Total CVEs

138,714

Critical Severity

3,596

High Severity

12,883

Last 7 Days

1,753
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 5,801 - 5,820 of 35,119 CVEs
CVE-2026-49384 MEDIUM - 6.1

In JetBrains PyCharm before 2025.3.4 stored XSS in Jupyter notebook Markdown cells was possible

Vendor: JetBrains
Product: PyCharm
Published: May 29, 2026
Source: NVD

In JetBrains IntelliJ IDEA before 2026.1 xXE in the UI Designer form parser was possible

Vendor: JetBrains
Product: IntelliJ IDEA
Published: May 29, 2026
Source: NVD
CVE-2026-49382 MEDIUM - 4.5

In JetBrains IntelliJ IDEA before 2026.1 code execution was possible via template injection in the Copyright plugin

Vendor: JetBrains
Product: IntelliJ IDEA
Published: May 29, 2026
Source: NVD

In JetBrains TeamCity before 2026.1 stored XSS on the SAML login page was possible

Vendor: JetBrains
Product: TeamCity
Published: May 29, 2026
Source: NVD

In JetBrains TeamCity before 2026.1 open redirect in the SAML plugin was possible

Vendor: JetBrains
Product: TeamCity
Published: May 29, 2026
Source: NVD
CVE-2026-49379 MEDIUM - 6.5

In JetBrains TeamCity before 2026.1 credentials could be exposed in thread names

Vendor: JetBrains
Product: TeamCity
Published: May 29, 2026
Source: NVD
CVE-2026-49378 MEDIUM - 4.3

In JetBrains TeamCity before 2026.1 credentials parameters were exposed via parameter autocompletion

Vendor: JetBrains
Product: TeamCity
Published: May 29, 2026
Source: NVD
CVE-2026-49377 MEDIUM - 4.3

In JetBrains TeamCity before 2025.11.2 exposure of sensitive data via default agent parameters

Vendor: JetBrains
Product: TeamCity
Published: May 29, 2026
Source: NVD
CVE-2026-49376 MEDIUM - 6.5

In JetBrains TeamCity before 2026.1 insufficient username validation in the SAML plugin

Vendor: JetBrains
Product: TeamCity
Published: May 29, 2026
Source: NVD
CVE-2026-49375 MEDIUM - 6.1

In JetBrains TeamCity before 2026.1, 2025.11.5 reflected XSS was possible on the repository download page

Vendor: JetBrains
Product: TeamCity
Published: May 29, 2026
Source: NVD
CVE-2026-49374 HIGH - 7.6

In JetBrains TeamCity before 2026.1 improper permission checks exposed build configuration parameters

Vendor: JetBrains
Product: TeamCity
Published: May 29, 2026
Source: NVD
CVE-2026-49373 HIGH - 7.1

In JetBrains TeamCity before 2026.1 remote code execution was possible via Perforce connection settings

Vendor: JetBrains
Product: TeamCity
Published: May 29, 2026
Source: NVD
CVE-2026-49372 HIGH - 7.5

In JetBrains TeamCity before 2026.1, 2025.11.5 unauthenticated SSRF via build status was possible

Vendor: JetBrains
Product: TeamCity
Published: May 29, 2026
Source: NVD
CVE-2026-49371 HIGH - 7.1

In JetBrains TeamCity before 2026.1.1 reflected XSS in the keyword filter was possible

Vendor: JetBrains
Product: TeamCity
Published: May 29, 2026
Source: NVD

In JetBrains YouTrack before 2026.1.13162 information disclosure was possible on fetchApp requests

Vendor: JetBrains
Product: YouTrack
Published: May 29, 2026
Source: NVD
CVE-2026-49369 MEDIUM - 4.3

In JetBrains YouTrack before 2026.1.13162 information disclosure was possible on Users and Groups pages

Vendor: JetBrains
Product: YouTrack
Published: May 29, 2026
Source: NVD
CVE-2026-49368 HIGH - 8.7

In JetBrains YouTrack before 2026.1.13162 stored XSS in project notification templates was possible

Vendor: JetBrains
Product: YouTrack
Published: May 29, 2026
Source: NVD
CVE-2026-49367 HIGH - 8.0

In JetBrains IntelliJ IDEA before 2026.1.1 command execution was possible via the guest user account

Vendor: JetBrains
Product: IntelliJ IDEA
Published: May 29, 2026
Source: NVD
CVE-2026-49366 HIGH - 7.8

In JetBrains IntelliJ IDEA before 2026.1.1 command injection was possible via filename completion

Vendor: JetBrains
Product: IntelliJ IDEA
Published: May 29, 2026
Source: NVD
CVE-2026-47745 MEDIUM - 6.5

Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, the admin tables for PaymentMethods, Currencies and Carriers exposed inline toggles and per-record actions (enable, disable, edit, delete) that were rendered for any authenticated panel user without checking the corresponding per-action p...

Vendor: shopperlabs
Product: shopper
Published: May 29, 2026
Source: NVD