Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

28297
Total
2180
Critical
8507
High
8806
Medium
CVE ID Severity Score Description Published
CVE-2026-49382 MEDIUM 4.5 In JetBrains IntelliJ IDEA before 2026.1 code execution was possible via template injection in the Copyright plugin May 29, 2026
CVE-2026-49381 LOW 3.4 In JetBrains TeamCity before 2026.1 stored XSS on the SAML login page was possible May 29, 2026
CVE-2026-49380 LOW 3.1 In JetBrains TeamCity before 2026.1 open redirect in the SAML plugin was possible May 29, 2026
CVE-2026-49379 MEDIUM 6.5 In JetBrains TeamCity before 2026.1 credentials could be exposed in thread names May 29, 2026
CVE-2026-49378 MEDIUM 4.3 In JetBrains TeamCity before 2026.1 credentials parameters were exposed via parameter autocompletion May 29, 2026
CVE-2026-49377 MEDIUM 4.3 In JetBrains TeamCity before 2025.11.2 exposure of sensitive data via default agent parameters May 29, 2026
CVE-2026-49376 MEDIUM 6.5 In JetBrains TeamCity before 2026.1 insufficient username validation in the SAML plugin May 29, 2026
CVE-2026-49375 MEDIUM 6.1 In JetBrains TeamCity before 2026.1, 2025.11.5 reflected XSS was possible on the repository download page May 29, 2026
CVE-2026-49374 HIGH 7.6 In JetBrains TeamCity before 2026.1 improper permission checks exposed build configuration parameters May 29, 2026
CVE-2026-49373 HIGH 7.1 In JetBrains TeamCity before 2026.1 remote code execution was possible via Perforce connection settings May 29, 2026
CVE-2026-49372 HIGH 7.5 In JetBrains TeamCity before 2026.1, 2025.11.5 unauthenticated SSRF via build status was possible May 29, 2026
CVE-2026-49371 HIGH 7.1 In JetBrains TeamCity before 2026.1.1 reflected XSS in the keyword filter was possible May 29, 2026
CVE-2026-49370 LOW 3.4 In JetBrains YouTrack before 2026.1.13162 information disclosure was possible on fetchApp requests May 29, 2026
CVE-2026-49369 MEDIUM 4.3 In JetBrains YouTrack before 2026.1.13162 information disclosure was possible on Users and Groups pages May 29, 2026
CVE-2026-49368 HIGH 8.7 In JetBrains YouTrack before 2026.1.13162 stored XSS in project notification templates was possible May 29, 2026
CVE-2026-49367 HIGH 8.0 In JetBrains IntelliJ IDEA before 2026.1.1 command execution was possible via the guest user account May 29, 2026
CVE-2026-49366 HIGH 7.8 In JetBrains IntelliJ IDEA before 2026.1.1 command injection was possible via filename completion May 29, 2026
CVE-2026-47745 MEDIUM 6.5 Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, the admin tables for PaymentMethods, Currencies and Carriers exposed inline toggles and per-record actions (enable, … May 29, 2026
CVE-2026-47744 CRITICAL 9.9 Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, two distinct authorization defects in the team settings allowed any authenticated panel user to take … May 29, 2026
CVE-2026-47742 MEDIUM 6.5 Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, Sub-form Livewire components used in the product editor (Edit, Inventory, Seo, Shipping, Files) had no … May 29, 2026
CVE-2026-47741 MEDIUM 5.9 Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, CreateOrderFromCartAction::execute previously created the Order row before checking and incrementing the discount's total_use counter. Under … May 29, 2026
CVE-2026-47740 HIGH 8.1 Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, Multiple Filament actions on the admin Order detail and Order shipments table were callable by … May 29, 2026
CVE-2026-46372 HIGH 8.5 SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models. … May 29, 2026
CVE-2026-46344 MEDIUM 5.3 liboqs is a C-language cryptographic library that provides implementations of post-quantum cryptography algorithms. Prior to 0.16.0, an out-of-bounds read has been identified in the XMSS … May 29, 2026
CVE-2026-44652 UNKNOWN SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models. … May 29, 2026