Search
9,841 CVEs
CVEs (9,841, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 151–175 of 9,841 (capped at 500)
| CVE ID | Severity | Patch | CVSS | Published ↑ | Description |
|---|---|---|---|---|---|
| CVE-2026-57301 | HIGH | Patched | 8.8 | 2026-06-24 | Jenkins OWASP ZAP Plugin 1.0.7 and earlier performs build operations on the Jenkins controller rather than the assigned agent, allowing attackers with Item/Configure permis… |
| CVE-2026-57302 | MEDIUM | Patched | 4.3 | 2026-06-24 | Jenkins FitNesse Plugin 1.36 and earlier stores passwords unencrypted in job config.xml files on the Jenkins controller, where they can be viewed by users with Extended Rea… |
| CVE-2026-57303 | HIGH | Patched | 7.1 | 2026-06-24 | Jenkins Assembla Plugin 1.4 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks, allowing attackers able to control the responses of … |
| CVE-2026-57304 | MEDIUM | Patched | 5.4 | 2026-06-24 | A missing permission check in Jenkins Assembla Plugin 1.4 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using an attacke… |
| CVE-2026-57305 | MEDIUM | Patched | 5.4 | 2026-06-24 | A cross-site request forgery (CSRF) vulnerability in Jenkins Assembla Plugin 1.4 and earlier allows attackers to connect to an attacker-specified URL using an attacker-spec… |
| CVE-2026-57306 | MEDIUM | Patched | 4.2 | 2026-06-24 | A cross-site request forgery (CSRF) vulnerability in Jenkins Zowe zDevOps Plugin 1.1.3.50.ve350c9b_450b_1 and earlier allows attackers to connect to an attacker-specified U… |
| CVE-2026-57307 | MEDIUM | Patched | 4.2 | 2026-06-24 | A missing permission check in Jenkins Zowe zDevOps Plugin 1.1.3.50.ve350c9b_450b_1 and earlier allows attackers with Overall/Read permission to connect to an attacker-speci… |
| CVE-2026-11877 | HIGH | Patched | 7.5 | 2026-06-24 | An unauthorized user can modify configuration through API calls that affects the OpenText Access Manager. This issue affects Access Manager before 5.1.3. |
| CVE-2026-11878 | MEDIUM | Patched | 6.1 | 2026-06-24 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in OpenText Access Manager allows Cross-Site Scripting (XSS). This issue… |
| CVE-2026-12986 | NONE | — | 2026-06-24 | A critical vulnerability in Admin GUI in Payara Server Full 4.x, 5.x, 6.x, 7.x, 7.2026.x, 6.2025.x, 6.2024.x on All platforms that allows the attacker to leak the admin gfr… | |
| CVE-2026-50698 | NONE | — | 2026-06-24 | A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of user-controlled input before generating HT… | |
| CVE-2026-50699 | NONE | — | 2026-06-24 | A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev. An authenticated attacker with write access to Auto Repeat can persist HTML… | |
| CVE-2026-49269 | HIGH | 8.6 | 2026-06-24 | Apple M1 GPUs retain register file data between compute shader dispatches from different processes. A sandboxed Metal attacker app can run a GPU reader shader that reads st… | |
| CVE-2026-50700 | NONE | — | 2026-06-24 | A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of user-controlled input in the frappe.get_av… | |
| CVE-2026-50701 | NONE | — | 2026-06-24 | A Reflected Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of user-controlled input in the dashboard-… | |
| CVE-2026-50703 | NONE | — | 2026-06-24 | A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of user-controlled input in the Desk desktop … | |
| CVE-2026-50704 | NONE | — | 2026-06-24 | A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of user-controlled input in the File View bre… | |
| CVE-2026-50705 | NONE | — | 2026-06-24 | A Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of untrusted input in the Form Dashboard headline renderer. | |
| CVE-2026-50708 | NONE | — | 2026-06-24 | A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of user-controlled input in the MultiSelectDi… | |
| CVE-2026-50709 | NONE | — | 2026-06-24 | A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of user-controlled input in the Notifications… | |
| CVE-2026-50710 | NONE | — | 2026-06-24 | A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to unsafe evaluation of user-controlled data in the Number Card component. | |
| CVE-2026-50711 | NONE | — | 2026-06-24 | A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of user-controlled input in the Number Card c… | |
| CVE-2026-50712 | NONE | — | 2026-06-24 | A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of user-controlled input in the frappe.ui.Tre… | |
| CVE-2026-55488 | NONE | — | 2026-06-24 | motionEye (mEye) is an online interface for a piece of software called "motion," which is a video surveillance program with motion detection. Versions prior to 0.44.0 conta… | |
| CVE-2026-56111 | CRITICAL | Patched | 9.1 | 2026-06-24 | Marlin Firmware through 2.1.2.7, fixed in commit 1f255d1, when built with MESH_BED_LEVELING enabled, contains an out-of-bounds write vulnerability in the M421 G-code handle… |