Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
42028
Total
3422
Critical
12413
High
12340
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-84648 | HIGH | 8.8 | In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, the system log viewer does not escape log record metadata (source, level, and timestamp) resulting in … | Sep 02, 2026 |
| CVE-2026-84647 | HIGH | 8.8 | In Stapler 2107.v8dfcb_e8ed317 and earlier, except 2088.2093.vd7c3e58008a_6, included in Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, Stapler does not restrict the types of objects … | Sep 02, 2026 |
| CVE-2026-84646 | MEDIUM | 4.3 | In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, user objects can appear as nested field values in other deserialized XML objects, allowing attackers with … | Sep 02, 2026 |
| CVE-2026-84645 | HIGH | 8.8 | In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, objects of types marked as storing their configuration in independent top-level configuration files in Jenkins (such … | Sep 02, 2026 |
| CVE-2026-78689 | HIGH | 8.1 | Description NGINX JavaScript (njs) has a vulnerability in the XML module's namespace prefix list parser, reachable through the xml.exclusiveC14n() method. An unauthenticated remote attacker can … | Sep 02, 2026 |
| CVE-2026-78410 | HIGH | 7.8 | A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. … | Sep 02, 2026 |
| CVE-2026-78409 | HIGH | 7.0 | The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does … | Sep 02, 2026 |
| CVE-2026-78408 | HIGH | 7.9 | The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across … | Sep 02, 2026 |
| CVE-2026-78222 | HIGH | 7.5 | A vulnerability exists in NGINX JavaScript where a malformed HTTP response received by ngx.fetch() can crash an NGINX worker when trusted JavaScript reads Response.statusText. Exploitation … | Sep 02, 2026 |
| CVE-2026-77180 | HIGH | 8.3 | When NGINX Ingress Controller is configured with Ingress annotations, an injection vulnerability exists in the configuration generator of NGINX Ingress Controller. Multiple user-controllable fields are … | Sep 02, 2026 |
| CVE-2026-66842 | HIGH | 8.8 | BIG-IP has a vulnerability where an authenticated user of any role may be able to create administrative user accounts through an undisclosed request to Traffic … | Sep 02, 2026 |
| CVE-2026-66362 | HIGH | 8.1 | Description: When NGINX Plus is configured as the data plane for NGINX Gateway Fabric, an injection vulnerability exists in the NGINX configuration generator component of … | Sep 02, 2026 |
| CVE-2026-63020 | LOW | 3.1 | A vulnerability exists in an undisclosed BIG-IP Configuration utility page that may allow an attacker to spoof error messages Impact: An attacker may trick authenticated … | Sep 02, 2026 |
| CVE-2026-53611 | CRITICAL | 9.8 | Looking Glass is a modern, stateless network-diagnostic platform — a single self-contained Go binary that fronts a fleet of routers over SSH and exposes ping … | Sep 02, 2026 |
| CVE-2026-53600 | UNKNOWN | — | async-tar is a tar archive reading/writing library for async Rust. Prior to version 0.6.1, async-tar mis-applies a buffered PAX size extension to an intermediary extension … | Sep 02, 2026 |
| CVE-2026-19475 | MEDIUM | 6.5 | An authenticated user with permission to query a SQL data source can bypass the fix for CVE-2026-33375 by injecting the timeGroup macro through a WHERE … | Sep 02, 2026 |
| CVE-2026-18329 | HIGH | 8.2 | Description NGINX JavaScript (njs) and QuickJS (qjs) engines have a vulnerability when a js_access handler performs asynchronous request body processing and an exception is thrown … | Sep 02, 2026 |
| CVE-2026-18058 | HIGH | 7.5 | The mobile Smart Connect dashboard UI was subject to manipulation by 3rd party apps. When paired with a phishing attack, this manipulation could result in … | Sep 02, 2026 |
| CVE-2026-14199 | HIGH | 7.1 | Only self-managed Grafana instances with Auth Proxy authentication and identity caching enabled (sync_ttl greater than zero) are affected. The Auth Proxy cache key concatenated the … | Sep 02, 2026 |
| CVE-2026-12704 | MEDIUM | 6.8 | When SAML IdP-initiated login is enabled in Grafana Enterprise, the SAML library skips validation of the InResponseTo field on all SAML responses, including SP-initiated logins. … | Sep 02, 2026 |
| CVE-2026-8151 | MEDIUM | 5.4 | The Simple Membership MailChimp Integration WordPress plugin before 1.9.8 does not have CSRF checks in its settings page, allowing attackers to trick a logged-in administrator … | Sep 02, 2026 |
| CVE-2026-83547 | MEDIUM | 6.8 | The Xpro Addons WordPress plugin before 1.7.4 does not properly escape some of its widgets' settings before outputting them within HTML attributes, which could allow … | Sep 02, 2026 |
| CVE-2026-83533 | MEDIUM | 5.3 | The WP Express Checkout WordPress plugin before 2.4.9 does not verify server-side that a payment was actually completed before marking an order as paid, allowing … | Sep 02, 2026 |
| CVE-2026-82955 | UNKNOWN | — | In the current development version of Eclipse aeriOS, which has not yet had an official release, the KrakenD instance included in the API Gateway component … | Sep 02, 2026 |
| CVE-2026-82884 | MEDIUM | 6.8 | The All in One SEO WordPress plugin before 5.0.0.1 does not sanitise and escape some content stored in posts before rendering it back in the … | Sep 02, 2026 |