Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 8.3 CVE-2026-13281

CVE-2026-13281_CVE-2026-13281

Integer overflow in Mojo in Google Chrome prior to 149.0.7827.201 allowed a remote attacker who had compromised the renderer process to potentially...

Google Chrome 149.0.7827.201 CVE
MEDIUM 6.5 CVE-2026-57914

Apache Kerby: StackOverflow on parsing deeply nested ASN1 structures_CVE-2026-57914

By sending a deeply nested ASN1 structure to a Apache Kerby client or service, it's possible to trigger a StackOverFlow Exception which can lead to...

Apache Software Foundation Apache Kerby CVE
LOW 2.1 CVE-2026-57940

CVE-2026-57940_CVE-2026-57940

HTMLy 3.1.1 contains a Server-Side Request Forgery (SSRF) vulnerability in the RSS feed import functionality. The function get_feed() in system/adm...

danpros HTMLy 3.1.1 CVE
LOW 2.6 CVE-2026-57926

CVE-2026-57926_CVE-2026-57926

In JetBrains YouTrack before 2026.2.16593 the websandbox bridge was vulnerable to a prototype pollution attack

JetBrains YouTrack CVE
MEDIUM 4.3 CVE-2026-57925

CVE-2026-57925_CVE-2026-57925

In JetBrains YouTrack before 2026.2.16593 improper access control allowed reading saved queries and tags

JetBrains YouTrack CVE
MEDIUM 4.3 CVE-2026-57924

CVE-2026-57924_CVE-2026-57924

In JetBrains YouTrack before 2026.2.16593 default role configuration exposed excessive user profile details

JetBrains YouTrack CVE
MEDIUM 5.3 CVE-2026-57923

CVE-2026-57923_CVE-2026-57923

In JetBrains YouTrack before 2026.2.16593 improper authorisation in the app configurations endpoint allowed modifying project settings

JetBrains YouTrack CVE
LOW 3.1 CVE-2026-57922

CVE-2026-57922_CVE-2026-57922

In JetBrains YouTrack before 2026.2.16593 project settings disclosure via the MCP was possible

JetBrains YouTrack CVE
MEDIUM 4.3 CVE-2026-57921

CVE-2026-57921_CVE-2026-57921

In JetBrains YouTrack before 2026.2.16593 improper access control allowed reading users' private data via the comment templates endpoint

JetBrains YouTrack CVE
MEDIUM 6.7 CVE-2026-53914

CVE-2026-53914_CVE-2026-53914

In JetBrains Kotlin before 2.4.20 code execution was possible via unsafe deserialization in the build cache metadata

JetBrains Kotlin CVE