Vulnerabilities
Vulnerable Software
Security Vulnerabilities
In JetBrains YouTrack before 2026.2.19422 iDOR in the issue activities API allowed reading restricted issues
CVSS Score
6.5
EPSS Score
0.002
Published
2026-10-01
In JetBrains YouTrack before 2026.2.19422 doS attack was possible via crafted PSD attachments
CVSS Score
6.5
EPSS Score
0.007
Published
2026-10-01
In JetBrains YouTrack before 2026.2.19422 stored XSS via Mermaid and LaTeX content was possible
CVSS Score
8.1
EPSS Score
0.002
Published
2026-10-01
In JetBrains YouTrack before 2026.2.19422 privilege escalation was possible via user group membership changes
CVSS Score
6.6
EPSS Score
0.002
Published
2026-10-01
pypdf is a free and open-source pure-python PDF library. Prior to 6.17.0, a crafted PDF can provide unusually large Roman page-label values that cause pypdf/_page_labels.py to generate excessively large numeral strings when an application retrieves document page labels, consuming large amounts of memory and potentially making the application unavailable. This issue is fixed in version 6.17.0.
CVSS Score
8.7
EPSS Score
0.004
Published
2026-09-30
CVE-2026-102489
Known exploited
Zammad versions 6.3.0 to 6.5.4 are vulnerable a session hijack vulnerability that leads to remote code execution as the zammad user. The vulnerability is also present in version 7.0.0 to version 7.1.3, but not exploitable due to environment conditions.
CVSS Score
9.4
EPSS Score
0.014
Published
2026-09-30
CVE-2026-102490
Known exploited
All versions of Zammad including the latest alpha enable the local zammad user to escalate privileges to root.
CVSS Score
9.4
EPSS Score
0.006
Published
2026-09-30
Joomla Extension - ordasoft.com - Unauthenticated Remote Code Execution in OrdaSoft Joomla CCK < 8.3.16 - site/uploader.php is reached through the component’s normal frontend routing (task=getContent), a task with no authentication or ACL check anywhere in the dispatch chain. The handler validates the uploaded file’s content with a real magic-byte MIME check, but the extension allow-list that would otherwise restrict the saved file’s extension was present in the source and commented out. The saved file’s extension was taken directly from the attacker-supplied filename with no validation, and the file was written to a path directly under the Joomla web root that is executed by the PHP handler. An image/PHP polyglot, a file whose header bytes satisfy the MIME check with PHP source appended after, passed the content check while carrying a .php extension of the attacker’s choosing.
CVSS Score
10.0
EPSS Score
0.008
Published
2026-09-30
In JetBrains YouTrack before 2026.2.19197 stored XSS in the workflow error notification toast was possible
CVSS Score
6.9
EPSS Score
0.002
Published
2026-09-30
In JetBrains YouTrack before 2026.2.19197 guest users could remove a workflow action's visibility restriction and run the action
CVSS Score
5.9
EPSS Score
0.002
Published
2026-09-30


Contact Us

Shodan ® - All rights reserved