Vulnerabilities
Vulnerable Software
Security Vulnerabilities
Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in its SVG processing feature that allows unauthenticated attackers to read arbitrary files from the server filesystem by supplying a crafted request. Attackers can exploit this path traversal weakness to disclose sensitive server files, including authentication credentials, enabling full unauthorized access to the application. The vulnerability is specific to the DataHub module, which was introduced in Bold Reports 6.3. Therefore, versions prior to 6.3 are not affected.
CVSS Score
9.3
EPSS Score
0.006
Published
2026-07-23
In JetBrains PyCharm before 2026.1.4, 2026.2 arbitrary code execution via malicious Python executable was possible on untrusted project open
CVSS Score
8.6
EPSS Score
0.001
Published
2026-07-23
In JetBrains IntelliJ IDEA before 2026.2 unauthorized file access was possible in a Remote Development session
CVSS Score
8.6
EPSS Score
0.003
Published
2026-07-23
In JetBrains IntelliJ IDEA before 2026.2 arbitrary code injection was possible via UI Designer form files
CVSS Score
8.1
EPSS Score
0.003
Published
2026-07-23
In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via the configured Node.js interpreter
CVSS Score
8.4
EPSS Score
0.001
Published
2026-07-23
In JetBrains WebStorm before 2026.2 arbitrary code execution was possible via a project-supplied linter configuration
CVSS Score
7.8
EPSS Score
0.001
Published
2026-07-23
In JetBrains PhpStorm before 2026.2 arbitrary code execution was possible before granting project trust via project tooling
CVSS Score
8.4
EPSS Score
0.001
Published
2026-07-23
In JetBrains PhpStorm before 2026.2 arbitrary code execution was possible before granting project trust via the configured interpreter
CVSS Score
8.4
EPSS Score
0.001
Published
2026-07-23
In JetBrains IntelliJ IDEA before 2026.2 hTML injection was possible in an IDE notification, allowing silent user activity tracking
CVSS Score
4.3
EPSS Score
0.001
Published
2026-07-23
In JetBrains IntelliJ IDEA before 2026.2 arbitrary code execution was possible before granting project trust via development container configuration
CVSS Score
7.8
EPSS Score
0.001
Published
2026-07-23


Contact Us

Shodan ® - All rights reserved