Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
26383
Total
1955
Critical
7969
High
8219
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-49046 | HIGH | 8.5 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Arjun Thakur Duplicate Page and Post allows Blind SQL Injection. This … | May 27, 2026 |
| CVE-2026-49045 | MEDIUM | 4.3 | Missing Authorization vulnerability in WP Media Adminimize allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Adminimize: from n/a through 1.11.11. | May 27, 2026 |
| CVE-2026-49044 | MEDIUM | 6.5 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Justin Kruit Advanced Custom Fields: Font Awesome Field allows Stored XSS. This issue … | May 27, 2026 |
| CVE-2026-48973 | MEDIUM | 4.3 | Missing Authorization vulnerability in Benbodhi SVG Support allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects SVG Support: from n/a through 2.5.14. | May 27, 2026 |
| CVE-2026-48927 | MEDIUM | 5.5 | Jenkins buildgraph-view Plugin 1.8 and earlier does not escape the build URL, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to … | May 27, 2026 |
| CVE-2026-48926 | MEDIUM | 4.3 | Jenkins Job Import Plugin 143.v044a_2e819b_27 and earlier does not perform a permission check in an HTTP endpoint, allowing attackers with Overall/Read permission to enumerate credentials … | May 27, 2026 |
| CVE-2026-48925 | MEDIUM | 4.3 | A cross-site request forgery (CSRF) vulnerability in Jenkins GitHub Integration Plugin 0.7.3 and earlier allows attackers to attackers to trigger a build for a pull … | May 27, 2026 |
| CVE-2026-48924 | MEDIUM | 4.3 | Jenkins Bitbucket OAuth Plugin 0.17 and earlier does not restrict the redirect URL after login, allowing attackers to perform phishing attacks. | May 27, 2026 |
| CVE-2026-48923 | MEDIUM | 4.3 | Jenkins AppSpider Plugin 1.0.17 and earlier does not perform a permission check in a method implementing form validation, allowing attackers with Overall/Read permission to connect … | May 27, 2026 |
| CVE-2026-48922 | HIGH | 7.5 | Jenkins Credentials Binding Plugin 720.v3f6decef43ea_ and earlier does not properly sanitize file names for file and zip file credentials, allowing attackers able to provide credentials … | May 27, 2026 |
| CVE-2026-48921 | HIGH | 7.5 | Jenkins Pipeline: Groovy Libraries Plugin 797.v90ea_a_9b_e45a_0 and earlier does not prohibit symbolic links in shared libraries, allowing attackers able to control the content of a … | May 27, 2026 |
| CVE-2026-48920 | HIGH | 8.8 | Jenkins Email Extension Plugin 1933.v45cec755423f and earlier allows inlining images as `base64` in email content by setting the `data-inline` attribute, without restrictions on the image … | May 27, 2026 |
| CVE-2026-48919 | MEDIUM | 6.6 | Jenkins Active Directory Plugin 2.41 and earlier deserializes data from LDAP referrals without validation. | May 27, 2026 |
| CVE-2026-48918 | MEDIUM | 6.6 | Jenkins Active Directory Plugin 2.41 and earlier follows LDAP referrals by default. | May 27, 2026 |
| CVE-2026-48917 | MEDIUM | 6.6 | Jenkins LDAP Plugin 807.v7d7de30930cf and earlier deserializes data from LDAP referrals without validation. | May 27, 2026 |
| CVE-2026-48916 | MEDIUM | 6.6 | Jenkins LDAP Plugin 807.v7d7de30930cf and earlier follows LDAP referrals. | May 27, 2026 |
| CVE-2026-48545 | MEDIUM | 6.8 | Gradio before version 6.15.0 contains a cookie injection vulnerability that allows remote attackers to perform cross-Space session fixation by exploiting a shared module-level HTTP client … | May 27, 2026 |
| CVE-2026-48544 | HIGH | 7.5 | Taipy 4.1.1, fixed in commit 129fd40, contains a path traversal vulnerability in the ElementLibrary.get_resource() method in taipy/gui/extension/library.py that allows unauthenticated attackers to escape the intended … | May 27, 2026 |
| CVE-2026-47119 | MEDIUM | 6.1 | Agent Zero before version 1.15 contains a stored cross-site scripting vulnerability that allows attackers to execute arbitrary JavaScript in the application origin by serving SVG … | May 27, 2026 |
| CVE-2026-47118 | MEDIUM | 6.5 | Agent Zero before version 1.15 contains a path traversal vulnerability that allows unauthenticated attackers to read arbitrary files by supplying crafted paths to the image … | May 27, 2026 |
| CVE-2026-45571 | MEDIUM | 5.4 | go-git is an extensible git implementation library written in pure Go. Prior to 5.19.1 and 6.0.0-alpha.4, a path validation issue in go-git could allow crafted … | May 27, 2026 |
| CVE-2026-45570 | UNKNOWN | — | go-git is an extensible git implementation library written in pure Go. Prior to 5.19.1 and 6.0.0-alpha.4, go-git's SSH transport constructs the remote exec command by … | May 27, 2026 |
| CVE-2026-45022 | UNKNOWN | — | go-git is an extensible git implementation library written in pure Go. Prior to 5.19.0 and 6.0.0-alpha.3, go-git may parse malformed Git objects in a way … | May 27, 2026 |
| CVE-2026-44988 | HIGH | 8.8 | LibVNCClient is a library for easy implementation of a VNC client. In 0.9.15 and earlier, LibVNCClient's Tight encoding decoder uses fixed-size 2048-pixel scratch buffers for … | May 27, 2026 |
| CVE-2026-44972 | MEDIUM | 5.0 | GuardDog is a CLI tool to identify malicious PyPI packages. From 2.6.0 to 2.9.0, GuardDog includes attacker-controlled filenames, file locations, messages, and code snippets in … | May 27, 2026 |