebSocket protocol handler with pluggable I/O. Prior to 0.8.2, WebSocket::Driver.server() passes a malformed Host header to URI.parse in lib/websocket/http/request.rb without catching URI::InvalidURIError, … Aug 17, 2026
CVE-2026-40145 UNKNOWN A vulnerability exists in the interaction between a Endpoint Privilege Management (Windows Deployment) support utility and the agent's tamper protection controls. Under certain conditions, the … Aug 17, 2026
CVE-2026-12630 MEDIUM 4.3 Zephyr's 6LoWPAN IP Header Compression (IPHC) uncompression code contains an out-of-bounds read in get_ihpc_inlined_size() (subsys/net/ip/6lo.c). The destination inline size is looked up in da_inline_size_table, which … Aug 17, 2026
CVE-2026-12629 MEDIUM 4.6 The ARM PL011 UART driver in drivers/serial/uart_pl011.c fails to acknowledge receive error interrupts. On the PL011, the framing, parity, break, and overrun error interrupts (PL011_IMSC_ERROR_MASK) … Aug 17, 2026
CVE-2026-12519 MEDIUM 5.0 The WNC-M14A2A LTE-M modem driver mishandles unsolicited %NOTIFYEV: events in on_cmd_socknotifyev() (drivers/modem/vendor_standalone/wncm14a2a.c). The response line is linearized into a fixed 40-byte stack buffer via net_buf_linearize(), … Aug 17, 2026
CVE-2026-75060 HIGH 8.4 In JetBrains PyCharm before 2026.2.1 code execution was possible via unauthenticated Jupyter MCP tools Aug 17, 2026
CVE-2026-75059 MEDIUM 4.4 In JetBrains PyCharm before 2026.2.1 code execution via Quick Documentation was possible Aug 17, 2026
CVE-2026-75058 MEDIUM 5.5 In JetBrains IntelliJ IDEA before 2026.2.1 xXE was possible in the Eclipse settings importers Aug 17, 2026
CVE-2026-75057 MEDIUM 6.2 In JetBrains IntelliJ IDEA before 2026.1.5 git credentials were written in plaintext to the IDE log Aug 17, 2026
CVE-2026-75056 HIGH 7.8 In JetBrains IntelliJ IDEA before 2026.2.1 rCE via Markdown export tool was possible Aug 17, 2026
CVE-2026-75055 MEDIUM 5.5 In JetBrains IntelliJ IDEA before 2026.2.1 hadoop ResourceManager could read local files via XXE Aug 17, 2026
CVE-2026-75054 MEDIUM 6.3 In JetBrains IntelliJ IDEA before 2026.2.1 sSRF was possible via the OpenAPI preview proxy in untrusted projects Aug 17, 2026
CVE-2026-75053 MEDIUM 5.4 In JetBrains IntelliJ IDEA before 2026.2.1 sSRF was possible via the DevKit debug listener endpoint Aug 17, 2026
CVE-2026-75052 LOW 3.6 In JetBrains IntelliJ IDEA before 2026.2.1 command execution via crafted Markdown preview content was possible in trusted projects Aug 17, 2026
CVE-2026-75051 HIGH 8.1 In JetBrains YouTrack before 2026.2.17917 unauthorised project transfer between organisations was possible Aug 17, 2026
CVE-2026-75050 HIGH 7.1 In JetBrains YouTrack before 2026.1.13901, 2026.2.17950 doS attack was possible via crafted type parameters Aug 17, 2026
CVE-2026-75049 MEDIUM 6.5 In JetBrains YouTrack before 2026.1.13903, 2026.2.17950 an authenticated user could read restricted articles from other projects via the draft creation endpoint Aug 17, 2026
CVE-2026-75048 HIGH 8.2 In JetBrains YouTrack before 2026.2.18068 stored XSS via the fenced code-block language label was possible Aug 17, 2026
CVE-2026-75047 MEDIUM 6.5 In JetBrains YouTrack before 2026.2.18177 doS attack was possible via a decompression bomb in the import endpoint Aug 17, 2026
CVE-2026-75046 MEDIUM 4.3 In JetBrains YouTrack before 2026.2.18112 an authenticated user could enumerate accounts via the users search endpoint Aug 17, 2026
CVE-2026-75045 CRITICAL 9.1 In JetBrains YouTrack before 2025.3.156085, 2026.1.13913, 2026.2.18112 an unauthenticated attacker could download database backups via shared draft signature Aug 17, 2026
CVE-2026-75044 HIGH 8.1 In JetBrains YouTrack before 2025.3.156085, 2026.1.13914, 2026.2.18095 missing authorisation allowed an authenticated user to delete arbitrary entities via the mailbox endpoint Aug 17, 2026
CVE-2026-74858 MEDIUM 6.3 A vulnerability has been found in jae-jae fetcher-mcp up to 0.3.9. Impacted is the function fetch_url/fetch_urls of the file /latest/meta-data/iam/security-credentials/ of the component URL Validation. … Aug 17, 2026
CVE-2026-73646 HIGH 7.5 PostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rules into an Abstract Syntax Tree. Prior … Aug 17, 2026