Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
49645
Total
4014
Critical
14740
High
14481
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-70444 | MEDIUM | 4.3 | A missing permission check in Jenkins Violation Comments to GitLab Plugin 2.62.0 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials … | Aug 05, 2026 |
| CVE-2026-70443 | MEDIUM | 4.3 | Jenkins Horreum Plugin 0.16.162.v33b_4a_a_b_5f828 and earlier does not set the appropriate context for credentials lookup, allowing attackers with Item/Configure permission to have Jenkins send credentials … | Aug 05, 2026 |
| CVE-2026-70442 | MEDIUM | 4.3 | Jenkins Google Chat Notification Plugin 166.ve6b_de280f2e8 and earlier does not set the appropriate context for credentials lookup, allowing attackers with Item/Configure permission to access and … | Aug 05, 2026 |
| CVE-2026-70441 | MEDIUM | 5.4 | Jenkins Summary Display Plugin 1.15 and earlier does not escape the job name in a JavaScript context in build report pages, resulting in a stored … | Aug 05, 2026 |
| CVE-2026-70440 | MEDIUM | 5.4 | Jenkins Qualys Container Scanning Connector Plugin 1.8.0.5 and earlier does not escape user-controlled field values in a JavaScript context, resulting in a stored cross-site scripting … | Aug 05, 2026 |
| CVE-2026-70439 | MEDIUM | 6.5 | Jenkins XML Job to Job DSL Plugin 0.1.13 and earlier does not perform permission checks, allowing attackers lacking appropriate permissions to invoke the conversion functionality. | Aug 05, 2026 |
| CVE-2026-70438 | MEDIUM | 4.3 | A missing permission check in Jenkins Parameterized Remote Trigger Plugin 3.2.2 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored … | Aug 05, 2026 |
| CVE-2026-70437 | LOW | 3.7 | Jenkins Webhook Secret Credentials Provider Plugin 16.v0cfa_f0215cf5 and earlier does not use a constant-time comparison function when checking whether the provided and expected webhook bearer … | Aug 05, 2026 |
| CVE-2026-70436 | MEDIUM | 4.3 | Jenkins External Workspace Manager Plugin 1.4.1 and earlier does not perform a permission check (1.4.0 and earlier) or performs an improper permission check (1.4.1) when … | Aug 05, 2026 |
| CVE-2026-70435 | MEDIUM | 4.2 | A missing permission check in Jenkins SCM-Manager Plugin 1.11.1 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials … | Aug 05, 2026 |
| CVE-2026-70434 | MEDIUM | 4.2 | A cross-site request forgery (CSRF) vulnerability in Jenkins SCM-Manager Plugin 1.11.1 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials IDs … | Aug 05, 2026 |
| CVE-2026-70433 | MEDIUM | 4.3 | Missing permission checks in Jenkins HCL AppScan Plugin 1.8.3 and earlier allow attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins. | Aug 05, 2026 |
| CVE-2026-70432 | HIGH | 8.8 | A cross-site request forgery (CSRF) vulnerability in Jenkins Multijob Plugin 669.v9d96a_d9c71b_0 and earlier allows attackers to execute arbitrary code in the context of the Jenkins … | Aug 05, 2026 |
| CVE-2026-70431 | HIGH | 8.8 | Jenkins Multijob Plugin 669.v9d96a_d9c71b_0 and earlier provides Groovy scripting features that do not integrate with Script Security Plugin, allowing attackers with Item/Create or Item/Configure permission … | Aug 05, 2026 |
| CVE-2026-70430 | LOW | 2.7 | Jenkins 2.575 and earlier, LTS 2.568.1 and earlier does not restrict the types of objects that can be instantiated as part of the project naming … | Aug 05, 2026 |
| CVE-2026-70429 | HIGH | 8.1 | Jenkins 2.575 and earlier, LTS 2.568.1 and earlier handles case-insensitivity in user names and group names inconsistently, allowing attackers able to create new users or … | Aug 05, 2026 |
| CVE-2026-70428 | MEDIUM | 4.3 | Jenkins 2.575 and earlier, LTS 2.568.1 and earlier improperly identifies file paths attempting path traversal in file parameter names, allowing attackers with Item/Configure and Item/Build … | Aug 05, 2026 |
| CVE-2026-70427 | MEDIUM | 4.3 | Jenkins 2.575 and earlier, LTS 2.568.1 and earlier does not safely handle symbolic links with effectively empty names during the extraction of `.tar` and `.tar.gz` … | Aug 05, 2026 |
| CVE-2026-70426 | CRITICAL | 9.0 | In Remoting 3384.v60d89463d9e0 and earlier, except 3355.3357.v931d3c992987, included in Jenkins 2.575 and earlier, LTS 2.568.1 and earlier, the JEP-200 class filter is not applied to … | Aug 05, 2026 |
| CVE-2026-44605 | MEDIUM | 5.5 | A flaw was found in the RPM Package Manager (RPM). A local user could be affected by a heap buffer overflow vulnerability when processing a … | Aug 05, 2026 |
| CVE-2026-17625 | HIGH | 7.2 | IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, and 1.0.0 through 1.10.3 … | Aug 05, 2026 |
| CVE-2026-10716 | UNKNOWN | — | Directus contains an authenticated SQL injection vulnerability in the collection creation flow when the instance uses PostgreSQL with PostGIS enabled. An administrator can create a … | Aug 05, 2026 |
| CVE-2026-10128 | MEDIUM | 6.5 | IBM Langflow OSS 1.0.0 through 1.10.3 allows authenticated users can exploit a built-in Langflow component to read arbitrary server environment variables, exposing sensitive secrets despite … | Aug 05, 2026 |
| CVE-2026-9077 | HIGH | 8.5 | IBM Langflow OSS 1.0.0 through 1.10.3 Langflow allows remote authenticated attackers to bypass localhost-only restrictions and write arbitrary MCP server configurations to IDE configuration files … | Aug 05, 2026 |
| CVE-2026-8446 | HIGH | 7.5 | IBM Langflow OSS 1.0.0 through 1.10.3 contain an authentication bypass vulnerability in the Model Context Protocol (MCP) composer endpoint when mcp_composer_enabled=true (default) and projects are … | Aug 05, 2026 |