Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

26383
Total
1955
Critical
7969
High
8219
Medium
CVE ID Severity Score Description Published
CVE-2026-49046 HIGH 8.5 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Arjun Thakur Duplicate Page and Post allows Blind SQL Injection. This … May 27, 2026
CVE-2026-49045 MEDIUM 4.3 Missing Authorization vulnerability in WP Media Adminimize allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Adminimize: from n/a through 1.11.11. May 27, 2026
CVE-2026-49044 MEDIUM 6.5 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Justin Kruit Advanced Custom Fields: Font Awesome Field allows Stored XSS. This issue … May 27, 2026
CVE-2026-48973 MEDIUM 4.3 Missing Authorization vulnerability in Benbodhi SVG Support allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects SVG Support: from n/a through 2.5.14. May 27, 2026
CVE-2026-48927 MEDIUM 5.5 Jenkins buildgraph-view Plugin 1.8 and earlier does not escape the build URL, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to … May 27, 2026
CVE-2026-48926 MEDIUM 4.3 Jenkins Job Import Plugin 143.v044a_2e819b_27 and earlier does not perform a permission check in an HTTP endpoint, allowing attackers with Overall/Read permission to enumerate credentials … May 27, 2026
CVE-2026-48925 MEDIUM 4.3 A cross-site request forgery (CSRF) vulnerability in Jenkins GitHub Integration Plugin 0.7.3 and earlier allows attackers to attackers to trigger a build for a pull … May 27, 2026
CVE-2026-48924 MEDIUM 4.3 Jenkins Bitbucket OAuth Plugin 0.17 and earlier does not restrict the redirect URL after login, allowing attackers to perform phishing attacks. May 27, 2026
CVE-2026-48923 MEDIUM 4.3 Jenkins AppSpider Plugin 1.0.17 and earlier does not perform a permission check in a method implementing form validation, allowing attackers with Overall/Read permission to connect … May 27, 2026
CVE-2026-48922 HIGH 7.5 Jenkins Credentials Binding Plugin 720.v3f6decef43ea_ and earlier does not properly sanitize file names for file and zip file credentials, allowing attackers able to provide credentials … May 27, 2026
CVE-2026-48921 HIGH 7.5 Jenkins Pipeline: Groovy Libraries Plugin 797.v90ea_a_9b_e45a_0 and earlier does not prohibit symbolic links in shared libraries, allowing attackers able to control the content of a … May 27, 2026
CVE-2026-48920 HIGH 8.8 Jenkins Email Extension Plugin 1933.v45cec755423f and earlier allows inlining images as `base64` in email content by setting the `data-inline` attribute, without restrictions on the image … May 27, 2026
CVE-2026-48919 MEDIUM 6.6 Jenkins Active Directory Plugin 2.41 and earlier deserializes data from LDAP referrals without validation. May 27, 2026
CVE-2026-48918 MEDIUM 6.6 Jenkins Active Directory Plugin 2.41 and earlier follows LDAP referrals by default. May 27, 2026
CVE-2026-48917 MEDIUM 6.6 Jenkins LDAP Plugin 807.v7d7de30930cf and earlier deserializes data from LDAP referrals without validation. May 27, 2026
CVE-2026-48916 MEDIUM 6.6 Jenkins LDAP Plugin 807.v7d7de30930cf and earlier follows LDAP referrals. May 27, 2026
CVE-2026-48545 MEDIUM 6.8 Gradio before version 6.15.0 contains a cookie injection vulnerability that allows remote attackers to perform cross-Space session fixation by exploiting a shared module-level HTTP client … May 27, 2026
CVE-2026-48544 HIGH 7.5 Taipy 4.1.1, fixed in commit 129fd40, contains a path traversal vulnerability in the ElementLibrary.get_resource() method in taipy/gui/extension/library.py that allows unauthenticated attackers to escape the intended … May 27, 2026
CVE-2026-47119 MEDIUM 6.1 Agent Zero before version 1.15 contains a stored cross-site scripting vulnerability that allows attackers to execute arbitrary JavaScript in the application origin by serving SVG … May 27, 2026
CVE-2026-47118 MEDIUM 6.5 Agent Zero before version 1.15 contains a path traversal vulnerability that allows unauthenticated attackers to read arbitrary files by supplying crafted paths to the image … May 27, 2026
CVE-2026-45571 MEDIUM 5.4 go-git is an extensible git implementation library written in pure Go. Prior to 5.19.1 and 6.0.0-alpha.4, a path validation issue in go-git could allow crafted … May 27, 2026
CVE-2026-45570 UNKNOWN go-git is an extensible git implementation library written in pure Go. Prior to 5.19.1 and 6.0.0-alpha.4, go-git's SSH transport constructs the remote exec command by … May 27, 2026
CVE-2026-45022 UNKNOWN go-git is an extensible git implementation library written in pure Go. Prior to 5.19.0 and 6.0.0-alpha.3, go-git may parse malformed Git objects in a way … May 27, 2026
CVE-2026-44988 HIGH 8.8 LibVNCClient is a library for easy implementation of a VNC client. In 0.9.15 and earlier, LibVNCClient's Tight encoding decoder uses fixed-size 2048-pixel scratch buffers for … May 27, 2026
CVE-2026-44972 MEDIUM 5.0 GuardDog is a CLI tool to identify malicious PyPI packages. From 2.6.0 to 2.9.0, GuardDog includes attacker-controlled filenames, file locations, messages, and code snippets in … May 27, 2026