CVE.report search for "CVE-2026-76961"
Listed below are 50 relevant search results for "CVE-2026-76961" based on Vendor, Software, and CVE description
These results are gathered from attempted matches with listed vendor and software data, as well as a keyword search in the description of all known CVEs.
If you notice a "Not Listed" in either the vendor or software columns, the underlying source record does not currently include normalized affected-product data.
Search Results
| CVE ID | Vendor | Software | Description |
|---|---|---|---|
| CVE-2026-86506 | In JetBrains GoLand before 2026.2.2.1 missing authentication on the GoLand profiler's injected pprof server exposed profiling... | ||
| CVE-2026-86505 | In JetBrains IntelliJ IDEA before 2026.2.2 missing project-trust check leaked project metadata to JetBrains Marketplace | ||
| CVE-2026-86504 | In JetBrains IntelliJ IDEA before 2026.2.2 missing project-trust confirmation before building a Dev Container allowed host-le... | ||
| CVE-2026-86503 | In JetBrains IntelliJ IDEA before 2026.2.2 opening an untrusted project could trigger SSRF via Kubernetes spec-source URL fet... | ||
| CVE-2026-86502 | In JetBrains IntelliJ IDEA before 2026.2.2 missing TLS and authentication on the IJent gRPC server allowed local code executi... | ||
| CVE-2026-86501 | In JetBrains IntelliJ IDEA before 2026.2.2 terminal command input could be written to idea.log | ||
| CVE-2026-86500 | In JetBrains YouTrack before 2026.1.14047 a missing escalation check let a user with project update permissions grant themsel... | ||
| CVE-2026-86499 | In JetBrains YouTrack before 2026.1.14047 predefined search fields leaked all group names to any user, regardless of visibili... | ||
| CVE-2026-86498 | In JetBrains YouTrack before 2025.3.160480, 2026.1.14047 pUT requests on link sub-resources allowed modification linked enti... | ||
| CVE-2026-86497 | In JetBrains YouTrack before 2026.2.18769 changing a mailbox host without re-authentication allowed a project administrator t... | ||
| CVE-2026-86496 | In JetBrains YouTrack before 2026.2.18769 missing access control on Helpdesk authorized reporters exposed reporter email addr... | ||
| CVE-2026-86495 | In JetBrains YouTrack before 2026.2.18687 missing permission checks allowed creating knowledge base articles in inaccessible ... | ||
| CVE-2026-86494 | In JetBrains YouTrack before 2026.2.18634 cloning a whiteboard allowed unauthorized changes to links on inaccessible issues | ||
| CVE-2026-86493 | In JetBrains YouTrack before 2026.2.18634 improper permission checks allowed read-only users to create and modify whiteboard ... | ||
| CVE-2026-86492 | In JetBrains YouTrack before 2026.2.18634 a shared token cache allowed cross-tenant theft of GitHub App installation tokens | ||
| CVE-2026-86491 | In JetBrains YouTrack before 2026.2.18634 stored XSS was possible via project and organization icon uploads | ||
| CVE-2026-86490 | In JetBrains YouTrack before 2026.2.18634 improper permission checks allowed overwriting of bundled apps via the app import e... | ||
| CVE-2026-86489 | In JetBrains YouTrack before 2026.2.18634 an IDOR in the user profile API disclosed private issues and starred folders across... | ||
| CVE-2026-86488 | In JetBrains YouTrack before 2026.2.18634 iDOR via the watchRules and issueListConfig endpoints exposed private saved searche... | ||
| CVE-2026-86487 | In JetBrains YouTrack before 2026.2.18634 a crafted WebSocket message allowed read-only whiteboard users to modify canvas con... | ||
| CVE-2026-86486 | In JetBrains YouTrack before 2026.2.18634 the generic VCS webhook handler failed open when its secret was blank | ||
| CVE-2026-86485 | In JetBrains YouTrack before 2026.2.18634 iP spoofing via HTTP headers allowed forged Bitbucket webhooks | ||
| CVE-2026-86484 | In JetBrains YouTrack before 2026.2.18634 angularJS template injection in assignee names led to stored XSS | ||
| CVE-2026-86483 | In JetBrains YouTrack before 2026.2.18634 stored XSS via a custom field on Agile board cards was possible | ||
| CVE-2026-86482 | In JetBrains YouTrack before 2026.2.18634 unchecked group membership changes allowed privilege escalation | ||
| CVE-2026-86481 | In JetBrains YouTrack before 2026.2.18634 signed URL reuse allowed disclosure of restricted project icons | ||
| CVE-2026-86480 | In JetBrains Hub before 2026.2.52442 an unauthenticated attacker could register a trusted service and gain superuser privileg... | ||
| CVE-2026-86479 | In JetBrains YouTrack before 2026.2.18788, 2026.1.14055, 2025.3.161254 missing authorisation allowed access to restricted R... | ||
| CVE-2026-86478 | In JetBrains YouTrack before 2025.3.161254, 2026.1.14042 improper authentication in YouTrack Helpdesk allowed unauthenticate... | ||
| CVE-2026-86332 | A flaw was found in odh-dashboard in Red Hat OpenShift AI. The backend-for-frontend route GET /api/nim-serving/:nimResource r... | ||
| CVE-2026-86218 | N-central is vulnerable to a pre-auth remote code execution This issue affects N-central: before 2026.3.1.14. | ||
| CVE-2026-86207 | An authentication bypass in N-central < 2026.3 HF 3 leads to authentication bypass in internal only APIs | ||
| CVE-2026-86206 | A vulnerability in the N-central internal API access control filter allows unauthorised access to internal APIs. This is fixe... | ||
| CVE-2026-85786 | Improper handling of highly compressed data in Amazon ion-java before 1.12.1 might allow remote attackers to cause a denial o... | ||
| CVE-2026-85692 | Nightingale (n9e), as of commit 8362cbe (main branch, confirmed 2026-08-27), contains a server-side request forgery vulnerabi... | ||
| CVE-2026-85505 | ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer over-read in ipmi_oem_fujitsu_get_sel_entry_long_text in ipmi-oem... | ||
| CVE-2026-85393 | node-forge through 1.4.0 fails to validate element count in nested DigestAlgorithm sequences during RSA PKCS#1 v1.5 signature... | ||
| CVE-2026-85388 | Worklenz through 3.0.0 fails to properly validate the sort-field query parameter in pagination helper functions, allowing aut... | ||
| CVE-2026-84365 | Hono is a Web application framework that provides support for any JavaScript runtime. From 4.12.12 until 4.13.5, the fix rele... | ||
| CVE-2026-82823 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-82814. Reason: This candidate is a reser... | ||
| CVE-2026-82562 | ### Summary When `qs.parse` is called with `comma: true` and `throwOnLimitExceeded: true`, a comma-separated value under a... | ||
| CVE-2026-81574 | In CodeMeter Runtime before versions 8.41a and 9.10, the logger does not sanitize input strings in certain cases, allowing an... | ||
| CVE-2026-80853 | In the Linux kernel, the following vulnerability has been resolved: KVM: SEV: Allocate full pages for {DE,EN}CRYPT ops on SN... | ||
| CVE-2026-80724 | In the Linux kernel, the following vulnerability has been resolved: ptp: vmclock: prevent read-only mappings from becoming w... | ||
| CVE-2026-78468 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-78270. Reason: This candidate is a reser... | ||
| CVE-2026-78467 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-78272. Reason: This candidate is a reser... | ||
| CVE-2026-78466 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-78278. Reason: This candidate is a reser... | ||
| CVE-2026-78417 | Insufficient verification of data authenticity in the IronVNC client in Devolutions Remote Desktop Manager 2026.2.17.0 and ea... | ||
| CVE-2026-78195 | Rejected reason: Rejecting as a duplicate of CVE-2026-78047 | ||
| CVE-2026-78147 | A vulnerability was found in ggml-org llama.cpp bec4772f6. The impacted element is the function deserialize_tensor of the fil... | ||