CVE-2026-45184
Kdenlive before 26.04.1 allows dangerous proxy parameters when an attacker-controlled project file is used.
CVSS
6.5
Medium
EPSS
0.1%
p5
KEV
—
Exploit Today
1
0-100
Published: May 9, 2026 · Last modified: Jul 20, 2026 · CWE-829
0.1%EPSS · 30 days0.1%
2026-07-022026-07-29
Kdenlive before 26.04.1 allows dangerous proxy parameters when an attacker-controlled project file is used.
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-661417.4 HIG1.1%
——0Exim before 4.99.5 allows .forward privilege escalation because force_command for a pipe transport is mishandled.13hCVE-2026-659088.6 HIG2.7%
——1In JetBrains PyCharm before 2026.1.4, 2026.2 arbitrary code execution via malicious Python executable was possible on untrusted project open7dCVE-2026-648117.8 HIG2.7%
——1In JetBrains IntelliJ IDEA before 2026.2 arbitrary code execution was possible before granting project trust via development container configuration2dCVE-2026-648098.4 HIG3.8%
——1In JetBrains PhpStorm before 2026.2 arbitrary code execution was possible before granting project trust via the configured interpreter2dCVE-2026-648088.4 HIG3.8%
——1In JetBrains PhpStorm before 2026.2 arbitrary code execution was possible before granting project trust via project tooling2dCVE-2026-648077.8 HIG2.7%
——1In JetBrains WebStorm before 2026.2 arbitrary code execution was possible via a project-supplied linter configuration2d