CVE Database

52085+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-57293
4.3 MEDIUM

An incorrect permission check in Jenkins Gitee Plugin 1288.v18b_deb_c9069b_ and earlier allows attackers with global Item/Configure permission (while lacking Item/Configure permission on any particular job) …

Jun 24, 2026
CVE-2026-57292
5.4 MEDIUM

A cross-site request forgery (CSRF) vulnerability in Jenkins Gitee Plugin 1288.v18b_deb_c9069b_ and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials IDs …

Jun 24, 2026
CVE-2026-57291
5.4 MEDIUM

Missing permission checks in Jenkins Gitee Plugin 1288.v18b_deb_c9069b_ and earlier allow attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs …

Jun 24, 2026
CVE-2026-57290
4.3 MEDIUM

A cross-site request forgery (CSRF) vulnerability in Jenkins Priority Sorter Plugin 936.v2c01c6b_84449 and earlier allows attackers to overwrite the global job priority configuration.

Jun 24, 2026
CVE-2026-57289
4.8 MEDIUM

Jenkins Bitbucket Push and Pull Request Plugin 3.3.8 and earlier unconditionally disables SSL/TLS certificate and hostname validation for connections sending Bearer token authenticated requests to …

Jun 24, 2026
CVE-2026-57287
4.3 MEDIUM

Jenkins Job Configuration History Plugin 1356.ve360da_6c523a_ and earlier does not redact the encrypted values of secrets when displaying historical job and agent configurations, allowing attackers …

Jun 24, 2026
CVE-2026-57286
4.3 MEDIUM

A missing permission check in Jenkins Git Parameter Plugin 462.vdcf3df2ed2ca_ and earlier allows attackers with Item/Read permission to obtain information about the SCM repository used …

Jun 24, 2026
CVE-2026-57285
4.3 MEDIUM

A missing permission check in Jenkins GitHub Branch Source Plugin 1967.1969.v205fd594c821 and earlier allows attackers with Overall/Read permission to obtain the URLs of GitHub Enterprise …

Jun 24, 2026
CVE-2026-57284
4.3 MEDIUM

Jenkins Pipeline: Groovy Plugin 4331.v9d06ed4658ff and earlier does not restrict the types that can be instantiated through the Pipeline Snippet Generator, allowing attackers to instantiate …

Jun 24, 2026
CVE-2026-57283
4.3 MEDIUM

A cross-site request forgery (CSRF) vulnerability in Jenkins Pipeline: Groovy Plugin 4331.v9d06ed4658ff and earlier allows attackers to instantiate types related to job or system configuration …

Jun 24, 2026
CVE-2026-57282
5.0 MEDIUM

Jenkins Git client Plugin 6.6.0 and earlier does not correctly escape the workspace directory name when it is embedded into a generated SSH wrapper script, …

Jun 24, 2026
CVE-2026-56761
4.3 MEDIUM

hono before 4.12.14 contains an html injection vulnerability in jsx server-side rendering that allows attackers to inject unintended html by using malformed attribute names. Attackers …

Jun 24, 2026
CVE-2026-56358
5.4 MEDIUM

n8n before 1.123.25 (1.x) and before 2.11.2 (2.x), with the fix also included in 2.12.0, contains a stored cross-site scripting vulnerability in the Form Trigger …

Jun 24, 2026
CVE-2026-56338
5.3 MEDIUM

Capgo before 12.128.2 contains a denial of service vulnerability in the /auth/v1/otp endpoint that prevents email verification for two-factor authentication due to captcha validation failures. …

Jun 24, 2026
CVE-2026-56337
5.3 MEDIUM

Capgo before 12.128.2 contains an information disclosure vulnerability in the public.exist_app_v2 RPC function that allows unauthenticated attackers to enumerate app_ids by calling POST /rest/v1/rpc/exist_app_v2 with …

Jun 24, 2026
CVE-2026-56310
4.3 MEDIUM

Cap-go before 12.128.2 contains an authorization bypass vulnerability in the GET /organization/members endpoint that allows org-limited API keys to bypass limited_to_orgs restrictions. Attackers with org-limited …

Jun 24, 2026
CVE-2026-56302
6.5 MEDIUM

Capgo before 12.128.2 contains an unsecured images bucket lacking any row level security controls, allowing unauthenticated attackers to read, insert, and delete stored app icons. …

Jun 24, 2026
CVE-2026-56272
4.1 MEDIUM

Flowise before 3.0.13 uses bcrypt with default salt rounds of 5, providing only 32 iterations instead of the OWASP-recommended minimum of 10 rounds. Attackers can …

Jun 24, 2026
CVE-2026-56269
4.6 MEDIUM

Flowise before 3.1.0 (npm package flowise, versions 3.0.13 and earlier) uses a weak hardcoded default value 'Secre$t' for the TOKEN_HASH_SECRET environment variable in packages/server/src/enterprise/utils/tempTokenUtils.ts when …

Jun 24, 2026
CVE-2026-56262
6.5 MEDIUM

Crawl4AI before 0.8.7 contains an authentication bypass vulnerability in the monitor router endpoints that allows unauthenticated attackers to access destructive operations. Remote attackers can invoke …

Jun 24, 2026
CVE-2025-71332
6.5 MEDIUM

Flowise through 2.2.7 contains a SQL injection vulnerability in the importChatflows API. Due to insufficient validation of the chatflow.id value, an authenticated user can supply …

Jun 24, 2026
CVE-2026-11968
5.5 MEDIUM

Argument Injection in TortoiseGitBlame via Malicious Git History Filenames Leads to Arbitrary File Write in TortoiseGit

Jun 24, 2026
CVE-2026-9724
4.3 MEDIUM

The MotorDesk plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.2. This is due to missing or …

Jun 24, 2026
CVE-2026-9721
4.3 MEDIUM

The Book a Room Event Calendar plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.9. This is …

Jun 24, 2026
CVE-2026-9620
6.4 MEDIUM

The WP Latest Posts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via crafted image src attributes in post content in versions up to, …

Jun 24, 2026
CVE-2026-9619
4.3 MEDIUM

The Reviews and Rating – Docplanner plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.1.4. This is due …

Jun 24, 2026
CVE-2026-9616
4.3 MEDIUM

The Generate Security.txt plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.0.12. This is due to the plugin …

Jun 24, 2026
CVE-2026-9612
5.3 MEDIUM

The WhatsOrder – Instant Checkout for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.0.1 via …

Jun 24, 2026
CVE-2026-9184
4.3 MEDIUM

The 24liveblog - live blog tool plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the update_lb24_token() …

Jun 24, 2026
CVE-2026-9183
4.3 MEDIUM

The 24liveblog - live blog tool plugin for WordPress is vulnerable to Exposure of Sensitive Information in versions up to, and including, 2.2. This is …

Jun 24, 2026
CVE-2026-9175
5.3 MEDIUM

The Devs Accounting – Simple Accounting and Invoicing Solution plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.2.0. …

Jun 24, 2026
CVE-2026-9172
5.3 MEDIUM

The Devs Accounting – Simple Accounting and Invoicing Solution plugin for WordPress is vulnerable to unauthorized modification/deletion of data due to a missing capability check …

Jun 24, 2026
CVE-2026-8905
6.1 MEDIUM

The Osiris Signature Banner plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.5. This is due to …

Jun 24, 2026
CVE-2026-8896
6.4 MEDIUM

The MIR blocks and shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title' attribute (and other attributes such as 'ready_animation_text') of …

Jun 24, 2026
CVE-2026-8865
6.4 MEDIUM

The Avalon23 Products Filter for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'avalon23_qr' shortcode in all versions up to, and …

Jun 24, 2026
CVE-2026-8690
5.3 MEDIUM

The RentMy Real-Time Rental Management Plugin plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.0.4.1. This is due …

Jun 24, 2026
CVE-2026-8688
4.3 MEDIUM

The Advance Nav Menu Manager plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.3. This is due to …

Jun 24, 2026
CVE-2026-8628
6.1 MEDIUM

The EntreDroppers plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via PHP_SELF Parameter in all versions up to, and including, 1.1.2 due to insufficient …

Jun 24, 2026
CVE-2026-8622
6.1 MEDIUM

The Image Sizes on Demand plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via PHP_SELF Server Variable in all versions up to, and including, …

Jun 24, 2026
CVE-2026-8617
5.3 MEDIUM

The SearchPlus plugin for WordPress is vulnerable to unauthorized modification and deletion of data in versions up to, and including, 1.7.1. This is due to …

Jun 24, 2026
CVE-2026-8614
4.3 MEDIUM

The Assistio plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check and missing nonce verification on the assistio_plugin_delete_assistio_settings() …

Jun 24, 2026
CVE-2026-7617
5.3 MEDIUM

The Secufor_OAuth plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 1.0.7. This is due to the plugin not …

Jun 24, 2026
CVE-2026-6292
4.3 MEDIUM

The MP Customize Login Page plugin for WordPress is vulnerable to Cross-Site Request Forgery (CSRF) in all versions up to and including 1.0. This is …

Jun 24, 2026
CVE-2026-12094
5.3 MEDIUM

The Advanced Contact Form 7 - Compact DB plugin for WordPress is vulnerable to unauthorized deletion of data due to a missing capability check on …

Jun 24, 2026
CVE-2026-11997
4.3 MEDIUM

The Bulk SEO Image plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to and including 1.1. This is due to missing …

Jun 24, 2026
CVE-2026-11370
6.4 MEDIUM

The WP Meta SEO plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4.5.18 via the 'new_link' parameter. …

Jun 24, 2026
CVE-2026-10552
4.3 MEDIUM

The Blue Captcha plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to and including 2.0.1. This is due to missing or …

Jun 24, 2026
CVE-2026-10531
5.4 MEDIUM

The AI Share & Summarize WordPress plugin before 2.0.4 does not sanitise and escape some of its shortcode attributes before outputting them in a page, …

Jun 24, 2026
CVE-2026-50267
4.7 MEDIUM

Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applications. In Steeltoe.Configuration.Abstractions 4.0.0 through 4.1.0, when MySQL …

Jun 17, 2026
CVE-2026-50202
5.9 MEDIUM

Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applications. In Steeltoe.Security.Authentication.CloudFoundryBase prior to version 3.4.0, Steeltoe.Security.Authentication.JwtBearer …

Jun 17, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.