Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
28297
Total
2180
Critical
8507
High
8806
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-49382 | MEDIUM | 4.5 | In JetBrains IntelliJ IDEA before 2026.1 code execution was possible via template injection in the Copyright plugin | May 29, 2026 |
| CVE-2026-49381 | LOW | 3.4 | In JetBrains TeamCity before 2026.1 stored XSS on the SAML login page was possible | May 29, 2026 |
| CVE-2026-49380 | LOW | 3.1 | In JetBrains TeamCity before 2026.1 open redirect in the SAML plugin was possible | May 29, 2026 |
| CVE-2026-49379 | MEDIUM | 6.5 | In JetBrains TeamCity before 2026.1 credentials could be exposed in thread names | May 29, 2026 |
| CVE-2026-49378 | MEDIUM | 4.3 | In JetBrains TeamCity before 2026.1 credentials parameters were exposed via parameter autocompletion | May 29, 2026 |
| CVE-2026-49377 | MEDIUM | 4.3 | In JetBrains TeamCity before 2025.11.2 exposure of sensitive data via default agent parameters | May 29, 2026 |
| CVE-2026-49376 | MEDIUM | 6.5 | In JetBrains TeamCity before 2026.1 insufficient username validation in the SAML plugin | May 29, 2026 |
| CVE-2026-49375 | MEDIUM | 6.1 | In JetBrains TeamCity before 2026.1, 2025.11.5 reflected XSS was possible on the repository download page | May 29, 2026 |
| CVE-2026-49374 | HIGH | 7.6 | In JetBrains TeamCity before 2026.1 improper permission checks exposed build configuration parameters | May 29, 2026 |
| CVE-2026-49373 | HIGH | 7.1 | In JetBrains TeamCity before 2026.1 remote code execution was possible via Perforce connection settings | May 29, 2026 |
| CVE-2026-49372 | HIGH | 7.5 | In JetBrains TeamCity before 2026.1, 2025.11.5 unauthenticated SSRF via build status was possible | May 29, 2026 |
| CVE-2026-49371 | HIGH | 7.1 | In JetBrains TeamCity before 2026.1.1 reflected XSS in the keyword filter was possible | May 29, 2026 |
| CVE-2026-49370 | LOW | 3.4 | In JetBrains YouTrack before 2026.1.13162 information disclosure was possible on fetchApp requests | May 29, 2026 |
| CVE-2026-49369 | MEDIUM | 4.3 | In JetBrains YouTrack before 2026.1.13162 information disclosure was possible on Users and Groups pages | May 29, 2026 |
| CVE-2026-49368 | HIGH | 8.7 | In JetBrains YouTrack before 2026.1.13162 stored XSS in project notification templates was possible | May 29, 2026 |
| CVE-2026-49367 | HIGH | 8.0 | In JetBrains IntelliJ IDEA before 2026.1.1 command execution was possible via the guest user account | May 29, 2026 |
| CVE-2026-49366 | HIGH | 7.8 | In JetBrains IntelliJ IDEA before 2026.1.1 command injection was possible via filename completion | May 29, 2026 |
| CVE-2026-47745 | MEDIUM | 6.5 | Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, the admin tables for PaymentMethods, Currencies and Carriers exposed inline toggles and per-record actions (enable, … | May 29, 2026 |
| CVE-2026-47744 | CRITICAL | 9.9 | Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, two distinct authorization defects in the team settings allowed any authenticated panel user to take … | May 29, 2026 |
| CVE-2026-47742 | MEDIUM | 6.5 | Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, Sub-form Livewire components used in the product editor (Edit, Inventory, Seo, Shipping, Files) had no … | May 29, 2026 |
| CVE-2026-47741 | MEDIUM | 5.9 | Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, CreateOrderFromCartAction::execute previously created the Order row before checking and incrementing the discount's total_use counter. Under … | May 29, 2026 |
| CVE-2026-47740 | HIGH | 8.1 | Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, Multiple Filament actions on the admin Order detail and Order shipments table were callable by … | May 29, 2026 |
| CVE-2026-46372 | HIGH | 8.5 | SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models. … | May 29, 2026 |
| CVE-2026-46344 | MEDIUM | 5.3 | liboqs is a C-language cryptographic library that provides implementations of post-quantum cryptography algorithms. Prior to 0.16.0, an out-of-bounds read has been identified in the XMSS … | May 29, 2026 |
| CVE-2026-44652 | UNKNOWN | — | SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models. … | May 29, 2026 |