Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
56890
Total
4508
Critical
16896
High
16708
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-92363 | MEDIUM | 4.3 | A flaw has been found in ag-ui-protocol ag-ui 1.0. Affected is an unknown function of the file src/stream/sse_parser.cpp of the component JSON Parser. Executing a … | Sep 16, 2026 |
| CVE-2026-92362 | HIGH | 7.3 | A vulnerability was detected in ag-ui-protocol ag-ui 1.0. This impacts an unknown function of the file crates/ag-ui-client/src/sse.rs of the component SSE Frame Parser. Performing a … | Sep 16, 2026 |
| CVE-2026-92141 | MEDIUM | 4.3 | Jenkins Keycloak Authentication Plugin 2.4.1 and earlier does not restrict the redirect URL after login, allowing attackers to perform phishing attacks. | Sep 16, 2026 |
| CVE-2026-92140 | MEDIUM | 6.8 | Jenkins Gitee Plugin 1301.v8957053c7902 and earlier does not escape the sender name from Gitee push webhook payloads in build causes, resulting in a stored cross-site … | Sep 16, 2026 |
| CVE-2026-92139 | MEDIUM | 6.5 | Jenkins Bitbucket Push and Pull Request Plugin 4.0.1 and earlier trusts values provided in the webhook payload, including certain URLs, and uses configured Bitbucket credentials … | Sep 16, 2026 |
| CVE-2026-92138 | MEDIUM | 4.2 | The OAuth authorization endpoint in Jenkins Bitbucket Server Integration Plugin 6.0.1 and earlier reads the `oauth_callback` URL from the submitted form rather than from the … | Sep 16, 2026 |
| CVE-2026-92137 | HIGH | 8.8 | Jenkins Robot Framework Plugin 6.2.2 and earlier does not check that the archive directory configured for Robot Framework report files is contained within the build … | Sep 16, 2026 |
| CVE-2026-92136 | HIGH | 8.0 | Jenkins OWASP Dependency-Check Plugin 5.6.4 and earlier does not escape CWE values from Dependency-Check reports on the Jenkins UI, resulting in a stored cross-site scripting … | Sep 16, 2026 |
| CVE-2026-92135 | HIGH | 8.0 | Jenkins Coverage Plugin 3.3358.v9487dde48783 and earlier does not validate the coverage results ID when a job configuration is submitted through the REST API, allowing attackers … | Sep 16, 2026 |
| CVE-2026-92134 | HIGH | 8.0 | Jenkins Warnings Plugin 13.10258.va_17d49a_78c3b_ and earlier does not validate the analysis results ID when a job configuration is submitted through the REST API, allowing attackers … | Sep 16, 2026 |
| CVE-2026-92133 | MEDIUM | 5.4 | Jenkins GitLab Plugin 1.2149.vcfc32c82b_f7f and earlier caches the GitLab API client built for alternative GitLab API token credentials under a cache key derived from the … | Sep 16, 2026 |
| CVE-2026-92132 | MEDIUM | 5.4 | Jenkins Gradle Plugin 2.19.1252.v15196b_5a_6e10 and earlier requests build scan data from the build scan link detected in the build log, even when a Develocity server … | Sep 16, 2026 |
| CVE-2026-92131 | MEDIUM | 4.2 | Jenkins Pipeline: Groovy Libraries Plugin 805.va_fc79344957d and earlier does not restrict the library path provided to the library Pipeline step to a relative path inside … | Sep 16, 2026 |
| CVE-2026-92130 | LOW | 3.1 | Jenkins Pipeline: Multibranch Plugin 841.vec5b_9e1806ec and earlier does not set the appropriate context for credentials lookup in the resolveScm Pipeline step, allowing attackers with Item/Configure … | Sep 16, 2026 |
| CVE-2026-92129 | HIGH | 7.5 | Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier does not check calls from sandboxed scripts to methods added dynamically to a class at runtime, allowing attackers … | Sep 16, 2026 |
| CVE-2026-92128 | HIGH | 7.5 | Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier downloads a JAR file specified by URL twice, confirming the approval of the first download and loading the … | Sep 16, 2026 |
| CVE-2026-92127 | HIGH | 8.0 | Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier automatically approves the classpath entries in an item configuration when a user with Overall/Administer permission copies the item, … | Sep 16, 2026 |
| CVE-2026-92126 | UNKNOWN | — | Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier does not reject @Builder annotations whose builderStrategy member names an arbitrary class, allowing attackers with permission to define … | Sep 16, 2026 |
| CVE-2026-92125 | HIGH | 8.8 | Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier does not reject the @GroovyASTTransformationClass annotation, allowing attackers with permission to define and run sandboxed scripts, including Pipelines, … | Sep 16, 2026 |
| CVE-2026-92124 | HIGH | 8.8 | Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier checks the operations Groovy will perform with the elements it reads from a collection that a sandboxed script … | Sep 16, 2026 |
| CVE-2026-92123 | HIGH | 8.8 | Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier does not intercept operations performed on a null receiver (method calls, property and attribute accesses, and array accesses), … | Sep 16, 2026 |
| CVE-2026-92122 | HIGH | 8.8 | Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier does not check the method called through the proxy created when a sandboxed script coerces a value to … | Sep 16, 2026 |
| CVE-2026-91843 | CRITICAL | 9.8 | A stack overflow during the unauthenticated login process may allow an attacker to run arbitrary code remotely with root privileges. | Sep 16, 2026 |
| CVE-2026-89030 | MEDIUM | 4.3 | Adenion Blog2Social plugin for WordPress before 9.1.0 exposes the email addresses of all registered WordPress users to low-privileged accounts. The b2s_search_user AJAX handler in includes/Ajax/Get.php … | Sep 16, 2026 |
| CVE-2026-89029 | MEDIUM | 4.3 | Adenion Blog2Social plugin for WordPress before 9.1.0 allows low-privileged users to enumerate WordPress user accounts. The b2s_get_select_mandant_user AJAX handler in includes/Ajax/Get.php resolves arbitrary user IDs … | Sep 16, 2026 |