Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

46113
Total
3679
Critical
13638
High
13568
Medium
CVE ID Severity Score Description Published
CVE-2026-75048 HIGH 8.2 In JetBrains YouTrack before 2026.2.18068 stored XSS via the fenced code-block language label was possible Aug 17, 2026
CVE-2026-75047 MEDIUM 6.5 In JetBrains YouTrack before 2026.2.18177 doS attack was possible via a decompression bomb in the import endpoint Aug 17, 2026
CVE-2026-75046 MEDIUM 4.3 In JetBrains YouTrack before 2026.2.18112 an authenticated user could enumerate accounts via the users search endpoint Aug 17, 2026
CVE-2026-75045 CRITICAL 9.1 In JetBrains YouTrack before 2025.3.156085, 2026.1.13913, 2026.2.18112 an unauthenticated attacker could download database backups via shared draft signature Aug 17, 2026
CVE-2026-75044 HIGH 8.1 In JetBrains YouTrack before 2025.3.156085, 2026.1.13914, 2026.2.18095 missing authorisation allowed an authenticated user to delete arbitrary entities via the mailbox endpoint Aug 17, 2026
CVE-2026-74858 MEDIUM 6.3 A vulnerability has been found in jae-jae fetcher-mcp up to 0.3.9. Impacted is the function fetch_url/fetch_urls of the file /latest/meta-data/iam/security-credentials/ of the component URL Validation. … Aug 17, 2026
CVE-2026-73646 HIGH 7.5 PostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rules into an Abstract Syntax Tree. Prior … Aug 17, 2026
CVE-2026-71479 CRITICAL 9.1 New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to 1.0.0-rc.18, user-controlled image n, video seconds and … Aug 17, 2026
CVE-2026-68762 MEDIUM 5.9 In JetBrains Ktor before 3.4.1 potential DoS attack via WebSocket decompression was possible Aug 17, 2026
CVE-2026-64868 HIGH 7.5 New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to 1.0.0-rc.11, POST /api/stripe/webhook, POST /api/creem/webhook, and POST … Aug 17, 2026
CVE-2026-64866 UNKNOWN New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. From 0.9.1.3 until 1.0.0-rc.7, AdminResetPasskey in controller/passkey.go lacks the … Aug 17, 2026
CVE-2026-64865 UNKNOWN New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to 1.0.0-rc.16, repeated PUT /api/user/self requests that update … Aug 17, 2026
CVE-2026-64859 CRITICAL 9.1 New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to 1.0.0-rc.7, the admin user list and user … Aug 17, 2026
CVE-2026-59829 MEDIUM 4.3 Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.1, on sites with category group moderation enabled, the review queue could include … Aug 17, 2026
CVE-2026-55704 MEDIUM 4.3 Discourse is an open-source discussion platform. Prior o 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, users who were allowed to view a group’s activity, but were not … Aug 17, 2026
CVE-2026-55674 CRITICAL 9.3 Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, an unauthenticated attacker could send a single request with a crafted color_scheme_id … Aug 17, 2026
CVE-2026-53960 MEDIUM 5.3 Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, hidden or otherwise unviewable first-post content was leaked as an excerpt in … Aug 17, 2026
CVE-2026-40144 UNKNOWN A memory-corruption vulnerability exists in a kernel-mode component of BeyondTrust Endpoint Privilege Management (Windows deployments) prior to version 26.1.2. Insufficient validation of input processed by … Aug 17, 2026
CVE-2025-27772 UNKNOWN UpTrain is an open-source platform to evaluate and improve generative AI applications. In version 0.7.1 and prior, the `/new_run` endpoint is vulnerable to remote code … Aug 17, 2026
CVE-2025-27771 UNKNOWN UpTrain is an open-source platform to evaluate and improve generative AI applications. In version 0.7.1 and prior, the `/add_prompts` endpoint is vulnerable to remote code … Aug 17, 2026
CVE-2025-27770 UNKNOWN UpTrain is an open-source platform to evaluate and improve generative AI applications. In version 0.7.1 and prior, the `/create_project` endpoint is vulnerable to remote code … Aug 17, 2026
CVE-2025-27621 UNKNOWN UpTrain is an open-source platform to evaluate and improve generative AI applications. In version 0.7.1 and prior, the UpTrain backend creates a new default user … Aug 17, 2026
CVE-2026-73851 UNKNOWN Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1 and 1.34.0, an attacker who controls or tampers with the OpenAPI description consumed … Aug 17, 2026
CVE-2026-71567 HIGH 7.7 In openshift-metal3/fakefish there is a repeated pattern in some of the scripts where shell variables are injected without quoting them either into command lines or … Aug 17, 2026
CVE-2026-71566 CRITICAL 9.3 FakeFish handles incoming credentials by passing them down to scripts. This works for real hardware because in the end it's up to the BMC to … Aug 17, 2026