|
2151
|
4.3 |
MEDIUM
Network
|
jetbrains
|
youtrack
|
In JetBrains YouTrack before 2026.1.13162 information disclosure was possible on Users and Groups pages
|
CWE-863
Incorrect Authorization
|
CVE-2026-49369
|
2026-06-1 21:56 |
2026-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2152
|
7.5 |
HIGH
Network
|
jetbrains
|
youtrack
|
In JetBrains YouTrack before 2026.1.13162 information disclosure was possible on fetchApp requests
|
CWE-201
Insertion of Sensitive Information Into Sent Data
|
CVE-2026-49370
|
2026-06-1 21:52 |
2026-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2153
|
6.1 |
MEDIUM
Network
|
jetbrains
|
pycharm
|
In JetBrains PyCharm before 2025.3.4 stored XSS in Jupyter notebook Markdown cells was possible
|
CWE-79
Cross-site Scripting
|
CVE-2026-49384
|
2026-06-1 21:44 |
2026-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2154
|
6.5 |
MEDIUM
Network
|
jetbrains
|
youtrack
|
In JetBrains YouTrack before 2026.1.13570 improper access control allowed low-privileged users to modify service accounts
|
CWE-862
Missing Authorization
|
CVE-2026-49385
|
2026-06-1 21:41 |
2026-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2155
|
6.5 |
MEDIUM
Network
|
jetbrains
|
youtrack
|
In JetBrains YouTrack before 2026.1.13570 improper access control allowed enumeration of restricted issues and articles on Planning Canvas
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2026-49386
|
2026-06-1 21:40 |
2026-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2156
|
7.3 |
HIGH
Network
|
-
|
-
|
Heap buffer overflow vulnerability in libjxl 0.12.0 via crafted PBM images to the jxl::extras::DecodeImagePNM function in file lib/extras/dec/pnm.cc.
|
CWE-122
Heap-based Buffer Overflow
|
CVE-2025-70103
|
2026-05-31 05:16 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2157
|
7.8 |
HIGH
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
net: skbuff: preserve shared-frag marker during coalescing
skb_try_coalesce() can attach paged frags from @from to @to. If @from…
|
CWE-787
Out-of-bounds Write
|
CVE-2026-46300
|
2026-05-30 20:17 |
2026-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2158
|
7.8 |
HIGH
Local
|
-
|
-
|
In the Linux kernel, the following vulnerability has been resolved:
media: iris: Fix use-after-free in iris_release_internal_buffers()
The recent change in commit 1dabf00ee206 ("media: iris: gen1: …
|
-
|
CVE-2026-46240
|
2026-05-30 20:17 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2159
|
8.1 |
HIGH
Adjacent
|
-
|
-
|
In the Linux kernel, the following vulnerability has been resolved:
HID: playstation: Clamp num_touch_reports
A device would never lie about the number of touch reports would it?
If it does the lo…
|
-
|
CVE-2026-46232
|
2026-05-30 20:17 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2160
|
7.8 |
HIGH
Local
|
-
|
-
|
In the Linux kernel, the following vulnerability has been resolved:
drm: Set old handle to NULL before prime swap in change_handle
There was a potential race condition in change_handle. The ioctl
b…
|
-
|
CVE-2026-46215
|
2026-05-30 20:17 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|