2026 CVE Vulnerabilities

62,186 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-49383LOW3.3In JetBrains IntelliJ IDEA before 2026.1 xXE in the UI Designer form parser was possible
CVE-2026-49382HIGH7.8In JetBrains IntelliJ IDEA before 2026.1 code execution was possible via template injection in the Copyright plugin
CVE-2026-49381MEDIUM4.8In JetBrains TeamCity before 2026.1 stored XSS on the SAML login page was possible
CVE-2026-49380MEDIUM6.1In JetBrains TeamCity before 2026.1 open redirect in the SAML plugin was possible
CVE-2026-49379MEDIUM6.5In JetBrains TeamCity before 2026.1 credentials could be exposed in thread names
CVE-2026-49378MEDIUM4.3In JetBrains TeamCity before 2026.1 credentials parameters were exposed via parameter autocompletion
CVE-2026-49377MEDIUM4.3In JetBrains TeamCity before 2025.11.2 exposure of sensitive data via default agent parameters
CVE-2026-49376MEDIUM6.5In JetBrains TeamCity before 2026.1 insufficient username validation in the SAML plugin
CVE-2026-49375MEDIUM6.1In JetBrains TeamCity before 2026.1, 2025.11.5 reflected XSS was possible on the repository download page
CVE-2026-49374HIGH7.6In JetBrains TeamCity before 2026.1 improper permission checks exposed build configuration parameters
CVE-2026-49373HIGH8.8In JetBrains TeamCity before 2026.1 remote code execution was possible via Perforce connection settings
CVE-2026-49372HIGH7.5In JetBrains TeamCity before 2026.1, 2025.11.5 unauthenticated SSRF via build status was possible
CVE-2026-49371HIGH8.2In JetBrains TeamCity before 2026.1.1 reflected XSS in the keyword filter was possible
CVE-2026-49370HIGH7.5In JetBrains YouTrack before 2026.1.13162 information disclosure was possible on fetchApp requests
CVE-2026-49369MEDIUM4.3In JetBrains YouTrack before 2026.1.13162 information disclosure was possible on Users and Groups pages
CVE-2026-49368MEDIUM5.4In JetBrains YouTrack before 2026.1.13162 stored XSS in project notification templates was possible
CVE-2026-49367HIGH8.8In JetBrains IntelliJ IDEA before 2026.1.1 command execution was possible via the guest user account
CVE-2026-49366HIGH7.8In JetBrains IntelliJ IDEA before 2026.1.1 command injection was possible via filename completion
CVE-2026-47745MEDIUM6.5Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, the admin tables for PaymentMethods, Currencies and Carrie...
CVE-2026-47744CRITICAL9.9Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, two distinct authorization defects in the team settings al...
CVE-2026-47742MEDIUM6.5Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, Sub-form Livewire components used in the product editor (E...
CVE-2026-47741MEDIUM5.9Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, CreateOrderFromCartAction::execute previously created the ...
CVE-2026-47740HIGH8.1Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, Multiple Filament actions on the admin Order detail and Or...
CVE-2026-46372HIGH8.5SillyTavern is a locally installed user interface that allows users to interact with text generation large language mode...
CVE-2026-46344MEDIUM5.3liboqs is a C-language cryptographic library that provides implementations of post-quantum cryptography algorithms. Prio...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now