Search
2,372 CVEs
CVEs (2,372, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 301–325 of 2,372 (capped at 500)
| CVE ID | Severity | Patch | CVSS ↓ | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-84671 | HIGH | 8.8 | 2026-09-02 | Jenkins File Parameter Plugin 425.v3fa_801681b_5e and earlier allows writing files to arbitrary locations on the Jenkins controller file system through Stapler data binding… | |
| CVE-2026-84672 | HIGH | 8.8 | 2026-09-02 | Jenkins Microsoft Entra ID (previously Azure AD) Plugin 710.v0b_ff8e9cc2d2 and earlier grants Entra group permissions using both the group's unique object ID and its displa… | |
| CVE-2026-84673 | HIGH | 8.8 | 2026-09-02 | Jenkins Customizable Header Plugin 295.v2544b_ca_19b_97 and earlier allows overwriting the plugin's appearance configuration through Stapler data binding, allowing attacker… | |
| CVE-2026-84645 | HIGH | 8.8 | 2026-09-02 | In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, objects of types marked as storing their configuration in independent top-level configuration files in Jenkins (such … | |
| CVE-2026-84647 | HIGH | 8.8 | 2026-09-02 | In Stapler 2107.v8dfcb_e8ed317 and earlier, except 2088.2093.vd7c3e58008a_6, included in Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, Stapler does not restrict the t… | |
| CVE-2026-84648 | HIGH | 8.8 | 2026-09-02 | In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, the system log viewer does not escape log record metadata (source, level, and timestamp) resulting in a stored cross-… | |
| CVE-2026-84649 | HIGH | 8.8 | 2026-09-02 | In Stapler 1839.ved17667b_a_eb_5 through 2107.v8dfcb_e8ed317 (both inclusive), except 2088.2093.vd7c3e58008a_6, included in Jenkins 2.447 through 2.579 (both inclusive), LT… | |
| CVE-2026-84650 | HIGH | 8.8 | 2026-09-02 | In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, transient fields cannot be excluded from deserialization, allowing attackers able to submit configuration updates to … | |
| CVE-2026-66842 | HIGH | 8.8 | 2026-09-02 | BIG-IP has a vulnerability where an authenticated user of any role may be able to create administrative user accounts through an undisclosed request to Traffic Management U… | |
| CVE-2026-84796 | HIGH | Patched | 8.8 | 2026-09-02 | Craft CMS versions before 5.10.11 contain a site scope bypass vulnerability in GraphQL entry mutation resolvers that fail to validate siteId through ArgumentManager::prepar… |
| CVE-2026-84801 | HIGH | Patched | 8.8 | 2026-09-02 | Craft CMS versions before 5.10.11 fail to validate admin status in the actionGetPasswordResetUrl endpoint, allowing non-admin users with administrateUsers permission to min… |
| CVE-2026-84764 | HIGH | 8.8 | 2026-09-02 | Unauthenticated Cross Site Request Forgery (CSRF) in Simply Schedule Appointments <= 1.6.12.23 versions. | |
| CVE-2026-84770 | HIGH | 8.8 | 2026-09-02 | Unauthenticated Cross Site Request Forgery (CSRF) in Mang Board WP <= 2.3.8 versions. | |
| CVE-2026-81772 | HIGH | 8.8 | 2026-09-02 | Unauthenticated PHP Object Injection in Ninja Forms - Layout & Styles <= 3.0.31 versions. | |
| CVE-2026-81283 | HIGH | 8.8 | 2026-09-02 | Subscriber PHP Object Injection in WP User Frontend <= 4.3.10 versions. | |
| CVE-2026-81769 | HIGH | 8.8 | 2026-09-02 | Incorrect Privilege Assignment vulnerability in LiquidThemes Booking Hub allows Privilege Escalation. This issue affects Booking Hub: from n/a through 1.3.1. | |
| CVE-2026-14828 | HIGH | Patched | 8.8 | 2026-09-02 | Zohocorp ManageEngine Password Manager Pro versions before 13235, PAM360 versions before 8561, and Access Manager Plus versions before 4405 are vulnerable to an authenticat… |
| CVE-2026-81737 | HIGH | Patched | 8.8 | 2026-09-02 | The FAQ Builder AYS WordPress plugin before 1.8.5 does not sanitize or escape content submitted by unauthenticated visitors before storing it and outputting it in an admin … |
| CVE-2026-81807 | HIGH | Patched | 8.8 | 2026-09-02 | The Simple Ajax Chat WordPress plugin before 20260827 does not escape chat message content before rendering it, allowing unauthenticated users to inject arbitrary HTML att… |
| CVE-2026-14357 | HIGH | 8.8 | 2026-09-02 | The DevKit Pro plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 2.3.0. This is due to a missing capability check and missing no… | |
| CVE-2026-19116 | HIGH | Patched | 8.8 | 2026-09-02 | The User Frontend WordPress plugin before 4.3.11 does not prevent user-supplied field values from being deserialized when a submitted post is reopened in its frontend edit… |
| CVE-2026-84715 | HIGH | Patched | 8.8 | 2026-09-02 | FeatherPanel versions before 1.3.7.10 fail to validate permissions in the SubuserController updateSubuser handler, allowing authenticated subusers to modify their own permi… |
| CVE-2026-84694 | HIGH | Patched | 8.8 | 2026-09-02 | Coolify before 4.2.0 fails to properly escape environment variable key names in Docker commands executed over SSH on managed servers. Authenticated attackers can inject she… |
| CVE-2026-84347 | HIGH | Patched | 8.8 | 2026-09-02 | Use after free in WebRTC in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium s… |
| CVE-2026-84350 | HIGH | Patched | 8.8 | 2026-09-02 | Use after free in TabStrip in Google Chrome prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via… |