Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2026-57324

Unauthenticated Broken Access Control in GIFT4U <= 1.0.10 versions.

PUBLISHED
Vendor
VillaTheme
Product
GIFT4U
Provider severity
MEDIUM
Conflicts
0

CVE-2026-57323

Unauthenticated Broken Access Control in Flash & HTML5 Video <= 2.11.0 versions.

PUBLISHED
Vendor
bPlugins
Product
Flash & HTML5 Video
Provider severity
MEDIUM
Conflicts
0

CVE-2026-57322

Unauthenticated Cross Site Scripting (XSS) in weMail <= 2.1.2 versions.

PUBLISHED
Vendor
weDevs
Product
weMail
Provider severity
HIGH
Conflicts
0

CVE-2026-57321

Contributor Arbitrary File Deletion in H5P <= 1.17.7 versions.

PUBLISHED
Vendor
icc0rz
Product
H5P
Provider severity
HIGH
Conflicts
0

CVE-2026-57320

Unauthenticated Cross Site Scripting (XSS) in BEAR <= 1.1.8 versions.

PUBLISHED
Vendor
RealMag777
Product
BEAR
Provider severity
HIGH
Conflicts
0

CVE-2026-5732

A flaw was found in Firefox and Thunderbird. The Mozilla Foundation's Security Advisory describes the following issue: Incorrect boundary conditions, integer overflow in the Graphics: Text component

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Mozilla, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Mozilla
Product
Red Hat Enterprise Linux 10, Red Hat Enterprise Linux AppStream EUS (v.9.6), Red Hat Enterprise Linux AppStream TUS (v.8.6), Red Hat Enterprise Linux AppStream AUS (v. 8.2), Red Hat Enterprise Linux AppStream EUS EXTENSION (v.8.4), Red Hat Enterprise Linux AppStream (v. 9), Red Hat Enterprise Linux Server (v. 7 ELS), Red Hat Enterprise Linux AppStream EUS (v. 10.0), Red Hat Enterprise Linux AppStream AUS (v.8.6), Red Hat Enterprise Linux AppStream (v. 8), Red Hat Enterprise Linux 7, Red Hat Enterprise Linux AppStream AUS (v.8.4), Firefox, Red Hat Enterprise Linux AppStream E4S (v.8.6), Red Hat Enterprise Linux AppStream E4S (v.9.0), Red Hat Enterprise Linux AppStream TUS (v.8.8), Red Hat Enterprise Linux 6, Red Hat Enterprise Linux AppStream E4S (v.9.2), Red Hat Enterprise Linux AppStream (v. 10), Red Hat Enterprise Linux AppStream E4S (v.8.8), Red Hat Enterprise Linux AppStream EUS (v.9.4), Thunderbird
Provider severity
HIGH
Conflicts
2

CVE-2026-57319

Unauthenticated Cross Site Scripting (XSS) in FOX <= 1.4.8 versions.

PUBLISHED
Vendor
RealMag777
Product
FOX
Provider severity
HIGH
Conflicts
0

CVE-2026-57318

Subscriber Sensitive Data Exposure in Site Reviews <= 8.0.11 versions.

PUBLISHED
Vendor
Gemini Labs
Product
Site Reviews
Provider severity
MEDIUM
Conflicts
0

CVE-2026-57317

Unauthenticated Cross Site Scripting (XSS) in Simply Schedule Appointments <= 1.6.12.2 versions.

PUBLISHED
Vendor
NSquared
Product
Simply Schedule Appointments
Provider severity
HIGH
Conflicts
0

CVE-2026-57316

Subscriber Sensitive Data Exposure in GetGenie <= 4.4.2 versions.

PUBLISHED
Vendor
Roxnor
Product
GetGenie
Provider severity
MEDIUM
Conflicts
0

CVE-2026-57315

Contributor Remote Code Execution (RCE) in Blocksy Companion Pro <= 2.1.45 versions.

PUBLISHED
Vendor
Creative Themes
Product
Blocksy Companion Pro
Provider severity
HIGH
Conflicts
0

CVE-2026-57314

Unauthenticated Cross Site Scripting (XSS) in SureCart <= 4.3.2 versions.

PUBLISHED
Vendor
SureCart
Product
SureCart
Provider severity
HIGH
Conflicts
0

CVE-2026-57313

Subscriber Cross Site Scripting (XSS) in SureCart <= 4.2.2 versions.

PUBLISHED
Vendor
SureCart
Product
SureCart
Provider severity
MEDIUM
Conflicts
0

CVE-2026-57312

Unauthenticated Cross Site Scripting (XSS) in Everest Forms <= 3.4.8 versions.

PUBLISHED
Vendor
wpeverest
Product
Everest Forms
Provider severity
HIGH
Conflicts
0

CVE-2026-57311

Windu CMS does not validate types of uploaded files. An authenticated attacker can upload arbitrary files, including PHP. This can lead to Remote Code Execution. Because vendor contact attempts were unsuccessful, the vulnerability has only been confirmed in version 4.1 but may also affect other versions.

PUBLISHED
Vendor
JCD
Product
Windu CMS
Provider severity
MEDIUM
Conflicts
0

CVE-2026-57310

Windu CMS uses hashing algorithm based on MD5 and SHA1 with static salt to store user passwords. This allows an attacker who obtain password hash to decode user credentials. Because vendor contact attempts were unsuccessful, the vulnerability has only been confirmed in version 4.1 but may also affect other versions.

PUBLISHED
Vendor
JCD
Product
Windu CMS
Provider severity
MEDIUM
Conflicts
0

CVE-2026-5731

Memory safety bugs present in Firefox ESR 115.34.0, Firefox ESR 140.9.0, Thunderbird ESR 140.9.0, Firefox 149.0.1 and Thunderbird 149.0.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 149.0.2, Firefox ESR 115.34.1, Firefox ESR 140.9.1, Thunderbird 149.0.2, and Thunderbird 140.9.1.

PUBLISHED
Vendor
Mozilla, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Mozilla, Red Hat, Red Hat, Red Hat
Product
Firefox, Red Hat Enterprise Linux 8.8 Telecommunications Update Service, Red Hat Enterprise Linux 8.6 Telecommunications Update Service, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support, Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions, Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 9.6 Extended Update Support, Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions, Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support, Red Hat Enterprise Linux 9.4 Extended Update Support, Red Hat Enterprise Linux 8.2 Advanced Update Support, Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support, Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions, Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support, Red Hat Enterprise Linux 10.0 Extended Update Support, Red Hat Enterprise Linux 9.4 Extended Update Support, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 7 Extended Lifecycle Support, Red Hat Enterprise Linux 8.6 Telecommunications Update Service, Red Hat Enterprise Linux 8.8 Telecommunications Update Service, Red Hat Enterprise Linux 10.0 Extended Update Support, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions, Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions, Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions, Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On, Red Hat Enterprise Linux 9.6 Extended Update Support, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 10, Thunderbird, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On, Red Hat Enterprise Linux 6
Provider severity
CRITICAL, HIGH
Conflicts
3

CVE-2026-57309

A Blind SQL injection vulnerability has been identified in Windu CMS. A remote unauthenticated attacker is able to inject SQL syntax into URL path in HTTP header resulting in Blind SQL Injection. Because vendor contact attempts were unsuccessful, the vulnerability has only been confirmed in version 4.1 but may also affect other versions.

PUBLISHED
Vendor
JCD
Product
Windu CMS
Provider severity
CRITICAL
Conflicts
0

CVE-2026-57308

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Syncope. An administrator with adequate entitlements can achieve execution of arbitrary SQL via stacked queries, leveraging unsanitized sort parameters. This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 Through 4.0.6, from 4.1.0-M0 through 4.1.1. Users are recommended to upgrade to version 4.0.7 / 4.1.2, which fix this issue.

PUBLISHED
Vendor
Apache Software Foundation
Product
Apache Syncope
Provider severity
CRITICAL
Conflicts
0

CVE-2026-57307

A missing permission check in Jenkins Zowe zDevOps Plugin 1.1.3.50.ve350c9b_450b_1 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.

PUBLISHED
Vendor
Jenkins Project
Product
Jenkins Zowe zDevOps Plugin
Provider severity
MEDIUM
Conflicts
0

CVE-2026-57306

A cross-site request forgery (CSRF) vulnerability in Jenkins Zowe zDevOps Plugin 1.1.3.50.ve350c9b_450b_1 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.

PUBLISHED
Vendor
Jenkins Project
Product
Jenkins Zowe zDevOps Plugin
Provider severity
MEDIUM
Conflicts
0

CVE-2026-57305

A cross-site request forgery (CSRF) vulnerability in Jenkins Assembla Plugin 1.4 and earlier allows attackers to connect to an attacker-specified URL using an attacker-specified username and password.

PUBLISHED
Vendor
Jenkins Project
Product
Jenkins Assembla Plugin
Provider severity
MEDIUM
Conflicts
0

CVE-2026-57304

A missing permission check in Jenkins Assembla Plugin 1.4 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using an attacker-specified username and password.

PUBLISHED
Vendor
Jenkins Project
Product
Jenkins Assembla Plugin
Provider severity
MEDIUM
Conflicts
0

CVE-2026-57303

Jenkins Assembla Plugin 1.4 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks, allowing attackers able to control the responses of the configured Assembla server to extract secrets from the Jenkins controller or perform server-side request forgery.

PUBLISHED
Vendor
Jenkins Project
Product
Jenkins Assembla Plugin
Provider severity
HIGH
Conflicts
0

CVE-2026-57302

Jenkins FitNesse Plugin 1.36 and earlier stores passwords unencrypted in job config.xml files on the Jenkins controller, where they can be viewed by users with Extended Read permission or access to the Jenkins controller file system.

PUBLISHED
Vendor
Jenkins Project
Product
Jenkins FitNesse Plugin
Provider severity
MEDIUM
Conflicts
0

CVE-2026-57301

Jenkins OWASP ZAP Plugin 1.0.7 and earlier performs build operations on the Jenkins controller rather than the assigned agent, allowing attackers with Item/Configure permission to execute arbitrary code on the Jenkins controller.

PUBLISHED
Vendor
Jenkins Project
Product
Jenkins OWASP ZAP Plugin
Provider severity
HIGH
Conflicts
0

CVE-2026-57300

A missing permission check in Jenkins MCP Server Plugin 0.177.v629fdb_2557fe and earlier allows attackers with Item/Read permission to read the Pipeline replay scripts of jobs they can access.

PUBLISHED
Vendor
Jenkins Project
Product
Jenkins MCP Server Plugin
Provider severity
MEDIUM
Conflicts
0

CVE-2026-5730

Authorization bypass through User-Controlled key vulnerability in Idvlabs Software and Consulting Services Inc. Ontime allows Exploitation of Trusted Identifiers. This issue affects Ontime: through 04052026.

PUBLISHED
Vendor
Idvlabs Software and Consulting Services Inc.
Product
Ontime
Provider severity
HIGH
Conflicts
0

CVE-2026-57299

Missing permission checks in Jenkins Contrast Continuous Application Security Plugin 3.11 and earlier allow attackers with Overall/Read permission to enumerate the names of configured Contrast metadata.

PUBLISHED
Vendor
Jenkins Project
Product
Jenkins Contrast Continuous Application Security Plugin
Provider severity
MEDIUM
Conflicts
0

CVE-2026-57298

A cross-site request forgery (CSRF) vulnerability in Jenkins Contrast Continuous Application Security Plugin 3.11 and earlier allows attackers to have Jenkins connect to an attacker-specified URL using an attacker-specified username, API key, and service key.

PUBLISHED
Vendor
Jenkins Project
Product
Jenkins Contrast Continuous Application Security Plugin
Provider severity
MEDIUM
Conflicts
0

CVE-2026-57297

A missing permission check in Jenkins Contrast Continuous Application Security Plugin 3.11 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using an attacker-specified username, API key, and service key.

PUBLISHED
Vendor
Jenkins Project
Product
Jenkins Contrast Continuous Application Security Plugin
Provider severity
MEDIUM
Conflicts
0

CVE-2026-57296

Jenkins External Workspace Manager Plugin 1.3.2 and earlier does not reject path traversal sequences in the custom workspace path provided to the exwsAllocate Pipeline step, allowing attackers with Item/Configure permission to read arbitrary files on the Jenkins controller file system, which can lead to remote code execution.

PUBLISHED
Vendor
Jenkins Project
Product
Jenkins External Workspace Manager Plugin
Provider severity
HIGH
Conflicts
0

CVE-2026-57295

A cross-site request forgery (CSRF) vulnerability in Jenkins EC2 Fleet Plugin 4.2.3.539.v8fedff2a_81c3 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing AWS credentials stored in Jenkins.

PUBLISHED
Vendor
Jenkins Project
Product
Jenkins EC2 Fleet Plugin
Provider severity
MEDIUM
Conflicts
0

CVE-2026-57294

A missing permission check in Jenkins EC2 Fleet Plugin 4.2.3.539.v8fedff2a_81c3 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing AWS credentials stored in Jenkins.

PUBLISHED
Vendor
Jenkins Project
Product
Jenkins EC2 Fleet Plugin
Provider severity
MEDIUM
Conflicts
0

CVE-2026-57293

An incorrect permission check in Jenkins Gitee Plugin 1288.v18b_deb_c9069b_ and earlier allows attackers with global Item/Configure permission (while lacking Item/Configure permission on any particular job) to enumerate credentials IDs of credentials stored in Jenkins.

PUBLISHED
Vendor
Jenkins Project
Product
Jenkins Gitee Plugin
Provider severity
MEDIUM
Conflicts
0

CVE-2026-57292

A cross-site request forgery (CSRF) vulnerability in Jenkins Gitee Plugin 1288.v18b_deb_c9069b_ and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method.

PUBLISHED
Vendor
Jenkins Project
Product
Jenkins Gitee Plugin
Provider severity
MEDIUM
Conflicts
0

CVE-2026-57291

Missing permission checks in Jenkins Gitee Plugin 1288.v18b_deb_c9069b_ and earlier allow attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method.

PUBLISHED
Vendor
Jenkins Project
Product
Jenkins Gitee Plugin
Provider severity
MEDIUM
Conflicts
0

CVE-2026-57290

A cross-site request forgery (CSRF) vulnerability in Jenkins Priority Sorter Plugin 936.v2c01c6b_84449 and earlier allows attackers to overwrite the global job priority configuration.

PUBLISHED
Vendor
Jenkins Project
Product
Jenkins Priority Sorter Plugin
Provider severity
MEDIUM
Conflicts
0

CVE-2026-57289

Jenkins Bitbucket Push and Pull Request Plugin 3.3.8 and earlier unconditionally disables SSL/TLS certificate and hostname validation for connections sending Bearer token authenticated requests to the configured Bitbucket Server endpoint, allowing attackers able to intercept network traffic to capture the token.

PUBLISHED
Vendor
Jenkins Project
Product
Jenkins Bitbucket Push and Pull Request Plugin
Provider severity
MEDIUM
Conflicts
0

CVE-2026-57288

Jenkins Active Directory Plugin 2.41.1 and earlier does not escape the user name before building the LDAP search filter in the Windows native (ADSI) authentication path, allowing unauthenticated attackers to inject LDAP wildcard characters to enumerate directory entries and to authenticate as a matching user whose password they know without knowing their exact user name.

PUBLISHED
Vendor
Jenkins Project
Product
Jenkins Active Directory Plugin
Provider severity
LOW
Conflicts
0

CVE-2026-57287

Jenkins Job Configuration History Plugin 1356.ve360da_6c523a_ and earlier does not redact the encrypted values of secrets when displaying historical job and agent configurations, allowing attackers with Extended Read permission to view encrypted secret values that would otherwise be redacted.

PUBLISHED
Vendor
Jenkins Project
Product
Jenkins Job Configuration History Plugin
Provider severity
MEDIUM
Conflicts
0

CVE-2026-57286

A missing permission check in Jenkins Git Parameter Plugin 462.vdcf3df2ed2ca_ and earlier allows attackers with Item/Read permission to obtain information about the SCM repository used by a job, such as branch names, tag names, and revision metadata.

PUBLISHED
Vendor
Jenkins Project
Product
Jenkins Git Parameter Plugin
Provider severity
MEDIUM
Conflicts
0

CVE-2026-57285

A missing permission check in Jenkins GitHub Branch Source Plugin 1967.1969.v205fd594c821 and earlier allows attackers with Overall/Read permission to obtain the URLs of GitHub Enterprise servers configured in the global plugin configuration.

PUBLISHED
Vendor
Jenkins Project
Product
Jenkins GitHub Branch Source Plugin
Provider severity
MEDIUM
Conflicts
0

CVE-2026-57284

Jenkins Pipeline: Groovy Plugin 4331.v9d06ed4658ff and earlier does not restrict the types that can be instantiated through the Pipeline Snippet Generator, allowing attackers to instantiate types related to job or system configuration other than Pipeline steps.

PUBLISHED
Vendor
Jenkins Project
Product
Jenkins Pipeline: Groovy Plugin
Provider severity
MEDIUM
Conflicts
0

CVE-2026-57283

A cross-site request forgery (CSRF) vulnerability in Jenkins Pipeline: Groovy Plugin 4331.v9d06ed4658ff and earlier allows attackers to instantiate types related to job or system configuration other than Pipeline steps through the Pipeline Snippet Generator.

PUBLISHED
Vendor
Jenkins Project
Product
Jenkins Pipeline: Groovy Plugin
Provider severity
MEDIUM
Conflicts
0

CVE-2026-57282

Jenkins Git client Plugin 6.6.0 and earlier does not correctly escape the workspace directory name when it is embedded into a generated SSH wrapper script, allowing attackers able to control the name of a build's working directory to execute arbitrary operating system commands on the agent.

PUBLISHED
Vendor
Jenkins Project
Product
Jenkins Git client Plugin
Provider severity
MEDIUM
Conflicts
0

CVE-2026-57281

A flaw was found in the Jenkins Script Security Plugin. Attackers with the ability to run sandboxed Groovy scripts can exploit this vulnerability to execute arbitrary code outside the sandbox environment. This is due to the plugin's failure to reject Groovy Abstract Syntax Tree (AST) transformation annotations that include an extensions member, allowing unauthorized script execution if a suitable script exists on the classpath.

PUBLISHED
Vendor
Red Hat, Jenkins Project, Red Hat, Red Hat, Red Hat
Product
OpenShift Developer Tools and Services, Jenkins Script Security Plugin, OpenShift Developer Tools and Services, OpenShift Developer Tools and Services, OpenShift Developer Tools and Services
Provider severity
HIGH
Conflicts
3

CVE-2026-57280

Jenkins Script Security Plugin 1402.v94c9ce464861 and earlier does not intercept the implicit type casts applied to the elements of typed for-each loops in sandboxed Groovy scripts, allowing attackers able to provide such scripts to invoke arbitrary constructors and bypass the sandbox protection.

PUBLISHED
Vendor
Jenkins Project
Product
Jenkins Script Security Plugin
Provider severity
HIGH
Conflicts
0

CVE-2026-57278

GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is an addon that can be installed with various GeoVision software (GV-VMS, GV-Cloud, ...). It creates a websocket server that expands the capabilities of the various web-interfaces provided by the GeoVision software and may be necessary for them to function properly. The Websocket server can accept various commands coming from localhost. One of them, `connectionInfo` is meant to provide the necessa

PUBLISHED
Vendor
GeoVision Inc.
Product
GeoWebPlayer
Provider severity
HIGH
Conflicts
0

CVE-2026-57277

GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is an addon that can be installed with various GeoVision software (GV-VMS, GV-Cloud, ...). It creates a websocket server that expands the capabilities of the various web-interfaces provided by the GeoVision software and may be necessary for them to function properly. The Websocket server can accept various commands coming from localhost. One of them, `connectionInfo` is meant to provide the necessa

PUBLISHED
Vendor
GeoVision Inc.
Product
GeoWebPlayer
Provider severity
HIGH
Conflicts
0