Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

26383
Total
1955
Critical
7969
High
8219
Medium
CVE ID Severity Score Description Published
CVE-2026-57286 MEDIUM 4.3 A missing permission check in Jenkins Git Parameter Plugin 462.vdcf3df2ed2ca_ and earlier allows attackers with Item/Read permission to obtain information about the SCM repository used … Jun 24, 2026
CVE-2026-57285 MEDIUM 4.3 A missing permission check in Jenkins GitHub Branch Source Plugin 1967.1969.v205fd594c821 and earlier allows attackers with Overall/Read permission to obtain the URLs of GitHub Enterprise … Jun 24, 2026
CVE-2026-57284 MEDIUM 4.3 Jenkins Pipeline: Groovy Plugin 4331.v9d06ed4658ff and earlier does not restrict the types that can be instantiated through the Pipeline Snippet Generator, allowing attackers to instantiate … Jun 24, 2026
CVE-2026-57283 MEDIUM 4.3 A cross-site request forgery (CSRF) vulnerability in Jenkins Pipeline: Groovy Plugin 4331.v9d06ed4658ff and earlier allows attackers to instantiate types related to job or system configuration … Jun 24, 2026
CVE-2026-57282 MEDIUM 5.0 Jenkins Git client Plugin 6.6.0 and earlier does not correctly escape the workspace directory name when it is embedded into a generated SSH wrapper script, … Jun 24, 2026
CVE-2026-57281 HIGH 7.5 Jenkins Script Security Plugin 1402.v94c9ce464861 and earlier does not reject Groovy AST transformation annotations carrying an extensions member, allowing attackers able to run sandboxed Groovy … Jun 24, 2026
CVE-2026-57280 HIGH 8.8 Jenkins Script Security Plugin 1402.v94c9ce464861 and earlier does not intercept the implicit type casts applied to the elements of typed for-each loops in sandboxed Groovy … Jun 24, 2026
CVE-2026-42450 UNKNOWN OpenColorIO is a color management framework for visual effects and animation. Prior to version 2.5.2, `FileFormatSpi3D.cpp:163` uses `sscanf` with `%s` into 64-byte stack buffers when … Jun 24, 2026
CVE-2026-35025 HIGH 8.1 ProFTPD through 1.3.9b and 1.3.10rc2 contains an access control bypass vulnerability that allows authenticated FTP users to circumvent Directory ACL restrictions by prefixing paths with … Jun 24, 2026
CVE-2026-29034 UNKNOWN Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. Jun 24, 2026
CVE-2026-12537 UNKNOWN Improper Neutralization used in an OS Command in the container launcher in Google Gemini CLI (versions prior to 0.39.1) and run-gemini-cli GitHub Action (versions prior … Jun 24, 2026
CVE-2026-56761 MEDIUM 4.3 hono before 4.12.14 contains an html injection vulnerability in jsx server-side rendering that allows attackers to inject unintended html by using malformed attribute names. Attackers … Jun 24, 2026
CVE-2026-56370 LOW 3.3 ImageMagick before 7.1.2-19 contains an out-of-bounds access vulnerability in ConnectedComponentsImage() when processing connected-components artifacts with invalid indices. Attackers can trigger access violations by specifying malformed … Jun 24, 2026
CVE-2026-56368 LOW 3.7 ImageMagick before 7.1.2-15 contains a memory leak vulnerability in multiple coders that write raw pixel data where allocated objects are not properly freed. Attackers can … Jun 24, 2026
CVE-2026-56358 MEDIUM 5.4 n8n before 1.123.25 (1.x) and before 2.11.2 (2.x), with the fix also included in 2.12.0, contains a stored cross-site scripting vulnerability in the Form Trigger … Jun 24, 2026
CVE-2026-56351 HIGH 8.2 n8n before version 2.4.0 contains a sql injection vulnerability in MySQL, PostgreSQL, and Microsoft SQL nodes that allows authenticated users to inject arbitrary SQL through … Jun 24, 2026
CVE-2026-56338 MEDIUM 5.3 Capgo before 12.128.2 contains a denial of service vulnerability in the /auth/v1/otp endpoint that prevents email verification for two-factor authentication due to captcha validation failures. … Jun 24, 2026
CVE-2026-56337 MEDIUM 5.3 Capgo before 12.128.2 contains an information disclosure vulnerability in the public.exist_app_v2 RPC function that allows unauthenticated attackers to enumerate app_ids by calling POST /rest/v1/rpc/exist_app_v2 with … Jun 24, 2026
CVE-2026-56310 MEDIUM 4.3 Cap-go before 12.128.2 contains an authorization bypass vulnerability in the GET /organization/members endpoint that allows org-limited API keys to bypass limited_to_orgs restrictions. Attackers with org-limited … Jun 24, 2026
CVE-2026-56302 MEDIUM 6.5 Capgo before 12.128.2 contains an unsecured images bucket lacking any row level security controls, allowing unauthenticated attackers to read, insert, and delete stored app icons. … Jun 24, 2026
CVE-2026-56272 MEDIUM 4.1 Flowise before 3.0.13 uses bcrypt with default salt rounds of 5, providing only 32 iterations instead of the OWASP-recommended minimum of 10 rounds. Attackers can … Jun 24, 2026
CVE-2026-56270 HIGH 7.5 Flowise before 3.1.0 (versions 3.0.13 and earlier) contains a missing authentication vulnerability in the /api/v1/loginmethod endpoint that allows unauthenticated users to retrieve an organization's complete … Jun 24, 2026
CVE-2026-56269 MEDIUM 4.6 Flowise before 3.1.0 (npm package flowise, versions 3.0.13 and earlier) uses a weak hardcoded default value 'Secre$t' for the TOKEN_HASH_SECRET environment variable in packages/server/src/enterprise/utils/tempTokenUtils.ts when … Jun 24, 2026
CVE-2026-56262 MEDIUM 6.5 Crawl4AI before 0.8.7 contains an authentication bypass vulnerability in the monitor router endpoints that allows unauthenticated attackers to access destructive operations. Remote attackers can invoke … Jun 24, 2026
CVE-2026-56257 HIGH 7.1 Capgo before 12.128.2 allows direct patching of public.apps.owner_org through PostgREST, bypassing the transfer_app() workflow and creating split-brain ownership. Attackers can directly update apps.owner_org while leaving … Jun 24, 2026