CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
-
-
Aug 28, 2026
Aug 13, 2026
N/A· v4
9.6 CRITICAL· v3
N/A· v2
Vault Secrets Operator 1.3.0 up to 1.4.1 is vulnerable to an arbitrary file read and credential exfiltration issue in the AppRole authentication configuration that may allow a tenant with limited Kubernetes RBAC permissi...Show more
Vault Secrets Operator 1.3.0 up to 1.4.1 is vulnerable to an arbitrary file read and credential exfiltration issue in the AppRole authentication configuration that may allow a tenant with limited Kubernetes RBAC permissions to read files from the operator pod's filesystem and transmit their contents to a tenant-controlled endpoint, potentially leading to privilege escalation within the cluster. This vulnerability (CVE-2026-8715) is fixed in Vault Secrets Operator 1.5.0.Show less
-
-
Aug 28, 2026
Aug 13, 2026
N/A· v4
6.4 MEDIUM· v3
N/A· v2
The PPWP – Password Protect Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `ppwp` shortcode attributes in all versions up to, and including, 1.9.21 due to insufficient input sani...Show more
The PPWP – Password Protect Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `ppwp` shortcode attributes in all versions up to, and including, 1.9.21 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.Show less
-
-
Aug 28, 2026
Jun 12, 2026
6.3 MEDIUM· v4
N/A· v3
N/A· v2
Virtual attribute handling in Ping Identity PingDirectory in affected versions allows only authorized users to exhaust java memory heap when recent login history is enabled and copying virtual attributes that reference d...Show more
Virtual attribute handling in Ping Identity PingDirectory in affected versions allows only authorized users to exhaust java memory heap when recent login history is enabled and copying virtual attributes that reference ds-privilege-name values.Show less
-
-
Aug 28, 2026
Aug 10, 2026
4.9 MEDIUM· v4
N/A· v3
N/A· v2
Cross-Site Request Forgery weaknesses in the Administrative Console of PingFederate versions before version 13.1 may allow actors to perform unauthorized actions via specially-crafted links triggered by administrators wi...Show more
Cross-Site Request Forgery weaknesses in the Administrative Console of PingFederate versions before version 13.1 may allow actors to perform unauthorized actions via specially-crafted links triggered by administrators with active sessions.Show less
-
-
Aug 28, 2026
Aug 17, 2026
N/A· v4
8.4 HIGH· v3
N/A· v2
In JetBrains PyCharm before 2026.2.1 code execution was possible via unauthenticated Jupyter MCP tools
-
-
Aug 28, 2026
Aug 17, 2026
N/A· v4
4.4 MEDIUM· v3
N/A· v2
In JetBrains PyCharm before 2026.2.1 code execution via Quick Documentation was possible
-
-
Aug 28, 2026
Aug 17, 2026
N/A· v4
5.5 MEDIUM· v3
N/A· v2
In JetBrains IntelliJ IDEA before 2026.2.1 xXE was possible in the Eclipse settings importers
-
-
Aug 28, 2026
Aug 17, 2026
N/A· v4
6.2 MEDIUM· v3
N/A· v2
In JetBrains IntelliJ IDEA before 2026.1.5 git credentials were written in plaintext to the IDE log
-
-
Aug 28, 2026
Aug 17, 2026
N/A· v4
7.8 HIGH· v3
N/A· v2
In JetBrains IntelliJ IDEA before 2026.2.1 rCE via Markdown export tool was possible
-
-
Aug 28, 2026
Aug 17, 2026
N/A· v4
5.5 MEDIUM· v3
N/A· v2
In JetBrains IntelliJ IDEA before 2026.2.1 hadoop ResourceManager could read local files via XXE
-
-
Aug 28, 2026
Aug 17, 2026
N/A· v4
6.3 MEDIUM· v3
N/A· v2
In JetBrains IntelliJ IDEA before 2026.2.1 sSRF was possible via the OpenAPI preview proxy in untrusted projects
-
-
Aug 28, 2026
Aug 17, 2026
N/A· v4
5.4 MEDIUM· v3
N/A· v2
In JetBrains IntelliJ IDEA before 2026.2.1 sSRF was possible via the DevKit debug listener endpoint
-
-
Aug 28, 2026
Aug 17, 2026
N/A· v4
3.6 LOW· v3
N/A· v2
In JetBrains IntelliJ IDEA before 2026.2.1 command execution via crafted Markdown preview content was possible in trusted projects
-
-
Aug 28, 2026
Aug 17, 2026
N/A· v4
8.1 HIGH· v3
N/A· v2
In JetBrains YouTrack before 2026.2.17917 unauthorised project transfer between organisations was possible
-
-
Aug 28, 2026
Aug 17, 2026
N/A· v4
7.1 HIGH· v3
N/A· v2
In JetBrains YouTrack before 2026.1.13901, 2026.2.17950 doS attack was possible via crafted type parameters
-
-
Aug 28, 2026
Aug 17, 2026
N/A· v4
6.5 MEDIUM· v3
N/A· v2
In JetBrains YouTrack before 2026.1.13903, 2026.2.17950 an authenticated user could read restricted articles from other projects via the draft creation endpoint
-
-
Aug 28, 2026
Aug 17, 2026
N/A· v4
8.2 HIGH· v3
N/A· v2
In JetBrains YouTrack before 2026.2.18068 stored XSS via the fenced code-block language label was possible
-
-
Aug 28, 2026
Aug 17, 2026
N/A· v4
6.5 MEDIUM· v3
N/A· v2
In JetBrains YouTrack before 2026.2.18177 doS attack was possible via a decompression bomb in the import endpoint
-
-
Aug 28, 2026
Aug 17, 2026
N/A· v4
4.3 MEDIUM· v3
N/A· v2
In JetBrains YouTrack before 2026.2.18112 an authenticated user could enumerate accounts via the users search endpoint
-
-
Aug 28, 2026
Aug 17, 2026
N/A· v4
9.1 CRITICAL· v3
N/A· v2
In JetBrains YouTrack before 2025.3.156085, 2026.1.13913, 2026.2.18112 an unauthenticated attacker could download database backups via shared draft signature
-
-
Aug 28, 2026
Aug 17, 2026
N/A· v4
8.1 HIGH· v3
N/A· v2
In JetBrains YouTrack before 2025.3.156085, 2026.1.13914, 2026.2.18095 missing authorisation allowed an authenticated user to delete arbitrary entities via the mailbox endpoint
-
-
Aug 28, 2026
Aug 12, 2026
N/A· v4
4.3 MEDIUM· v3
N/A· v2
An authenticated user without repository read permission may access package metadata under specific conditions.
-
-
Aug 28, 2026
Aug 12, 2026
N/A· v4
5.9 MEDIUM· v3
N/A· v2
An unauthenticated user may access restricted artifacts in JFrog Artifactory under specific conditions.
-
-
Aug 28, 2026
Aug 12, 2026
N/A· v4
8.8 HIGH· v3
N/A· v2
A low-privileged user may poison cached artifact metadata under specific conditions, potentially causing consumers to retrieve untrusted content.
-
-
Aug 28, 2026
Aug 12, 2026
N/A· v4
8.1 HIGH· v3
N/A· v2
An unauthenticated attacker may cause untrusted package content to be cached under specific conditions, potentially affecting artifact integrity and availability.