Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 374 083

Количество 374 083

nvd логотип

CVE-2026-64813

17 дней назад

In JetBrains IntelliJ IDEA before 2026.2 unauthorized settings modification was possible in a Remote Development session

CVSS3: 10
EPSS: Низкий
nvd логотип

CVE-2026-64812

17 дней назад

In JetBrains IntelliJ IDEA before 2026.2 unauthorized input injection was possible in a Remote Development session

CVSS3: 10
EPSS: Низкий
nvd логотип

CVE-2026-64811

17 дней назад

In JetBrains IntelliJ IDEA before 2026.2 arbitrary code execution was possible before granting project trust via development container configuration

CVSS3: 7.8
EPSS: Низкий
nvd логотип

CVE-2026-64810

17 дней назад

In JetBrains IntelliJ IDEA before 2026.2 hTML injection was possible in an IDE notification, allowing silent user activity tracking

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2026-64809

17 дней назад

In JetBrains PhpStorm before 2026.2 arbitrary code execution was possible before granting project trust via the configured interpreter

CVSS3: 8.4
EPSS: Низкий
nvd логотип

CVE-2026-64808

17 дней назад

In JetBrains PhpStorm before 2026.2 arbitrary code execution was possible before granting project trust via project tooling

CVSS3: 8.4
EPSS: Низкий
nvd логотип

CVE-2026-64807

17 дней назад

In JetBrains WebStorm before 2026.2 arbitrary code execution was possible via a project-supplied linter configuration

CVSS3: 7.8
EPSS: Низкий
nvd логотип

CVE-2026-64806

17 дней назад

In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via the configured Node.js interpreter

CVSS3: 8.4
EPSS: Низкий
nvd логотип

CVE-2026-64805

17 дней назад

In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via project-local package-manager tooling

CVSS3: 8.4
EPSS: Низкий
nvd логотип

CVE-2026-64804

17 дней назад

In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via project-local linter tooling

CVSS3: 8.4
EPSS: Низкий
nvd логотип

CVE-2026-64803

17 дней назад

In JetBrains GoLand before 2026.2 arbitrary code execution was possible before granting project trust via the configured Go SDK

CVSS3: 7.8
EPSS: Низкий
nvd логотип

CVE-2026-64802

17 дней назад

In JetBrains GoLand before 2026.2 arbitrary code execution was possible before granting project trust in the Go Modules integration

CVSS3: 7.8
EPSS: Низкий
nvd логотип

CVE-2026-64800

17 дней назад

In JetBrains GoLand before 2026.2 sensitive configuration values written to log files by default

CVSS3: 3.5
EPSS: Низкий
nvd логотип

CVE-2026-6479

3 месяца назад

Uncontrolled recursion in PostgreSQL SSL and GSS negotiation allows an attacker able to connect to a PostgreSQL AF_UNIX socket to achieve sustained denial of service. If SSL and GSS are both disabled, an attacker can do the same via access to a PostgreSQL TCP socket. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2026-64799

17 дней назад

Joomla Extension - regularlabs.com - SSRF via remote image downloads in Articles Anywhere and Users Anywhere extensions - Content-controlled image URLs could request private or reserved network services, follow unsafe redirects and save responses without validating that they were images. This could result in SSRF, internal-data access or writing attacker-controlled files into a web-accessible folder.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2026-64798

17 дней назад

Joomla Extension - regularlabs.com - Insecure login URL keys in IP login extension - Persistent URL login keys were also generated using a non-cryptographic random generator with insufficient entropy.

CVSS3: 9.1
EPSS: Низкий
nvd логотип

CVE-2026-64797

17 дней назад

Joomla Extension - regularlabs.com - IP spoofing vulnerability in IP login extension - IP Login trusted forwarded client-IP headers without requiring a configured trusted proxy. Attackers could spoof the IP used for automatic login and potentially impersonate mapped accounts.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2026-64796

17 дней назад

Joomla Extension - regularlabs.com - various code injection vectors in Sourcerer extension - Free did not require both the article creator and last modifier to be Super Users before executing article PHP. Pro did not consistently enforce configured CSS, JavaScript and PHP permissions across tags, attributes, files and both article owners. PHP include attributes could also escape the configured include folder, and executable script/style variants could bypass detection.

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2026-64795

17 дней назад

Joomla Extension - regularlabs.com - XSS vectors in tag-provided inputs in various Regular Labs extensions - Tag-provided custom HTML, module content/title overrides and decoded modal or tooltip values could execute unsafe markup. A content author could inject JavaScript that ran in visitors’ browsers.

CVSS3: 5.4
EPSS: Низкий
nvd логотип

CVE-2026-64794

17 дней назад

Joomla Extension - regularlabs.com - restricted user-data exposure in Users Anywhere and Articles Anywhere extensions - User tags, filters and conditions allowed access to insufficiently restricted user fields. Crafted content could expose authentication-related data, raw user parameters or restricted contact details.

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2026-64813

In JetBrains IntelliJ IDEA before 2026.2 unauthorized settings modification was possible in a Remote Development session

CVSS3: 10
0%
Низкий
17 дней назад
nvd логотип
CVE-2026-64812

In JetBrains IntelliJ IDEA before 2026.2 unauthorized input injection was possible in a Remote Development session

CVSS3: 10
0%
Низкий
17 дней назад
nvd логотип
CVE-2026-64811

In JetBrains IntelliJ IDEA before 2026.2 arbitrary code execution was possible before granting project trust via development container configuration

CVSS3: 7.8
0%
Низкий
17 дней назад
nvd логотип
CVE-2026-64810

In JetBrains IntelliJ IDEA before 2026.2 hTML injection was possible in an IDE notification, allowing silent user activity tracking

CVSS3: 4.3
0%
Низкий
17 дней назад
nvd логотип
CVE-2026-64809

In JetBrains PhpStorm before 2026.2 arbitrary code execution was possible before granting project trust via the configured interpreter

CVSS3: 8.4
0%
Низкий
17 дней назад
nvd логотип
CVE-2026-64808

In JetBrains PhpStorm before 2026.2 arbitrary code execution was possible before granting project trust via project tooling

CVSS3: 8.4
0%
Низкий
17 дней назад
nvd логотип
CVE-2026-64807

In JetBrains WebStorm before 2026.2 arbitrary code execution was possible via a project-supplied linter configuration

CVSS3: 7.8
0%
Низкий
17 дней назад
nvd логотип
CVE-2026-64806

In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via the configured Node.js interpreter

CVSS3: 8.4
0%
Низкий
17 дней назад
nvd логотип
CVE-2026-64805

In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via project-local package-manager tooling

CVSS3: 8.4
0%
Низкий
17 дней назад
nvd логотип
CVE-2026-64804

In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via project-local linter tooling

CVSS3: 8.4
0%
Низкий
17 дней назад
nvd логотип
CVE-2026-64803

In JetBrains GoLand before 2026.2 arbitrary code execution was possible before granting project trust via the configured Go SDK

CVSS3: 7.8
0%
Низкий
17 дней назад
nvd логотип
CVE-2026-64802

In JetBrains GoLand before 2026.2 arbitrary code execution was possible before granting project trust in the Go Modules integration

CVSS3: 7.8
0%
Низкий
17 дней назад
nvd логотип
CVE-2026-64800

In JetBrains GoLand before 2026.2 sensitive configuration values written to log files by default

CVSS3: 3.5
0%
Низкий
17 дней назад
nvd логотип
CVE-2026-6479

Uncontrolled recursion in PostgreSQL SSL and GSS negotiation allows an attacker able to connect to a PostgreSQL AF_UNIX socket to achieve sustained denial of service. If SSL and GSS are both disabled, an attacker can do the same via access to a PostgreSQL TCP socket. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.

CVSS3: 7.5
0%
Низкий
3 месяца назад
nvd логотип
CVE-2026-64799

Joomla Extension - regularlabs.com - SSRF via remote image downloads in Articles Anywhere and Users Anywhere extensions - Content-controlled image URLs could request private or reserved network services, follow unsafe redirects and save responses without validating that they were images. This could result in SSRF, internal-data access or writing attacker-controlled files into a web-accessible folder.

CVSS3: 7.5
0%
Низкий
17 дней назад
nvd логотип
CVE-2026-64798

Joomla Extension - regularlabs.com - Insecure login URL keys in IP login extension - Persistent URL login keys were also generated using a non-cryptographic random generator with insufficient entropy.

CVSS3: 9.1
0%
Низкий
17 дней назад
nvd логотип
CVE-2026-64797

Joomla Extension - regularlabs.com - IP spoofing vulnerability in IP login extension - IP Login trusted forwarded client-IP headers without requiring a configured trusted proxy. Attackers could spoof the IP used for automatic login and potentially impersonate mapped accounts.

CVSS3: 7.5
0%
Низкий
17 дней назад
nvd логотип
CVE-2026-64796

Joomla Extension - regularlabs.com - various code injection vectors in Sourcerer extension - Free did not require both the article creator and last modifier to be Super Users before executing article PHP. Pro did not consistently enforce configured CSS, JavaScript and PHP permissions across tags, attributes, files and both article owners. PHP include attributes could also escape the configured include folder, and executable script/style variants could bypass detection.

CVSS3: 9.8
0%
Низкий
17 дней назад
nvd логотип
CVE-2026-64795

Joomla Extension - regularlabs.com - XSS vectors in tag-provided inputs in various Regular Labs extensions - Tag-provided custom HTML, module content/title overrides and decoded modal or tooltip values could execute unsafe markup. A content author could inject JavaScript that ran in visitors’ browsers.

CVSS3: 5.4
0%
Низкий
17 дней назад
nvd логотип
CVE-2026-64794

Joomla Extension - regularlabs.com - restricted user-data exposure in Users Anywhere and Articles Anywhere extensions - User tags, filters and conditions allowed access to insufficiently restricted user fields. Crafted content could expose authentication-related data, raw user parameters or restricted contact details.

CVSS3: 6.5
0%
Низкий
17 дней назад

Уязвимостей на страницу