CVE.report search for "CVE-2026-74880"
Listed below are 50 relevant search results for "CVE-2026-74880" based on Vendor, Software, and CVE description
These results are gathered from attempted matches with listed vendor and software data, as well as a keyword search in the description of all known CVEs.
If you notice a "Not Listed" in either the vendor or software columns, the underlying source record does not currently include normalized affected-product data.
Search Results
| CVE ID | Vendor | Software | Description |
|---|---|---|---|
| CVE-2026-75060 | In JetBrains PyCharm before 2026.2.1 code execution was possible via unauthenticated Jupyter MCP tools | ||
| CVE-2026-75059 | In JetBrains PyCharm before 2026.2.1 code execution via Quick Documentation was possible | ||
| CVE-2026-75058 | In JetBrains IntelliJ IDEA before 2026.2.1 xXE was possible in the Eclipse settings importers | ||
| CVE-2026-75057 | In JetBrains IntelliJ IDEA before 2026.1.5 git credentials were written in plaintext to the IDE log | ||
| CVE-2026-75056 | In JetBrains IntelliJ IDEA before 2026.2.1 rCE via Markdown export tool was possible | ||
| CVE-2026-75055 | In JetBrains IntelliJ IDEA before 2026.2.1 hadoop ResourceManager could read local files via XXE | ||
| CVE-2026-75054 | In JetBrains IntelliJ IDEA before 2026.2.1 sSRF was possible via the OpenAPI preview proxy in untrusted projects | ||
| CVE-2026-75053 | In JetBrains IntelliJ IDEA before 2026.2.1 sSRF was possible via the DevKit debug listener endpoint | ||
| CVE-2026-75052 | In JetBrains IntelliJ IDEA before 2026.2.1 command execution via crafted Markdown preview content was possible in trusted pro... | ||
| CVE-2026-75051 | In JetBrains YouTrack before 2026.2.17917 unauthorised project transfer between organisations was possible | ||
| CVE-2026-75050 | In JetBrains YouTrack before 2026.1.13901, 2026.2.17950 doS attack was possible via crafted type parameters | ||
| CVE-2026-75049 | In JetBrains YouTrack before 2026.1.13903, 2026.2.17950 an authenticated user could read restricted articles from other proj... | ||
| CVE-2026-75048 | In JetBrains YouTrack before 2026.2.18068 stored XSS via the fenced code-block language label was possible | ||
| CVE-2026-75047 | In JetBrains YouTrack before 2026.2.18177 doS attack was possible via a decompression bomb in the import endpoint | ||
| CVE-2026-75046 | In JetBrains YouTrack before 2026.2.18112 an authenticated user could enumerate accounts via the users search endpoint | ||
| CVE-2026-75045 | In JetBrains YouTrack before 2025.3.156085, 2026.1.13913, 2026.2.18112 an unauthenticated attacker could download database ... | ||
| CVE-2026-75044 | In JetBrains YouTrack before 2025.3.156085, 2026.1.13914, 2026.2.18095 missing authorisation allowed an authenticated user ... | ||
| CVE-2026-75006 | In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, insufficient Cascading Style Sheets (CSS) sanitization in HTML e-m... | ||
| CVE-2026-74516 | In the Linux kernel, the following vulnerability has been resolved: KVM: SVM: Update x2APIC MSR intercepts if AVIC is inhibi... | ||
| CVE-2026-74289 | In the Linux kernel, the following vulnerability has been resolved: ipv4: fib: Don't dump dying fib_info in fib_leaf_notify(... | ||
| CVE-2026-74264 | In the Linux kernel, the following vulnerability has been resolved: net: watchdog: fix refcount tracking races Blamed commi... | ||
| CVE-2026-74257 | In the Linux kernel, the following vulnerability has been resolved: sockmap: Fix use-after-free in udp_bpf_recvmsg() syzbot... | ||
| CVE-2026-74234 | Legora before 2026-08-14 contains a cross-site scripting vulnerability that allows attackers to achieve arbitrary JavaScript ... | ||
| CVE-2026-73649 | Velocity.js is a JavaScript implementation of the Apache Velocity template engine. Prior to 2.1.7, the earlier fix for CVE-20... | ||
| CVE-2026-73434 | Gstreamer | Gstreamer | A flaw was found in GStreamer gst-plugins-good (avidemux). In gst_avi_demux_riff_parse_vprp(), the number of available gst_ri... |
| CVE-2026-73433 | Gstreamer | Gstreamer | A flaw was found in GStreamer gst-plugins-good (avidemux). When parsing FUJIFILM metadata in an AVI strd chunk, gst_avi_demux... |
| CVE-2026-73230 | Ente provides end-to-end encrypted cloud services and security tools. Prior to 2026.07.28, Ente 2of3 card format version 1 st... | ||
| CVE-2026-73210 | A Server-Side Request Forgery (SSRF) vulnerability existed in Lookyloo's PlaywrightCapture when the only_global_lookup option... | ||
| CVE-2026-73188 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. Duplicate to CVE-2026-13610. | ||
| CVE-2026-72867 | Dokploy is a free, self-hostable Platform as a Service (PaaS). From 0.29.3 until 0.29.13, the incomplete fix for CVE-2026-456... | ||
| CVE-2026-72834 | filebrowser before 2.63.19 contains a permission bypass in the /api/resources endpoint. The checksum (?checksum=) branch of r... | ||
| CVE-2026-72759 | In affected versions of MISP cti-transmute, the conversion-history details endpoint performs an incomplete authorization chec... | ||
| CVE-2026-72746 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority as it's a duplicate of CVE-2026-73... | ||
| CVE-2026-72745 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority as it's a duplicate of CVE-2026-73... | ||
| CVE-2026-72735 | Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, writeTraefikConfigRemote in packages/server/... | ||
| CVE-2026-72732 | Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, the discourse_templates... | ||
| CVE-2026-72731 | Discourse is an open-source discussion platform. From 2026.1.0-latest until 2026.1.7, 2026.6.2, 2026.7.1, and 2026.8.0-latest... | ||
| CVE-2026-72730 | Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, the Rich Text Editor re... | ||
| CVE-2026-72729 | Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, the discourse-local-dat... | ||
| CVE-2026-72728 | Discourse is an open-source discussion platform. Prior to 2026.1.7, an authenticated user could submit specially formed URLs ... | ||
| CVE-2026-72727 | Discourse is an open-source discussion platform. Prior to 026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, a low-privileged user co... | ||
| CVE-2026-72726 | Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, an authenticated user c... | ||
| CVE-2026-72725 | Discourse is an open-source discussion platform. Prior to 2026.1.6, the staff action log model rendered unescaped previous an... | ||
| CVE-2026-72724 | Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, plugins/chat/lib/chat/o... | ||
| CVE-2026-72723 | Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, SiteSerializer.anonymou... | ||
| CVE-2026-72722 | Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, TopicLink.extract_from,... | ||
| CVE-2026-72721 | Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, Onebox::DomainChecker.i... | ||
| CVE-2026-72720 | Discourse is an open-source discussion platform. Prior to 2026.1.7, 2026.6.2, 2026.7.1, and 2026.8.0-latest.1, Discourse has ... | ||
| CVE-2026-72597 | A server-side request forgery vulnerability in Friendica through the 2026.08-dev branch allows authenticated users with a fre... | ||
| CVE-2026-72595 | A broken access control vulnerability in BadChoice Handesk as of 2026-07-10 allows any authenticated agent to update ticket r... | ||