Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
54243
Total
4300
Critical
16125
High
15819
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-100278 | MEDIUM | 4.9 | In JetBrains YouTrack before 2026.2.19197 users with restricted permission could edit and hide other users' comments | Sep 30, 2026 |
| CVE-2026-100277 | HIGH | 8.9 | In JetBrains YouTrack before 2026.2.19197 account takeover was possible by replaying a notification signature | Sep 30, 2026 |
| CVE-2026-100276 | MEDIUM | 5.9 | In JetBrains YouTrack before 2026.2.19197 guest users could remove a workflow action's visibility restriction and run the action | Sep 30, 2026 |
| CVE-2026-100275 | MEDIUM | 6.9 | In JetBrains YouTrack before 2026.2.19197 stored XSS in the workflow error notification toast was possible | Sep 30, 2026 |
| CVE-2026-100274 | MEDIUM | 6.5 | In JetBrains YouTrack before 2026.2.19197 project Admin could trigger DoS via a notification template | Sep 30, 2026 |
| CVE-2026-100273 | HIGH | 8.2 | In JetBrains YouTrack before 2026.2.19197 authorisation bypass in the scripts debugger allowed arbitrary code execution | Sep 30, 2026 |
| CVE-2026-100272 | MEDIUM | 4.9 | In JetBrains YouTrack before 2026.2.19197 missing authorisation in the notification template preview allowed Project Administrators to read restricted issues | Sep 30, 2026 |
| CVE-2026-100271 | LOW | 2.7 | In JetBrains YouTrack before 2026.2.19197 missing authorisation on several endpoints allowed authenticated users to access information from other projects | Sep 30, 2026 |
| CVE-2026-100270 | LOW | 3.3 | In JetBrains YouTrack before 2026.2.19197 low-level Admin Read permission users could disclose integration credentials via import configurations | Sep 30, 2026 |
| CVE-2026-100269 | MEDIUM | 4.3 | In JetBrains YouTrack before 2026.2.19197 helpdesk project's Authorized Reporters list could be bypassed | Sep 30, 2026 |
| CVE-2026-100268 | HIGH | 7.7 | In JetBrains YouTrack before 2026.2.19197 project administrators could read comments from other projects via notification templates | Sep 30, 2026 |
| CVE-2026-100267 | MEDIUM | 5.9 | In JetBrains YouTrack before 2026.2.19197 reDoS attack was possible via mailbox regex mail-rule filters | Sep 30, 2026 |
| CVE-2026-100266 | HIGH | 7.7 | In JetBrains Hub before 2026.2.52366 missing authorisation allowed authenticated users to send arbitrary emails from the server's trusted address | Sep 30, 2026 |
| CVE-2026-100265 | MEDIUM | 4.8 | In JetBrains Rider before 2026.2.1 aI Assistant could auto-update third-party skills without user confirmation | Sep 30, 2026 |
| CVE-2026-100264 | LOW | 2.7 | In JetBrains YouTrack before 2026.2.18991 stored SMTP server credentials could be disclosed by changing the server host | Sep 30, 2026 |
| CVE-2026-100263 | MEDIUM | 4.7 | In JetBrains YouTrack before 2026.2.18991 stored HTML injection via the User-Agent header was possible | Sep 30, 2026 |
| CVE-2026-100262 | HIGH | 7.6 | In JetBrains YouTrack before 2026.2.18991 missing authorisation allowed users with read-only project access to overwrite project notification templates | Sep 30, 2026 |
| CVE-2026-100261 | MEDIUM | 5.4 | In JetBrains YouTrack before 2026.2.18991 changing article visibility settings was possible without update permission | Sep 30, 2026 |
| CVE-2026-100260 | MEDIUM | 5.3 | In JetBrains YouTrack before 2026.2.18991 mailbox integration allowed authentication after a password reset | Sep 30, 2026 |
| CVE-2026-100259 | MEDIUM | 4.3 | In JetBrains YouTrack before 2026.2.18991 improper access control on Gantt chart allowed edits by users with view-only access | Sep 30, 2026 |
| CVE-2026-100258 | MEDIUM | 4.3 | In JetBrains YouTrack before 2026.2.18991 missing authorisation allowed read-only users to read project settings | Sep 30, 2026 |
| CVE-2026-100257 | MEDIUM | 4.3 | In JetBrains YouTrack before 2026.2.18991 sSRF via stored XHTML injection was possible during PDF export | Sep 30, 2026 |
| CVE-2026-100256 | HIGH | 7.8 | In JetBrains IntelliJ IDEA before 2026.2.3 rCE via Structural Search script constraints was possible in untrusted projects | Sep 30, 2026 |
| CVE-2026-100255 | HIGH | 8.1 | In JetBrains TeamCity before 2026.2, 2026.1.4, 2025.11.8 administrator account takeover was possible via password reset | Sep 30, 2026 |
| CVE-2026-100254 | HIGH | 8.8 | In JetBrains TeamCity before 2026.2, 2026.1.4, 2025.11.8 authenticated users could execute commands on Windows servers via CRLF injection in Pipeline Git connection settings | Sep 30, 2026 |