Количество 374 083
Количество 374 083
CVE-2026-64813
In JetBrains IntelliJ IDEA before 2026.2 unauthorized settings modification was possible in a Remote Development session
CVE-2026-64812
In JetBrains IntelliJ IDEA before 2026.2 unauthorized input injection was possible in a Remote Development session
CVE-2026-64811
In JetBrains IntelliJ IDEA before 2026.2 arbitrary code execution was possible before granting project trust via development container configuration
CVE-2026-64810
In JetBrains IntelliJ IDEA before 2026.2 hTML injection was possible in an IDE notification, allowing silent user activity tracking
CVE-2026-64809
In JetBrains PhpStorm before 2026.2 arbitrary code execution was possible before granting project trust via the configured interpreter
CVE-2026-64808
In JetBrains PhpStorm before 2026.2 arbitrary code execution was possible before granting project trust via project tooling
CVE-2026-64807
In JetBrains WebStorm before 2026.2 arbitrary code execution was possible via a project-supplied linter configuration
CVE-2026-64806
In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via the configured Node.js interpreter
CVE-2026-64805
In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via project-local package-manager tooling
CVE-2026-64804
In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via project-local linter tooling
CVE-2026-64803
In JetBrains GoLand before 2026.2 arbitrary code execution was possible before granting project trust via the configured Go SDK
CVE-2026-64802
In JetBrains GoLand before 2026.2 arbitrary code execution was possible before granting project trust in the Go Modules integration
CVE-2026-64800
In JetBrains GoLand before 2026.2 sensitive configuration values written to log files by default
CVE-2026-6479
Uncontrolled recursion in PostgreSQL SSL and GSS negotiation allows an attacker able to connect to a PostgreSQL AF_UNIX socket to achieve sustained denial of service. If SSL and GSS are both disabled, an attacker can do the same via access to a PostgreSQL TCP socket. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.
CVE-2026-64799
Joomla Extension - regularlabs.com - SSRF via remote image downloads in Articles Anywhere and Users Anywhere extensions - Content-controlled image URLs could request private or reserved network services, follow unsafe redirects and save responses without validating that they were images. This could result in SSRF, internal-data access or writing attacker-controlled files into a web-accessible folder.
CVE-2026-64798
Joomla Extension - regularlabs.com - Insecure login URL keys in IP login extension - Persistent URL login keys were also generated using a non-cryptographic random generator with insufficient entropy.
CVE-2026-64797
Joomla Extension - regularlabs.com - IP spoofing vulnerability in IP login extension - IP Login trusted forwarded client-IP headers without requiring a configured trusted proxy. Attackers could spoof the IP used for automatic login and potentially impersonate mapped accounts.
CVE-2026-64796
Joomla Extension - regularlabs.com - various code injection vectors in Sourcerer extension - Free did not require both the article creator and last modifier to be Super Users before executing article PHP. Pro did not consistently enforce configured CSS, JavaScript and PHP permissions across tags, attributes, files and both article owners. PHP include attributes could also escape the configured include folder, and executable script/style variants could bypass detection.
CVE-2026-64795
Joomla Extension - regularlabs.com - XSS vectors in tag-provided inputs in various Regular Labs extensions - Tag-provided custom HTML, module content/title overrides and decoded modal or tooltip values could execute unsafe markup. A content author could inject JavaScript that ran in visitors’ browsers.
CVE-2026-64794
Joomla Extension - regularlabs.com - restricted user-data exposure in Users Anywhere and Articles Anywhere extensions - User tags, filters and conditions allowed access to insufficiently restricted user fields. Crafted content could expose authentication-related data, raw user parameters or restricted contact details.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-64813 In JetBrains IntelliJ IDEA before 2026.2 unauthorized settings modification was possible in a Remote Development session | CVSS3: 10 | 0% Низкий | 17 дней назад | |
CVE-2026-64812 In JetBrains IntelliJ IDEA before 2026.2 unauthorized input injection was possible in a Remote Development session | CVSS3: 10 | 0% Низкий | 17 дней назад | |
CVE-2026-64811 In JetBrains IntelliJ IDEA before 2026.2 arbitrary code execution was possible before granting project trust via development container configuration | CVSS3: 7.8 | 0% Низкий | 17 дней назад | |
CVE-2026-64810 In JetBrains IntelliJ IDEA before 2026.2 hTML injection was possible in an IDE notification, allowing silent user activity tracking | CVSS3: 4.3 | 0% Низкий | 17 дней назад | |
CVE-2026-64809 In JetBrains PhpStorm before 2026.2 arbitrary code execution was possible before granting project trust via the configured interpreter | CVSS3: 8.4 | 0% Низкий | 17 дней назад | |
CVE-2026-64808 In JetBrains PhpStorm before 2026.2 arbitrary code execution was possible before granting project trust via project tooling | CVSS3: 8.4 | 0% Низкий | 17 дней назад | |
CVE-2026-64807 In JetBrains WebStorm before 2026.2 arbitrary code execution was possible via a project-supplied linter configuration | CVSS3: 7.8 | 0% Низкий | 17 дней назад | |
CVE-2026-64806 In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via the configured Node.js interpreter | CVSS3: 8.4 | 0% Низкий | 17 дней назад | |
CVE-2026-64805 In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via project-local package-manager tooling | CVSS3: 8.4 | 0% Низкий | 17 дней назад | |
CVE-2026-64804 In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via project-local linter tooling | CVSS3: 8.4 | 0% Низкий | 17 дней назад | |
CVE-2026-64803 In JetBrains GoLand before 2026.2 arbitrary code execution was possible before granting project trust via the configured Go SDK | CVSS3: 7.8 | 0% Низкий | 17 дней назад | |
CVE-2026-64802 In JetBrains GoLand before 2026.2 arbitrary code execution was possible before granting project trust in the Go Modules integration | CVSS3: 7.8 | 0% Низкий | 17 дней назад | |
CVE-2026-64800 In JetBrains GoLand before 2026.2 sensitive configuration values written to log files by default | CVSS3: 3.5 | 0% Низкий | 17 дней назад | |
CVE-2026-6479 Uncontrolled recursion in PostgreSQL SSL and GSS negotiation allows an attacker able to connect to a PostgreSQL AF_UNIX socket to achieve sustained denial of service. If SSL and GSS are both disabled, an attacker can do the same via access to a PostgreSQL TCP socket. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected. | CVSS3: 7.5 | 0% Низкий | 3 месяца назад | |
CVE-2026-64799 Joomla Extension - regularlabs.com - SSRF via remote image downloads in Articles Anywhere and Users Anywhere extensions - Content-controlled image URLs could request private or reserved network services, follow unsafe redirects and save responses without validating that they were images. This could result in SSRF, internal-data access or writing attacker-controlled files into a web-accessible folder. | CVSS3: 7.5 | 0% Низкий | 17 дней назад | |
CVE-2026-64798 Joomla Extension - regularlabs.com - Insecure login URL keys in IP login extension - Persistent URL login keys were also generated using a non-cryptographic random generator with insufficient entropy. | CVSS3: 9.1 | 0% Низкий | 17 дней назад | |
CVE-2026-64797 Joomla Extension - regularlabs.com - IP spoofing vulnerability in IP login extension - IP Login trusted forwarded client-IP headers without requiring a configured trusted proxy. Attackers could spoof the IP used for automatic login and potentially impersonate mapped accounts. | CVSS3: 7.5 | 0% Низкий | 17 дней назад | |
CVE-2026-64796 Joomla Extension - regularlabs.com - various code injection vectors in Sourcerer extension - Free did not require both the article creator and last modifier to be Super Users before executing article PHP. Pro did not consistently enforce configured CSS, JavaScript and PHP permissions across tags, attributes, files and both article owners. PHP include attributes could also escape the configured include folder, and executable script/style variants could bypass detection. | CVSS3: 9.8 | 0% Низкий | 17 дней назад | |
CVE-2026-64795 Joomla Extension - regularlabs.com - XSS vectors in tag-provided inputs in various Regular Labs extensions - Tag-provided custom HTML, module content/title overrides and decoded modal or tooltip values could execute unsafe markup. A content author could inject JavaScript that ran in visitors’ browsers. | CVSS3: 5.4 | 0% Низкий | 17 дней назад | |
CVE-2026-64794 Joomla Extension - regularlabs.com - restricted user-data exposure in Users Anywhere and Articles Anywhere extensions - User tags, filters and conditions allowed access to insufficiently restricted user fields. Crafted content could expose authentication-related data, raw user parameters or restricted contact details. | CVSS3: 6.5 | 0% Низкий | 17 дней назад |
Уязвимостей на страницу