Export limit exceeded: 378611 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (378611 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2019-25759 | 1 Wdmtech | 1 Vbizz | 2026-08-17 | 7.1 High |
| Joomla! Component vBizz 1.0.7 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL queries by injecting malicious code through the payid parameter. Attackers can submit POST requests to the employee management interface with crafted payid array values containing SQL commands to extract sensitive database information including version and database names. | ||||
| CVE-2026-62820 | 1 Microsoft | 9 Windows 10 1607, Windows 10 1809, Windows Server 2016 and 6 more | 2026-08-17 | 8.1 High |
| Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DNS allows an unauthorized attacker to execute code over a network. | ||||
| CVE-2026-75060 | 2026-08-17 | 8.4 High | ||
| In JetBrains PyCharm before 2026.2.1 code execution was possible via unauthenticated Jupyter MCP tools | ||||
| CVE-2026-75059 | 2026-08-17 | 4.4 Medium | ||
| In JetBrains PyCharm before 2026.2.1 code execution via Quick Documentation was possible | ||||
| CVE-2026-75058 | 2026-08-17 | 5.5 Medium | ||
| In JetBrains IntelliJ IDEA before 2026.2.1 xXE was possible in the Eclipse settings importers | ||||
| CVE-2026-75057 | 2026-08-17 | 6.2 Medium | ||
| In JetBrains IntelliJ IDEA before 2026.1.5 git credentials were written in plaintext to the IDE log | ||||
| CVE-2026-75056 | 2026-08-17 | 7.8 High | ||
| In JetBrains IntelliJ IDEA before 2026.2.1 rCE via Markdown export tool was possible | ||||
| CVE-2026-75055 | 2026-08-17 | 5.5 Medium | ||
| In JetBrains IntelliJ IDEA before 2026.2.1 hadoop ResourceManager could read local files via XXE | ||||
| CVE-2026-75054 | 2026-08-17 | 6.3 Medium | ||
| In JetBrains IntelliJ IDEA before 2026.2.1 sSRF was possible via the OpenAPI preview proxy in untrusted projects | ||||
| CVE-2026-75053 | 2026-08-17 | 5.4 Medium | ||
| In JetBrains IntelliJ IDEA before 2026.2.1 sSRF was possible via the DevKit debug listener endpoint | ||||
| CVE-2026-75052 | 2026-08-17 | 3.6 Low | ||
| In JetBrains IntelliJ IDEA before 2026.2.1 command execution via crafted Markdown preview content was possible in trusted projects | ||||
| CVE-2026-75051 | 2026-08-17 | 8.1 High | ||
| In JetBrains YouTrack before 2026.2.17917 unauthorised project transfer between organisations was possible | ||||
| CVE-2026-75050 | 2026-08-17 | 7.1 High | ||
| In JetBrains YouTrack before 2026.1.13901, 2026.2.17950 doS attack was possible via crafted type parameters | ||||
| CVE-2026-75049 | 2026-08-17 | 6.5 Medium | ||
| In JetBrains YouTrack before 2026.1.13903, 2026.2.17950 an authenticated user could read restricted articles from other projects via the draft creation endpoint | ||||
| CVE-2026-75048 | 2026-08-17 | 8.2 High | ||
| In JetBrains YouTrack before 2026.2.18068 stored XSS via the fenced code-block language label was possible | ||||
| CVE-2026-75047 | 2026-08-17 | 6.5 Medium | ||
| In JetBrains YouTrack before 2026.2.18177 doS attack was possible via a decompression bomb in the import endpoint | ||||
| CVE-2026-75046 | 2026-08-17 | 4.3 Medium | ||
| In JetBrains YouTrack before 2026.2.18112 an authenticated user could enumerate accounts via the users search endpoint | ||||
| CVE-2026-75045 | 2026-08-17 | 9.1 Critical | ||
| In JetBrains YouTrack before 2025.3.156085, 2026.1.13913, 2026.2.18112 an unauthenticated attacker could download database backups via shared draft signature | ||||
| CVE-2026-75044 | 2026-08-17 | 8.1 High | ||
| In JetBrains YouTrack before 2025.3.156085, 2026.1.13914, 2026.2.18095 missing authorisation allowed an authenticated user to delete arbitrary entities via the mailbox endpoint | ||||
| CVE-2026-68762 | 2026-08-17 | 5.9 Medium | ||
| In JetBrains Ktor before 3.4.1 potential DoS attack via WebSocket decompression was possible | ||||