CVE Vulnerability Database

Search and browse 11,425 known security vulnerabilities. Filter by severity, vendor, product, and year.

11,425 vulnerabilities found
CVE-2026-49383
3.3 low

In JetBrains IntelliJ IDEA before 2026.1 xXE in the UI Designer form parser was possible

Jetbrains Intellij Idea May 29, 2026
CVE-2026-49382
4.5 medium

In JetBrains IntelliJ IDEA before 2026.1 code execution was possible via template injection in the Copyright plugin

Jetbrains Intellij Idea May 29, 2026
CVE-2026-49381
3.4 low

In JetBrains TeamCity before 2026.1 stored XSS on the SAML login page was possible

Jetbrains Teamcity May 29, 2026
CVE-2026-49380
3.1 low

In JetBrains TeamCity before 2026.1 open redirect in the SAML plugin was possible

Jetbrains Teamcity May 29, 2026
CVE-2026-49379
6.5 medium

In JetBrains TeamCity before 2026.1 credentials could be exposed in thread names

Jetbrains Teamcity May 29, 2026
CVE-2026-49378
4.3 medium

In JetBrains TeamCity before 2026.1 credentials parameters were exposed via parameter autocompletion

Jetbrains Teamcity May 29, 2026
CVE-2026-49377
4.3 medium

In JetBrains TeamCity before 2025.11.2 exposure of sensitive data via default agent parameters

Jetbrains Teamcity May 29, 2026
CVE-2026-49376
6.5 medium

In JetBrains TeamCity before 2026.1 insufficient username validation in the SAML plugin

Jetbrains Teamcity May 29, 2026
CVE-2026-49375
6.1 medium

In JetBrains TeamCity before 2026.1, 2025.11.5 reflected XSS was possible on the repository download page

Jetbrains Teamcity May 29, 2026
CVE-2026-49374
7.6 high

In JetBrains TeamCity before 2026.1 improper permission checks exposed build configuration parameters

Jetbrains Teamcity May 29, 2026
CVE-2026-49373
7.1 high

In JetBrains TeamCity before 2026.1 remote code execution was possible via Perforce connection settings

Jetbrains Teamcity May 29, 2026
CVE-2026-49372
7.5 high

In JetBrains TeamCity before 2026.1, 2025.11.5 unauthenticated SSRF via build status was possible

Jetbrains Teamcity May 29, 2026
CVE-2026-49371
7.1 high

In JetBrains TeamCity before 2026.1.1 reflected XSS in the keyword filter was possible

Jetbrains Teamcity May 29, 2026
CVE-2026-49370
3.4 low

In JetBrains YouTrack before 2026.1.13162 information disclosure was possible on fetchApp requests

Jetbrains Youtrack May 29, 2026
CVE-2026-49369
4.3 medium

In JetBrains YouTrack before 2026.1.13162 information disclosure was possible on Users and Groups pages

Jetbrains Youtrack May 29, 2026
CVE-2026-49368
8.7 high

In JetBrains YouTrack before 2026.1.13162 stored XSS in project notification templates was possible

Jetbrains Youtrack May 29, 2026
CVE-2026-49367
8.0 high

In JetBrains IntelliJ IDEA before 2026.1.1 command execution was possible via the guest user account

Jetbrains Intellij Idea May 29, 2026
CVE-2026-49366
7.8 high

In JetBrains IntelliJ IDEA before 2026.1.1 command injection was possible via filename completion

Jetbrains Intellij Idea May 29, 2026
CVE-2026-46344
5.3 medium

liboqs is a C-language cryptographic library that provides implementations of post-quantum cryptography algorithms. Prior to 0.16.0, an out-of-bounds read has been identified in the XMSS and XMSS^MT stateful signature verification code. When the verification function is called with a correctly-sized

Openquantumsafe Liboqs May 29, 2026
CVE-2026-44649
9.8 critical

SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models. Prior to 1.18.0, SillyTavern accepts Remote-User (Authelia) and X-Authentik-Username (Authentik) HTTP headers to auto

May 29, 2026
CVE-2026-44611
5.4 medium

Danelec MacGregor Voyage Data Recorder passwords are stored with a hashing method which limits password length and is susceptible to brute force attacks.

Macgregor Interschalt Vdr G4E Firmware May 29, 2026
CVE-2026-44518
5.3 medium

liboqs is a C-language cryptographic library that provides implementations of post-quantum cryptography algorithms. Prior to 0.16.0, an out-of-bounds read has been identified in the XMSS and XMSS^MT stateful signature verification code. When the verification function is called with a signature buffe

Openquantumsafe Liboqs May 29, 2026
CVE-2026-42951
5.4 medium

An authenticated user can download a backup of the Danelec MacGregor Voyage Data Recorder device which includes account data and password hashes.

Macgregor Interschalt Vdr G4E Firmware May 29, 2026
CVE-2026-42941
8.3 high

The Danelec MacGregor Voyage Data Recorder device includes a default username and password, with no enforced password change.

Macgregor Interschalt Vdr G4E Firmware May 29, 2026