Vulnerabilities (CVE)
Yack CVE helps teams search and track vulnerabilities.
TOTAL
388,134 CVE
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
In JetBrains IntelliJ IDEA before 2026.2.2 missing project-trust confirmation before building a Dev Container allowed host-level code execution |
In JetBrains IntelliJ IDEA before 2026.2.2 missing TLS and authentication on the IJent gRPC server allowed local code execution on Remote Development hosts |
In JetBrains YouTrack before 2026.2.18634 unchecked group membership changes allowed privilege escalation |
In JetBrains Hub before 2026.2.52442 an unauthenticated attacker could register a trusted service and gain superuser privileges |
In JetBrains YouTrack before 2026.2.18788,
2026.1.14055,
2025.3.161254 missing authorisation allowed access to restricted REST API resources via IDOR |
In JetBrains YouTrack before 2025.3.161254,
2026.1.14042 improper authentication in YouTrack Helpdesk allowed unauthenticated account takeover via a self-asserted email address |
N-central is vulnerable to a pre-auth remote code execution This issue affects N-central: before 2026.3.1.14. |
PostgreSQL Anonymizer contains a vulnerability in the anon.anonymize_database_parallel() function that allows the owner of a table to run arbitrary code with superuser privilege. The issue is fixed in PostgreSQL Anonymiz...Show more |
An Authentication Bypass vulnerability in Sentry before R10.8.2, R10.7.3 and R10.6.4 allows a remote unauthenticated attacker to gain administrative level access. |
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Privilege Management vulnerability. An unauthenticated attacker with local access could...Show more |
Cvlaunchd contained a missing authorization issue affecting command execution authorization. Software customers upgrade to resolved maintenance release. Update all Commvault installations, including Commserve, Webserver,...Show more |
SAP NetWeaver Business Client does not perform sufficient validation when processing certain locally stored data during application startup. An attacker with low privileges on the local system could replace this data wit...Show more |
1Adobe 3Commerce Commerce B2bMagentoSep 9, 2026 Sep 7, 2026 N/A· v4 10.0 CRITICAL· v3 N/A· v2 Adobe Commerce is affected by an Improper Neutralization of Special Elements Used in a Template Engine vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exp...Show more |
Use after free in Windows Hello allows an authorized attacker to elevate privileges locally. |
Heap-based buffer overflow in Windows Fax Service allows an authorized attacker to elevate privileges locally. |
Use after free in Windows Deployment Services allows an unauthorized attacker to execute code over a network. |
Heap-based buffer overflow in Windows Compressed Folder allows an unauthorized attacker to execute code over a network. |
Use after free in Remote Desktop Gateway Service allows an authorized attacker to elevate privileges over a network. |
Use after free in Windows Device Association Broker service allows an authorized attacker to elevate privileges over a network. |
Double free in Remote Desktop Gateway Service allows an authorized attacker to elevate privileges locally. |
Use after free in Windows File History Service allows an authorized attacker to elevate privileges locally. |
Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network. |
Use after free in SQL Server allows an authorized attacker to execute code over a network. |
Stack-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network. |
RouterOS does not compare the complete RSA public key when matching an SSH authentication request to an authorized user key, checking the key type and modulus but omitting the exponent. Because signature verification use...Show more |