Search
140,606 CVEs · High severity
CVEs (140,606, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 426–450 of 140,606 (capped at 500)
| CVE ID | Severity | Patch | CVSS | Published ↓ | Description |
|---|---|---|---|---|---|
| CVE-2026-84838 | HIGH | 7.8 | 2026-09-02 | A flaw was found in rpmuncompress. This command injection vulnerability allows a local attacker to execute arbitrary commands. This occurs when rpmuncompress processes a sp… | |
| CVE-2026-84837 | HIGH | 7.8 | 2026-09-02 | A flaw was found in rpm. An attacker can exploit a command injection vulnerability by influencing the path or filename of a tarball processed by `rpmbuild -t*` to include s… | |
| CVE-2026-84675 | HIGH | 7.4 | 2026-09-02 | OS command injection vulnerability in Jenkins TICS Plugin 2025.1.1 and earlier allows attackers able to control build environment variable values to execute arbitrary comma… | |
| CVE-2026-84673 | HIGH | 8.8 | 2026-09-02 | Jenkins Customizable Header Plugin 295.v2544b_ca_19b_97 and earlier allows overwriting the plugin's appearance configuration through Stapler data binding, allowing attacker… | |
| CVE-2026-84672 | HIGH | 8.8 | 2026-09-02 | Jenkins Microsoft Entra ID (previously Azure AD) Plugin 710.v0b_ff8e9cc2d2 and earlier grants Entra group permissions using both the group's unique object ID and its displa… | |
| CVE-2026-84671 | HIGH | 8.8 | 2026-09-02 | Jenkins File Parameter Plugin 425.v3fa_801681b_5e and earlier allows writing files to arbitrary locations on the Jenkins controller file system through Stapler data binding… | |
| CVE-2026-84670 | HIGH | 8.8 | 2026-09-02 | Jenkins Performance Plugin 1015.v09ca_52b_3370e and earlier does not restrict the classes that can be instantiated when deserializing cached performance reports stored in t… | |
| CVE-2026-84669 | HIGH | 8.8 | 2026-09-02 | A path traversal vulnerability in Jenkins Allure Plugin 2.35.2 and earlier allows attackers with Item/Read permission on jobs that publish Allure report results to read arb… | |
| CVE-2026-84668 | HIGH | 8.8 | 2026-09-02 | Jenkins SAML Plugin 4.618.v441a_27fa_46d2 and earlier allows overwriting the SAML identity provider metadata file through Stapler data binding, allowing attackers to replac… | |
| CVE-2026-84667 | HIGH | 7.1 | 2026-09-02 | Jenkins ThinBackup Plugin 2.1.4 and earlier allows overwriting the plugin's backup configuration through Stapler data binding, allowing attackers to redirect backup writes … | |
| CVE-2026-84665 | HIGH | 8.0 | 2026-09-02 | Jenkins SonarQube Scanner Plugin 2.18.3 and earlier does not limit URL schemes for the dashboard links it creates based on SonarQube scanner results, allowing the `javascri… | |
| CVE-2026-84652 | HIGH | 7.3 | 2026-09-02 | In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, Jenkins does not rotate the session when a user is authenticated via the "remember me" cookie, allowing attackers abl… | |
| CVE-2026-84650 | HIGH | 8.8 | 2026-09-02 | In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, transient fields cannot be excluded from deserialization, allowing attackers able to submit configuration updates to … | |
| CVE-2026-84649 | HIGH | 8.8 | 2026-09-02 | In Stapler 1839.ved17667b_a_eb_5 through 2107.v8dfcb_e8ed317 (both inclusive), except 2088.2093.vd7c3e58008a_6, included in Jenkins 2.447 through 2.579 (both inclusive), LT… | |
| CVE-2026-84648 | HIGH | 8.8 | 2026-09-02 | In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, the system log viewer does not escape log record metadata (source, level, and timestamp) resulting in a stored cross-… | |
| CVE-2026-84647 | HIGH | 8.8 | 2026-09-02 | In Stapler 2107.v8dfcb_e8ed317 and earlier, except 2088.2093.vd7c3e58008a_6, included in Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, Stapler does not restrict the t… | |
| CVE-2026-84645 | HIGH | 8.8 | 2026-09-02 | In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, objects of types marked as storing their configuration in independent top-level configuration files in Jenkins (such … | |
| CVE-2026-78689 | HIGH | 8.1 | 2026-09-02 | Description NGINX JavaScript (njs) has a vulnerability in the XML module's namespace prefix list parser, reachable through the xml.exclusiveC14n() method. An unauthentica… | |
| CVE-2026-78410 | HIGH | 7.8 | 2026-09-02 | A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who… | |
| CVE-2026-78409 | HIGH | 7.0 | 2026-09-02 | The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag d… | |
| CVE-2026-78408 | HIGH | 7.9 | 2026-09-02 | The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across ex… | |
| CVE-2026-78222 | HIGH | 7.5 | 2026-09-02 | A vulnerability exists in NGINX JavaScript where a malformed HTTP response received by ngx.fetch() can crash an NGINX worker when trusted JavaScript reads Response.statusTe… | |
| CVE-2026-77180 | HIGH | 8.3 | 2026-09-02 | When NGINX Ingress Controller is configured with Ingress annotations, an injection vulnerability exists in the configuration generator of NGINX Ingress Controller. Multiple… | |
| CVE-2026-66842 | HIGH | 8.8 | 2026-09-02 | BIG-IP has a vulnerability where an authenticated user of any role may be able to create administrative user accounts through an undisclosed request to Traffic Management U… | |
| CVE-2026-66362 | HIGH | 8.1 | 2026-09-02 | Description: When NGINX Plus is configured as the data plane for NGINX Gateway Fabric, an injection vulnerability exists in the NGINX configuration generator component of N… |