Vulnerabilities (CVE)
Yack CVE helps teams search and track vulnerabilities.
TOTAL
383,104 CVE
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Vault Secrets Operator 1.3.0 up to 1.4.1 is vulnerable to an arbitrary file read and credential exfiltration issue in the AppRole authentication configuration that may allow a tenant with limited Kubernetes RBAC permissi...Show more |
The PPWP – Password Protect Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `ppwp` shortcode attributes in all versions up to, and including, 1.9.21 due to insufficient input sani...Show more |
Virtual attribute handling in Ping Identity PingDirectory in affected versions allows only authorized users to exhaust java memory heap when recent login history is enabled and copying virtual attributes that reference d...Show more |
Cross-Site Request Forgery weaknesses in the Administrative Console of PingFederate versions before version 13.1 may allow actors to perform unauthorized actions via specially-crafted links triggered by administrators wi...Show more |
In JetBrains PyCharm before 2026.2.1 code execution was possible via unauthenticated Jupyter MCP tools |
In JetBrains PyCharm before 2026.2.1 code execution via Quick Documentation was possible |
In JetBrains IntelliJ IDEA before 2026.2.1 xXE was possible in the Eclipse settings importers |
In JetBrains IntelliJ IDEA before 2026.1.5 git credentials were written in plaintext to the IDE log |
In JetBrains IntelliJ IDEA before 2026.2.1 rCE via Markdown export tool was possible |
In JetBrains IntelliJ IDEA before 2026.2.1 hadoop ResourceManager could read local files via XXE |
In JetBrains IntelliJ IDEA before 2026.2.1 sSRF was possible via the OpenAPI preview proxy in untrusted projects |
In JetBrains IntelliJ IDEA before 2026.2.1 sSRF was possible via the DevKit debug listener endpoint |
In JetBrains IntelliJ IDEA before 2026.2.1 command execution via crafted Markdown preview content was possible in trusted projects |
In JetBrains YouTrack before 2026.2.17917 unauthorised project transfer between organisations was possible |
In JetBrains YouTrack before 2026.1.13901,
2026.2.17950 doS attack was possible via crafted type parameters |
In JetBrains YouTrack before 2026.1.13903,
2026.2.17950 an authenticated user could read restricted articles from other projects via the draft creation endpoint |
In JetBrains YouTrack before 2026.2.18068 stored XSS via the fenced code-block language label was possible |
In JetBrains YouTrack before 2026.2.18177 doS attack was possible via a decompression bomb in the import endpoint |
In JetBrains YouTrack before 2026.2.18112 an authenticated user could enumerate accounts via the users search endpoint |
In JetBrains YouTrack before 2025.3.156085,
2026.1.13913,
2026.2.18112 an unauthenticated attacker could download database backups via shared draft signature |
In JetBrains YouTrack before 2025.3.156085,
2026.1.13914,
2026.2.18095 missing authorisation allowed an authenticated user to delete arbitrary entities via the mailbox endpoint |
An authenticated user without repository read permission may access package metadata under specific conditions. |
An unauthenticated user may access restricted artifacts in JFrog Artifactory under specific conditions. |
A low-privileged user may poison cached artifact metadata under specific conditions, potentially causing consumers to retrieve untrusted content. |
An unauthenticated attacker may cause untrusted package content to be cached under specific conditions, potentially affecting artifact integrity and availability. |