Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
41987
Total
3420
Critical
12405
High
12324
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-84657 | MEDIUM | 4.2 | In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, the build CLI command does not check the Item/Cancel permission when using the -s flag to … | Sep 02, 2026 |
| CVE-2026-84656 | MEDIUM | 4.3 | A missing permission check in Jenkins 2.579 and earlier, LTS 2.568.2 and earlier allows attackers with Item/Read permission on at least one job to read … | Sep 02, 2026 |
| CVE-2026-84655 | MEDIUM | 4.3 | Jenkins 2.579 and earlier, LTS 2.568.2 and earlier does not escape map keys when serializing objects as JSON and Python through its REST API, allowing … | Sep 02, 2026 |
| CVE-2026-84654 | MEDIUM | 5.4 | In Stapler 2107.v8dfcb_e8ed317 and earlier, except 2088.2093.vd7c3e58008a_6, included in Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, form data binding allows setting public static fields … | Sep 02, 2026 |
| CVE-2026-84653 | UNKNOWN | — | Jenkins 2.421 through 2.579 (both inclusive), LTS 2.426.1 through 2.568.2 (both inclusive) does not correctly perform permission checks in the Appearance configuration page, allowing attackers … | Sep 02, 2026 |
| CVE-2026-84652 | UNKNOWN | — | In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, Jenkins does not rotate the session when a user is authenticated via the "remember me" cookie, … | Sep 02, 2026 |
| CVE-2026-84651 | MEDIUM | 6.3 | In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, the REST API and CLI endpoints for updating agent configuration do not prevent a submitted configuration … | Sep 02, 2026 |
| CVE-2026-84650 | HIGH | 8.8 | In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, transient fields cannot be excluded from deserialization, allowing attackers able to submit configuration updates to specify … | Sep 02, 2026 |
| CVE-2026-84649 | HIGH | 8.8 | In Stapler 1839.ved17667b_a_eb_5 through 2107.v8dfcb_e8ed317 (both inclusive), except 2088.2093.vd7c3e58008a_6, included in Jenkins 2.447 through 2.579 (both inclusive), LTS 2.452.1 through 2.568.2 (both inclusive), an HTTP … | Sep 02, 2026 |
| CVE-2026-84648 | HIGH | 8.8 | In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, the system log viewer does not escape log record metadata (source, level, and timestamp) resulting in … | Sep 02, 2026 |
| CVE-2026-84647 | HIGH | 8.8 | In Stapler 2107.v8dfcb_e8ed317 and earlier, except 2088.2093.vd7c3e58008a_6, included in Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, Stapler does not restrict the types of objects … | Sep 02, 2026 |
| CVE-2026-84646 | MEDIUM | 4.3 | In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, user objects can appear as nested field values in other deserialized XML objects, allowing attackers with … | Sep 02, 2026 |
| CVE-2026-84645 | HIGH | 8.8 | In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, objects of types marked as storing their configuration in independent top-level configuration files in Jenkins (such … | Sep 02, 2026 |
| CVE-2026-78689 | HIGH | 8.1 | Description NGINX JavaScript (njs) has a vulnerability in the XML module's namespace prefix list parser, reachable through the xml.exclusiveC14n() method. An unauthenticated remote attacker can … | Sep 02, 2026 |
| CVE-2026-78410 | HIGH | 7.8 | A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. … | Sep 02, 2026 |
| CVE-2026-78409 | HIGH | 7.0 | The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does … | Sep 02, 2026 |
| CVE-2026-78408 | HIGH | 7.9 | The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across … | Sep 02, 2026 |
| CVE-2026-78222 | HIGH | 7.5 | A vulnerability exists in NGINX JavaScript where a malformed HTTP response received by ngx.fetch() can crash an NGINX worker when trusted JavaScript reads Response.statusText. Exploitation … | Sep 02, 2026 |
| CVE-2026-77180 | HIGH | 8.3 | When NGINX Ingress Controller is configured with Ingress annotations, an injection vulnerability exists in the configuration generator of NGINX Ingress Controller. Multiple user-controllable fields are … | Sep 02, 2026 |
| CVE-2026-66842 | HIGH | 8.8 | BIG-IP has a vulnerability where an authenticated user of any role may be able to create administrative user accounts through an undisclosed request to Traffic … | Sep 02, 2026 |
| CVE-2026-66362 | HIGH | 8.1 | Description: When NGINX Plus is configured as the data plane for NGINX Gateway Fabric, an injection vulnerability exists in the NGINX configuration generator component of … | Sep 02, 2026 |
| CVE-2026-63020 | LOW | 3.1 | A vulnerability exists in an undisclosed BIG-IP Configuration utility page that may allow an attacker to spoof error messages Impact: An attacker may trick authenticated … | Sep 02, 2026 |
| CVE-2026-53611 | CRITICAL | 9.8 | Looking Glass is a modern, stateless network-diagnostic platform — a single self-contained Go binary that fronts a fleet of routers over SSH and exposes ping … | Sep 02, 2026 |
| CVE-2026-53600 | UNKNOWN | — | async-tar is a tar archive reading/writing library for async Rust. Prior to version 0.6.1, async-tar mis-applies a buffered PAX size extension to an intermediary extension … | Sep 02, 2026 |
| CVE-2026-19475 | MEDIUM | 6.5 | An authenticated user with permission to query a SQL data source can bypass the fix for CVE-2026-33375 by injecting the timeGroup macro through a WHERE … | Sep 02, 2026 |