Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
26383
Total
1955
Critical
7969
High
8219
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-57286 | MEDIUM | 4.3 | A missing permission check in Jenkins Git Parameter Plugin 462.vdcf3df2ed2ca_ and earlier allows attackers with Item/Read permission to obtain information about the SCM repository used … | Jun 24, 2026 |
| CVE-2026-57285 | MEDIUM | 4.3 | A missing permission check in Jenkins GitHub Branch Source Plugin 1967.1969.v205fd594c821 and earlier allows attackers with Overall/Read permission to obtain the URLs of GitHub Enterprise … | Jun 24, 2026 |
| CVE-2026-57284 | MEDIUM | 4.3 | Jenkins Pipeline: Groovy Plugin 4331.v9d06ed4658ff and earlier does not restrict the types that can be instantiated through the Pipeline Snippet Generator, allowing attackers to instantiate … | Jun 24, 2026 |
| CVE-2026-57283 | MEDIUM | 4.3 | A cross-site request forgery (CSRF) vulnerability in Jenkins Pipeline: Groovy Plugin 4331.v9d06ed4658ff and earlier allows attackers to instantiate types related to job or system configuration … | Jun 24, 2026 |
| CVE-2026-57282 | MEDIUM | 5.0 | Jenkins Git client Plugin 6.6.0 and earlier does not correctly escape the workspace directory name when it is embedded into a generated SSH wrapper script, … | Jun 24, 2026 |
| CVE-2026-57281 | HIGH | 7.5 | Jenkins Script Security Plugin 1402.v94c9ce464861 and earlier does not reject Groovy AST transformation annotations carrying an extensions member, allowing attackers able to run sandboxed Groovy … | Jun 24, 2026 |
| CVE-2026-57280 | HIGH | 8.8 | Jenkins Script Security Plugin 1402.v94c9ce464861 and earlier does not intercept the implicit type casts applied to the elements of typed for-each loops in sandboxed Groovy … | Jun 24, 2026 |
| CVE-2026-42450 | UNKNOWN | — | OpenColorIO is a color management framework for visual effects and animation. Prior to version 2.5.2, `FileFormatSpi3D.cpp:163` uses `sscanf` with `%s` into 64-byte stack buffers when … | Jun 24, 2026 |
| CVE-2026-35025 | HIGH | 8.1 | ProFTPD through 1.3.9b and 1.3.10rc2 contains an access control bypass vulnerability that allows authenticated FTP users to circumvent Directory ACL restrictions by prefixing paths with … | Jun 24, 2026 |
| CVE-2026-29034 | UNKNOWN | — | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | Jun 24, 2026 |
| CVE-2026-12537 | UNKNOWN | — | Improper Neutralization used in an OS Command in the container launcher in Google Gemini CLI (versions prior to 0.39.1) and run-gemini-cli GitHub Action (versions prior … | Jun 24, 2026 |
| CVE-2026-56761 | MEDIUM | 4.3 | hono before 4.12.14 contains an html injection vulnerability in jsx server-side rendering that allows attackers to inject unintended html by using malformed attribute names. Attackers … | Jun 24, 2026 |
| CVE-2026-56370 | LOW | 3.3 | ImageMagick before 7.1.2-19 contains an out-of-bounds access vulnerability in ConnectedComponentsImage() when processing connected-components artifacts with invalid indices. Attackers can trigger access violations by specifying malformed … | Jun 24, 2026 |
| CVE-2026-56368 | LOW | 3.7 | ImageMagick before 7.1.2-15 contains a memory leak vulnerability in multiple coders that write raw pixel data where allocated objects are not properly freed. Attackers can … | Jun 24, 2026 |
| CVE-2026-56358 | MEDIUM | 5.4 | n8n before 1.123.25 (1.x) and before 2.11.2 (2.x), with the fix also included in 2.12.0, contains a stored cross-site scripting vulnerability in the Form Trigger … | Jun 24, 2026 |
| CVE-2026-56351 | HIGH | 8.2 | n8n before version 2.4.0 contains a sql injection vulnerability in MySQL, PostgreSQL, and Microsoft SQL nodes that allows authenticated users to inject arbitrary SQL through … | Jun 24, 2026 |
| CVE-2026-56338 | MEDIUM | 5.3 | Capgo before 12.128.2 contains a denial of service vulnerability in the /auth/v1/otp endpoint that prevents email verification for two-factor authentication due to captcha validation failures. … | Jun 24, 2026 |
| CVE-2026-56337 | MEDIUM | 5.3 | Capgo before 12.128.2 contains an information disclosure vulnerability in the public.exist_app_v2 RPC function that allows unauthenticated attackers to enumerate app_ids by calling POST /rest/v1/rpc/exist_app_v2 with … | Jun 24, 2026 |
| CVE-2026-56310 | MEDIUM | 4.3 | Cap-go before 12.128.2 contains an authorization bypass vulnerability in the GET /organization/members endpoint that allows org-limited API keys to bypass limited_to_orgs restrictions. Attackers with org-limited … | Jun 24, 2026 |
| CVE-2026-56302 | MEDIUM | 6.5 | Capgo before 12.128.2 contains an unsecured images bucket lacking any row level security controls, allowing unauthenticated attackers to read, insert, and delete stored app icons. … | Jun 24, 2026 |
| CVE-2026-56272 | MEDIUM | 4.1 | Flowise before 3.0.13 uses bcrypt with default salt rounds of 5, providing only 32 iterations instead of the OWASP-recommended minimum of 10 rounds. Attackers can … | Jun 24, 2026 |
| CVE-2026-56270 | HIGH | 7.5 | Flowise before 3.1.0 (versions 3.0.13 and earlier) contains a missing authentication vulnerability in the /api/v1/loginmethod endpoint that allows unauthenticated users to retrieve an organization's complete … | Jun 24, 2026 |
| CVE-2026-56269 | MEDIUM | 4.6 | Flowise before 3.1.0 (npm package flowise, versions 3.0.13 and earlier) uses a weak hardcoded default value 'Secre$t' for the TOKEN_HASH_SECRET environment variable in packages/server/src/enterprise/utils/tempTokenUtils.ts when … | Jun 24, 2026 |
| CVE-2026-56262 | MEDIUM | 6.5 | Crawl4AI before 0.8.7 contains an authentication bypass vulnerability in the monitor router endpoints that allows unauthenticated attackers to access destructive operations. Remote attackers can invoke … | Jun 24, 2026 |
| CVE-2026-56257 | HIGH | 7.1 | Capgo before 12.128.2 allows direct patching of public.apps.owner_org through PostgREST, bypassing the transfer_app() workflow and creating split-brain ownership. Attackers can directly update apps.owner_org while leaving … | Jun 24, 2026 |