2026 CVE Vulnerabilities
62,186 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-49383 | LOW | 3.3 | 0.1% | May 29, 2026 | In JetBrains IntelliJ IDEA before 2026.1 xXE in the UI Designer form parser was possible |
| CVE-2026-49382 | HIGH | 7.8 | 0.1% | May 29, 2026 | In JetBrains IntelliJ IDEA before 2026.1 code execution was possible via template injection in the Copyright plugin |
| CVE-2026-49381 | MEDIUM | 4.8 | 0.2% | May 29, 2026 | In JetBrains TeamCity before 2026.1 stored XSS on the SAML login page was possible |
| CVE-2026-49380 | MEDIUM | 6.1 | 0.2% | May 29, 2026 | In JetBrains TeamCity before 2026.1 open redirect in the SAML plugin was possible |
| CVE-2026-49379 | MEDIUM | 6.5 | 0.2% | May 29, 2026 | In JetBrains TeamCity before 2026.1 credentials could be exposed in thread names |
| CVE-2026-49378 | MEDIUM | 4.3 | 0.2% | May 29, 2026 | In JetBrains TeamCity before 2026.1 credentials parameters were exposed via parameter autocompletion |
| CVE-2026-49377 | MEDIUM | 4.3 | 0.7% | May 29, 2026 | In JetBrains TeamCity before 2025.11.2 exposure of sensitive data via default agent parameters |
| CVE-2026-49376 | MEDIUM | 6.5 | 0.2% | May 29, 2026 | In JetBrains TeamCity before 2026.1 insufficient username validation in the SAML plugin |
| CVE-2026-49375 | MEDIUM | 6.1 | 0.2% | May 29, 2026 | In JetBrains TeamCity before 2026.1, 2025.11.5 reflected XSS was possible on the repository download page |
| CVE-2026-49374 | HIGH | 7.6 | 0.2% | May 29, 2026 | In JetBrains TeamCity before 2026.1 improper permission checks exposed build configuration parameters |
| CVE-2026-49373 | HIGH | 8.8 | 0.4% | May 29, 2026 | In JetBrains TeamCity before 2026.1 remote code execution was possible via Perforce connection settings |
| CVE-2026-49372 | HIGH | 7.5 | 0.3% | May 29, 2026 | In JetBrains TeamCity before 2026.1, 2025.11.5 unauthenticated SSRF via build status was possible |
| CVE-2026-49371 | HIGH | 8.2 | 0.3% | May 29, 2026 | In JetBrains TeamCity before 2026.1.1 reflected XSS in the keyword filter was possible |
| CVE-2026-49370 | HIGH | 7.5 | 0.2% | May 29, 2026 | In JetBrains YouTrack before 2026.1.13162 information disclosure was possible on fetchApp requests |
| CVE-2026-49369 | MEDIUM | 4.3 | 0.2% | May 29, 2026 | In JetBrains YouTrack before 2026.1.13162 information disclosure was possible on Users and Groups pages |
| CVE-2026-49368 | MEDIUM | 5.4 | 0.2% | May 29, 2026 | In JetBrains YouTrack before 2026.1.13162 stored XSS in project notification templates was possible |
| CVE-2026-49367 | HIGH | 8.8 | 0.3% | May 29, 2026 | In JetBrains IntelliJ IDEA before 2026.1.1 command execution was possible via the guest user account |
| CVE-2026-49366 | HIGH | 7.8 | 0.5% | May 29, 2026 | In JetBrains IntelliJ IDEA before 2026.1.1 command injection was possible via filename completion |
| CVE-2026-47745 | MEDIUM | 6.5 | 0.2% | May 29, 2026 | Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, the admin tables for PaymentMethods, Currencies and Carrie... |
| CVE-2026-47744 | CRITICAL | 9.9 | 0.3% | May 29, 2026 | Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, two distinct authorization defects in the team settings al... |
| CVE-2026-47742 | MEDIUM | 6.5 | 0.2% | May 29, 2026 | Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, Sub-form Livewire components used in the product editor (E... |
| CVE-2026-47741 | MEDIUM | 5.9 | 0.2% | May 29, 2026 | Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, CreateOrderFromCartAction::execute previously created the ... |
| CVE-2026-47740 | HIGH | 8.1 | 0.3% | May 29, 2026 | Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, Multiple Filament actions on the admin Order detail and Or... |
| CVE-2026-46372 | HIGH | 8.5 | 0.9% | May 29, 2026 | SillyTavern is a locally installed user interface that allows users to interact with text generation large language mode... |
| CVE-2026-46344 | MEDIUM | 5.3 | 0.3% | May 29, 2026 | liboqs is a C-language cryptographic library that provides implementations of post-quantum cryptography algorithms. Prio... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now