CVE Feed

    Dashboard / CVE

    7.1
    High

    CVE-2026-57303

    Last Modified: 24 Jun 2026

    Jenkins Assembla Plugin 1.4 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks, allowing attackers able to control the responses of the configured Assembla server to extract secrets from the Jenkins controller or perform server-side request forgery.

    Published: 24 Jun 2026
    4.3
    Medium

    CVE-2026-57302

    Last Modified: 24 Jun 2026

    Jenkins FitNesse Plugin 1.36 and earlier stores passwords unencrypted in job config.xml files on the Jenkins controller, where they can be viewed by users with Extended Read permission or access to the Jenkins controller file system.

    Published: 24 Jun 2026
    8.8
    High

    CVE-2026-57301

    Last Modified: 24 Jun 2026

    Jenkins OWASP ZAP Plugin 1.0.7 and earlier performs build operations on the Jenkins controller rather than the assigned agent, allowing attackers with Item/Configure permission to execute arbitrary code on the Jenkins controller.

    Published: 24 Jun 2026
    4.3
    Medium

    CVE-2026-57300

    Last Modified: 24 Jun 2026

    A missing permission check in Jenkins MCP Server Plugin 0.177.v629fdb_2557fe and earlier allows attackers with Item/Read permission to read the Pipeline replay scripts of jobs they can access.

    Published: 24 Jun 2026
    4.3
    Medium

    CVE-2026-57299

    Last Modified: 3 Aug 2026

    Missing permission checks in Jenkins Contrast Continuous Application Security Plugin 3.11 and earlier allow attackers with Overall/Read permission to enumerate the names of configured Contrast metadata.

    Published: 24 Jun 2026
    5.4
    Medium

    CVE-2026-57298

    Last Modified: 24 Jun 2026

    A cross-site request forgery (CSRF) vulnerability in Jenkins Contrast Continuous Application Security Plugin 3.11 and earlier allows attackers to have Jenkins connect to an attacker-specified URL using an attacker-specified username, API key, and service key.

    Published: 24 Jun 2026
    4.3
    Medium

    CVE-2026-57297

    Last Modified: 3 Aug 2026

    A missing permission check in Jenkins Contrast Continuous Application Security Plugin 3.11 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using an attacker-specified username, API key, and service key.

    Published: 24 Jun 2026
    8.8
    High

    CVE-2026-57296

    Last Modified: 24 Jun 2026

    Jenkins External Workspace Manager Plugin 1.3.2 and earlier does not reject path traversal sequences in the custom workspace path provided to the exwsAllocate Pipeline step, allowing attackers with Item/Configure permission to read arbitrary files on the Jenkins controller file system, which can lead to remote code execution.

    Published: 24 Jun 2026
    5.4
    Medium

    CVE-2026-57295

    Last Modified: 24 Jun 2026

    A cross-site request forgery (CSRF) vulnerability in Jenkins EC2 Fleet Plugin 4.2.3.539.v8fedff2a_81c3 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing AWS credentials stored in Jenkins.

    Published: 24 Jun 2026
    5.4
    Medium

    CVE-2026-57294

    Last Modified: 24 Jun 2026

    A missing permission check in Jenkins EC2 Fleet Plugin 4.2.3.539.v8fedff2a_81c3 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing AWS credentials stored in Jenkins.

    Published: 24 Jun 2026
    4.3
    Medium

    CVE-2026-57293

    Last Modified: 24 Jun 2026

    An incorrect permission check in Jenkins Gitee Plugin 1288.v18b_deb_c9069b_ and earlier allows attackers with global Item/Configure permission (while lacking Item/Configure permission on any particular job) to enumerate credentials IDs of credentials stored in Jenkins.

    Published: 24 Jun 2026
    5.4
    Medium

    CVE-2026-57292

    Last Modified: 24 Jun 2026

    A cross-site request forgery (CSRF) vulnerability in Jenkins Gitee Plugin 1288.v18b_deb_c9069b_ and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method.

    Published: 24 Jun 2026
    5.4
    Medium

    CVE-2026-57291

    Last Modified: 24 Jun 2026

    Missing permission checks in Jenkins Gitee Plugin 1288.v18b_deb_c9069b_ and earlier allow attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method.

    Published: 24 Jun 2026
    4.3
    Medium

    CVE-2026-57290

    Last Modified: 24 Jun 2026

    A cross-site request forgery (CSRF) vulnerability in Jenkins Priority Sorter Plugin 936.v2c01c6b_84449 and earlier allows attackers to overwrite the global job priority configuration.

    Published: 24 Jun 2026
    4.8
    Medium

    CVE-2026-57289

    Last Modified: 24 Jun 2026

    Jenkins Bitbucket Push and Pull Request Plugin 3.3.8 and earlier unconditionally disables SSL/TLS certificate and hostname validation for connections sending Bearer token authenticated requests to the configured Bitbucket Server endpoint, allowing attackers able to intercept network traffic to capture the token.

    Published: 24 Jun 2026
    8.4
    High

    CVE-2026-42450

    Last Modified: 24 Jun 2026

    OpenColorIO is a color management framework for visual effects and animation. Prior to version 2.5.2, `FileFormatSpi3D.cpp:163` uses `sscanf` with `%s` into 64-byte stack buffers when parsing LUT data lines. Input comes from `lineBuffer[4096]`, so a crafted .spi3d file can overflow by ~4000 bytes on non-Windows. Version 2.5.2 fixes the issue.

    Published: 24 Jun 2026
    3.7
    Low

    CVE-2026-57288

    Last Modified: 24 Jun 2026

    Jenkins Active Directory Plugin 2.41.1 and earlier does not escape the user name before building the LDAP search filter in the Windows native (ADSI) authentication path, allowing unauthenticated attackers to inject LDAP wildcard characters to enumerate directory entries and to authenticate as a matching user whose password they know without knowing their exact user name.

    Published: 24 Jun 2026
    4.3
    Medium

    CVE-2026-57287

    Last Modified: 24 Jun 2026

    Jenkins Job Configuration History Plugin 1356.ve360da_6c523a_ and earlier does not redact the encrypted values of secrets when displaying historical job and agent configurations, allowing attackers with Extended Read permission to view encrypted secret values that would otherwise be redacted.

    Published: 24 Jun 2026
    4.3
    Medium

    CVE-2026-57286

    Last Modified: 24 Jun 2026

    A missing permission check in Jenkins Git Parameter Plugin 462.vdcf3df2ed2ca_ and earlier allows attackers with Item/Read permission to obtain information about the SCM repository used by a job, such as branch names, tag names, and revision metadata.

    Published: 24 Jun 2026
    4.3
    Medium

    CVE-2026-57284

    Last Modified: 24 Jun 2026

    Jenkins Pipeline: Groovy Plugin 4331.v9d06ed4658ff and earlier does not restrict the types that can be instantiated through the Pipeline Snippet Generator, allowing attackers to instantiate types related to job or system configuration other than Pipeline steps.

    Published: 24 Jun 2026
    4.3
    Medium

    CVE-2026-57285

    Last Modified: 25 Jun 2026

    A missing permission check in Jenkins GitHub Branch Source Plugin 1967.1969.v205fd594c821 and earlier allows attackers with Overall/Read permission to obtain the URLs of GitHub Enterprise servers configured in the global plugin configuration.

    Published: 24 Jun 2026
    4.3
    Medium

    CVE-2026-57283

    Last Modified: 24 Jun 2026

    A cross-site request forgery (CSRF) vulnerability in Jenkins Pipeline: Groovy Plugin 4331.v9d06ed4658ff and earlier allows attackers to instantiate types related to job or system configuration other than Pipeline steps through the Pipeline Snippet Generator.

    Published: 24 Jun 2026
    5
    Medium

    CVE-2026-57282

    Last Modified: 24 Jun 2026

    Jenkins Git client Plugin 6.6.0 and earlier does not correctly escape the workspace directory name when it is embedded into a generated SSH wrapper script, allowing attackers able to control the name of a build's working directory to execute arbitrary operating system commands on the agent.

    Published: 24 Jun 2026
    7.5
    High

    CVE-2026-57281

    Last Modified: 27 Aug 2026

    Jenkins Script Security Plugin 1402.v94c9ce464861 and earlier does not reject Groovy AST transformation annotations carrying an extensions member, allowing attackers able to run sandboxed Groovy scripts to execute code outside the sandbox if a suitable script is present on the classpath of the component that evaluates the script.

    Published: 24 Jun 2026
    8.8
    High

    CVE-2026-57280

    Last Modified: 13 Jul 2026

    Jenkins Script Security Plugin 1402.v94c9ce464861 and earlier does not intercept the implicit type casts applied to the elements of typed for-each loops in sandboxed Groovy scripts, allowing attackers able to provide such scripts to invoke arbitrary constructors and bypass the sandbox protection.

    Published: 24 Jun 2026
    5.3
    Medium

    CVE-2026-13163

    Last Modified: 24 Jun 2026

    Open redirect vulnerability (CWE-601) in the _safe_redirect function of the click-tracking endpoint (/c/<token>/) in Mailerup <1.0.0 on all platforms allows remote unauthenticated attackers to redirect victims to arbitrary external sites and conduct phishing attacks via a crafted u query parameter, because the URL scheme is validated (blocking javascript: and data:) but the destination host is not restricted to an allowlist, and a signing.BadSignature exception is silently caught so a valid signed token is not required.

    Published: 24 Jun 2026
    8.8
    High

    CVE-2026-12242

    Last Modified: 24 Jun 2026

    The AdRotate Banner Manager plugin for WordPress is vulnerable to PHP Code Injection in all versions up to, and including, 5.17.7 via the 'banner' attribute of the adrotate shortcode. This is due to insufficient input validation and sanitization of the banner shortcode attribute before concatenation into a PHP code string wrapped in W3 Total Cache mfunc or Borlabs Cache fragment markers. This makes it possible for authenticated attackers, with Contributor-level access and above, to execute arbitrary PHP code on the server. This vulnerability requires W3 Total Cache or Borlabs Cache support to be enabled in AdRotate settings.

    Published: 24 Jun 2026
    5.3
    Medium

    CVE-2026-56761

    Last Modified: 24 Jun 2026

    hono before 4.12.14 contains an html injection vulnerability in jsx server-side rendering that allows attackers to inject unintended html by using malformed attribute names. Attackers can craft specially crafted attribute keys containing characters like quotes or angle brackets to break html tag boundaries and inject arbitrary attributes or elements.

    Published: 24 Jun 2026
    4.8
    Medium

    CVE-2026-56370

    Last Modified: 25 Jun 2026

    ImageMagick before 7.1.2-19 contains an out-of-bounds access vulnerability in ConnectedComponentsImage() when processing connected-components artifacts with invalid indices. Attackers can trigger access violations by specifying malformed connected-components definitions via CLI, causing denial of service or potential code execution.

    Published: 24 Jun 2026
    6.3
    Medium

    CVE-2026-56368

    Last Modified: 24 Jun 2026

    ImageMagick before 7.1.2-15 contains a memory leak vulnerability in multiple coders that write raw pixel data where allocated objects are not properly freed. Attackers can trigger this leak by processing specially crafted images, causing memory exhaustion and denial of service.

    Published: 24 Jun 2026
    5.1
    Medium

    CVE-2026-56358

    Last Modified: 24 Jun 2026

    n8n before 1.123.25 (1.x) and before 2.11.2 (2.x), with the fix also included in 2.12.0, contains a stored cross-site scripting vulnerability in the Form Trigger node's CSS sanitization that allows authenticated users to inject malicious scripts. Attackers with workflow creation permissions can inject XSS payloads that execute persistently for all form visitors, enabling form hijacking and phishing attacks.

    Published: 24 Jun 2026
    5.3
    Medium

    CVE-2026-56351

    Last Modified: 24 Jun 2026

    n8n before version 2.4.0 contains a sql injection vulnerability in MySQL, PostgreSQL, and Microsoft SQL nodes that allows authenticated users to inject arbitrary SQL through unescaped identifier values in node configuration parameters. Attackers with workflow creation permissions can supply specially crafted table or column names to execute unauthorized database commands and compromise data integrity.

    Published: 24 Jun 2026
    6.9
    Medium

    CVE-2026-56338

    Last Modified: 24 Jun 2026

    Capgo before 12.128.2 contains a denial of service vulnerability in the /auth/v1/otp endpoint that prevents email verification for two-factor authentication due to captcha validation failures. Authenticated users cannot complete 2FA enrollment as the backend consistently returns HTTP 500 errors with captcha verification process failed messages, blocking access to security controls.

    Published: 24 Jun 2026
    6.9
    Medium

    CVE-2026-56337

    Last Modified: 24 Jun 2026

    Capgo before 12.128.2 contains an information disclosure vulnerability in the public.exist_app_v2 RPC function that allows unauthenticated attackers to enumerate app_ids by calling POST /rest/v1/rpc/exist_app_v2 with arbitrary appid parameters. Remote attackers can exploit this SECURITY DEFINER function to determine whether specific app_ids exist in the public.apps table, enabling cross-tenant app enumeration and privacy violations.

    Published: 24 Jun 2026
    5.3
    Medium

    CVE-2026-56310

    Last Modified: 25 Jun 2026

    Cap-go before 12.128.2 contains an authorization bypass vulnerability in the GET /organization/members endpoint that allows org-limited API keys to bypass limited_to_orgs restrictions. Attackers with org-limited API keys can read membership data including uid, email, image_url, role, and is_tmp from organizations outside their assigned scope.

    Published: 24 Jun 2026
    6.9
    Medium

    CVE-2026-56302

    Last Modified: 24 Jun 2026

    Capgo before 12.128.2 contains an unsecured images bucket lacking any row level security controls, allowing unauthenticated attackers to read, insert, and delete stored app icons. Remote attackers can exploit this misconfiguration to delete all icons and leak sensitive app IDs and user IDs.

    Published: 24 Jun 2026
    5.6
    Medium

    CVE-2026-56272

    Last Modified: 24 Jun 2026

    Flowise before 3.0.13 uses bcrypt with default salt rounds of 5, providing only 32 iterations instead of the OWASP-recommended minimum of 10 rounds. Attackers can crack password hashes approximately 30 times faster with modern GPU hardware, potentially compromising all user accounts in a database breach scenario.

    Published: 24 Jun 2026
    8.7
    High

    CVE-2026-56270

    Last Modified: 24 Jun 2026

    Flowise before 3.1.0 (versions 3.0.13 and earlier) contains a missing authentication vulnerability in the /api/v1/loginmethod endpoint that allows unauthenticated users to retrieve an organization's complete SSO configuration, including OAuth client secrets in cleartext, by providing an organizationId parameter. Remote attackers can send a GET request to harvest sensitive API credentials for Google, Microsoft/Azure, GitHub, and Auth0 integrations. This affects FlowiseAI Cloud and self-hosted instances where the endpoint is exposed.

    Published: 24 Jun 2026
    4.3
    Medium

    CVE-2026-56269

    Last Modified: 24 Jun 2026

    Flowise before 3.1.0 (npm package flowise, versions 3.0.13 and earlier) uses a weak hardcoded default value 'Secre$t' for the TOKEN_HASH_SECRET environment variable in packages/server/src/enterprise/utils/tempTokenUtils.ts when the variable is not configured. This secret derives the AES-256-CBC key used to encrypt user IDs and workspace IDs in the 'meta' field of JWT tokens. An attacker who knows the default secret can decrypt this metadata to extract internal user and workspace identifiers, and re-encrypt manipulated values such as altered user or workspace IDs. Because the JWT signature is validated separately, decrypting or tampering with this metadata does not by itself grant access, but the disclosure of internal identifiers and possible metadata manipulation could aid privilege escalation or unauthorized data access.

    Published: 24 Jun 2026
    6.9
    Medium

    CVE-2026-56262

    Last Modified: 14 Jul 2026

    Crawl4AI before 0.8.7 contains an authentication bypass vulnerability in the monitor router endpoints that allows unauthenticated attackers to access destructive operations. Remote attackers can invoke the /monitor/actions/cleanup endpoint and manipulate monitoring state without authentication, causing service disruption.

    Published: 24 Jun 2026
    7.1
    High

    CVE-2026-56257

    Last Modified: 25 Jun 2026

    Capgo before 12.128.2 allows direct patching of public.apps.owner_org through PostgREST, bypassing the transfer_app() workflow and creating split-brain ownership. Attackers can directly update apps.owner_org while leaving app_versions.owner_org unchanged, enabling old-org keys to retain access to version data while new-org keys control the app record.

    Published: 24 Jun 2026
    7.1
    High

    CVE-2026-56256

    Last Modified: 24 Jun 2026

    Capgo before 12.128.2 enforces mandatory two-factor authentication only at the UI level. Sensitive Organization (ORG) management API endpoints (e.g., editing organization details, inviting users) do not validate 2FA completion on the backend. An authenticated Admin user who has not enabled 2FA can replay or modify a previously captured ORG API request to perform privileged organization actions, bypassing the globally enforced 2FA requirement.

    Published: 24 Jun 2026
    8.8
    High

    CVE-2026-56245

    Last Modified: 24 Jun 2026

    Supabase Capgo before 12.128.2 contains an authorization bypass vulnerability in the SECURITY DEFINER record_build_time RPC function that allows unauthenticated attackers to insert arbitrary build-time records. Attackers can exploit this by calling POST /rest/v1/rpc/record_build_time with a public API key to poison billing and quota data for any organization, enabling resource exhaustion and cross-tenant billing manipulation.

    Published: 24 Jun 2026
    7.1
    High

    CVE-2026-56244

    Last Modified: 24 Jun 2026

    Capgo before 12.128.2 allows non-admin API keys to read webhook signing secrets via Supabase REST due to insufficient row-level security policies on the webhooks table. Attackers can retrieve the webhook secret and forge valid X-Capgo-Signature headers to send authenticated webhook events to configured receivers, breaking webhook authenticity and integrity.

    Published: 24 Jun 2026
    9.3
    Critical

    CVE-2026-56237

    Last Modified: 24 Jun 2026

    Capgo before 12.128.2 contains a broken authentication vulnerability in its API key generation mechanism. API keys are exposed in frontend requests, and the backend fails to validate that keys are securely generated and bound to the authenticated user. An attacker can tamper with the API key parameter in the generation request and supply arbitrary values, generating custom API keys without proper authorization, which can lead to unauthorized access to protected endpoints.

    Published: 24 Jun 2026
    8.7
    High

    CVE-2026-56232

    Last Modified: 24 Jun 2026

    Capgo before 12.128.2 fails to enforce limited_to_orgs and limited_to_apps constraints on subkeys provided via x-limited-key-id header in middlewareKey function. Attackers can bypass subkey scope restrictions by referencing their own subkeys, causing all downstream route handlers to use the unrestricted parent key instead of the scoped subkey.

    Published: 24 Jun 2026
    7.2
    High

    CVE-2026-56231

    Last Modified: 25 Jun 2026

    Capgo before 12.128.2 contains a broken object level authorization (BOLA) vulnerability in the POST /build/start/:jobId and POST /build/cancel/:jobId endpoints. The handlers authorize the request based only on the attacker-controlled app_id supplied in the request body and never verify that the jobId in the URL belongs to that app_id (or the same tenant/org) before issuing privileged builder commands with the server-held builder API key. An authenticated user with the app.build_native permission for any app they control can start or cancel arbitrary builder jobs belonging to other tenants by supplying a victim jobId, resulting in cross-tenant build sabotage (denial of service), unauthorized compute actions, and potential billing impact.

    Published: 24 Jun 2026
    9.3
    Critical

    CVE-2026-56223

    Last Modified: 24 Jun 2026

    Capgo before 12.128.2 contains a cross-domain SSO account takeover vulnerability in the provision-user endpoint that allows attackers to merge arbitrary victim accounts based on email match without validating SSO provider domain authorization. An attacker with enterprise org admin access and a malicious IdP can forge SAML assertions containing victim email addresses to trigger account merge and gain full access to victim accounts, organizations, and data.

    Published: 24 Jun 2026
    7.6
    High

    CVE-2025-71361

    Last Modified: 24 Jun 2026

    picklescan before 0.0.29 fails to detect malicious idlelib.calltip.Calltip.fetch_tip calls in pickle files, allowing remote code execution. Attackers can embed undetected payloads in pickle files that execute arbitrary code when loaded via pickle.load().

    Published: 24 Jun 2026
    7.6
    High

    CVE-2025-71354

    Last Modified: 24 Jun 2026

    picklescan before 0.0.29 fails to detect malicious pickle files that exploit idlelib.debugobj.ObjectTreeItem.SetText function in reduce methods. Attackers can craft pickle files with embedded code that bypasses picklescan detection and executes arbitrary commands when pickle.load() is called.

    Published: 24 Jun 2026